Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: Running ipa-server-install on Fedora rawhide fails with Configuring certificate server (pki-tomcatd): Estimated time 3 minutes 30 seconds [1/22]: creating certificate server user [2/22]: configuring certificate server instance ipa : CRITICAL failed to configure ca instance Command '/usr/sbin/pkispawn -s CA -f /tmp/tmpz9dOsT' returned non-zero exit status 1 Configuration of CA failed Version-Release number of selected component (if applicable): pki-server-10.2.0-0.1.fc21.noarch jettison-1.3.4-3.fc21.noarch How reproducible: Seen once, assume deterministic. Steps to Reproduce: 1. Run ipa-server-install with freeipa-server and dependencies installed from Fedora rawhide repo. Actual results: ipa : CRITICAL failed to configure ca instance Command '/usr/sbin/pkispawn -s CA -f /tmp/tmpz9dOsT' returned non-zero exit status 1 and /var/log/ipaserver-install.log ends with 2014-05-30T13:27:41Z DEBUG Starting external process 2014-05-30T13:27:41Z DEBUG args=/usr/sbin/pkispawn -s CA -f /tmp/tmpz9dOsT 2014-05-30T13:27:42Z DEBUG Process finished, return code=1 2014-05-30T13:27:42Z DEBUG stdout=Loading deployment configuration from /tmp/tmpz9dOsT. Installing CA into /var/lib/pki/pki-tomcat. Storing deployment configuration into /etc/sysconfig/pki/tomcat/pki-tomcat/ca/deployment.cfg. Installation failed. 2014-05-30T13:27:42Z DEBUG stderr=pkispawn : WARNING ....... Dangling symlink '/var/lib/pki/pki-tomcat/common/lib/jettison.jar'-->'/usr/share/java/jettison.jar' 2014-05-30T13:27:42Z CRITICAL failed to configure ca instance Command '/usr/sbin/pkispawn -s CA -f /tmp/tmpz9dOsT' returned non-zero exit status 1 2014-05-30T13:27:42Z DEBUG File "/usr/lib/python2.7/site-packages/ipaserver/install/installutils.py", line 638, in run_script return_value = main_function() File "/usr/sbin/ipa-server-install", line 1074, in main dm_password, subject_base=options.subject) File "/usr/lib/python2.7/site-packages/ipaserver/install/cainstance.py", line 478, in configure_instance self.start_creation(runtime=210) File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 364, in start_creation method() File "/usr/lib/python2.7/site-packages/ipaserver/install/cainstance.py", line 604, in __spawn_instance raise RuntimeError('Configuration of CA failed') 2014-05-30T13:27:42Z DEBUG The ipa-server-install command failed, exception: RuntimeError: Configuration of CA failed Expected results: No error. Additional info: The /usr/share/java/jettison.jar does not exist. It is now in /usr/share/java/jettison/jettison.jar, it seems.
(In reply to Jan Pazdziora from comment #0) > The /usr/share/java/jettison.jar does not exist. It is now in > /usr/share/java/jettison/jettison.jar, it seems. Running ln -sf jettison/jettison.jar /usr/share/java/jettison.jar before ipa-server-install makes all the 22 steps pass.
Upstream ticket: https://fedorahosted.org/pki/ticket/1030
The SRPM utilized in this bug/ticket was built by me on 2013-12-19 22:11:25, and contained the following changelog message: * Fri Nov 22 2013 Dogtag Team <pki-devel> 10.2.0-0.1 - Updated version number to 10.2.0-0.1. - Added option to build without server packages. However, the current source on the master branch contains the following changelog message: * Fri Nov 22 2013 Dogtag Team <pki-devel> 10.2.0-0.1 - Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package. Therefore, it is my belief that since 'Jettison' has been replaced by 'Jackson', and upgrade scripts have been provided to deal with legacy instances, this problem should go away once ​PKI TRAC Ticket #1029 - pki-core FTBFS has been resolved, and the next build has been successfully generated. It is an unfortunate coincidence that the SRPM changelog message is dated the same date as the source changelog message and each contains a slightly different message. I will leave this bug in the assigned state until such time as a valid new build can be tested to verify that this problem is no longer an issue.
My run on Fedora rawhide no longer seems to fail. Is that expected? Can you provide Fixed In Version if the issue was in fact addressed? Thank you, Jan
NOTE: Although rawhide is currently F22, I believe that this issue was originally fixed by "https://fedorahosted.org/pki/ticket/1029 PKI TRAC Ticket #1029 - pki-core FTBFS" as documented in "https://fedorahosted.org/pki/ticket/1030 PKI TRAC Ticket #1030 - ipa-server-install fails due to Dangling symlink '/var/lib/pki/pki-tomcat/common/lib/jettison.jar'--> '/usr/share/java/jettison.jar'".
This bug appears to have been reported against 'rawhide' during the Fedora 22 development cycle. Changing version to '22'. More information and reason for this action is here: https://fedoraproject.org/wiki/Fedora_Program_Management/HouseKeeping/Fedora22
Fedora 22 changed to end-of-life (EOL) status on 2016-07-19. Fedora 22 is no longer maintained, which means that it will not receive any further security or bug fix updates. As a result we are closing this bug. If you can reproduce this bug against a currently maintained version of Fedora please feel free to reopen this bug against that version. If you are unable to reopen this bug, please file a new report against the current release. If you experience problems, please add a comment to this bug. Thank you for reporting this bug and we are sorry it could not be fixed.