Login
[x]
Log in using an account from:
Fedora Account System
Red Hat Associate
Red Hat Customer
Or login using a Red Hat Bugzilla account
Forgot Password
Login:
Hide Forgot
Create an Account
Red Hat Bugzilla – Attachment 952361 Details for
Bug 1159086
RHEL7.1 ipa-server-install with external-cert-file from ADCS fails
[?]
New
Simple Search
Advanced Search
My Links
Browse
Requests
Reports
Current State
Search
Tabular reports
Graphical reports
Duplicates
Other Reports
User Changes
Plotly Reports
Bug Status
Bug Severity
Non-Defaults
|
Product Dashboard
Help
Page Help!
Bug Writing Guidelines
What's new
Browser Support Policy
5.0.4.rh83 Release notes
FAQ
Guides index
User guide
Web Services
Contact
Legal
This site requires JavaScript to be enabled to function correctly, please enable it.
ipaserver-install.log
ipaserver-install.log (text/plain), 36.63 KB, created by
Scott Poore
on 2014-10-30 22:40:51 UTC
(
hide
)
Description:
ipaserver-install.log
Filename:
MIME Type:
Creator:
Scott Poore
Created:
2014-10-30 22:40:51 UTC
Size:
36.63 KB
patch
obsolete
>2014-10-30T21:57:46Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' >2014-10-30T21:57:46Z DEBUG /usr/sbin/ipa-server-install was invoked with options: {'http_cert_files': None, 'ip_addresses': [CheckedIPAddress('192.168.122.71')], 'mkhomedir': False, 'create_sshfp': True, 'conf_sshd': True, 'conf_ntp': True, 'reverse_zones': [], 'no_forwarders': False, 'ui_redirect': True, 'external_ca_type': None, 'domain_name': 'example.com', 'idmax': 0, 'hbac_allow': False, 'http_cert_name': None, 'dirsrv_cert_files': None, 'ca_signing_algorithm': None, 'no_reverse': False, 'subject': None, 'unattended': True, 'external_cert_files': ['/root/ipa.cer', '/root/testnssdb/adcs1.asc'], 'trust_sshfp': False, 'no_host_dns': False, 'dirsrv_cert_name': None, 'realm_name': 'EXAMPLE.COM', 'forwarders': [CheckedIPAddress('192.168.122.1')], 'idstart': 156800000, 'external_ca': False, 'conf_ssh': True, 'zonemgr': None, 'ca_cert_files': None, 'setup_dns': True, 'host_name': 'rhel7-1.example.com', 'debug': False, 'uninstall': False} >2014-10-30T21:57:46Z DEBUG missing options might be asked for interactively later > >2014-10-30T21:57:46Z DEBUG IPA version 4.1.0-3.el7 >2014-10-30T21:57:46Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' >2014-10-30T21:57:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/usr/bin/gpg-agent' '--batch' '--homedir' '/tmp/tmpougdjMipa/ipa-5QlgfZ/.gnupg' '--daemon' '/usr/bin/gpg' '--batch' '--homedir' '/tmp/tmpougdjMipa/ipa-5QlgfZ/.gnupg' '--passphrase-fd' '0' '--yes' '--no-tty' '-o' '/tmp/tmpougdjMipa/cache' '-d' '/root/.ipa_cache' >2014-10-30T21:57:46Z DEBUG Process finished, return code=0 >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpGv6a1P' '-N' '-f' '/tmp/tmp3fPwDT' >2014-10-30T21:57:46Z DEBUG Process finished, return code=0 >2014-10-30T21:57:46Z DEBUG stdout= >2014-10-30T21:57:46Z DEBUG stderr= >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpGv6a1P' '-A' '-n' 'CN=Certificate Authority,O=EXAMPLE.COM' '-t' ',,' >2014-10-30T21:57:46Z DEBUG Process finished, return code=0 >2014-10-30T21:57:46Z DEBUG stdout= >2014-10-30T21:57:46Z DEBUG stderr= >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpGv6a1P' '-A' '-n' 'CN=adroot2-ADCS1-CA,DC=adroot2,DC=example,DC=com' '-t' ',,' >2014-10-30T21:57:46Z DEBUG Process finished, return code=0 >2014-10-30T21:57:46Z DEBUG stdout= >2014-10-30T21:57:46Z DEBUG stderr= >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpGv6a1P' '-L' >2014-10-30T21:57:46Z DEBUG Process finished, return code=0 >2014-10-30T21:57:46Z DEBUG stdout= >Certificate Nickname Trust Attributes > SSL,S/MIME,JAR/XPI > >CN=Certificate Authority,O=EXAMPLE.COM ,, >CN=adroot2-ADCS1-CA,DC=adroot2,DC=example,DC=com ,, > >2014-10-30T21:57:46Z DEBUG stderr= >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpGv6a1P' '-L' '-n' 'CN=Certificate Authority,O=EXAMPLE.COM' '-a' >2014-10-30T21:57:46Z DEBUG Process finished, return code=0 >2014-10-30T21:57:46Z DEBUG stdout=-----BEGIN CERTIFICATE----- >MIIFejCCBGKgAwIBAgIKFll2tgABAAAACzANBgkqhkiG9w0BAQUFADBiMRMwEQYK >CZImiZPyLGQBGRYDY29tMRcwFQYKCZImiZPyLGQBGRYHZXhhbXBsZTEXMBUGCgmS >JomT8ixkARkWB2Fkcm9vdDIxGTAXBgNVBAMTEGFkcm9vdDItQURDUzEtQ0EwHhcN >MTQxMDMwMjEzNTUwWhcNMTYxMDMwMjE0NTUwWjA2MRQwEgYDVQQKEwtFWEFNUExF >LkNPTTEeMBwGA1UEAxMVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MIIBIjANBgkqhkiG >9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs5lgVuMGDx4gtUyl7JYkxaLtd1TeeZVPYGRP >l/je5Cm3vadZdLpsfgM6K3aNsv6fupKBHbHIeKWz5WfDetAu8coMW+9epAOjdmMo >tVESLVSG9OoEz6PgH06evO4MYGCl/FGPQ01m8/O91GUZ180DhxZ1pd7z/A7hcIcx >IxI+vjXMsBf7GT0DsTiTYA4O95zEkGXMTrz0tdecDsvvVbo2X2fKdkiE4CGWidU/ >n3D/ZJXe6uJjkzdeNT71rHZCGtYjGsovMF18geyj27IS2zHiQ2QYWb+ibwrpNL6z >6fSCs2dpQ3D+WHmRwPwjfLN1eQozewrX4wQ3oKxVLvxzTVXM/wIDAQABo4ICXDCC >AlgwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0OBBYEFPyw >cVYDgc/GwN0x86QTBS/K3tOPMB8GA1UdIwQYMBaAFJLPPcqQBVQSGlg33Mn0ycRp >x3YEMIHwBgNVHR8EgegwgeUwgeKggd+ggdyGgdlsZGFwOi8vYWRjczEuYWRyb290 >Mi5leGFtcGxlLmNvbS9DTj1hZHJvb3QyLUFEQ1MxLUNBLENOPWFkY3MxLENOPUNE >UCxDTj1QdWJsaWMlMjBLZXklMjBTZXJ2aWNlcyxDTj1TZXJ2aWNlcyxDTj1Db25m >aWd1cmF0aW9uLERDPWFkcm9vdDIsREM9ZXhhbXBsZSxEQz1jb20/Y2VydGlmaWNh >dGVSZXZvY2F0aW9uTGlzdD9iYXNlP29iamVjdENsYXNzPWNSTERpc3RyaWJ1dGlv >blBvaW50MIHmBggrBgEFBQcBAQSB2TCB1jCB0wYIKwYBBQUHMAKGgcZsZGFwOi8v >YWRjczEuYWRyb290Mi5leGFtcGxlLmNvbS9DTj1hZHJvb3QyLUFEQ1MxLUNBLENO >PUFJQSxDTj1QdWJsaWMlMjBLZXklMjBTZXJ2aWNlcyxDTj1TZXJ2aWNlcyxDTj1D >b25maWd1cmF0aW9uLERDPWFkcm9vdDIsREM9ZXhhbXBsZSxEQz1jb20/Y0FDZXJ0 >aWZpY2F0ZT9iYXNlP29iamVjdENsYXNzPWNlcnRpZmljYXRpb25BdXRob3JpdHkw >GQYJKwYBBAGCNxQCBAweCgBTAHUAYgBDAEEwDQYJKoZIhvcNAQEFBQADggEBAHZv >PVsLdpBrSerPdx6lXyWQ8DL+rZGyuA6Pd0ZtQTsORxiFKzHI8NZe4hoqUujAdb4j >5yGzu648ZtOlBpCZ63klwRYVm/8+rElJKEQqBMXBvSg2y/LEU4qX772JxFxnjxRu >GcokqFZMUloVglv2OThbvzK8NpSjlb7qQ2f4huad09/1DCjxH3KGpuKBXrs+mMcb >pYt8iWSZxiA2ukzgTawODfiF9YwGOb0g6FmT9/KUb4OxLfqFNhBv6GMrVE2AA+OJ >GbUnQS47a9o4xlLU78Rxn8UK3OpPD7LhQIEJOQ6ORZjlpSP84T9EVOkhTmuUcwr/ >NQyCQh+xtTExoeNEI9s= >-----END CERTIFICATE----- > >2014-10-30T21:57:46Z DEBUG stderr= >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpGv6a1P' '-M' '-n' 'CN=Certificate Authority,O=EXAMPLE.COM' '-t' 'C,,' >2014-10-30T21:57:46Z DEBUG Process finished, return code=0 >2014-10-30T21:57:46Z DEBUG stdout= >2014-10-30T21:57:46Z DEBUG stderr= >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpGv6a1P' '-L' '-n' 'CN=adroot2-ADCS1-CA,DC=adroot2,DC=example,DC=com' '-a' >2014-10-30T21:57:46Z DEBUG Process finished, return code=0 >2014-10-30T21:57:46Z DEBUG stdout=-----BEGIN CERTIFICATE----- >MIIDnzCCAoegAwIBAgIQTlMytlVM9oBMgOG+A8AtejANBgkqhkiG9w0BAQUFADBi >MRMwEQYKCZImiZPyLGQBGRYDY29tMRcwFQYKCZImiZPyLGQBGRYHZXhhbXBsZTEX >MBUGCgmSJomT8ixkARkWB2Fkcm9vdDIxGTAXBgNVBAMTEGFkcm9vdDItQURDUzEt >Q0EwHhcNMTQxMDI5MTYwOTEyWhcNMTkxMDI5MTYxOTEyWjBiMRMwEQYKCZImiZPy >LGQBGRYDY29tMRcwFQYKCZImiZPyLGQBGRYHZXhhbXBsZTEXMBUGCgmSJomT8ixk >ARkWB2Fkcm9vdDIxGTAXBgNVBAMTEGFkcm9vdDItQURDUzEtQ0EwggEiMA0GCSqG >SIb3DQEBAQUAA4IBDwAwggEKAoIBAQCt0rKIqPOAtcjGUtn7dlRiKrWEHUXBud1P >DrOuCJWH6Ze9lVX1qtFPeBdVVDWwC1rDMeNpvJGtaDgzt5kNel5nz3Gkqi74wQOs >A83jf00NLoltyKWjPnubayp8oY/lxTAfBvfrtGCnN8N4x2ZfYlGvnaFpTQ4+zMcy >oaS8QE56OtRUc/HN9F7hMikTrv3uWzEUaLWyLrrUAWKRBDRq523rbW1quL5jFkly >iQHt9rDx4kT35qJdS1RJ3YIG1PWqarFpur0l3jOGWSXnubXd/ApDL9KDkWoPU/hE >RAIP4T+BwT2Pq9cXYq7OGoPcXygfky/iCEhhVNNk0/wZ38d3syldAgMBAAGjUTBP >MAsGA1UdDwQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBSSzz3KkAVU >EhpYN9zJ9MnEacd2BDAQBgkrBgEEAYI3FQEEAwIBADANBgkqhkiG9w0BAQUFAAOC >AQEAK9DPhcsMIRfTpSU0YAjcREbSX6hSIbru7Lf+UrNDXGmCuh9qhhGcYXwFOecb >RliAotF0CVCBQLTYNI7zhPcO5EZqbDFk9/NtKVQEiaCMxEee2H/lMwLGgCYxwn3l >sBILUy+HEIj1+y6q/JyhnI4ZLuZyOcsegAyBbpQbn//Nx/bACD95xVjt9SGXSN3B >OZsQehKm8RcNzPCoCB/CAQCLwo+i0KvL+sbZX6P2LWL8RNOOEvA8xNP3JYtjFCq4 >APk6o11s5XGLtfNZ3hZQDJNvLjQB7o1DgwVtrGalb5V9urRG3RdvGHv7Tn+3sp97 >tLTsCGskN1EG2Eq8HpecgrH2XQ== >-----END CERTIFICATE----- > >2014-10-30T21:57:46Z DEBUG stderr= >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpGv6a1P' '-M' '-n' 'CN=adroot2-ADCS1-CA,DC=adroot2,DC=example,DC=com' '-t' 'C,,' >2014-10-30T21:57:46Z DEBUG Process finished, return code=0 >2014-10-30T21:57:46Z DEBUG stdout= >2014-10-30T21:57:46Z DEBUG stderr= >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpGv6a1P' '-O' '-n' 'CN=Certificate Authority,O=EXAMPLE.COM' >2014-10-30T21:57:46Z DEBUG Process finished, return code=0 >2014-10-30T21:57:46Z DEBUG stdout="CN=adroot2-ADCS1-CA,DC=adroot2,DC=example,DC=com" [CN=adroot2-ADCS1-CA,DC=adroot2,DC=example,DC=com] > > "CN=Certificate Authority,O=EXAMPLE.COM" [CN=Certificate Authority,O=EXAMPLE.COM] > > >2014-10-30T21:57:46Z DEBUG