Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1215464

Summary: ipa-server-install fails when configuring CA
Product: Red Hat Enterprise Linux 6 Reporter: Dalibor Pospíšil <dapospis>
Component: tomcat6Assignee: David Knox <dknox>
Status: CLOSED CURRENTRELEASE QA Contact: tomcat-qe
Severity: medium Docs Contact:
Priority: medium    
Version: 6.7CC: dahorak, dapospis, jclere, mbukatov, mkosek, pkis
Target Milestone: rcKeywords: TestBlocker
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 1140855 Environment:
Last Closed: 2015-05-05 12:59:31 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dalibor Pospíšil 2015-04-26 21:27:27 UTC
+++ This bug was initially created as a clone of Bug #1140855 +++

Description of problem:
Attempting to install ipa-server with dns, but getting error:
Configuring NTP daemon (ntpd)
  [1/4]: stopping ntpd
  [2/4]: writing configuration
  [3/4]: configuring ntpd to start on boot
  [4/4]: starting ntpd
Done configuring NTP daemon (ntpd).
Configuring directory server for the CA (pkids): Estimated time 30 seconds
  [1/3]: creating directory server user
  [2/3]: creating directory server instance
  [3/3]: restarting directory server
Done configuring directory server for the CA (pkids).
Configuring certificate server (pki-cad): Estimated time 3 minutes 30 seconds
  [1/20]: creating certificate server user
  [2/20]: configuring certificate server instance
ipa         : CRITICAL failed to configure ca instance Command '/usr/bin/perl /usr/bin/pkisilent ConfigureCA -cs_hostname dhcp-24-151.brq.redhat.com -cs_port 9445 -client_certdb_dir /tmp/tmp-gogTS9 -client_certdb_pwd XXXXXXXX -preop_pin GK4oQNn3zQdslGyDVLB1 -domain_name IPA -admin_user admin -admin_email root@localhost -admin_password XXXXXXXX -agent_name ipa-ca-agent -agent_key_size 2048 -agent_key_type rsa -agent_cert_subject CN=ipa-ca-agent,O=TESTREALM -ldap_host dhcp-24-151.brq.redhat.com -ldap_port 7389 -bind_dn cn=Directory Manager -bind_password XXXXXXXX -base_dn o=ipaca -db_name ipaca -key_size 2048 -key_type rsa -key_algorithm SHA256withRSA -save_p12 true -backup_pwd XXXXXXXX -subsystem_name pki-cad -token_name internal -ca_subsystem_cert_subject_name CN=CA Subsystem,O=TESTREALM -ca_subsystem_cert_subject_name CN=CA Subsystem,O=TESTREALM -ca_ocsp_cert_subject_name CN=OCSP Subsystem,O=TESTREALM -ca_server_cert_subject_name CN=dhcp-24-151.brq.redhat.com,O=TESTREALM -ca_audit_signing_cert_subject_name CN=CA Audit,O=TESTREALM -ca_sign_cert_subject_name CN=Certificate Authority,O=TESTREALM -external false -clone false' returned non-zero exit status 255
Configuration of CA failed
:: [   FAIL   ] :: Command 'ipa-server-install --hostname=dhcp-24-151.brq.redhat.com -r TESTREALM -n brq.redhat.com -p Secret123 -P Secret123 -a Secret123 --unattended --ip-address 10.34.24.151' (Expected 0, got 1)

Version-Release number of selected component (if applicable):
sssd-1.11.6-29.el6.x86_64
ipa-server-3.0.0-42.el6.x86_64
389-ds-base-1.2.11.15-45.el6.x86_64
pki-ca-9.0.3-37.el6.noarch
tomcat6-6.0.24-78.el6_5

and also
sssd-1.12.4-31.el6.x86_64
ipa-server-3.0.0-46.el6.x86_64
389-ds-base-1.2.11.15-53.el6.x86_64
pki-ca-9.0.3-40.el6.noarch
tomcat6-6.0.24-88.el6

How reproducible:
always

Steps to Reproduce:
1. Install ipa-server-install --hostname=dhcp-24-151.brq.redhat.com -r TESTREALM -n brq.redhat.com -p Secret123 -P Secret123 -a Secret123 --unattended --ip-address 10.34.24.151


