Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1558139

Summary: CRMFPopClient ignores -n option
Product: Red Hat Enterprise Linux 8 Reporter: Geetika Kapoor <gkapoor>
Component: pki-coreAssignee: RHCS Maintainers <rhcs-maint>
Status: CLOSED UPSTREAM QA Contact: Asha Akkiangady <aakkiang>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 8.3CC: ascheel, cfu, mharmsen
Target Milestone: rcFlags: pm-rhel: mirror+
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-01-07 16:29:25 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Geetika Kapoor 2018-03-19 17:22:16 UTC
Description of problem:

Refer Document: http://pki.fedoraproject.org/wiki/Certificate_Key_Archival
This doc uses -m -n -u -r all in one cli.

CRMFPopClient -v -d test -p SECret.123 -n CN=testuser -f caSigningUserCert -b transport.pem -m $HOSTNAME:8080  -u testuser23 -r testuser23

In runtime, it fails with error:


Request ID: 157
Request Status: rejected
Reason: Request 157 Rejected - Subject Name Not Matched UID=testuser23

-- If we test the same with caUserCert , which uses subject dn format as uid=*.

CRMFPopClient -v -d test -p SECret.123 -n UID=testuser00 -f caDualCert -b transport.pem -m $HOSTNAME:8080  -u testuser23 -r testuser23

It works and a request gets created with CA Agent page but that request has subject dn as:

 Certificate Pretty Print

    Certificate: 
        Data: 
            Version:  v3
            Serial Number: 0xCDB6EED
            Signature Algorithm: SHA512withRSA - 1.2.840.113549.1.1.13
            Issuer: CN=CA Signing Certificate,OU=pki-ca-Mar8,O=Example-rhcs92-CA
            Validity: 
                Not Before: Monday, March 19, 2018 1:10:49 PM EDT America/New_York
                Not  After: Saturday, September 15, 2018 1:10:49 PM EDT America/New_York
            Subject: UID=testuser23

==> Ideally it should be "UID=testuser00" i.e input provided to option -n


Version-Release number of selected component (if applicable):

10.5

How reproducible:

always 

Steps to Reproduce:
1. Use this document and follow the process http://pki.fedoraproject.org/wiki/Certificate_Key_Archival
2. 
3.

Actual results:

failure.

Expected results:

It should work


Additional info:

