Bug 1452617
| Summary: | Unable to create IPA Sub CA | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Abhijeet Kasurde <akasurde> | ||||
| Component: | pki-core | Assignee: | Fraser Tweedale <ftweedal> | ||||
| Status: | CLOSED ERRATA | QA Contact: | Abhijeet Kasurde <akasurde> | ||||
| Severity: | unspecified | Docs Contact: | |||||
| Priority: | unspecified | ||||||
| Version: | 7.4 | CC: | akasurde, ftweedal, ksiddiqu, mharmsen, pvoborni, rcritten, tscherf | ||||
| Target Milestone: | rc | Keywords: | Regression, TestBlocker | ||||
| Target Release: | --- | ||||||
| Hardware: | Unspecified | ||||||
| OS: | Unspecified | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | pki-core-10.4.1-7.el7 | Doc Type: | No Doc Update | ||||
| Doc Text: |
(Fixed a regression only introduced in 10.4 and
found by QE)
|
Story Points: | --- | ||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2017-08-01 22:52:53 UTC | Type: | Bug | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Attachments: |
|
||||||
|
Description
Abhijeet Kasurde
2017-05-19 10:48:56 UTC
ipa: ERROR: No valid Negotiate header in server response is not an error related to Sub CA but more for session handling and authentication. So in theory on this machine every ipa CLI command should give you this error. Does: systemctl restart gssproxy.service systemctl restart httpd.service help? If so. Is it really just after clean ipa install? Isn't there update step or something? Ideally a beaker job if it is available. (In reply to Petr Vobornik from comment #3) > ipa: ERROR: No valid Negotiate header in server response > > is not an error related to Sub CA but more for session handling and > authentication. So in theory on this machine every ipa CLI command should > give you this error. > > Does: > systemctl restart gssproxy.service > systemctl restart httpd.service > > help? > After restarting error disappeared, but now there is new error [root@ipaserver01 ~]# echo Secret123 | kinit admin Password for admin: [root@ipaserver01 ~]# ipa ca-add Name: SampleCA Subject DN: CN=SampleCA,DN=testrelm.test ipa: ERROR: Request failed with status 400: Non-2xx response from CA REST API: 400. java.lang.IllegalArgumentException: Invalid Subject DN: CN=SampleCA,DN=testrelm.test [root@ipaserver01 ~]# ipactl status Directory Service: RUNNING krb5kdc Service: RUNNING kadmin Service: RUNNING named Service: RUNNING httpd Service: RUNNING ipa-custodia Service: RUNNING ntpd Service: RUNNING pki-tomcatd Service: RUNNING ipa-otpd Service: RUNNING ipa-dnskeysyncd Service: RUNNING ipa: INFO: The ipactl command was successful > If so. Is it really just after clean ipa install? Isn't there update step or > something? > IPA server installation is clean installation. There is no update or upgrade. > Ideally a beaker job if it is available. Here is link of CI job - https://platform-stg-jenkins.rhev-ci-vms.eng.rdu2.redhat.com/job/ipa-rhel-7.4-candidate-runtest-subca-pytest/21/testReport/ The Subject DN "CN=SampleCA,DN=testrelm.test" is invalid (there is no "DN" attribute). So there is not really a bug; but we should detect and handle this error gracefully. (In reply to Fraser Tweedale from comment #5) > The Subject DN "CN=SampleCA,DN=testrelm.test" is invalid > (there is no "DN" attribute). So there is not really a bug; > but we should detect and handle this error gracefully. Yes, I agree Subject DN is not valid. But, command still fails with correct Subject DN. # ipa ca-add Name: SampleCA1 Subject DN: CN=SampleCA1,O=testrelm.test ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500. Error creating CA: Error creating lightweight CA certificate: java.lang.NullPointerException Huh. Can you provide a traceback, Abhijeet? Confirmed. It is regression in Dogtag. Patch imminent. Upstream patch committed (2866f6195eb49012cf7c42089a9fbf1be819129a). Verified using IPA and PKI Server version:: ipa-server-4.5.0-14.el7.x86_64 pki-server-10.4.1-7.el7.noarch Marking BZ as verified. See attachments for console.log. Created attachment 1284331 [details]
console.log
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:2110 |