<div dir="ltr">Hi, <div><br></div><div>I have done that and reran provisioner.sh with the same result.</div><div><br></div><div>As I understand, I am copying the files _PrivacyCA.cer_ and _TrustStore.jks_ to /usr/share/oat-client, </div>
<div>while the java error complains about the missing file _aik.cer_, as follows:</div><div><br></div><div><div><b>java.io.FileNotFoundException: /usr/share/oat-client/aik.cer</b> (No such file or directory)</div><div><span class="" style="white-space:pre">        </span>at java.io.FileInputStream.open(Native Method)</div>
<div><span class="" style="white-space:pre">        </span>at java.io.FileInputStream.&lt;init&gt;(FileInputStream.java:146)</div><div><span class="" style="white-space:pre">        </span>at java.io.FileInputStream.&lt;init&gt;(FileInputStream.java:101)</div>
<div><span class="" style="white-space:pre">        </span>at gov.niarl.his.privacyca.TpmUtils.certFromFile(TpmUtils.java:612)</div><div><span class="" style="white-space:pre">        </span>at gov.niarl.his.privacyca.HisRegisterIdentity.main(HisRegisterIdentity.java:99)</div>
</div><div><br></div><div>is the file _aik.cer_ supposed to be generated at some point here?</div><div><br></div><div>Just to clarify, I am using CentOS 6.4, TruSerS and tpm-tools.</div><div><br></div><div>Cheers,</div><div>
/Nicolae.</div><div><br></div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On 15 November 2013 03:23, Wei, Gang <span dir="ltr">&lt;<a href="mailto:gang.wei@intel.com" target="_blank">gang.wei@intel.com</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div lang="ZH-CN" link="blue" vlink="purple"><div><p class="MsoNormal"><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d">So, just as what I suggested in last mail, please copy the files from server to client again and run provisioner.sh:<u></u><u></u></span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d"><u></u> <u></u></span></p><p class="MsoNormal" style="margin-right:0cm;margin-bottom:11.25pt;margin-left:0cm;background:white">
<b><span lang="EN-US" style="font-size:18.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;;color:#333333">1.3.1 copy PrivacyCA.cer and TrustStore.jks from appraiser to client.<u></u><u></u></span></b></p><p class="MsoNormal" style="margin-right:0cm;margin-bottom:11.25pt;margin-left:0cm;line-height:18.75pt;background:white">
<span lang="EN-US" style="font-size:11.5pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;;color:#333333">Copy :/var/lib/oat-appraiser/ClientFiles/PrivacyCA.cer to :/usr/share/oat-client/<u></u><u></u></span></p>
<p class="MsoNormal" style="margin-right:0cm;margin-bottom:11.25pt;margin-left:0cm;line-height:18.75pt;background:white"><span lang="EN-US" style="font-size:11.5pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;;color:#333333">Copy :/var/lib/oat-appraiser/ClientFiles/TrustStore.jks to :/usr/share/oat-client/<u></u><u></u></span></p>
<p class="MsoNormal" style="margin-right:0cm;margin-bottom:11.25pt;margin-left:0cm;line-height:18.75pt;background:white"><b><i><span lang="EN-US" style="font-size:11.5pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;;color:#333333">Notes: please repeat above steps in case you have re-deployed your oat appraiser.</span></i></b><span lang="EN-US" style="font-size:11.5pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;;color:#333333"><u></u><u></u></span></p>
<p class="MsoNormal"><span lang="EN" style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d"><u></u> <u></u></span></p><p class="MsoNormal"><span lang="EN" style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d">Thanks<u></u><u></u></span></p>