stderr= >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/bin/systemctl' 'is-enabled' 'chronyd.service' >2014-10-30T21:57:46Z DEBUG Process finished, return code=1 >2014-10-30T21:57:46Z DEBUG stdout= >2014-10-30T21:57:46Z DEBUG stderr=Failed to issue method call: No such file or directory > >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/bin/systemctl' 'is-active' 'chronyd.service' >2014-10-30T21:57:46Z DEBUG Process finished, return code=3 >2014-10-30T21:57:46Z DEBUG stdout=unknown > >2014-10-30T21:57:46Z DEBUG stderr= >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/usr/sbin/httpd' '-t' '-D' 'DUMP_VHOSTS' >2014-10-30T21:57:46Z DEBUG Process finished, return code=0 >2014-10-30T21:57:46Z DEBUG stdout=VirtualHost configuration: >*:8443 is a NameVirtualHost > default server rhel7-1.example.com (/etc/httpd/conf.d/nss.conf:86) > port 8443 namevhost rhel7-1.example.com (/etc/httpd/conf.d/nss.conf:86) > port 8443 namevhost rhel7-1.example.com (/etc/httpd/conf.d/nss.conf:86) > >2014-10-30T21:57:46Z DEBUG stderr= >2014-10-30T21:57:46Z DEBUG Check if rhel7-1.example.com is a primary hostname for localhost >2014-10-30T21:57:46Z DEBUG Primary hostname for localhost: rhel7-1.example.com >2014-10-30T21:57:46Z DEBUG will use host_name: rhel7-1.example.com > >2014-10-30T21:57:46Z DEBUG Starting external process >2014-10-30T21:57:46Z DEBUG args='/sbin/ip' '-family' 'inet' '-oneline' 'address' 'show' >2014-10-30T21:57:46Z DEBUG Process finished, return code=0 >2014-10-30T21:57:46Z DEBUG stdout=1: lo inet 127.0.0.1/8 scope host lo\ valid_lft forever preferred_lft forever >2: eth0 inet 192.168.122.71/24 brd 192.168.122.255 scope global eth0\ valid_lft forever preferred_lft forever > >2014-10-30T21:57:46Z DEBUG stderr= >2014-10-30T21:57:46Z DEBUG Backing up system configuration file '/etc/hosts' >2014-10-30T21:57:46Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' >2014-10-30T21:57:46Z DEBUG Checking forwarder: 192.168.122.1 >2014-10-30T21:57:47Z WARNING DNS forwarder 192.168.122.1 does not return DNSSEC signatures in answers >2014-10-30T21:57:47Z WARNING Please fix forwarder configuration to enable DNSSEC support. >(For BIND 9 add directive "dnssec-enable yes;" to "options {}") >2014-10-30T21:57:47Z DEBUG will use dns_forwarders: [CheckedIPAddress('192.168.122.1')] > >2014-10-30T21:57:47Z DEBUG importing all plugin modules in '/usr/lib/python2.7/site-packages/ipalib/plugins'... >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/aci.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/automember.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/automount.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/baseldap.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/batch.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/cert.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/config.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/delegation.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/dns.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/group.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hbacrule.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hbacsvc.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hbacsvcgroup.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hbactest.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/host.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hostgroup.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/idrange.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/idviews.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/internal.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/kerberos.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/krbtpolicy.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/migration.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/misc.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/netgroup.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/otptoken.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/otptoken_yubikey.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/passwd.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/permission.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/ping.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/pkinit.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/privilege.