Bug 504292

Summary: getting registration error with sslCACert configured to non default location
Product: Red Hat Enterprise Linux 5 Reporter: Jan Hutař <jhutar>
Component: rhn-client-toolsAssignee: Pradeep Kilambi <pkilambi>
Status: CLOSED ERRATA QA Contact: Red Hat Satellite QA List <satqe-list>
Severity: medium Docs Contact:
Priority: medium    
Version: 5.4Keywords: Regression
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-09-02 11:21:23 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 500798    

Description Jan Hutař 2009-06-05 13:30:04 UTC
Description of problem:
I have configured sslCACert option and when I try to register using rhn_register TUI/GUI (rhnreg_ks seems to work fine), I'm getting error as shown below.


Version-Release number of selected component (if applicable):
rhn-setup-0.4.20-5.el5.noarch


How reproducible:
always


Steps to Reproduce:
1. # grep sslCACert= /etc/sysconfig/rhn/up2date
sslCACert=/etc/sysconfig/rhn/RHN-ORG-TRUSTED-SSL-CERT
2. # rhn_register


Actual results:
┌──────────────┤ Fatal Error ├──────────────┐
│                                           │
│ ERROR: can not find RHNS CA file:         │
│ /usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT   │
│                                           │
│ Please verify the value of sslCACert in   │
│ /etc/sysconfig/rhn/up2date                │
│                                           │
│                  ┌────┐                   │
│                  │ OK │                   │
│                  └────┘                   │


Expected results:
no error, same as in previous version rhn-setup-0.4.19-17.el5.noarch

Comment 2 Pradeep Kilambi 2009-06-05 17:00:28 UTC
is it the right cert? meaning does the cert and the server match?

Comment 3 Jan Hutař 2009-06-08 03:43:43 UTC
Hello. Yes, it is a right cert. I have checked thad again (also, rhnreg_ks works):

# wget -O /etc/sysconfig/rhn/RHN-ORG-TRUSTED-SSL-CERT https://sputnik-stage.brq.redhat.com/pub/RHN-ORG-TRUSTED-SSL-CERT --no-check-certificate
[...]
05:37:32 (22.9 MB/s) - `/etc/sysconfig/rhn/RHN-ORG-TRUSTED-SSL-CERT' saved [5269/5269]

# grep sslCACert= /etc/sysconfig/rhn/up2date
sslCACert=/etc/sysconfig/rhn/RHN-ORG-TRUSTED-SSL-CERT
# grep serverURL= /etc/sysconfig/rhn/up2date
serverURL=https://sputnik-stage.brq.redhat.com/XMLRPC

Comment 12 errata-xmlrpc 2009-09-02 11:21:23 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHBA-2009-1354.html