Bug 499014

Summary: DRM crashes. unable to renew server-cert via console (nethsm 2000)
Product: [Retired] Dogtag Certificate System Reporter: Chandrasekar Kannan <ckannan>
Component: ConsoleAssignee: Jack Magne <jmagne>
Status: CLOSED CURRENTRELEASE QA Contact: Chandrasekar Kannan <ckannan>
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: alee, benl, jgalipea, jmagne
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 499505 (view as bug list) Environment:
Last Closed: 2012-06-04 20:12:34 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 445047, 499505    

Description Chandrasekar Kannan 2009-05-04 19:44:16 UTC
1 - setup a kra instance with nethsm 2000
2 - use pkiconsole to login to kra
3 - goto "System Certificates/keys". select the kra server - cert.
4 - click add/renew
5 - when the wizard is ready to generate the server cert request , I see
    a message saying "server is unreachable".

And I see this in catalina.out

==> catalina.out <==
# Java VM: OpenJDK 64-Bit Server VM (1.6.0-b09 mixed mode linux-amd64)
# Problematic frame:
# V  [libjvm.so+0x36dd33]
#
# An error report file with more information is saved as:
# /tmp/hs_err_pid12644.log
#
# If you would like to submit a bug report, please visit:
#   http://icedtea.classpath.org/bugzilla
#

Comment 2 Jack Magne 2010-11-17 02:04:26 UTC
We had a similar bug reported to this for other subystems that did not specify the hsm token. Those bugs were fixed and cert renewal works just fine there. For this bug, I tested the same scenario on a very recent kra connected to the hsm2000. I was then able to successfully request a renewed kra server certificate just fine.  The progress made was past where the original server crash was noted. Marking modified for testing verification.

Comment 3 Kashyap Chamarthy 2010-12-06 04:05:40 UTC
VERIFIED.
CS8.1 nightly (x86_64) 
RHEL5.6(x86_64) nightly


1 - setup a kra instance with nethsm 2000
2 - use pkiconsole to login to kra
3 - goto "System Certificates/keys" -> "Local Certificates" -> select the kra SSL server - cert.
4 - click add/renew
5. wizard successfully generates certificate renewal request.