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/pwpolicy.py' >2014-10-30T21:57:47Z DEBUG Starting external process >2014-10-30T21:57:47Z DEBUG args='klist' '-V' >2014-10-30T21:57:47Z DEBUG Process finished, return code=0 >2014-10-30T21:57:47Z DEBUG stdout=Kerberos 5 version 1.12.2 > >2014-10-30T21:57:47Z DEBUG stderr= >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/radiusproxy.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/realmdomains.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/role.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/rpcclient.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/selfservice.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/selinuxusermap.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/service.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/sudocmd.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/sudocmdgroup.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/sudorule.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/trust.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/user.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/virtual.py' >2014-10-30T21:57:47Z DEBUG importing all plugin modules in '/usr/lib/python2.7/site-packages/ipaserver/install/plugins'... >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/adtrust.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/baseupdate.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/ca_renewal_master.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/dns.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/fix_replica_agreements.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/rename_managed.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/update_idranges.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/update_managed_permissions.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/update_pacs.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/update_services.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/update_uniqueness.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/updateclient.py' >2014-10-30T21:57:47Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/upload_cacrt.py' >2014-10-30T21:57:47Z DEBUG group dirsrv exists >2014-10-30T21:57:47Z DEBUG user dirsrv exists >2014-10-30T21:57:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' >2014-10-30T21:57:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' >2014-10-30T21:57:47Z DEBUG Configuring certificate server (pki-tomcatd): Estimated time 3 minutes 30 seconds >2014-10-30T21:57:47Z DEBUG [1/27]: creating certificate server user >2014-10-30T21:57:47Z DEBUG group pkiuser exists >2014-10-30T21:57:47Z DEBUG user pkiuser exists >2014-10-30T21:57:47Z DEBUG duration: 0 seconds >2014-10-30T21:57:47Z DEBUG [2/27]: configuring certificate server instance >2014-10-30T21:57:47Z DEBUG Starting external process >2014-10-30T21:57:47Z DEBUG args='/usr/bin/openssl' 'crl2pkcs7' '-certfile' '/tmp/tmpdClYY_' '-nocrl' >2014-10-30T21:57:47Z DEBUG Process finished, return code=0 >2014-10-30T21:57:47Z DEBUG stdout=-----BEGIN PKCS7----- >MIID0AYJKoZIhvcNAQcCoIIDwTCCA70CAQExADALBgkqhkiG9w0BBwGgggOjMIID >nzCCAoegAwIBAgIQTlMytlVM9oBMgOG+A8AtejANBgkqhkiG9w0BAQUFADBiMRMw >EQYKCZImiZPyLGQBGRYDY29tMRcwFQYKCZImiZPyLGQBGRYHZXhhbXBsZTEXMBUG >CgmSJomT8ixkARkWB2Fkcm9vdDIxGTAXBgNVBAMTEGFkcm9vdDItQURDUzEtQ0Ew >HhcNMTQxMDI5MTYwOTEyWhcNMTkxMDI5MTYxOTEyWjBiMRMwEQYKCZImiZPyLGQB >GRYDY29tMRcwFQYKCZImiZPyLGQBGRYHZXhhbXBsZTEXMBUGCgmSJomT8ixkARkW >B2Fkcm9vdDIxGTAXBgNVBAMTEGFkcm9vdDItQURDUzEtQ0EwggEiMA0GCSqGSIb3 >DQEBAQUAA4IBDwAwggEKAoIBAQCt0rKIqPOAtcjGUtn7dlRiKrWEHUXBud1PDrOu >CJWH6Ze9lVX1qtFPeBdVVDWwC1rDMeNpvJGtaDgzt5kNel5nz3Gkqi74wQOsA83j >f00NLoltyKWjPnubayp8oY/lxTAfBvfrtGCnN8N4x2ZfYlGvnaFpTQ4+zMcyoaS8 >QE56OtRUc/HN9F7hMikTrv3uWzEUaLWyLrrUAWKRBDRq523rbW1quL5jFklyiQHt >9rDx4kT35qJdS1RJ3YIG1PWqarFpur0l3jOGWSXnubXd/ApDL9KDkWoPU/hERAIP >4T+BwT2Pq9cXYq7OGoPcXygfky/iCEhhVNNk0/wZ38d3syldAgMBAAGjUTBPMAsG >A1UdDwQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBSSzz3KkAVUEhpY >N9zJ9MnEacd2BDAQBgkrBgEEAYI3FQEEAwIBADANBgkqhkiG9w0BAQUFAAOCAQEA >K9DPhcsMIRfTpSU0YAjcREbSX6hSIbru7Lf+UrNDXGmCuh9qhhGcYXwFOecbRliA >otF0CVCBQLTYNI7zhPcO5EZqbDFk9/NtKVQEiaCMxEee2H/lMwLGgCYxwn3lsBIL >Uy+HEIj1+y6q/JyhnI4ZLuZyOcsegAyBbpQbn//Nx/bACD95xVjt9SGXSN3BOZsQ >ehKm8RcNzPCoCB/CAQCLwo+i0KvL+sbZX6P2LWL8RNOOEvA8xNP3JYtjFCq4APk6 >o11s5XGLtfNZ3hZQDJNvLjQB7o1DgwVtrGalb5V9urRG3RdvGHv7Tn+3sp97tLTs >CGskN1EG2Eq8HpecgrH2XaEAMQA= >-----END PKCS7----- > >2014-10-30T21:57:47Z DEBUG stderr= >2014-10-30T21:57:47Z DEBUG Contents of pkispawn configuration file (/tmp/tmpMmgqnY): >[CA] >pki_security_domain_name = IPA >pki_enable_proxy = True >pki_restart_configured_instance = False >pki_backup_keys = True >pki_backup_password = XXXXXXXX >pki_client_database_dir = /tmp/tmp-YNzYJh >pki_client_database_password = XXXXXXXX >pki_client_database_purge = False >pki_client_pkcs12_password = XXXXXXXX >pki_admin_name = admin >pki_admin_uid = admin >pki_admin_email = root@localhost >pki_admin_password = XXXXXXXX >pki_admin_nickname = ipa-ca-agent >pki_admin_subject_dn = cn=ipa-ca-agent,O=EXAMPLE.COM >pki_client_admin_cert_p12 = /root/ca-agent.p12 >pki_ds_ldap_port = 389 >pki_ds_password = XXXXXXXX >pki_ds_base_dn = o=ipaca >pki_ds_database = ipaca >pki_subsystem_subject_dn = cn=CA Subsystem,O=EXAMPLE.COM >pki_ocsp_signing_subject_dn = cn=OCSP Subsystem,O=EXAMPLE.COM >pki_ssl_server_subject_dn = cn=rhel7-1.example.com,O=EXAMPLE.COM >pki_audit_signing_subject_dn = cn=CA Audit,O=EXAMPLE.COM >pki_ca_signing_subject_dn = cn=Certificate Authority,O=EXAMPLE.COM >pki_subsystem_nickname = subsystemCert cert-pki-ca >pki_ocsp_signing_nickname = ocspSigningCert cert-pki-ca >pki_ssl_server_nickname = Server-Cert cert-pki-ca >pki_audit_signing_nickname = auditSigningCert cert-pki-ca >pki_ca_signing_nickname = caSigningCert cert-pki-ca >pki_ca_signing_key_algorithm = SHA256withRSA >pki_external = True >pki_external_ca_cert_path = /tmp/tmpdv4Mni >pki_external_ca_cert_chain_path = /tmp/tmpZrm0Fa >pki_external_step_two = True > > >2014-10-30T21:57:47Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' >2014-10-30T21:57:47Z DEBUG Starting external process >2014-10-30T21:57:47Z DEBUG args='/usr/sbin/pkispawn' '-s' 'CA' '-f' '/tmp/tmpMmgqnY' >2014-10-30T21:57:52Z DEBUG Process finished, return code=0 >2014-10-30T21:57:52Z DEBUG stdout=Loading deployment configuration from /tmp/tmpMmgqnY. >Installing CA into /var/lib/pki/pki-tomcat. > > ========================================================================== > INSTALLATION SUMMARY > ========================================================================== > > Administrator's username: admin > Administrator's PKCS #12 file: > /root/ca-agent.p12 > > Administrator's certificate nickname: > ipa-ca-agent > Administrator's certificate database: > /tmp/tmp-YNzYJh > > To check the status of the subsystem: > systemctl status pki-tomcatd@pki-tomcat.service > To restart the subsystem: > systemctl restart pki-tomcatd@pki-tomcat.service > The URL for the subsystem is: > https://rhel7-1.example.com:8443/ca > > ========================================================================== > > >2014-10-30T21:57:52Z DEBUG stderr=Notice: Trust flag u is set automatically if the private key is present. > >2014-10-30T21:57:52Z DEBUG completed creating ca instance >2014-10-30T21:57:52Z DEBUG duration: 5 seconds >2014-10-30T21:57:52Z DEBUG [3/27]: stopping certificate server instance to update CS.cfg >2014-10-30T21:57:52Z DEBUG Starting external process >2014-10-30T21:57:52Z DEBUG args='/bin/systemctl' 'stop' 'pki-tomcatd.target' >2014-10-30T21:57:53Z DEBUG Process finished, return code=0 >2014-10-30T21:57:53Z DEBUG stdout= >2014-10-30T21:57:53Z DEBUG stderr= >2014-10-30T21:57:53Z DEBUG duration: 0 seconds >2014-10-30T21:57:53Z DEBUG [4/27]: backing up CS.cfg >2014-10-30T21:57:53Z WARNING Failed to backup CS.cfg: no magic attribute 'dogtag' >2014-10-30T21:57:53Z DEBUG duration: 0 seconds >2014-10-30T21:57:53Z DEBUG [5/27]: disabling nonces >2014-10-30T21:57:53Z DEBUG duration: 0 seconds >2014-10-30T21:57:53Z DEBUG [6/27]: set up CRL publishing >2014-10-30T21:57:53Z DEBUG Starting external process >2014-10-30T21:57:53Z DEBUG args='/usr/sbin/selinuxenabled' >2014-10-30T21:57:53Z DEBUG Process finished, return code=0 >2014-10-30T21:57:53Z DEBUG stdout= >2014-10-30T21:57:53Z DEBUG stderr= >2014-10-30T21:57:53Z DEBUG Starting external process >2014-10-30T21:57:53Z DEBUG args='/sbin/restorecon' '/var/lib/ipa/pki-ca/publish' >2014-10-30T21:57:53Z DEBUG Process finished, return code=0 >2014-10-30T21:57:53Z DEBUG stdout= >2014-10-30T21:57:53Z DEBUG stderr= >2014-10-30T21:57:53Z DEBUG