Re: new jcosign service produces error message at authn

OK, this problem is now resolved. It was certificate-related, as suspected.

So, for reference:

* The certificate used for CoSign can be signed by any CA, but that CA's cert must be imported as a trusted certificate *in the same keystore*.

* The Java keytool is picky about how certs are created and signed. You must first generate a keypair, which is stored as a self-signed cert. Then you must generate a certificate signing request from that, and finally you must re-import the signed cert from your CA *on top of* the self-signed cert to establish a trust chain.

* In my case, I imported the CA cert before I even created the keypair. Probably not necessary, but if wearing a bone in my nose would have helped, I would have done it. I think the important thing is that when the cert is imported, the CA cert already has to be trusted.