<p class="MsoNormal"><span lang="EN" style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d">Jimmy<u></u><u></u></span></p><p class="MsoNormal"><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d"><u></u> <u></u></span></p>
<div style="border:none;border-left:solid blue 1.5pt;padding:0cm 0cm 0cm 4.0pt"><div><div style="border:none;border-top:solid #b5c4df 1.0pt;padding:3.0pt 0cm 0cm 0cm"><p class="MsoNormal"><b><span lang="EN-US" style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span lang="EN-US" style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> Nicolae Paladi [mailto:<a href="mailto:n.paladi@gmail.com" target="_blank">n.paladi@gmail.com</a>] <br>
<b>Sent:</b> Thursday, November 14, 2013 6:30 PM</span></p><div><div class="h5"><br><b>To:</b> Wei, Gang<br><b>Cc:</b> Doron Fediuck; <a href="mailto:users@ovirt.org" target="_blank">users@ovirt.org</a><br><b>Subject:</b> Re: [Users] Trusted Pools and CentOS 6 packages<u></u><u></u></div>
</div><p></p></div></div><div><div class="h5"><p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p><div><p class="MsoNormal"><span lang="EN-US">Hi, <u></u><u></u></span></p><div><p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p>
</div><div><p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p></div><div><p class="MsoNormal"><span lang="EN-US">As far as I see, port 8443 is not occupied and tomcat6 is running:<u></u><u></u></span></p></div>
<div><p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p></div><div><div><p class="MsoNormal"><span lang="EN-US">root@host /usr/share/oat-client/script # netstat -anp | grep 8443<u></u><u></u></span></p></div>
<div><p class="MsoNormal"><span lang="EN-US">root@host /usr/share/oat-client/script # service tomcat6 status<u></u><u></u></span></p></div><div><p class="MsoNormal"><span lang="EN-US">tomcat6 (pid 30950) is running...                          [  OK  ]<u></u><u></u></span></p>
</div></div><div><p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p></div><div><p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p></div><div><p class="MsoNormal"><span lang="EN-US">Also, just in case, I&#39;ve checked if disabling iptables helps, and it doesn&#39;t;<u></u><u></u></span></p>
</div><div><p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p></div><div><p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p></div><div><p class="MsoNormal"><span lang="EN-US">In the error trace, there is a line: <u></u><u></u></span></p>
</div><div><p class="MsoNormal"><b><span lang="EN-US">java.io.FileNotFoundException: /usr/share/oat-client/aik.cer (No such file or directory)</span></b><span lang="EN-US"><u></u><u></u></span></p></div><div><p class="MsoNormal">
<span lang="EN-US"><u></u> <u></u></span></p></div><div><p class="MsoNormal"><span lang="EN-US">and indeed, there is not file aik.cer at /usr/share/oat-client/aik.cer; when is it supposed to<u></u><u></u></span></p></div>
<div><p class="MsoNormal"><span lang="EN-US">be generated?<u></u><u></u></span></p></div><div><p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p></div><div><p class="MsoNormal"><span lang="EN-US">cheers,<u></u><u></u></span></p>
</div><div><p class="MsoNormal"><span lang="EN-US">/Nicolae<u></u><u></u></span></p></div><div><p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p></div></div><div><p class="MsoNormal" style="margin-bottom:12.0pt">
<span lang="EN-US"><u></u> <u></u></span></p><div><p class="MsoNormal"><span lang="EN-US">On 14 November 2013 04:32, Wei, Gang &lt;<a href="mailto:gang.wei@intel.com" target="_blank">gang.wei@intel.com</a>&gt; wrote:<u></u><u></u></span></p>