duration: 0 seconds >2014-10-30T21:57:53Z DEBUG [7/27]: enable PKIX certificate path discovery and validation >2014-10-30T21:57:53Z DEBUG duration: 0 seconds >2014-10-30T21:57:53Z DEBUG [8/27]: starting certificate server instance >2014-10-30T21:57:53Z DEBUG Starting external process >2014-10-30T21:57:53Z DEBUG args='/bin/systemctl' 'start' 'pki-tomcatd.target' >2014-10-30T21:57:53Z DEBUG Process finished, return code=0 >2014-10-30T21:57:53Z DEBUG stdout= >2014-10-30T21:57:53Z DEBUG stderr= >2014-10-30T21:57:53Z DEBUG Starting external process >2014-10-30T21:57:53Z DEBUG args='/bin/systemctl' 'is-active' 'pki-tomcatd.target' >2014-10-30T21:57:53Z DEBUG Process finished, return code=0 >2014-10-30T21:57:53Z DEBUG stdout=active > >2014-10-30T21:57:53Z DEBUG stderr= >2014-10-30T21:57:53Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 300 >2014-10-30T21:57:55Z DEBUG The httpd proxy is not installed, wait on local port >2014-10-30T21:57:55Z DEBUG Waiting until the CA is running >2014-10-30T21:57:55Z DEBUG request 'https://rhel7-1.example.com:8443/ca/admin/ca/getStatus' >2014-10-30T21:57:55Z DEBUG request body '' >2014-10-30T21:58:09Z DEBUG request status 200 >2014-10-30T21:58:09Z DEBUG request reason_phrase u'OK' >2014-10-30T21:58:09Z DEBUG request headers {'date': 'Thu, 30 Oct 2014 21:58:09 GMT', 'content-length': '167', 'content-type': 'application/xml', 'server': 'Apache-Coyote/1.1'} >2014-10-30T21:58:09Z DEBUG request body '<?xml version="1.0" encoding="UTF-8" standalone="no"?><XMLResponse><State>1</State><Type>CA</Type><Status>running</Status><Version>10.1.2-3.el7</Version></XMLResponse>' >2014-10-30T21:58:09Z DEBUG The CA status is: running >2014-10-30T21:58:09Z DEBUG duration: 15 seconds >2014-10-30T21:58:09Z DEBUG [9/27]: creating RA agent certificate database >2014-10-30T21:58:09Z DEBUG Starting external process >2014-10-30T21:58:09Z DEBUG args='/usr/bin/certutil' '-d' '/etc/httpd/alias' '-f' XXXXXXXX '-N' >2014-10-30T21:58:09Z DEBUG Process finished, return code=0 >2014-10-30T21:58:09Z DEBUG stdout= >2014-10-30T21:58:09Z DEBUG stderr= >2014-10-30T21:58:09Z DEBUG duration: 0 seconds >2014-10-30T21:58:09Z DEBUG [10/27]: importing CA chain to RA certificate database >2014-10-30T21:58:09Z DEBUG Starting external process >2014-10-30T21:58:09Z DEBUG args='/usr/bin/openssl' 'pkcs7' '-inform' 'DER' '-print_certs' >2014-10-30T21:58:09Z DEBUG Process finished, return code=0 >2014-10-30T21:58:09Z DEBUG stdout=subject=/DC=com/DC=example/DC=adroot2/CN=adroot2-ADCS1-CA >issuer=/DC=com/DC=example/DC=adroot2/CN=adroot2-ADCS1-CA >-----BEGIN CERTIFICATE----- >MIIDnzCCAoegAwIBAgIQTlMytlVM9oBMgOG+A8AtejANBgkqhkiG9w0BAQUFADBi >MRMwEQYKCZImiZPyLGQBGRYDY29tMRcwFQYKCZImiZPyLGQBGRYHZXhhbXBsZTEX >MBUGCgmSJomT8ixkARkWB2Fkcm9vdDIxGTAXBgNVBAMTEGFkcm9vdDItQURDUzEt >Q0EwHhcNMTQxMDI5MTYwOTEyWhcNMTkxMDI5MTYxOTEyWjBiMRMwEQYKCZImiZPy >LGQBGRYDY29tMRcwFQYKCZImiZPyLGQBGRYHZXhhbXBsZTEXMBUGCgmSJomT8ixk >ARkWB2Fkcm9vdDIxGTAXBgNVBAMTEGFkcm9vdDItQURDUzEtQ0EwggEiMA0GCSqG >SIb3DQEBAQUAA4IBDwAwggEKAoIBAQCt0rKIqPOAtcjGUtn7dlRiKrWEHUXBud1P >DrOuCJWH6Ze9lVX1qtFPeBdVVDWwC1rDMeNpvJGtaDgzt5kNel5nz3Gkqi74wQOs >A83jf00NLoltyKWjPnubayp8oY/lxTAfBvfrtGCnN8N4x2ZfYlGvnaFpTQ4+zMcy >oaS8QE56OtRUc/HN9F7hMikTrv3uWzEUaLWyLrrUAWKRBDRq523rbW1quL5jFkly >iQHt9rDx4kT35qJdS1RJ3YIG1PWqarFpur0l3jOGWSXnubXd/ApDL9KDkWoPU/hE >RAIP4T+BwT2Pq9cXYq7OGoPcXygfky/iCEhhVNNk0/wZ38d3syldAgMBAAGjUTBP >MAsGA1UdDwQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBSSzz3KkAVU >EhpYN9zJ9MnEacd2BDAQBgkrBgEEAYI3FQEEAwIBADANBgkqhkiG9w0BAQUFAAOC >AQEAK9DPhcsMIRfTpSU0YAjcREbSX6hSIbru7Lf+UrNDXGmCuh9qhhGcYXwFOecb >RliAotF0CVCBQLTYNI7zhPcO5EZqbDFk9/NtKVQEiaCMxEee2H/lMwLGgCYxwn3l >sBILUy+HEIj1+y6q/JyhnI4ZLuZyOcsegAyBbpQbn//Nx/bACD95xVjt9SGXSN3B >OZsQehKm8RcNzPCoCB/CAQCLwo+i0KvL+sbZX6P2LWL8RNOOEvA8xNP3JYtjFCq4 >APk6o11s5XGLtfNZ3hZQDJNvLjQB7o1DgwVtrGalb5V9urRG3RdvGHv7Tn+3sp97 >tLTsCGskN1EG2Eq8HpecgrH2XQ== >-----END CERTIFICATE----- > >subject=/O=EXAMPLE.COM/CN=Certificate Authority >issuer=/DC=com/DC=example/DC=adroot2/CN=adroot2-ADCS1-CA >-----BEGIN CERTIFICATE----- >MIIFejCCBGKgAwIBAgIKFll2tgABAAAACzANBgkqhkiG9w0BAQUFADBiMRMwEQYK >CZImiZPyLGQBGRYDY29tMRcwFQYKCZImiZPyLGQBGRYHZXhhbXBsZTEXMBUGCgmS >JomT8ixkARkWB2Fkcm9vdDIxGTAXBgNVBAMTEGFkcm9vdDItQURDUzEtQ0EwHhcN >MTQxMDMwMjEzNTUwWhcNMTYxMDMwMjE0NTUwWjA2MRQwEgYDVQQKEwtFWEFNUExF >LkNPTTEeMBwGA1UEAxMVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MIIBIjANBgkqhkiG >9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs5lgVuMGDx4gtUyl7JYkxaLtd1TeeZVPYGRP >l/je5Cm3vadZdLpsfgM6K3aNsv6fupKBHbHIeKWz5WfDetAu8coMW+9epAOjdmMo >tVESLVSG9OoEz6PgH06evO4MYGCl/FGPQ01m8/O91GUZ180DhxZ1pd7z/A7hcIcx >IxI+vjXMsBf7GT0DsTiTYA4O95zEkGXMTrz0tdecDsvvVbo2X2fKdkiE4CGWidU/ >n3D/ZJXe6uJjkzdeNT71rHZCGtYjGsovMF18geyj27IS2zHiQ2QYWb+ibwrpNL6z >6fSCs2dpQ3D+WHmRwPwjfLN1eQozewrX4wQ3oKxVLvxzTVXM/wIDAQABo4ICXDCC >AlgwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0OBBYEFPyw >cVYDgc/GwN0x86QTBS/K3tOPMB8GA1UdIwQYMBaAFJLPPcqQBVQSGlg33Mn0ycRp >x3YEMIHwBgNVHR8EgegwgeUwgeKggd+ggdyGgdlsZGFwOi8vYWRjczEuYWRyb290 >Mi5leGFtcGxlLmNvbS9DTj1hZHJvb3QyLUFEQ1MxLUNBLENOPWFkY3MxLENOPUNE >UCxDTj1QdWJsaWMlMjBLZXklMjBTZXJ2aWNlcyxDTj1TZXJ2aWNlcyxDTj1Db25m >aWd1cmF0aW9uLERDPWFkcm9vdDIsREM9ZXhhbXBsZSxEQz1jb20/Y2VydGlmaWNh >dGVSZXZvY2F0aW9uTGlzdD9iYXNlP29iamVjdENsYXNzPWNSTERpc3RyaWJ1dGlv >blBvaW50MIHmBggrBgEFBQcBAQSB2TCB1jCB0wYIKwYBBQUHMAKGgcZsZGFwOi8v >YWRjczEuYWRyb290Mi5leGFtcGxlLmNvbS9DTj1hZHJvb3QyLUFEQ1MxLUNBLENO >PUFJQSxDTj1QdWJsaWMlMjBLZXklMjBTZXJ2aWNlcyxDTj1TZXJ2aWNlcyxDTj1D >b25maWd1cmF0aW9uLERDPWFkcm9vdDIsREM9ZXhhbXBsZSxEQz1jb20/Y0FDZXJ0 >aWZpY2F0ZT9iYXNlP29iamVjdENsYXNzPWNlcnRpZmljYXRpb25BdXRob3JpdHkw >GQYJKwYBBAGCNxQCBAweCgBTAHUAYgBDAEEwDQYJKoZIhvcNAQEFBQADggEBAHZv >PVsLdpBrSerPdx6lXyWQ8DL+rZGyuA6Pd0ZtQTsORxiFKzHI8NZe4hoqUujAdb4j >5yGzu648ZtOlBpCZ63klwRYVm/8+rElJKEQqBMXBvSg2y/LEU4qX772JxFxnjxRu >GcokqFZMUloVglv2OThbvzK8NpSjlb7qQ2f4huad09/1DCjxH3KGpuKBXrs+mMcb >pYt8iWSZxiA2ukzgTawODfiF9YwGOb0g6FmT9/KUb4OxLfqFNhBv6GMrVE2AA+OJ >GbUnQS47a9o4xlLU78Rxn8UK3OpPD7LhQIEJOQ6ORZjlpSP84T9EVOkhTmuUcwr/ >NQyCQh+xtTExoeNEI9s= >-----END CERTIFICATE----- > > >2014-10-30T21:58:09Z DEBUG stderr= >2014-10-30T21:58:09Z DEBUG Starting external process >2014-10-30T21:58:09Z DEBUG args='/usr/bin/certutil' '-d' '/etc/httpd/alias' '-f' XXXXXXXX '-A' '-t' ',,' '-n' 'CN=adroot2-ADCS1-CA,DC=adroot2,DC=example,DC=com' '-a' '-i' '/tmp/tmpUfOoVn' >2014-10-30T21:58:09Z DEBUG Process finished, return code=0 >2014-10-30T21:58:09Z DEBUG stdout= >2014-10-30T21:58:09Z DEBUG stderr= >2014-10-30T21:58:09Z DEBUG Starting external process >2014-10-30T21:58:09Z DEBUG args='/usr/bin/certutil' '-d' '/etc/httpd/alias' '-f' XXXXXXXX '-A' '-t' 'CT,C,C' '-n' 'EXAMPLE.COM IPA CA' '-a' '-i' '/tmp/tmpxDZ3hP' >2014-10-30T21:58:09Z DEBUG Process finished, return code=0 >2014-10-30T21:58:09Z DEBUG stdout= >2014-10-30T21:58:09Z DEBUG stderr= >2014-10-30T21:58:09Z DEBUG duration: 0 seconds >2014-10-30T21:58:09Z DEBUG [11/27]: fixing RA database permissions >2014-10-30T21:58:09Z DEBUG duration: 0 seconds >2014-10-30T21:58:09Z DEBUG [12/27]: setting up signing cert profile >2014-10-30T21:58:09Z DEBUG duration: 0 seconds >2014-10-30T21:58:09Z DEBUG [13/27]: set certificate subject base >2014-10-30T21:58:09Z DEBUG duration: 0 seconds >2014-10-30T21:58:09Z DEBUG [14/27]: enabling Subject Key Identifier >2014-10-30T21:58:09Z DEBUG duration: 0 seconds >2014-10-30T21:58:09Z DEBUG [15/27]: enabling Subject Alternative Name >2014-10-30T21:58:09Z DEBUG duration: 0 seconds >2014-10-30T21:58:09Z DEBUG [16/27]: enabling CRL and OCSP extensions for certificates >2014-10-30T21:58:09Z DEBUG duration: 0 seconds >2014-10-30T21:58:09Z DEBUG [17/27]: setting audit signing renewal to 2 years >2014-10-30T21:58:09Z DEBUG caSignedLogCert.cfg profile validity range is 720 >2014-10-30T21:58:09Z DEBUG duration: 0 seconds >2014-10-30T21:58:09Z DEBUG [18/27]: configuring certificate server to start on boot >2014-10-30T21:58:09Z DEBUG Starting external process >2014-10-30T21:58:09Z DEBUG args='/bin/systemctl' 'is-enabled' 'pki-tomcatd.target' >2014-10-30T21:58:09Z DEBUG Process finished, return code=1 >2014-10-30T21:58:09Z DEBUG stdout=disabled > >2014-10-30T21:58:09Z DEBUG stderr= >2014-10-30T21:58:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' >2014-10-30T21:58:09Z DEBUG duration: 0 seconds >2014-10-30T21:58:09Z DEBUG [19/27]: restarting certificate server >2014-10-30T21:58:09Z DEBUG Starting external process >2014-10-30T21:58:09Z DEBUG args='/bin/systemctl' 'restart' 'pki-tomcatd@pki-tomcat.service' >2014-10-30T21:58:10Z DEBUG Process finished, return code=0 >2014-10-30T21:58:10Z DEBUG stdout= >2014-10-30T21:58:10Z DEBUG stderr= >2014-10-30T21:58:10Z DEBUG Starting external