Red Hat Bugzilla – Bug 1318186
Misleading error message during external-ca IPA master install
Last modified: 2017-08-01 05:37:23 EDT
Description of problem: During second attempt of IPA external-ca install after first successful attempt, following error message shown which is misleading. ipa.ipapython.install.cli.install_tool(Server): ERROR Failed to load /root/ipa-ca/ipa.crt Honza helped me to figured out the cause for this. Here, uninstallation of IPA external-ca was not removing the certs from /etc/httpd/alias which is already reported in https://fedorahosted.org/freeipa/ticket/4639. But instead of error message "Failed to load /root/ipa-ca/ipa.crt ", we expect error message like "(SEC_ERROR_REUSED_ISSUER_AND_SERIAL) You are attempting to import a cert with the same issuer/serial as an existing cert" Also warning message is not logged in ipaserver-install.log . Version-Release number of selected component (if applicable): [root@auto-hv-01-guest02 ~]# rpm -q ipa-server ipa-server-4.2.0-15.el7_2.10.x86_64 [root@auto-hv-01-guest02 ~]# How reproducible: Always Steps to Reproduce: 1. Installl IPA with external-ca 2. Uninstall IPA 3. Install IPA with external-ca again Actual results: Installation of IPA fails in second attempt Expected results: Installation of IPA should be successful in second attempt also Additional info: 1. After removing the certs from /etc/httpd/alias, able to install IPA successfully.
Upstream ticket: https://fedorahosted.org/freeipa/ticket/4639
*** Bug 1340096 has been marked as a duplicate of this bug. ***
I have encountered same error message in RHEL 7.3. Any plan of fixing this ?
Fixed upstream ipa-4-5: https://pagure.io/freeipa/c/cf188c8513c6b36a0724866025ddc220683de8dc https://pagure.io/freeipa/c/f788e3e36bcaefc7d94c92895916246681e64291 master: https://pagure.io/freeipa/c/bbd18cf10f2e67e5205a3a3bee883272e89c0042 https://pagure.io/freeipa/c/e263cb46cba604421d5ed2e1dbf5dd1d66ce0221
Fixed upstream master: https://pagure.io/freeipa/c/5f5a3b29dba7cc736ba334aefb55484baeefeb76 ipa-4-5: https://pagure.io/freeipa/c/471dfcbe1cc3f319da788add3661cb6d63e3c0f0
Created attachment 1285980 [details] console logs
verified on ipa-server-4.5.0-15.el7.x86_64 too. Installation logs are attached.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:2304