Attaching logs and verbose output


[root@nocp1 ~]# CRMFPopClient -v -d test -p SECret.123 -n CN=testuser -f caSigningUserCert -b transport.pem -m $HOSTNAME:8080  -u testuser23 -r testuser23
Initializing security database: test
Loading transport certificate
Parsing subject DN
RDN: CN=testuser
Generating key pair
Keypair private key id: -617debb998d9c83edf3530390019b757a6f54219
Using key wrap algorithm: AES/CBC/PKCS5Padding
Creating certificate request
Creating signer
Creating POP
Creating CRMF request
Submitting CRMF request to nocp1.idm.lab.eng.rdu2.redhat.com:8080
Opening http://nocp1.idm.lab.eng.rdu2.redhat.com:8080/ca/ee/ca/profileSubmit?cert_request_type=crmf&cert_request=MIIIezCCCHcwggdbAgEBMIIBQIABAqUVMBMxETAPBgNVBAMTCHRlc3R1c2VypoIB%0D%0AIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzvq0D8oHCk3lmg6p%2F4i98E%2BM%0D%0AUEWb%2B90X%2FVdHYLF8jLHuXDnUk7%2BLsUTv9g%2Boa03fCt05xDDBEgkv%2FB%2FCri5I5mEp%0D%0A5BoMOjxiI%2FJPIe%2FCaJToUcPheSl7LBVeU5GX96GOLseVWh73sN6hMm4HjMAnLTqH%0D%0APHsKKWaAeG2xj8xQYmTie51okNekkAO4dQnDh4Ebw%2B1VcFQpp7n8A3W7cU22uqKK%0D%0ACvyjB4wl4N5D9Y2wH5YYBjTf7aaA7EiY4IK0%2FCcJG4xPka1KQbysrXS8STv6LZMo%0D%0Avuzxtl1LYHS6mh7bfCUeO5eIa9lRT7kVYgB5JHcmE1zfM1g2hk5%2FGgMJS2NSowID%0D%0AAQABMIIGEDCCBgwGCSsGAQUFBwUBBKCCBf0wggX5oR0GCWCGSAFlAwQBAgQQFJNx%0D%0AxkZsivUNxKRuCCE4t4KCAQEAjdKhpEP9aVI%2FBDxM%2F%2FYAD6cXa%2BJKJguodaFdsZXS%0D%0AAFpoLdHE9mDEFAR6km9S5Q07sFn79MC6b8VmQ6eJP%2BpdA0vLIIfS0Bl1yRf4wrJK%0D%0Ap3dMgNUEqIfmN2YxZ2jDfY5gkIT7dV0uQoQTUMOANjeOOwAYNnj7uAsyE3tPjHg8%0D%0A4CP4RIY5LyFZns5Ze%2Fxj9FGJPIjBGHazAWKZc1d6aeefv7Z9Uh%2BJar0szNlqBuaJ%0D%0A1NafJUYIVlpmB0%2FfvaYSPTlGAD2QDZ5osm8NHAxPI2jWHzBIcgIolFYl8s2vL4Mr%0D%0AumJEFSdZUJJTsGr2GutEGyGGvzqcHrZY0OIiXdFhf12SHQOCBNEAy5GlfCMeJYD4%0D%0AepZ07T11ziaCSq85aBbYrMJkryLyDXxuxseXR62DUvHvMGjsvJcAYVhSuMfYYCmy%0D%0AKk49yvUrNSy55%2FLB0jvFnuPmHyHaIKOQrJ57bRy0LxACBb0KOiB%2B%2B5CxxWfAJHj6%0D%0AB28Fpl2b2425r1kBo8CHYQfBPMdBEWqrIAoyt3u1CtsHR2KFHZGvTDrxQSFr6IcA%0D%0AXPWs%2Fi37zh4KDGvKGPAXDefj92sovs88tgiyq6wMC4phQcTeVu9yImYWqHbmH0xO%0D%0ANtF%2FjHweHBu%2B4SFzNShtj0vfWtZ0Z3K04wDeh0XCINitoq3zg%2Ftjwdg7t9qjB2D1%0D%0ARhxDiqN1U8aENUnB4WI3g4EkTvNIJU4BQ3Ll6A%2FttURe%2FM1eF3EZlMXwh5aHX%2BBq%0D%0AJEGjEiMIefiaoeVs1cEF6OkJknYG3fGM%2B%2Fh2XMsOx1hg8IOI1ymv9V1SKZL8w9lG%0D%0AbUP6cIgnLZGZd04tds98I15co3Ota%2FGfvbZHayHy2%2FC6qo65NupnES5bEcAnfc2I%0D%0A7oI4WLjfRprdhrwbklDx2MuY%2Fqes2V%2BmFJNAiI%2BNC0GpmqIU1IXuCXwyGcqyWQV9%0D%0AKmYi5PBz0nmZhcRdeKD8w2APYqHeRDaB4VZxGGJZIky573w9SSQVc0KRXeO4gc6L%0D%0AHteE1sQmz3TGW9E5un4LlGmkUiqEurPqIKq4IneH8g%2BoqBj268N5%2BezZHE2X3keU%0D%0AsieLW33kw1Lla4ONh8OdByR1oX%2B9RmYHaJQMlvOTLamor77xSw3mF2eBS7jyoqmH%0D%0A3qeJYcV4Oi0IsPwy%2BzdycCt3ep9eBnbqy%2FhPcgce4artCAqLFXZaKjBuCkmwINKL%0D%0ADiKnq0pN%2Fv2BTI2hIUpkuXV0rG79vAguH0C67qwb2GLEv4F28yQckl6UbJ%2F7rRNX%0D%0A1Hb%2B33pK1%2BEpNKudc3E5deVt8wR6h9RQGk3g68zTf2xSZf7gKSIiJG9oVNVCVZfh%0D%0AXejmUnPw5ZamAPswqXI%2FIECK%2BWlHxjOSQ03UfUkp4lQtBoLRn6xjv2qSNe%2FzvdC7%0D%0AkbSVeN9Lzg%2FpbM25p6PG5hpicBQf%2Fg7Uv4ykSjMO4qi7eiuGuolVKZfjmZ03Gsub%0D%0AS%2FjCEYAEqAeY%2FszVk5mgten6AzXlIlhT7R%2FvV8v7qifJacluRoDQEfTTttBF3Jm1%0D%0A8MHCJSxr0Vrmd4wc7hHSGWblTPsSKlrwTByyIUqelExq%2B2%2FNhk5AiAU7bYCGP3Xj%0D%0A8JCgUQ3ljoSOBzLl2VSOR3hQ7KBfi9vF%2BLW2Sj77Zf%2Bf2oyRYiMtIu2dTQACCEvz%0D%0AUta3ziyHazwUvJ1duXUnEkDU6Tm%2FPksSsSPkZFAaT8PXSoYvZ4jMYXh3n%2Fz3ZQbz%0D%0ANCC2Uarco4u4%2FHk%2F4etjg9cuvVs40QLzPLDEmzJewGSpMmp4p2SiV44pagu09C9D%0D%0A8Jyk%2Fq%2FiYuz2M%2BbMKQwA7U1SEiNRbd68EItEY4JxZd7RFnOedkhyU3yCIPR%2BTNFA%0D%0AfHeTf7qE%2BkiWy%2FgMPvJY9eHT0VVyhRbuQGrOcjQFGX%2FNvQa86J7eXnECgddTSYwQ%0D%0A7tZ1wGysNLiUSD%2BJBvhItPLEb5WGQgHOeroqU2TAX388%2Byjvmf6Wueo8yn5Ga1Mi%0D%0AC20%2Fl%2Bepb35HSTJcxHTz4y2Ep1mVJc6hggEUMA0GCSqGSIb3DQEBCwUAA4IBAQCT%0D%0AZptU6LBHvVmDM8%2F2e5Jqpp13xFvsNjhSS9abngN2SCEnsCAFIXfyK7%2Bwbn2o1n6Q%0D%0Af3px2MtEsLUneTZt%2B1BaA9gujDGNzC9vnddbrAv1uIJ%2Bj2%2B4aWQS6WChgEfOBd46%0D%0Ar5V0sYlJqtXqKn4EFycj6urjDdA%2BTGrLn5xPtgLhp9hPkBTkyS%2BTN8F3GI0XyGRi%0D%0AodOlQ1c9LeNKsOFl3ttPxY0nXqCwRqZpesdG%2Fo0EGVmM2UbKQ0x%2FSjPUaeMY%2FdDj%0D%0AkH3uOluJ%2FX877m1xZEsiaNjvTjPi3Y5zD9dhhn9k1fkXNMI1YYoK1ordNJ6qgktO%0D%0AKm%2FUHsudLjvPloVIZsmW%0D%0A&renewal=false&xmlOutput=false&profileId=caSigningUserCert&SubId=profile&uid=testuser23&sn_uid=testuser23&requestor_name=testuser23
--------------------
<!-- --- BEGIN COPYRIGHT BLOCK ---
     This program is free software; you can redistribute it and/or modify
     it under the terms of the GNU General Public License as published by
     the Free Software Foundation; version 2 of the License.

