Bug 1083878
| Summary: | Proxy change required on Master IPA Server to allow IPA Replica when using Dogtag | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 6 | Reporter: | Martin Kosek <mkosek> |
| Component: | ipa | Assignee: | Martin Kosek <mkosek> |
| Status: | CLOSED ERRATA | QA Contact: | Namita Soman <nsoman> |
| Severity: | high | Docs Contact: | |
| Priority: | medium | ||
| Version: | 6.6 | CC: | ksiddiqu, rcritten |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | ipa-3.0.0-38.el6 | Doc Type: | Bug Fix |
| Doc Text: |
Cause: When IdM PKI clone in RHEL-7.0 is being installed, it needs to access /ca/ee/ca/profileSubmit URI on the IdM server it replicates from. However, IdM in RHEL-6 does not export this URI in the httpd proxy configuration.
Consequence: Installation of IdM replica with PKI component in RHEL-7.0 fails when installed against a RHEL-6 master.
Fix: /ca/ee/ca/profileSubmit URI was added to RHEL-6 IdM proxy configuration.
Result: IdM in RHEL-7.0 with PKI component can be installed as a replica of RHEL-6 server.
|
Story Points: | --- |
| Clone Of: | 1080865 | Environment: | |
| Last Closed: | 2014-10-14 07:32:38 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1080865 | ||
| Bug Blocks: | |||
|
Description
Martin Kosek
2014-04-03 07:15:48 UTC
Fixed upstream: master: https://fedorahosted.org/freeipa/changeset/6ecc4600e9370a637916360396f18699e4b7f59b/ ipa-3-3: https://fedorahosted.org/freeipa/changeset/8e8a020f8d2476cca321349fa24db4bee95270d8/ Verified SanityOnly. Verification steps taken from https://bugzilla.redhat.com/show_bug.cgi?id=1080865#c5 IPA Version: ============ [root@hp-bl280cg6-01 ~]# rpm -q ipa-server ipa-server-3.0.0-42.el6.x86_64 [root@hp-bl280cg6-01 ~]# [root@hp-bl280cg6-01 ~]# grep /ca/ee/ca/profileSubmit /etc/httpd/conf.d/ipa-pki-proxy.conf <LocationMatch "^/ca/ee/ca/checkRequest|^/ca/ee/ca/getCertChain|^/ca/ee/ca/getTokenInfo|^/ca/ee/ca/tokenAuthenticate|^/ca/ocsp|^/ca/ee/ca/updateNumberRange|^/ca/ee/ca/getCRL|^/ca/ee/ca/profileSubmit"> [root@hp-bl280cg6-01 ~]# --------------------------------------------------------- [ PASS ] Install IPA REPLICA Server [ PASS ] Installing CA Replica with --no-host-dns option [ PASS ] Installing CA Replica without --no-host-dns option [ PASS ] Bugzilla 1040009 -- Automatic CA subsystem certificate renewal is broken on CA clones [ PASS ] /ipa-server/rhel66/ipa-ca-install Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2014-1383.html |