Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Private key not found, wrong tag (solved)

8,292 views
Skip to first unread message

Thomas Guettler

unread,
Apr 8, 2011, 11:29:06 AM4/8/11
to
Hi,

this is solved, I post it to help others find a solution:

> [Fri Apr 08 12:48:30 2011] [info] Loading certificate & private key of SSL-aware server
> [Fri Apr 08 12:48:30 2011] [error] Init: Private key not found
> [Fri Apr 08 12:48:30 2011] [error] SSL Library Error: 218529960 error:0D0680A8:asn1 encoding routines:ASN1_CHECK_TLEN:wrong tag
> [Fri Apr 08 12:48:30 2011] [error] SSL Library Error: 218640442 error:0D08303A:asn1 encoding routines:ASN1_TEMPLATE_NOEXP_D2I:nested asn1 error
> [Fri Apr 08 12:48:30 2011] [error] SSL Library Error: 218529960 error:0D0680A8:asn1 encoding routines:ASN1_CHECK_TLEN:wrong tag
> [Fri Apr 08 12:48:30 2011] [error] SSL Library Error: 218595386 error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1 error
> [Fri Apr 08 12:48:30 2011] [error] SSL Library Error: 67710980 error:04093004:rsa routines:OLD_RSA_PRIV_DECODE:RSA lib
> [Fri Apr 08 12:48:30 2011] [error] SSL Library Error: 218529960 error:0D0680A8:asn1 encoding routines:ASN1_CHECK_TLEN:wrong tag
> [Fri Apr 08 12:48:30 2011] [error] SSL Library Error: 218595386 error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1 error

You need to check if you certificate has a private key:

> openssl rsa -in www.pem

unable to load Private Key
140234728453800:error:0906D06C:PEM routines:PEM_read_bio:no start line:pem_lib.c:698:Expecting: ANY PRIVATE KEY

--> there is no private key.

If you have one pem file. It should look like this:

-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----

-----BEGIN RSA PRIVATE KEY-----
...
-----END RSA PRIVATE KEY-----

Thomas

--
Thomas Guettler, http://www.thomas-guettler.de/
E-Mail: guettli (*) thomas-guettler + de

mar...@gmail.com

unread,
Nov 13, 2013, 9:27:30 AM11/13/13
to
sorry I'm not seeing how this was solved? so your saying your cert doesn't ahve a private key for it , do you create one ?
0 new messages