     This program is distributed in the hope that it will be useful,
     but WITHOUT ANY WARRANTY; without even the implied warranty of
     MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
     GNU General Public License for more details.

     You should have received a copy of the GNU General Public License along
     with this program; if not, write to the Free Software Foundation, Inc.,
     51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.

     Copyright (C) 2007 Red Hat, Inc.
     All rights reserved.
     --- END COPYRIGHT BLOCK --- -->
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<script type="text/javascript">
errorReason="Request 157 Rejected - Subject Name Not Matched UID=testuser23";
requestListSet = new Array;
requestList = new Object;
requestList.requestId="157";
requestListSet[0] = requestList;
errorCode="3";
</script>
<script src="/pki/js/jquery.js"></script>
<script src="/pki/js/jquery.i18n.properties.js"></script>
<script src="/pki/js/underscore.js"></script>
<script src="/pki/js/backbone.js"></script>
<script src="/pki/js/pki.js"></script>
<script src="/pki/js/pki-banner.js"></script>
</head>
<font size="+1" face="PrimaSans BT, Verdana, Arial, Helvetica, sans-serif">
Certificate Profile
</font><br>
  <Font size="-1" face="PrimaSans BT, Verdana, Arial, Helvetica, sans-serif">
<p>
</font>
<table border="0" cellspacing="0" cellpadding="0" background="/pki/images/hr.gif"
width="100%">
  <tr>
    <td>&nbsp;</td>
  </tr>
</table>
<font size="-1" face="PrimaSans BT, Verdana, Arial, Helvetica, sans-serif">
<script language=javascript>

var autoImport = 'false';

if (errorCode == 0) { // processed
  document.write('Congratulations, your request has been processed successfully ');
  document.writeln('<P>');
  for (var i = 0; i < requestListSet.length; i++) {
    document.write('Your request ID is ');
    document.write('<B>'+requestListSet[i].requestId+'</B>.');
    document.writeln('<P>');
  }
  document.writeln('<b>');
  document.writeln('Outputs');
  document.writeln('</b>');
  document.writeln('<P>');
  document.writeln('<table width=100%>');
for (var i = 0; i < outputListSet.length; i++) {
    document.writeln('<tr valign=top>');
    document.writeln('<td>');
    document.writeln('<FONT size="-1" face="PrimaSans BT, Verdana, sans-serif">'
);
    document.writeln('<li>');
    document.writeln(outputListSet[i].outputName);
    document.writeln('</FONT>');
    document.writeln('</td>');
    document.writeln('<tr valign=top>');
    document.writeln('</tr>');
    document.writeln('<td>');
    if (outputListSet[i].outputSyntax == 'string') {
      document.writeln(outputListSet[i].outputVal);
    } else if (outputListSet[i].outputSyntax == 'pretty_print') {
      document.writeln('<pre>');
      document.writeln(outputListSet[i].outputVal);
      document.writeln('</pre>');
    }
    document.writeln('</td>');
    document.writeln('</tr>');
}
   document.writeln('</table>');
   document.writeln('<p>');
  document.writeln('<table width=100%>');
    document.writeln('<tr valign=top>');
    document.writeln('<td>');
    document.writeln('<FONT size="-1" face="PrimaSans BT, Verdana, sans-serif">'
);
    document.writeln('<li>');
    document.writeln('Certificate Imports');
    document.writeln('</FONT>');
    document.writeln('</td>');
   for (var i = 0; i < requestListSet.length; i++) {
    document.writeln('<tr valign=top>');
    document.writeln('<td>');
if (autoImport == 'true') {
    // only support one certificate import
   var loc = "getCertFromRequest?requestId="+ requestListSet[i].requestId + "&importCert=true";
   document.write("<iframe width='0' height='0' src='"+loc+"' </iframe>");
} else {
    document.writeln('<form method=post action="getCertFromRequest">');
 if (navigator.appName == "Netscape") {
    document.writeln('<input type=hidden name=importCert value=true>');
 } else {
    document.writeln('<input type=hidden name=importCert value=false>');
 }
    document.writeln('<input type=hidden name=requestId value=' + requestListSet[i].requestId + '>');
    document.writeln('<input type=submit name="Import Certificate" value="Import Certificate">');
    document.writeln('</form>');
}
    document.writeln('</td>');
    document.writeln('</tr>');
   }
   document.writeln('</table>');
} else if (errorCode == 1) { // not submitted
  document.write('Sorry, your request is not submitted. The reason is "' + errorReason + '".');
} else if (errorCode == 2) { // pending
  document.write('Congratulations, your request has been successfully ');
  document.write('submitted. ');
  document.write('Your request will be processed when an authorized agent ');
  document.writeln('verifies and validates the information in your request.');
  document.writeln('<P>');
  for (var i = 0; i < requestListSet.length; i++) {
    document.write('Your request ID is ');
    document.write('<B><a href="checkRequest?requestId=');
    document.write(requestListSet[i].requestId);
    document.write('">'+requestListSet[i].requestId+'</a></B>.');
    document.writeln('<P>');
  }
  document.write('Your can check on the status of your request with ');
  document.write('an authorized agent or local administrator ');
  document.writeln('by referring to this request ID.');
} else if (errorCode == 3) { // rejected
  document.write('Sorry, your request has been rejected. The reason is "' + errorReason + '"');
  document.writeln('<P>');
  for (var i = 0; i < requestListSet.length; i++) {
    document.write('Your request ID is ');
    document.write('<B>'+requestListSet[i].requestId+'</B>.');
    document.writeln('<P>');
  }
} else { // unknown state
  document.write('Sorry, your request is not submitted. The error code is "' + errorReason + '".');
}
</script>
</font>
</html>
--------------------
Request ID: 157
Request Status: rejected
Reason: Request 157 Rejected - Subject Name Not Matched UID=testuser23