process >2014-10-30T21:58:10Z DEBUG args='/bin/systemctl' 'is-active' 'pki-tomcatd@pki-tomcat.service' >2014-10-30T21:58:10Z DEBUG Process finished, return code=0 >2014-10-30T21:58:10Z DEBUG stdout=active > >2014-10-30T21:58:10Z DEBUG stderr= >2014-10-30T21:58:10Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 300 >2014-10-30T21:58:12Z DEBUG The httpd proxy is not installed, wait on local port >2014-10-30T21:58:12Z DEBUG Waiting until the CA is running >2014-10-30T21:58:12Z DEBUG request 'https://rhel7-1.example.com:8443/ca/admin/ca/getStatus' >2014-10-30T21:58:12Z DEBUG request body '' >2014-10-30T21:58:24Z DEBUG request status 200 >2014-10-30T21:58:24Z DEBUG request reason_phrase u'OK' >2014-10-30T21:58:24Z DEBUG request headers {'date': 'Thu, 30 Oct 2014 21:58:24 GMT', 'content-length': '167', 'content-type': 'application/xml', 'server': 'Apache-Coyote/1.1'} >2014-10-30T21:58:24Z DEBUG request body '<?xml version="1.0" encoding="UTF-8" standalone="no"?><XMLResponse><State>1</State><Type>CA</Type><Status>running</Status><Version>10.1.2-3.el7</Version></XMLResponse>' >2014-10-30T21:58:24Z DEBUG The CA status is: running >2014-10-30T21:58:24Z DEBUG duration: 15 seconds >2014-10-30T21:58:24Z DEBUG [20/27]: requesting RA certificate from CA >2014-10-30T21:58:24Z DEBUG Starting external process >2014-10-30T21:58:24Z DEBUG args='/usr/bin/certutil' '-d' '/etc/httpd/alias' '-f' XXXXXXXX '-R' '-k' 'rsa' '-g' '2048' '-s' 'CN=IPA RA,O=EXAMPLE.COM' '-z' '/tmp/tmpIjgV8u' '-a' >2014-10-30T21:58:25Z DEBUG Process finished, return code=0 >2014-10-30T21:58:25Z DEBUG stdout= >Certificate request generated by Netscape certutil >Phone: (not specified) > >Common Name: IPA RA >Email: (not specified) >Organization: EXAMPLE.COM >State: (not specified) >Country: (not specified) > >-----BEGIN NEW CERTIFICATE REQUEST----- >MIICbDCCAVQCAQAwJzEUMBIGA1UEChMLRVhBTVBMRS5DT00xDzANBgNVBAMTBklQ >QSBSQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPY1cbEXtA2QxfdD >HfKIHiJZwg/9/qv8DcfpYayqmQkcqPaVSm2DPKwoPGg06z/BKKJtZgkE9dUjwZnn >/9Dfhyhfq6wF/VOcGd0LZvTpjYLu1QWRLwwMTh+G4YJEyHbIrt9pdBOZhEm1/yu6 >dzzWfk1Fd8YrzCn8ySe+t3REE0CrA4Qh1b+haE4z3GSq1UISx/TYbzFQJP5JB1tF >cQMGQDlyQWWSjCzKDm4BAxH8O2YoaCm5YExM+skDtsIj0ZZnFFh+8LVhZkcGAIFh >iTRCfrzc3jwG26xTkmisMQQ/3kxquDHkb8H7xlt3B6fLHaoPy92VY4TAghuSE8nb >lWr2f/ECAwEAAaAAMA0GCSqGSIb3DQEBBQUAA4IBAQDxmiMRL41QbovyDYWKhGj0 >oB3NWX45PUg4vGV+CMaCe2SAuleet9DdFrcHliZjZh8QB2gKUG/kAYw7TNjpxkdb >/xad0g7/znXe0g5ed288ntaOt3LMs8zTkOJvUioNwmR5NgELN58NrEMdI6qG5rDe >IO0L1vtCuX+vDKOlwZw5SQ4Bqb/21SMeqwktCNdTroO9oGS99WUGm9vsS66UrX50 >rnUymcOMtrTFnCx2+j0jUlITC52OoxaZy52vhQomJoA8nTGovhFNXPUxPVmajHyq >A38UWokEwdToFUv9HKNopX9+trP8uaBsmqFxW/aOgJnmk6wecTruQgGPQj9XyF9e >-----END NEW CERTIFICATE REQUEST----- > >2014-10-30T21:58:25Z DEBUG stderr= > >Generating key. This may take a few moments... > > >2014-10-30T21:58:25Z DEBUG Traceback (most recent call last): > File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 382, in start_creation > run_step(full_msg, method) > File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 372, in run_step > method() > File "/usr/lib/python2.7/site-packages/ipaserver/install/cainstance.py", line 1147, in __request_ra_certificate > self.requestId = item_node[0].childNodes[0].data >IndexError: list index out of range > >2014-10-30T21:58:25Z DEBUG [error] IndexError: list index out of range >2014-10-30T21:58:25Z DEBUG File "/usr/lib/python2.7/site-packages/ipaserver/install/installutils.py", line 646, in run_script > return_value = main_function() > > File "/usr/sbin/ipa-server-install", line 1170, in main > ca_signing_algorithm=options.ca_signing_algorithm) > > File "/usr/lib/python2.7/site-packages/ipaserver/install/cainstance.py", line 518, in configure_instance > self.start_creation(runtime=210) > > File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 382, in start_creation > run_step(full_msg, method) > > File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 372, in run_step > method() > > File "/usr/lib/python2.7/site-packages/ipaserver/install/cainstance.py", line 1147, in __request_ra_certificate > self.requestId = item_node[0].childNodes[0].data > >2014-10-30T21:58:25Z DEBUG The ipa-server-install command failed, exception: IndexError: list index out of range
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 1159086
: 952361