Actual results:
Getting error mentioned above

Expected results:
install ipa server successfully

Additional info:
selinux in permissive, no AVCs
From ipaserver-install.log:
2015-04-26T21:10:02Z DEBUG   [2/20]: configuring certificate server instance
2015-04-26T21:10:04Z DEBUG args=/usr/bin/perl /usr/bin/pkisilent ConfigureCA -cs_hostname dhcp-24-151.brq.redhat.com -cs_port 9445 -client_certdb_dir /tmp/tmp-gogTS9 -client_certdb_pwd XXXXXXXX -preop_pin GK4oQNn3zQdslGyDVLB1 -domain_name IPA -admin_user admin -admin_email root@localhost -admin_password XXXXXXXX -agent_name ipa-ca-agent -agent_key_size 2048 -agent_key_type rsa -agent_cert_subject CN=ipa-ca-agent,O=TESTREALM -ldap_host dhcp-24-151.brq.redhat.com -ldap_port 7389 -bind_dn cn=Directory Manager -bind_password XXXXXXXX -base_dn o=ipaca -db_name ipaca -key_size 2048 -key_type rsa -key_algorithm SHA256withRSA -save_p12 true -backup_pwd XXXXXXXX -subsystem_name pki-cad -token_name internal -ca_subsystem_cert_subject_name CN=CA Subsystem,O=TESTREALM -ca_subsystem_cert_subject_name CN=CA Subsystem,O=TESTREALM -ca_ocsp_cert_subject_name CN=OCSP Subsystem,O=TESTREALM -ca_server_cert_subject_name CN=dhcp-24-151.brq.redhat.com,O=TESTREALM -ca_audit_signing_cert_subject_name CN=CA Audit,O=TESTREALM -ca_sign_cert_subject_name CN=Certificate Authority,O=TESTREALM -external false -clone false
2015-04-26T21:10:04Z DEBUG stdout=libpath=/usr/lib64
#######################################################################
CRYPTO INIT WITH CERTDB:/tmp/tmp-gogTS9
tokenpwd:XXXXXXXX
#############################################
Attempting to connect to: dhcp-24-151.brq.redhat.com:9445
Exception in LoginPanel(): java.lang.NullPointerException
ERROR: ConfigureCA: LoginPanel() failure
ERROR: unable to create CA

#######################################################################

2015-04-26T21:10:04Z DEBUG stderr=Exception: Unable to Send Request:java.net.ConnectException: Connection refused
java.net.ConnectException: Connection refused
   at gnu.java.net.PlainSocketImpl.connect(libgcj.so.10)
   at java.net.Socket.connect(libgcj.so.10)
   at java.net.Socket.connect(libgcj.so.10)
   at java.net.Socket.<init>(libgcj.so.10)
   at java.net.Socket.<init>(libgcj.so.10)
   at HTTPClient.sslConnect(HTTPClient.java:300)
   at ConfigureCA.LoginPanel(ConfigureCA.java:244)
   at ConfigureCA.ConfigureCAInstance(ConfigureCA.java:1157)
   at ConfigureCA.main(ConfigureCA.java:1672)
java.lang.NullPointerException
   at ConfigureCA.LoginPanel(ConfigureCA.java:245)
   at ConfigureCA.ConfigureCAInstance(ConfigureCA.java:1157)
   at ConfigureCA.main(ConfigureCA.java:1672)

2015-04-26T21:10:04Z CRITICAL failed to configure ca instance Command '/usr/bin/perl /usr/bin/pkisilent ConfigureCA -cs_hostname dhcp-24-151.brq.redhat.com -cs_port 9445 -client_certdb_dir /tmp/tmp-gogTS9 -client_certdb_pwd XXXXXXXX -preop_pin GK4oQNn3zQdslGyDVLB1 -domain_name IPA -admin_user admin -admin_email root@localhost -admin_password XXXXXXXX -agent_name ipa-ca-agent -agent_key_size 2048 -agent_key_type rsa -agent_cert_subject CN=ipa-ca-agent,O=TESTREALM -ldap_host dhcp-24-151.brq.redhat.com -ldap_port 7389 -bind_dn cn=Directory Manager -bind_password XXXXXXXX -base_dn o=ipaca -db_name ipaca -key_size 2048 -key_type rsa -key_algorithm SHA256withRSA -save_p12 true -backup_pwd XXXXXXXX -subsystem_name pki-cad -token_name internal -ca_subsystem_cert_subject_name CN=CA Subsystem,O=TESTREALM -ca_subsystem_cert_subject_name CN=CA Subsystem,O=TESTREALM -ca_ocsp_cert_subject_name CN=OCSP Subsystem,O=TESTREALM -ca_server_cert_subject_name CN=dhcp-24-151.brq.redhat.com,O=TESTREALM -ca_audit_signing_cert_subject_name CN=CA Audit,O=TESTREALM -ca_sign_cert_subject_name CN=Certificate Authority,O=TESTREALM -external false -clone false' returned non-zero exit status 255
2015-04-26T21:10:04Z INFO   File "/usr/lib/python2.6/site-packages/ipaserver/install/installutils.py", line 614, in run_script
    return_value = main_function()

  File "/usr/sbin/ipa-server-install", line 942, in main
    subject_base=options.subject)

  File "/usr/lib/python2.6/site-packages/ipaserver/install/cainstance.py", line 626, in configure_instance
    self.start_creation(runtime=210)

  File "/usr/lib/python2.6/site-packages/ipaserver/install/service.py", line 358, in start_creation
    method()

  File "/usr/lib/python2.6/site-packages/ipaserver/install/cainstance.py", line 888, in __configure_instance
    raise RuntimeError('Configuration of CA failed')

2015-04-26T21:10:04Z INFO The ipa-server-install command failed, exception: RuntimeError: Configuration of CA failed