++++++++++++++++++++++++++++++++++++++++++++++++++++++_________________________________________________________

[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: SessionContextInterceptor: CAInfoResource.getInfo()
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: SessionContextInterceptor: Not authenticated.
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: AuthMethodInterceptor: CAInfoResource.getInfo()
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: AuthMethodInterceptor: mapping: default
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: AuthMethodInterceptor: required auth methods: [*]
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: AuthMethodInterceptor: anonymous access allowed
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: ACLInterceptor: CAInfoResource.getInfo()
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: ACLInterceptor.filter: no authorization required
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: ACLInterceptor: No ACL mapping; authz not required.
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: SignedAuditLogger: event AUTHZ
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: MessageFormatInterceptor: CAInfoResource.getInfo()
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: MessageFormatInterceptor: content-type: null
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: MessageFormatInterceptor: accept: [application/xml]
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: MessageFormatInterceptor: response format: application/xml
[19/Mar/2018:12:49:11][http-bio-8080-exec-18]: according to ccMode, authorization for servlet: kraconnector is LDAP based, not XML {1}, use default authz mgr: {2}.
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet:service() uri = /ca/ee/ca/profileSubmit
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet::service() param name='cert_request_type' value='crmf'
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet::service() param name='cert_request' value='(sensitive)'
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet::service() param name='renewal' value='false'
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet::service() param name='xmlOutput' value='false'
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet::service() param name='profileId' value='caSigningUserCert'
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet::service() param name='SubId' value='profile'
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet::service() param name='uid' value='testuser23'
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet::service() param name='sn_uid' value='testuser23'
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet::service() param name='requestor_name' value='testuser23'
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet: caProfileSubmit start to service.
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: xmlOutput false
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: ProfileSubmitServlet: isRenewal false
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: according to ccMode, authorization for servlet: caProfileSubmit is LDAP based, not XML {1}, use default authz mgr: {2}.
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: ProfileSubmitServlet: profile: caSigningUserCert
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CAProcessor: Input Parameters:
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CAProcessor: - isRenewal: false
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CAProcessor: - sn_uid: testuser23
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CAProcessor: - remoteHost: 10.8.60.15
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CAProcessor: - cert_request_type: crmf
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CAProcessor: - profileId: caSigningUserCert
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CAProcessor: - cert_request: (sensitive)
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CAProcessor: - requestor_name: testuser23
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CAProcessor: - remoteAddr: 10.8.60.15
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollmentProcessor: isRenewal false
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollmentProcessor: profileId caSigningUserCert
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollmentProcessor: set Inputs into profile Context
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollmentProcessor: set sslClientCertProvider
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile: createRequests: begins
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile: Start parseCRMF(): 
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: Repository: in getNextSerialNumber. 
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: Repository: checkRange  mLastSerialNo=157
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: Repository: getNextSerialNumber: returning retSerial 157
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile: setDefaultCertInfo: setting issuerDN using exact CA signing cert subjectDN encoding
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile: createEnrollmentRequest 157
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CertProcessor: profileSetid=signingCertSet
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CertProcessor: request 157
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CertProcessor: populating request inputs
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CertReqInput: populate: begins
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CertReqInput: populate: cert_request_type= REQ_TYPE_CRMF
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile: Start parseCRMF(): 
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollInput ::in verifyPOP
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: POP verification begins:
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollInput: verifyPOP: POP verification using internal token
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: SignedAuditLogger: event PROOF_OF_POSSESSION
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile: fillCertReqMsg: Start parseCertReqMsg 
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile:  validity not supplied
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile: populate: begins
