Bug 1462563

Summary: Enabling CA with nuxwdog fails when CA is configured with HSM
Product: Red Hat Enterprise Linux 7 Reporter: Asha Akkiangady <aakkiang>
Component: pki-coreAssignee: Ade Lee <alee>
Status: CLOSED NOTABUG QA Contact: Asha Akkiangady <aakkiang>
Severity: urgent Docs Contact:
Priority: urgent    
Version: 7.4CC: alee, mharmsen, msauton, tlavigne
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1480383 (view as bug list) Environment:
Last Closed: 2017-09-27 00:34:26 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1480383    

Comment 2 Asha Akkiangady 2017-06-18 22:57:58 UTC
The pki-tomcatd-nuxwdog service did not ask for HSM password.

Comment 3 Asha Akkiangady 2017-07-17 17:43:49 UTC
The fix is required for CC set-up. Can we have this bz fixed in RHEL 7.4 z-stream update 1?

Comment 4 Ade Lee 2017-08-10 19:39:43 UTC
When you have an HSM, the following parameter needs to be added to CS.cfg:

cms.tokenList=<TOKEN_NAME>

For instance, if the token password in password.conf is specified as 
hardware-NHSM-RPATTATH-SOFTCARD=SECret.456

Then the entry will look like this:
cms.tokenList=NHSM-RPATTATH-SOFTCARD

When this is added, nuxwdog will prompt for the password to hardware-NHSM-RPATTATH-SOFTCARD on startup.


This additional parameter needs to added to documentation and/or knowledge base article.  It will be added to the man page for pki-server-nuxwdog in RHEL 7.5.

Comment 5 Ade Lee 2017-08-10 19:40:21 UTC
Propose that this bug be closed for RHEL 7.4