Bug 1082663 - CA not start during ipa server install in pure IPv6 env
Summary: CA not start during ipa server install in pure IPv6 env
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: pki-core   
(Show other bugs)
Version: 7.0
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: rc
: 7.3
Assignee: Ade Lee
QA Contact: Asha Akkiangady
Marc Muehlfeld
URL:
Whiteboard:
Keywords:
Depends On:
Blocks: 1081561
TreeView+ depends on / blocked
 
Reported: 2014-03-31 15:15 UTC by Martin Kosek
Modified: 2016-11-04 05:18 UTC (History)
11 users (show)

Fixed In Version: pki-core-10.3.2-3.el7
Doc Type: Bug Fix
Doc Text:
The IdM CA service now starts correctly on IPv6-only installations Previously, on systems only configured for IPv6, the *pki-tomcat* service was incorrectly bound to the IPv4 loopback device during Identity Management (IdM) installation. As a consequence, the certificate authority (CA) service failed to start. The IdM setup now binds on systems having only the IPv6 protocol configured, to the IPv6 loopback device. As a result, the CA service starts correctly.
Story Points: ---
Clone Of: 1081561
Environment:
Last Closed: 2016-11-04 05:18:26 UTC
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
evidence (10.73 KB, text/plain)
2016-09-21 11:33 UTC, Pavel Picka
no flags Details


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:2396 normal SHIPPED_LIVE pki-core bug fix and enhancement update 2016-11-03 13:55:03 UTC

Comment 5 Matthew Harmsen 2016-01-06 22:10:08 UTC
Per discussions in the RHEL 7.3 Triage meeting of 01/06/2016: priority low

Comment 6 Matthew Harmsen 2016-01-06 22:16:35 UTC
Upstream ticket:
https://fedorahosted.org/pki/ticket/1717

Comment 7 Matthew Harmsen 2016-06-10 15:56:47 UTC
fixed by alee:

Added option to pkispawn to add pki_ajp_host in the tomcat section.

Delta compression using up to 8 threads. Compressing objects: 100% (27/27), done. Writing objects: 100% (33/33), 7.41 KiB | 0 bytes/s, done. Total 33 (delta 18), reused 0 (delta 0) To ​ssh://vakwetu@git.fedorahosted.org/git/pki.git

Checked into master:
* d77c0f15ad4d51af998b7ab89f7482b7d0b3a370

Comment 9 Martin Kosek 2016-06-13 06:53:00 UTC
Thank you? What needs to be done on FreeIPA/IdM side, to make this setup working? (Bug 1081561).

Comment 10 Endi Sukma Dewata 2016-06-13 14:03:30 UTC
Based on alee's patch I believe you'd have to add the following parameter into pkispawn configuration:

[Tomcat]
pki_ajp_host=::1

Comment 11 Pavel Picka 2016-09-21 11:33 UTC
Created attachment 1203236 [details]
evidence

Verified

4.4.0-12

Comment 12 Endi Sukma Dewata 2016-09-21 13:10:47 UTC
This bug was fixed by alee.

Comment 14 Ade Lee 2016-10-20 19:08:06 UTC
Looks look fine.

Comment 15 Ade Lee 2016-10-20 19:08:36 UTC
That is Docs look fine.

Comment 17 errata-xmlrpc 2016-11-04 05:18:26 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2396.html


Note You need to log in before you can comment on or make changes to this bug.