Created attachment 1510815 [details]
Added CS.cfg file.
Description of problem:
ECC setup failure on the RHEL 8
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. Prepare ca installation script.
2. Install CA with ECC env.
It fails with error message:
pkispawn : ERROR Server unreachable due to SSL error: [SSL: SSLV3_ALERT_HANDSHAKE_FAILURE] sslv3 alert handshake failure (_ssl.c:872)
ECC installation should be successful.
- Attached cs.cfg file
- Attached debug log
[RHEL8.0] CA ECC installation is also failing on Safenet LunaSA HSM machine. also same scenario is working fine for CA RSA installation on Safenet LunaSA HSM.
Also tested with endi's copr bits as well it's not working.
*** Bug 1692253 has been marked as a duplicate of this bug. ***
Apparently there is a missing functionality in JSS:
The ECC installation should be working in PKI 10.8 (RHEL 8.2).
This bugzilla has been tested on following build (RHEL8.2)
ECC installation is successful. Attached is the ca.cfg file used for ECC CA installation.
ECC installation also works in pipeline.
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.