<p class="MsoNormal"><span lang="EN-US">And you need to copy files from server to client before you try to run<br>provisioner.sh every time you run OAT_configure.sh again.<br><br>Jimmy<u></u><u></u></span></p><div><div><p class="MsoNormal" style="margin-bottom:12.0pt">
<span lang="EN-US"><br><br>&gt; -----Original Message-----<br>&gt; From: Wei, Gang<br>&gt; Sent: Thursday, November 14, 2013 11:26 AM<br>&gt; To: Nicolae Paladi<br>&gt; Cc: Doron Fediuck; <a href="mailto:users@ovirt.org" target="_blank">users@ovirt.org</a>; Wei, Gang<br>
&gt; Subject: RE: [Users] Trusted Pools and CentOS 6 packages<br>&gt;<br>&gt; Can you try netstat -anp | grep 8443? Maybe it is occupied by apache.<br>&gt;<br>&gt; Meanwhile check whether tomcat is up.<br>&gt;<br>&gt; Jimmy<br>
&gt;<br>&gt;<br>&gt; &gt; -----Original Message-----<br>&gt; &gt; From: Nicolae Paladi [mailto:<a href="mailto:n.paladi@gmail.com" target="_blank">n.paladi@gmail.com</a>]<br>&gt; &gt; Sent: Wednesday, November 13, 2013 10:43 PM<br>
&gt; &gt; To: Wei, Gang<br>&gt; &gt; Cc: Doron Fediuck; <a href="mailto:users@ovirt.org" target="_blank">users@ovirt.org</a><br>&gt; &gt; Subject: Re: [Users] Trusted Pools and CentOS 6 packages<br>&gt; &gt;<br>&gt; &gt; Hi,<br>
&gt; &gt;<br>&gt; &gt; I am using port 8443, since no other process -- as far as I know -- is<br>&gt; using it;<br>&gt; &gt;<br>&gt; &gt; below you will find all of the requested configuration files:<br>&gt; &gt;<br>&gt; &gt; Contents of /etc/oat_client/*:<br>
&gt; &gt; log4j.properties: <a href="http://pastebin.com/MQLM68vs" target="_blank">http://pastebin.com/MQLM68vs</a><br>&gt; &gt; OAT.properties: <a href="http://pastebin.com/LwHihxah" target="_blank">http://pastebin.com/LwHihxah</a><br>
&gt; &gt; OATprovisioner.properties: <a href="http://pastebin.com/0x5TShtZ" target="_blank">http://pastebin.com/0x5TShtZ</a><br>&gt; &gt; TPMModule.properties: <a href="http://pastebin.com/hvw9gfRE" target="_blank">http://pastebin.com/hvw9gfRE</a><br>
&gt; &gt;<br>&gt; &gt;<br>&gt; &gt; server.xml: <a href="http://pastebin.com/VZ9Vk6iC" target="_blank">http://pastebin.com/VZ9Vk6iC</a><br>&gt; &gt; OAT_client.sh: <a href="http://pastebin.com/St4yCGcF" target="_blank">http://pastebin.com/St4yCGcF</a><br>
&gt; &gt;<br>&gt; &gt; provisioner.sh: <a href="http://pastebin.com/RedqQt8V" target="_blank">http://pastebin.com/RedqQt8V</a><br>&gt; &gt;<br>&gt; &gt;<br>&gt; &gt; cheers,<br>&gt; &gt; /Nicolae.<br>&gt; &gt;<br>&gt; &gt;<br>
&gt; &gt; On 13 November 2013 14:47, Wei, Gang &lt;<a href="mailto:gang.wei@intel.com" target="_blank">gang.wei@intel.com</a>&gt; wrote:<br>&gt; &gt;<br>&gt; &gt;<br>&gt; &gt;     This time it failed earlier. Looks like the PCA webservice2 was not<br>
&gt; &gt;     listening on 8443 port. Have you replaced the port 8443 with 8442 in<br>&gt; &gt; server<br>&gt; &gt;     side ($TOMCAT_HOME/conf/server.xml) but not change it in client side<br>&gt; &gt;     (/usr/share/oat-client/script/OAT_client.sh)? Or the 8443 port is<br>
&gt; occupied<br>&gt; &gt;     by another app?<br>&gt; &gt;<br>&gt; &gt;     Please copy the content from your current server.xml, OAT_client.sh,<br>&gt; &gt;     provisioner.sh and /etc/oat-client/* into the content of your reply<br>
&gt; for<br>&gt; &gt;     analysis. (don&#39;t attach *.sh as attachments, that will get filtered<br>&gt; by my<br>&gt; &gt;     company&#39;s mailing system).<br>&gt; &gt;<br>&gt; &gt;     Thanks<br>&gt; &gt;     Jimmy<br>
