Bug 1543242
| Summary: | Regression in lightweight CA key replication | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Fraser Tweedale <ftweedal> |
| Component: | pki-core | Assignee: | Fraser Tweedale <ftweedal> |
| Status: | CLOSED ERRATA | QA Contact: | Asha Akkiangady <aakkiang> |
| Severity: | unspecified | Docs Contact: | Marc Muehlfeld <mmuehlfe> |
| Priority: | unspecified | ||
| Version: | 7.4 | CC: | enewland, ftweedal, mharmsen, myusuf |
| Target Milestone: | rc | Keywords: | Regression |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | pki-core-10.5.1-8.el7 | Doc Type: | No Doc Update |
| Doc Text: |
undefined
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2018-04-10 17:04:05 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Fraser Tweedale
2018-02-08 04:41:24 UTC
Gerrit reviews: - master: https://review.gerrithub.io/#/c/398881/ - DOGTAG_10_5_BRANCH: https://review.gerrithub.io/#/c/398882/ Upstream fix pushed:
master: 49825ff4eff1c85147e4906c020bcb4393a8d94b
DOGTAG_10_5_BRANCH: 2251f78c22b2e3b23450cdb274207893932cbd0b
version: pki-ca-10.5.1-8.el7.noarch pki-base-10.5.1-8.el7.noarch krb5-pkinit-1.15.1-18.el7.x86_64 pki-base-java-10.5.1-8.el7.noarch pki-server-10.5.1-8.el7.noarch pki-tools-10.5.1-8.el7.x86_64 pki-kra-10.5.1-8.el7.noarch ipa-server-4.5.4-10.el7.x86_64 ~~~~~~~~~~ On master: ~~~~~~~~~~ [root@master ~]# kinit admin Password for admin: [root@master ~]# ipa ca-find ------------ 1 CA matched ------------ Name: ipa Description: IPA CA Authority ID: 910b42aa-4517-47d7-ba87-b7f0528e8c1e Subject DN: CN=Certificate Authority,O=TESTRELM.TEST Issuer DN: CN=Certificate Authority,O=TESTRELM.TEST ---------------------------- Number of entries returned 1 ---------------------------- [root@master ~]# ipa ca-add testsubca1 --subject="CN=testsubca1,O=TESTRELM.TEST" --desc=testsubca1 ----------------------- Created CA "testsubca1" ----------------------- Name: testsubca1 Description: testsubca1 Authority ID: 7b14435f-c879-417a-a3a5-6285fa1da9f6 Subject DN: CN=testsubca1,O=TESTRELM.TEST Issuer DN: CN=Certificate Authority,O=TESTRELM.TEST Certificate: MIIDhjCCAm6gAwIBAgIBDjANBgkqhkiG9w0BAQsFADA4MRYwFAYDVQQKDA1URVNUUkVMTS5URVNUMR4wHAYDVQQDDBVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcNMTgwMjE0MTM1NjA1WhcNMzgwMjE0MTM1NjA1WjAtMRYwFAYDVQQKDA1URVNUUkVMTS5URVNUMRMwEQYDVQQDDAp0ZXN0c3ViY2ExMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2R5wIbSTdZLpyYdtUZ/I+xIGK43xLh2qHkkggITjQ6hoH0s/kiJYjRzeyWt9f9f2TThqDPSxTRFui0onwd9oJKPPTWvMosjfFYGW+jyVoN8LwmaIPxsU7uoLk68AfyNw14r2dKUaYYXGnoi/1Xo7SThKHkEKQw1oEXQF1oBmdbNz/Muwifo1LgoyXRmbkOhP1VOIpaw/zc1rCI1bG5e1Dov/NatMOpKi5Jgk5whP35ss04MQHQPu8QpuSwIv/Scj+caX+WNI0mJJ8JFDj708qVjM67KANsiLIBVKKkrCj3MvOzcNF9kQ7dwTaHH160ZdIC0oS60usUhQrYECkiIKCwIDAQABo4GlMIGiMB8GA1UdIwQYMBaAFBEyY+0D3ue8QctQSFMdaCVYmPURMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgHGMB0GA1UdDgQWBBR22ZCPtbBCwMDKfv8K3Tix6QZXczA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAGGI2h0dHA6Ly9pcGEtY2EudGVzdHJlbG0udGVzdC9jYS9vY3NwMA0GCSqGSIb3DQEBCwUAA4IBAQB/4UW/ZDAd9JwcvgTEyoKSpKQH1LuPoZP1rf9dLyvPYcWgXMFRA7YTLwG/BRR0wsAAhRQ4FyGzjgDoZErM8gR1wdpP1+Mc/Kc8krZx4gy+NDlRwMvLAnnASnEbMbNMRRJbMtYo9igD1hrl/FYJsg71EDhYRK0p4mnA+RnOkW3lUYy9v0pAAQoPW5Q9HGvNZALVg/5ZSGOT9N65+qrgLA2Quvl42+MvI7KeDkEbnYgh0WMcmjed/hMHZAuuyWVPwFjsnnVQeSoqs/s/A1dwQllnQa6l1S7a0oxFXLDG6NLrM2bh+nPMpYiZF0jbVlTuFZASAdcAWNCIx6lFzCRlQE+L [root@master ~]# ipa ca-find ------------- 2 CAs matched ------------- Name: ipa Description: IPA CA Authority ID: 44b80db0-cbe5-477e-bd07-a58732ed3f36 Subject DN: CN=Certificate Authority,O=TESTRELM.TEST Issuer DN: CN=Certificate Authority,O=TESTRELM.TEST Name: testsubca1 Description: testsubca1 Authority ID: 7b14435f-c879-417a-a3a5-6285fa1da9f6 Subject DN: CN=testsubca1,O=TESTRELM.TEST Issuer DN: CN=Certificate Authority,O=TESTRELM.TEST ---------------------------- Number of entries returned 2 ---------------------------- ~~~~~~~~~~ On Replica: ~~~~~~~~~~ [root@replica ~]# ipa ca-find ------------- 2 CAs matched ------------- Name: ipa Description: IPA CA Authority ID: 44b80db0-cbe5-477e-bd07-a58732ed3f36 Subject DN: CN=Certificate Authority,O=TESTRELM.TEST Issuer DN: CN=Certificate Authority,O=TESTRELM.TEST Name: testsubca1 Description: testsubca1 Authority ID: 7b14435f-c879-417a-a3a5-6285fa1da9f6 Subject DN: CN=testsubca1,O=TESTRELM.TEST Issuer DN: CN=Certificate Authority,O=TESTRELM.TEST ---------------------------- Number of entries returned 2 ---------------------------- [root@replica ~]# ipa cert-request test1.csr --ca=testsubca1 --add --principal=HTTP/replica.testrelm.test Issuing CA: testsubca1 Certificate: MIIENTCCAx2gAwIBAgIED/8AAjANBgkqhkiG9w0BAQsFADAtMRYwFAYDVQQKDA1URVNUUkVMTS5URVNUMRMwEQYDVQQDDAp0ZXN0c3ViY2ExMB4XDTE4MDIxNDE1MjUxNFoXDTIwMDIxNTE1MjUxNFowODEWMBQGA1UECgwNVEVTVFJFTE0uVEVTVDEeMBwGA1UEAwwVcmVwbGljYS50ZXN0cmVsbS50ZXN0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqISO3mIi7SmESaVVQCzrIuaJSQxwbGbrA/mAgmoMgqWOD5SpB8uvKblybmUaITS6Zuf4YcxW1NdmJnc8gYoY/GObabnhkYGn8MyV1U4fh+as/jikjGQxbs5PoopzVD7dTKma09GZuaRu6mLL1c6ym6gjqCftwUSGcXUliL6Nvjs30Wt1vXn9eFIsl2Pp8Ui2njTk41V3l2laixM8Fp5x2ItdLt0vnzZewzLjTvPoPrlH28HIAwp6wy5Len5ucXfxi5NQkqhgMLckF+3n5NO2YmoX5lruFSaSpMVkR2C3Y8h1bpReYxpVzO30TNnPfsCnbJG78JcmPKHN//AjThKagwIDAQABo4IBUDCCAUwwHwYDVR0jBBgwFoAU/x8yuGXNH7rgIvBbUcFjZuCu8ZAwPwYIKwYBBQUHAQEEMzAxMC8GCCsGAQUFBzABhiNodHRwOi8vaXBhLWNhLnRlc3RyZWxtLnRlc3QvY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBPAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMHgGA1UdHwRxMG8wbaA1oDOGMWh0dHA6Ly9pcGEtY2EudGVzdHJlbG0udGVzdC9pcGEvY3JsL01hc3RlckNSTC5iaW6iNKQyMDAxDjAMBgNVBAoMBWlwYWNhMR4wHAYDVQQDDBVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHQYDVR0OBBYEFDjiO5/uJqqewQO6l7OlZ005Z5ayMCAGA1UdEQQZMBeCFXJlcGxpY2EudGVzdHJlbG0udGVzdDANBgkqhkiG9w0BAQsFAAOCAQEAY2WMvTlYSrknEBiWOOopNyjRMwXmSPyHKHML+X7Ib6Qp+DuDgMxmJ7DpgUbcBoiXXj+R4iD3N0J3AcoU0sG49mFuyO/7vth4nE+2n++oHqAzZsiQD32tm0wuDQPjH7aXkCV0locwjGNOX4SJZtt3VPVVnkYsQNrEkvF5QdKZwuGmaYL1OttfYK+sKKGnhw2RRslDml0YQewTjdrXyU5h0KP1xiGaDElh/MzGaxd9iP/OgnP3zLXgE8AU9gVd12m75N+eHTmhjV3pxeArZV/a22lwVHNn5UUQiqr0GYRl+rBsOngNNpl7B8dFnkIJyX431Hy8tHXwr4wgMe01n7gnsg== Subject: CN=replica.testrelm.test,O=TESTRELM.TEST Subject DNS name: replica.testrelm.test Issuer: CN=testsubca1,O=TESTRELM.TEST Not Before: Wed Feb 14 15:25:14 2018 UTC Not After: Sat Feb 15 15:25:14 2020 UTC Serial number: 268369922 Serial number (hex): 0xFFF0002 - No authorityMonitor thread crash observed. - LWCA replication succeed. - Signing of cert on replica succeed (using subca created on master) Based on above observation, marking bug as verified. Add doc text. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:0925 |