Hide Forgot
Created attachment 1510815 [details] Added CS.cfg file. Description of problem: ECC setup failure on the RHEL 8 Version-Release number of selected component (if applicable): 10.6.7-3.module+el8+2144+b013656f How reproducible: Always Steps to Reproduce: 1. Prepare ca installation script. 2. Install CA with ECC env. 3. Actual results: It fails with error message: pkispawn : ERROR Server unreachable due to SSL error: [SSL: SSLV3_ALERT_HANDSHAKE_FAILURE] sslv3 alert handshake failure (_ssl.c:872) Expected results: ECC installation should be successful. Additional info: - Attached cs.cfg file - Attached debug log
[RHEL8.0] CA ECC installation is also failing on Safenet LunaSA HSM machine. also same scenario is working fine for CA RSA installation on Safenet LunaSA HSM. Also tested with endi's copr bits as well it's not working.
*** Bug 1692253 has been marked as a duplicate of this bug. ***
Apparently there is a missing functionality in JSS: https://pagure.io/jss/issue/32
The ECC installation should be working in PKI 10.8 (RHEL 8.2).
This bugzilla has been tested on following build (RHEL8.2) pki-ca-10.8.2-1.module+el8.2.0+5758+57f3761f.noarch ECC installation is successful. Attached is the ca.cfg file used for ECC CA installation. ECC installation also works in pipeline.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2020:1644