&gt; &gt;<br>&gt; &gt;<br>&gt; &gt;<br>&gt; &gt;     &gt; -----Original Message-----<br>&gt; &gt;     &gt; From: Nicolae Paladi [mailto:<a href="mailto:n.paladi@gmail.com" target="_blank">n.paladi@gmail.com</a>]<br>&gt; &gt;     &gt; Sent: Wednesday, November 13, 2013 7:01 PM<br>
&gt; &gt;     &gt; To: Wei, Gang<br>&gt; &gt;     &gt; Cc: Doron Fediuck; <a href="mailto:users@ovirt.org" target="_blank">users@ovirt.org</a><br>&gt; &gt;     &gt; Subject: Re: [Users] Trusted Pools and CentOS 6 packages<br>
&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; &gt;     &gt; Hi,<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt; thank you for the feedback;<br>&gt; &gt;     &gt; I&#39;ve gone through the steps again, but obtained the exactly same<br>
&gt; &gt; problem:<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt; 1. I removed all of the previously installed packaged related to<br>&gt; OAT.<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt; 2. I followed the tutorial, until this command:<br>
&gt; &gt;     &gt;<br>&gt; &gt;     &gt; bash provisioner.sh<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt; provisioner.sh: line 7: systemctl: command not found<br>&gt; &gt;     &gt; ### ecStorage = NVRAM###<br>&gt; &gt;     &gt; Performing TPM provisioning...FAILED<br>
&gt; &gt;     &gt; javax.xml.ws.WebServiceException: Failed to access the WSDL at:<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; <a href="https://seoul:8443/HisPrivacyCAWebServices2/hisPrivacyCAWebService2Factor" target="_blank">https://seoul:8443/HisPrivacyCAWebServices2/hisPrivacyCAWebService2Factor</a><br>
&gt; &gt;     &gt; yService?wsdl. It failed with:<br>&gt; &gt;     &gt;         Connection refused.<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; com.sun.xml.ws.wsdl.parser.RuntimeWSDLParser.tryWithMex(RuntimeWSDLP<br>
&gt; &gt;     &gt; arser.java:162)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; com.sun.xml.ws.wsdl.parser.RuntimeWSDLParser.parse(RuntimeWSDLParser.j<br>&gt; &gt;     &gt; ava:144)<br>&gt; &gt;     &gt;         at<br>
&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; com.sun.xml.ws.client.WSServiceDelegate.parseWSDL(WSServiceDelegate.jav<br>&gt; &gt;     &gt; a:265)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; com.sun.xml.ws.client.WSServiceDelegate.&lt;init&gt;(WSServiceDelegate.java:228)<br>
&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; com.sun.xml.ws.client.WSServiceDelegate.&lt;init&gt;(WSServiceDelegate.java:176)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>
&gt; com.sun.xml.ws.spi.ProviderImpl.createServiceDelegate(ProviderImpl.jav<br>&gt; &gt; a:104<br>&gt; &gt;     &gt; )<br>&gt; &gt;     &gt;         at javax.xml.ws.Service.&lt;init&gt;(Service.java:77)<br>&gt; &gt;     &gt;         at<br>
&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; gov.niarl.his.webservices.hisprivacycawebservice2.server.HisPrivacyCAWe<br>&gt; &gt; bSer<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; vice2FactoryServiceService.&lt;init&gt;(HisPrivacyCAWebService2FactoryService<br>
&gt; &gt; Servi<br>&gt; &gt;     &gt; ce.java:42)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; gov.niarl.his.webservices.hisPrivacyCAWebService2.client.HisPrivacyCAWe<br>&gt; &gt; bSer<br>&gt; &gt;     &gt;<br>
&gt; &gt;<br>&gt; vices2ClientInvoker.getHisPrivacyCAWebService2(HisPrivacyCAWebServices2Cli<br>&gt; &gt;     &gt; entInvoker.java:32)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>gov.niarl.his.privacyca.HisTpmProvisioner.main(HisTpmProvisioner.java:205)<br>
