Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1082663 - CA not start during ipa server install in pure IPv6 env
CA not start during ipa server install in pure IPv6 env
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: pki-core (Show other bugs)
7.0
Unspecified Unspecified
low Severity low
: rc
: 7.3
Assigned To: Ade Lee
Asha Akkiangady
Marc Muehlfeld
:
Depends On:
Blocks: 1081561
  Show dependency treegraph
 
Reported: 2014-03-31 11:15 EDT by Martin Kosek
Modified: 2016-11-04 01:18 EDT (History)
11 users (show)

See Also:
Fixed In Version: pki-core-10.3.2-3.el7
Doc Type: Bug Fix
Doc Text:
The IdM CA service now starts correctly on IPv6-only installations Previously, on systems only configured for IPv6, the *pki-tomcat* service was incorrectly bound to the IPv4 loopback device during Identity Management (IdM) installation. As a consequence, the certificate authority (CA) service failed to start. The IdM setup now binds on systems having only the IPv6 protocol configured, to the IPv6 loopback device. As a result, the CA service starts correctly.
Story Points: ---
Clone Of: 1081561
Environment:
Last Closed: 2016-11-04 01:18:26 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
evidence (10.73 KB, text/plain)
2016-09-21 07:33 EDT, Pavel Picka
no flags Details


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:2396 normal SHIPPED_LIVE pki-core bug fix and enhancement update 2016-11-03 09:55:03 EDT

  None (edit)
Comment 5 Matthew Harmsen 2016-01-06 17:10:08 EST
Per discussions in the RHEL 7.3 Triage meeting of 01/06/2016: priority low
Comment 6 Matthew Harmsen 2016-01-06 17:16:35 EST
Upstream ticket:
https://fedorahosted.org/pki/ticket/1717
Comment 7 Matthew Harmsen 2016-06-10 11:56:47 EDT
fixed by alee:

Added option to pkispawn to add pki_ajp_host in the tomcat section.

Delta compression using up to 8 threads. Compressing objects: 100% (27/27), done. Writing objects: 100% (33/33), 7.41 KiB | 0 bytes/s, done. Total 33 (delta 18), reused 0 (delta 0) To ​ssh://vakwetu@git.fedorahosted.org/git/pki.git

Checked into master:
* d77c0f15ad4d51af998b7ab89f7482b7d0b3a370
Comment 9 Martin Kosek 2016-06-13 02:53:00 EDT
Thank you? What needs to be done on FreeIPA/IdM side, to make this setup working? (Bug 1081561).
Comment 10 Endi Sukma Dewata 2016-06-13 10:03:30 EDT
Based on alee's patch I believe you'd have to add the following parameter into pkispawn configuration:

[Tomcat]
pki_ajp_host=::1
Comment 11 Pavel Picka 2016-09-21 07:33 EDT
Created attachment 1203236 [details]
evidence

Verified

4.4.0-12
Comment 12 Endi Sukma Dewata 2016-09-21 09:10:47 EDT
This bug was fixed by alee.
Comment 14 Ade Lee 2016-10-20 15:08:06 EDT
Looks look fine.
Comment 15 Ade Lee 2016-10-20 15:08:36 EDT
That is Docs look fine.
Comment 17 errata-xmlrpc 2016-11-04 01:18:26 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2396.html

Note You need to log in before you can comment on or make changes to this bug.