Bug 1082663

Summary: CA not start during ipa server install in pure IPv6 env
Product: Red Hat Enterprise Linux 7 Reporter: Martin Kosek <mkosek>
Component: pki-coreAssignee: Ade Lee <alee>
Status: CLOSED ERRATA QA Contact: Asha Akkiangady <aakkiang>
Severity: low Docs Contact: Marc Muehlfeld <mmuehlfe>
Priority: low    
Version: 7.0CC: alee, arubin, edewata, ftweedal, ksiddiqu, mharmsen, nkinder, pbokoc, ppicka, rcritten, xdong
Target Milestone: rc   
Target Release: 7.3   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: pki-core-10.3.2-3.el7 Doc Type: Bug Fix
Doc Text:
The IdM CA service now starts correctly on IPv6-only installations Previously, on systems only configured for IPv6, the *pki-tomcat* service was incorrectly bound to the IPv4 loopback device during Identity Management (IdM) installation. As a consequence, the certificate authority (CA) service failed to start. The IdM setup now binds on systems having only the IPv6 protocol configured, to the IPv6 loopback device. As a result, the CA service starts correctly.
Story Points: ---
Clone Of: 1081561 Environment:
Last Closed: 2016-11-04 05:18:26 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1081561    
Attachments:
Description Flags
evidence none

Comment 5 Matthew Harmsen 2016-01-06 22:10:08 UTC
Per discussions in the RHEL 7.3 Triage meeting of 01/06/2016: priority low

Comment 6 Matthew Harmsen 2016-01-06 22:16:35 UTC
Upstream ticket:
https://fedorahosted.org/pki/ticket/1717

Comment 7 Matthew Harmsen 2016-06-10 15:56:47 UTC
fixed by alee:

Added option to pkispawn to add pki_ajp_host in the tomcat section.

Delta compression using up to 8 threads. Compressing objects: 100% (27/27), done. Writing objects: 100% (33/33), 7.41 KiB | 0 bytes/s, done. Total 33 (delta 18), reused 0 (delta 0) To ​ssh://vakwetu.org/git/pki.git

Checked into master:
* d77c0f15ad4d51af998b7ab89f7482b7d0b3a370

Comment 9 Martin Kosek 2016-06-13 06:53:00 UTC
Thank you? What needs to be done on FreeIPA/IdM side, to make this setup working? (Bug 1081561).

Comment 10 Endi Sukma Dewata 2016-06-13 14:03:30 UTC
Based on alee's patch I believe you'd have to add the following parameter into pkispawn configuration:

[Tomcat]
pki_ajp_host=::1

Comment 11 Pavel Picka 2016-09-21 11:33:03 UTC
Created attachment 1203236 [details]
evidence

Verified

4.4.0-12

Comment 12 Endi Sukma Dewata 2016-09-21 13:10:47 UTC
This bug was fixed by alee.

Comment 14 Ade Lee 2016-10-20 19:08:06 UTC
Looks look fine.

Comment 15 Ade Lee 2016-10-20 19:08:36 UTC
That is Docs look fine.

Comment 17 errata-xmlrpc 2016-11-04 05:18:26 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2396.html