&gt; &gt;     &gt; Caused by: java.net.ConnectException: Connection refused<br>&gt; &gt;     &gt;         at java.net.PlainSocketImpl.socketConnect(Native Method)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>
&gt; &gt;<br>&gt; java.net.AbstractPlainSocketImpl.doConnect(AbstractPlainSocketImpl.jav<br>&gt; &gt; a:339<br>&gt; &gt;     &gt; )<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; java.net.AbstractPlainSocketImpl.connectToAddress(AbstractPlainSocketI<br>
&gt; &gt; mpl.j<br>&gt; &gt;     &gt; ava:200)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>java.net.AbstractPlainSocketImpl.connect(AbstractPlainSocketImpl.java:182)<br>&gt; &gt;     &gt;         at<br>
&gt; &gt; java.net.SocksSocketImpl.connect(SocksSocketImpl.java:392)<br>&gt; &gt;     &gt;         at java.net.Socket.connect(Socket.java:579)<br>&gt; &gt;     &gt;         at<br>&gt; &gt; sun.security.ssl.SSLSocketImpl.connect(SSLSocketImpl.java:618)<br>
&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt; sun.security.ssl.BaseSSLSocketImpl.connect(BaseSSLSocketImpl.java:160)<br>&gt; &gt;     &gt;         at sun.net.NetworkClient.doConnect(NetworkClient.java:180)<br>
&gt; &gt;     &gt;         at<br>&gt; &gt; sun.net.www.http.HttpClient.openServer(HttpClient.java:432)<br>&gt; &gt;     &gt;         at<br>&gt; &gt; sun.net.www.http.HttpClient.openServer(HttpClient.java:527)<br>&gt; &gt;     &gt;         at<br>
&gt; &gt;     &gt;<br>&gt; sun.net.www.protocol.https.HttpsClient.&lt;init&gt;(HttpsClient.java:275)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt; sun.net.www.protocol.https.HttpsClient.New(HttpsClient.java:371)<br>
&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.getNewHt<br>&gt; &gt;     &gt; tpClient(AbstractDelegateHttpsURLConnection.java:191)<br>
&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; sun.net.www.protocol.http.HttpURLConnection.plainConnect(HttpURLConnec<br>&gt; &gt;     &gt; tion.java:932)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>
&gt; &gt;<br>&gt; sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(A<br>&gt; &gt;     &gt; bstractDelegateHttpsURLConnection.java:177)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>
&gt; sun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpURLConn<br>&gt; &gt;     &gt; ection.java:1300)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; sun.net.www.protocol.https.HttpsURLConnectionImpl.getInputStream(HttpsU<br>
&gt; &gt;     &gt; RLConnectionImpl.java:254)<br>&gt; &gt;     &gt;         at java.net.URL.openStream(URL.java:1037)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; com.sun.xml.ws.wsdl.parser.RuntimeWSDLParser.createReader(RuntimeWSD<br>
&gt; &gt;     &gt; LParser.java:804)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; com.sun.xml.ws.wsdl.parser.RuntimeWSDLParser.resolveWSDL(RuntimeWSDL<br>&gt; &gt;     &gt; Parser.java:262)<br>
&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; com.sun.xml.ws.wsdl.parser.RuntimeWSDLParser.parse(RuntimeWSDLParser.j<br>&gt; &gt;     &gt; ava:129)<br>&gt; &gt;     &gt;         ... 8 more<br>&gt; &gt;     &gt; Failed to initialize the TPM, error 1<br>
&gt; &gt;     &gt; Performing HIS identity provisioning...FAILED<br>&gt; &gt;     &gt; gov.niarl.his.privacyca.TpmModule$TpmModuleException:<br>&gt; &gt;     &gt; TpmModule.getCredential returned nonzero error: 2()<br>&gt; &gt;     &gt;         at<br>
&gt; &gt;     &gt;<br>&gt; gov.niarl.his.privacyca.TpmModule.getCredential(TpmModule.java:594)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt;<br>gov.niarl.his.privacyca.HisIdentityProvisioner.main(HisIdentityProvisioner.j<br>