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: BasicProfile: populate: policy setid =signingCertSet
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: UserSubjectNameDefault: start
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: UserSubjectNameDefault: end
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: ValidityDefault: start
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: ValidityDefault: start time: 0
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: ValidityDefault: not before: Mon Mar 19 12:49:12 EDT 2018
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: ValidityDefault: range: 180
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: ValidityDefault: range unit: day
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: ValidityDefault: not after: Sat Sep 15 12:49:12 EDT 2018
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: ValidityDefault: end
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: UserKeyDefault: start
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: UserKeyDefault: end
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: AuthorityKeyIdentifierExtDefault: start
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: AuthorityKeyIdentifierExtDefault: end
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: AuthInfoAccessExtDefault: start
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: AuthInfoAccess: createExtension i=0
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: AuthInfoAccessExtDefault: end
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: KeyUsageExtDefault: start
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: KeyUsageExtDefault: end
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: ExtendedKeyUsageExtDefault: start
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: ExtendedKeyUsageExtDefault: end
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: SubjectAltNameExtDefault: start
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: SubjectAltNameExtDefault: createExtension i=0
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: SubjectAltNameExtDefault: createExtension() pattern=$request.requestor_email$
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: SubjectAltNameExtDefault: createExtension got gname=$request.requestor_email$ with type=RFC822Name
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: adding gname: $request.requestor_email$
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: SubjectAlternativeNameExtension: n not null
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: SubjectAltNameExtDefault: end
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: SigningAlgDefault: start
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollDefault: populate: SigningAlgDefault: end
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet: in auditSubjectID
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet: auditSubjectID auditContext {sslClientCertProvider=com.netscape.cms.servlet.profile.SSLClientCertProvider@1f545900, profileContext=com.netscape.cms.profile.common.ProfileContext@1d845582}
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet auditSubjectID: subjectID: null
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CertProcessor.submitRequest: calling profile submit
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile: submit: begins
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile: submit: popChallengeRequired =false
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: In LdapBoundConnFactory::getConn()
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: masterConn is connected: true
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: getConn: conn is connected true
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: getConn: mNumConns now 5
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: returnConn: mNumConns now 6
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile: submit:  auth token is null; agent manual approval required;
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile: submit:  validating request
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile.validate: start
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollProfile.validate: cert subject name:UID=testuser23
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: SignedAuditLogger: event PROFILE_CERT_REQUEST
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: BasicProfile: validate start on setId=signingCertSet
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: SubjectNameConstraint: validate start
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: SubjectNameConstraint: validate start
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: SubjectNameConstraint: validate cert subject =UID=testuser23
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: SubjectNameConstraint: validate() - sn500 dname = UID=testuser23
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: SubjectNameConstraint: validate() - sn500 not matching pattern CN=.*
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CertProcessor: submit Subject Name Not Matched UID=testuser23
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: SignedAuditLogger: event CERT_REQUEST_PROCESSED
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: In LdapBoundConnFactory::getConn()
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: masterConn is connected: true
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: getConn: conn is connected true
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: getConn: mNumConns now 5
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: returnConn: mNumConns now 6
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: EnrollmentSubmitter: done serving
[19/Mar/2018:12:49:12][http-bio-8080-exec-19]: CMSServlet: curDate=Mon Mar 19 12:49:12 EDT 2018 id=caProfileSubmit time=334
[19/Mar/2018:12:50:43][Timer-0]: SessionTimer: run()
[19/Mar/2018:12:50:43][Timer-0]: LDAPSecurityDomainSessionTable: getSessionIds() 
[19/Mar/2018:12:50:43][Timer-0]: LDAPSecurityDomainSessionTable: searching ou=sessions,ou=Security Domain,o=pki-ca-Mar8-CA
[19/Mar/2018:12:50:43][Timer-0]: In LdapBoundConnFactory::getConn()
[19/Mar/2018:12:50:43][Timer-0]: masterConn is connected: true
[19/Mar/2018:12:50:43][Timer-0]: getConn: conn is connected true
[19/Mar/2018:12:50:43][Timer-0]: getConn: mNumConns now 2
[19/Mar/2018:12:50:44][Timer-0]: returnConn: mNumConns now 3

