Unable to check in certificate with Extended Validation fields for an AS2 partner in Sterling B2B Integrator
Attempting to check in a certificate with Extended Validation fields into the Trusted certificate session throws the following error in the UI:
We tried to process this file as DER encoded object. DER decoding failed with java.security.cert.CertificateException: Error parsing DER data com.trustpoint.asn.AsnException: Cannot find a class that corresponds to Oid 22.214.171.124.4.1.3126.96.36.199.1; please see oid.map for details.
Changing the format of the certificate results in the same error:
We tried PKCS7. PKCS7 decoding failed with java.security.cert.CertificateException: Error parsing PKCS7 SignedData com.trustpoint.asn.AsnException: Cannot find a class that corresponds to Oid 188.8.131.52.4.1.3184.108.40.206.1; please see oid.map for details
Sterling B2B Integrator does not yet support Extended Validation. The fields in the certificate causing a problem for SI were as follows:
220.127.116.11.4.1.318.104.22.168.1 = Shanghai
22.214.171.124.4.1.3126.96.36.199.2 = Shanghai
188.8.131.52.4.1.3184.108.40.206.3 = CN
These OIDs refer to the “IncorporationLocality”. “IncorporationStateOrProvince”, and “IncorporationCountry” fields in the certificate.
Excerpts from EV Cert Guideline:
9.2.5 Subject Jurisdiction of Incorporation or Registration Field
Locality (if required):
subject: jurisdictionOfIncorporationLocalityName (OID: 220.127.116.11.4.1.318.104.22.168.1)
ASN.1 - X520 LocalityName as specified in RFC 5280
State or province (if required):
subject: jurisdictionOfIncorporationStateOrProvinceName (OID: 22.214.171.124.4.1.3126.96.36.199.2)
ASN.1 - X520 StateOrProvinceName as specified in RFC 5280
subject: jurisdictionOfIncorporationCountryName (OID: 188.8.131.52.4.1.3184.108.40.206.3)
ASN.1 – X520 countryName as specified in RFC 5280
Resolving The Problem
Once the partner recreated the certificate without extended validation fields, the certificate could be checked in without issue.
Was this topic helpful?
16 June 2018