&gt; &gt;     ava:<br>&gt; &gt;     &gt; 217)<br>&gt; &gt;     &gt; Failed to receive AIC from Privacy CA, error 1<br>&gt; &gt;     &gt; Registering identity with server...FAILED<br>&gt; &gt;     &gt; java.io.FileNotFoundException: /usr/share/oat-client/aik.cer (No<br>
&gt; such file<br>&gt; &gt;     or<br>&gt; &gt;     &gt; directory)<br>&gt; &gt;     &gt;         at java.io.FileInputStream.open(Native Method)<br>&gt; &gt;     &gt;         at<br>&gt; java.io.FileInputStream.&lt;init&gt;(FileInputStream.java:146)<br>
&gt; &gt;     &gt;         at<br>&gt; java.io.FileInputStream.&lt;init&gt;(FileInputStream.java:101)<br>&gt; &gt;     &gt;         at<br>&gt; &gt;     gov.niarl.his.privacyca.TpmUtils.certFromFile(TpmUtils.java:612)<br>&gt; &gt;     &gt;         at<br>
&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; &gt;<br>&gt;<br>gov.niarl.his.privacyca.HisRegisterIdentity.main(HisRegisterIdentity.java:9<br>&gt; &gt; 9<br>&gt; &gt;     )<br>&gt; &gt;     &gt; Failed to register identity with appraiser, error 1<br>
&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; &gt;     &gt; Should I have updated anything else?<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt; cheers,<br>&gt; &gt;     &gt; /Nicolae.<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt;<br>
&gt; &gt;     &gt;<br>&gt; &gt;     &gt; On 1 November 2013 10:14, Wei, Gang &lt;<a href="mailto:gang.wei@intel.com" target="_blank">gang.wei@intel.com</a>&gt; wrote:<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt;       This is indeed an issue caused by the incompatibility<br>
&gt; between<br>&gt; &gt; OAT<br>&gt; &gt;     tpm<br>&gt; &gt;     &gt; access<br>&gt; &gt;     &gt;       code &amp; tpm-tools(tpm_takeownership -z). It has already been<br>&gt; &gt; fixed.<br>&gt; &gt;     &gt; Please<br>
&gt; &gt;     &gt;       follow below wiki and try again.<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; <a href="https://github.com/OpenAttestation/OpenAttestation/wiki/OAT-for-RHEL-" target="_blank">https://github.com/OpenAttestation/OpenAttestation/wiki/OAT-for-RHEL-</a><br>
&gt; &gt;     &gt; Recipe.<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt;       Thanks<br>&gt; &gt;     &gt;       Jimmy<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt;       Nicolae Paladi wrote on 2013-10-28:<br>&gt; &gt;     &gt;<br>
&gt; &gt;     &gt;       &gt; Hi, I&#39;ve followed the recipe<br>&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; (<a href="https://github.com/OpenAttestation/OpenAttestation/wiki/OAT-for-RHEL-Rec" target="_blank">https://github.com/OpenAttestation/OpenAttestation/wiki/OAT-for-RHEL-Rec</a><br>
&gt; &gt;     &gt;<br>&gt; &gt;     &gt;       &gt; i pe) but didn&#39;t get it to run yet; I think a step is<br>&gt; missing --<br>&gt; &gt;     the AIK<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt;       &gt; is not available is /usr/share/oat-client (it was not<br>
&gt; available in<br>&gt; &gt;     &gt;       &gt; /var/lig/oat-appraiser/ClientFiles either); when I try to<br>&gt; run<br>&gt; &gt;     &gt;       &gt; provisioner.sh, I get the following: provisioner.sh: line<br>&gt; 7:<br>
&gt; &gt;     systemctl:<br>&gt; &gt;     &gt;       &gt; command not found ### ecStorage = NVRAM### Performing<br>&gt; &gt; TPM<br>&gt; &gt;     &gt;       &gt; provisioning...710 DONE Successfully initialized TPM<br>&gt; &gt; Performing<br>
&gt; &gt;     HIS<br>&gt; &gt;     &gt;       &gt; identity provisioning...FAILED<br>&gt; &gt; java.util.NoSuchElementException<br>&gt; &gt;     &gt;       &gt;         at<br>&gt; &gt;     &gt; java.util.StringTokenizer.nextToken(StringTokenizer.java:349)<br>
