<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Secure Authentication中的主题 SE05x certificate sign request with Sectigo</title>
    <link>https://community.nxp.com/t5/Secure-Authentication/SE05x-certificate-sign-request-with-Sectigo/m-p/1580879#M1110</link>
    <description>&lt;P&gt;I'm trying to generate a valid CSR with the SE05x, but the CSR seems to have an invalid signature according to the online CRC checker&amp;nbsp;&lt;A href="https://redkestrel.co.uk/products/decoder/" target="_blank"&gt;https://redkestrel.co.uk/products/decoder/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's what I do:&amp;nbsp;&lt;/P&gt;&lt;P&gt;sscli erase 0x1234&lt;BR /&gt;ssscli generate ecc 0x1234 NIST_P256&lt;BR /&gt;ssscli refpem ecc pair 0x1234 aci200.ref.key --format PEM&lt;BR /&gt;openssl req -new -key aci200.ref.key -out &lt;STRONG&gt;aci200.csr&lt;/STRONG&gt; -config aci200.cnf&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;This is the result of the CSR check:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wyss11_0-1673444164369.png" style="width: 359px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/206908iD8311FB2069056CB/image-dimensions/359x135?v=v2" width="359" height="135" role="button" title="wyss11_0-1673444164369.png" alt="wyss11_0-1673444164369.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What could be the problem with my CSR file?&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Could it be because I generated the CSR with the private key reference file?&lt;/LI&gt;&lt;LI&gt;The CSR file is attached (rename it to aci200.csr)&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks, Stefan&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jan 2023 13:42:59 GMT</pubDate>
    <dc:creator>wyss-11</dc:creator>
    <dc:date>2023-01-11T13:42:59Z</dc:date>
    <item>
      <title>SE05x certificate sign request with Sectigo</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/SE05x-certificate-sign-request-with-Sectigo/m-p/1580879#M1110</link>
      <description>&lt;P&gt;I'm trying to generate a valid CSR with the SE05x, but the CSR seems to have an invalid signature according to the online CRC checker&amp;nbsp;&lt;A href="https://redkestrel.co.uk/products/decoder/" target="_blank"&gt;https://redkestrel.co.uk/products/decoder/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's what I do:&amp;nbsp;&lt;/P&gt;&lt;P&gt;sscli erase 0x1234&lt;BR /&gt;ssscli generate ecc 0x1234 NIST_P256&lt;BR /&gt;ssscli refpem ecc pair 0x1234 aci200.ref.key --format PEM&lt;BR /&gt;openssl req -new -key aci200.ref.key -out &lt;STRONG&gt;aci200.csr&lt;/STRONG&gt; -config aci200.cnf&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;This is the result of the CSR check:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wyss11_0-1673444164369.png" style="width: 359px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/206908iD8311FB2069056CB/image-dimensions/359x135?v=v2" width="359" height="135" role="button" title="wyss11_0-1673444164369.png" alt="wyss11_0-1673444164369.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What could be the problem with my CSR file?&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Could it be because I generated the CSR with the private key reference file?&lt;/LI&gt;&lt;LI&gt;The CSR file is attached (rename it to aci200.csr)&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks, Stefan&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2023 13:42:59 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/SE05x-certificate-sign-request-with-Sectigo/m-p/1580879#M1110</guid>
      <dc:creator>wyss-11</dc:creator>
      <dc:date>2023-01-11T13:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: SE05x certificate sign request with Sectigo</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/SE05x-certificate-sign-request-with-Sectigo/m-p/1581540#M1117</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/194626"&gt;@wyss-11&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you enabled the openssl engine? This engine is used to decode the key&amp;nbsp;&lt;SPAN&gt;references &lt;/SPAN&gt; and&amp;nbsp;&lt;SPAN&gt;invokes the SSS API with correct Key references for a cryptographic operation.&amp;nbsp; Please kindly refer to the doc of "simw-top/doc/sss/plugin/openssl/scripts/readme.html" for more details.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope that helps,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day,&lt;BR /&gt;Kan&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;BR /&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt;Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 08:19:44 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/SE05x-certificate-sign-request-with-Sectigo/m-p/1581540#M1117</guid>
      <dc:creator>Kan_Li</dc:creator>
      <dc:date>2023-01-12T08:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: SE05x certificate sign request with Sectigo</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/SE05x-certificate-sign-request-with-Sectigo/m-p/1581756#M1119</link>
      <description>&lt;P&gt;Thanks for the DOC pointer.&amp;nbsp;Yes, I can successfully run&amp;nbsp;the example scripts from the script folder. My OPENSSL_CONF is according to the readme.html.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So there seems to be another problem with the generated certificate in the example above?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you try to recreate my problem with your SE05x setup by entering my above listed commands and checking the resulting CSR with the online-tool link that I have provided?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 13:42:47 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/SE05x-certificate-sign-request-with-Sectigo/m-p/1581756#M1119</guid>
      <dc:creator>wyss-11</dc:creator>
      <dc:date>2023-01-12T13:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: SE05x certificate sign request with Sectigo</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/SE05x-certificate-sign-request-with-Sectigo/m-p/1581798#M1120</link>
      <description>&lt;P&gt;Well, out of nowhere, the invalid signature error disappeared when I re-generated the aci200.csr file. I don't know the reason for that, but my new aci200.csr is now accepted by the online CSR verification tool.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 14:45:21 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/SE05x-certificate-sign-request-with-Sectigo/m-p/1581798#M1120</guid>
      <dc:creator>wyss-11</dc:creator>
      <dc:date>2023-01-12T14:45:21Z</dc:date>
    </item>
  </channel>
</rss>