========================================================

for caDualcert:

CRMFPopClient -d test -p SECret.123 -n UID=testuser00 -f caDualCert -b transport.pem -m $HOSTNAME:8080  -u testuser23 -r testuser23
Keypair private key id: -240d250fd7fa6cbbf775b01cf8c002beab039c21
Submitting CRMF request to nocp1.idm.lab.eng.rdu2.redhat.com:8080
Request ID: 160
Request Status: pending
Reason: 


[19/Mar/2018:13:17:42][http-bio-8080-exec-25]: CMSServlet:service() uri = /ca/ee/ca/profileSubmit
[19/Mar/2018:13:17:42][http-bio-8080-exec-25]: CMSServlet::service() param name='cert_request_type' value='crmf'
[19/Mar/2018:13:17:42][http-bio-8080-exec-25]: CMSServlet::service() param name='cert_request' value='(sensitive)'
[19/Mar/2018:13:17:42][http-bio-8080-exec-25]: CMSServlet::service() param name='renewal' value='false'
[19/Mar/2018:13:17:42][http-bio-8080-exec-25]: CMSServlet::service() param name='xmlOutput' value='false'
[19/Mar/2018:13:17:42][http-bio-8080-exec-25]: CMSServlet::service() param name='profileId' value='caDualCert'
[19/Mar/2018:13:17:42][http-bio-8080-exec-25]: CMSServlet::service() param name='SubId' value='profile'
[19/Mar/2018:13:17:42][http-bio-8080-exec-25]: CMSServlet::service() param name='uid' value='testuser23'
[19/Mar/2018:13:17:42][http-bio-8080-exec-25]: CMSServlet::service() param name='sn_uid' value='testuser23'
[19/Mar/2018:13:17:42][http-bio-8080-exec-25]: CMSServlet::service() param name='requestor_name' value='testuser23'
[19/Mar/2018:13:17:42][http-bio-8080-exec-25]: CMSServlet: caProfileSubmit start to service.
[19/Mar/2018:13:17:42][http-bio-8080-exec-25]: xmlOutput false

Comment 2 Christina Fu 2018-04-17 21:08:22 UTC
I can see and am able to reproduce the issue.  I do not know the original intent of the design for having -u to override the -n value though.

I think it's worthwhile to investigate and fix.

Comment 4 Matthew Harmsen 2018-07-04 00:37:18 UTC
Moved to RHEL 7.7.

Comment 9 Alex Scheel 2021-01-07 16:29:25 UTC
See the linked upstream bug above.