&gt; &gt;     &gt;       &gt;         at<br>&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; gov.niarl.his.privacyca.TpmModule.executeVer2Command(TpmModule.java:21<br>&gt; &gt;     &gt;       &gt; 5)<br>
&gt; &gt;     &gt;       &gt;         at<br>&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; gov.niarl.his.privacyca.TpmModule.collateIdentityRequest(TpmModule.java:29<br>&gt; &gt;     &gt;       &gt; 2)<br>
&gt; &gt;     &gt;       &gt;         at<br>&gt; &gt;     &gt;       &gt;<br>&gt; &gt;<br>&gt; gov.niarl.his.privacyca.HisIdentityProvisioner.main(HisIdentityProvisione<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt;       &gt; r.java: 225) Failed to receive AIC from Privacy CA, error<br>
&gt; 1<br>&gt; &gt;     Registering<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt;       &gt; identity with server...FAILED<br>&gt; java.io.FileNotFoundException:<br>&gt; &gt;     &gt;       &gt; /usr/share/oat-client/aik.cer (No such file or directory)<br>
&gt; &gt;     &gt;       &gt;         at java.io.FileInputStream.open(Native Method)<br>&gt; &gt;     &gt;       &gt;         at<br>&gt; &gt;     java.io.FileInputStream.&lt;init&gt;(FileInputStream.java:137)<br>&gt; &gt;     &gt;       &gt;         at<br>
&gt; &gt; java.io.FileInputStream.&lt;init&gt;(FileInputStream.java:96)<br>&gt; &gt;     &gt;       &gt;         at<br>&gt; &gt;     &gt;<br>&gt; gov.niarl.his.privacyca.TpmUtils.certFromFile(TpmUtils.java:612)<br>&gt; &gt;     &gt;       &gt;         at<br>
&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt;<br>gov.niarl.his.privacyca.HisRegisterIdentity.main(HisRegisterIdentity.java:9<br>&gt; &gt;     &gt; 9<br>&gt; &gt;     &gt;       )<br>&gt; &gt;     &gt;       &gt; Failed to register identity with appraiser, error 1<br>
&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;       &gt; Thanks,<br>&gt; &gt;     &gt;       &gt; /Nicolae<br>&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;       &gt;<br>
&gt; &gt;     &gt;       &gt; On 27 October 2013 22:55, Nicolae Paladi<br>&gt; &gt; &lt;<a href="mailto:n.paladi@gmail.com" target="_blank">n.paladi@gmail.com</a>&gt;<br>&gt; &gt;     wrote:<br>&gt; &gt;     &gt;       &gt;<br>
&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;       &gt;       Awesome, thanks!<br>&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;       &gt;       I&#39;ll try this out in the morning<br>&gt; &gt;     &gt;       &gt;<br>
&gt; &gt;     &gt;       &gt;       /Nicolae<br>&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;       &gt;       On 27 October 2013 17:03, Wei, Gang<br>&gt; &gt; &lt;<a href="mailto:gang.wei@intel.com" target="_blank">gang.wei@intel.com</a>&gt;<br>
&gt; &gt;     &gt; wrote:<br>&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;       &gt;               Please refer to<br>&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;       &gt;<br>
&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; <a href="https://github.com/OpenAttestation/OpenAttestation/wiki/OAT-for-RHEL-" target="_blank">https://github.com/OpenAttestation/OpenAttestation/wiki/OAT-for-RHEL-</a><br>&gt; &gt;     &gt;       &gt; Recipe.<br>
&gt; &gt;     &gt;       &gt;<br>&gt; &gt;     &gt;       &gt;               Jimmy<br>&gt; &gt;     &gt;<br>&gt; &gt;     &gt;<br>&gt; &gt;<br>&gt; &gt;<br>&gt; &gt;<u></u><u></u></span></p></div></div></div><p class="MsoNormal">
<span lang="EN-US"><u></u> <u></u></span></p></div></div></div></div></div></div></blockquote></div><br></div>