Bug 1819656
| Summary: | Failed to install ipa-server due to RuntimeError: Certificate issuance failed | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Lukas Slebodnik <lslebodn> |
| Component: | ipa | Assignee: | Florence Blanc-Renaud <frenaud> |
| Status: | CLOSED DUPLICATE | QA Contact: | ipa-qe <ipa-qe> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 7.9 | CC: | abokovoy, edewata, ftweedal, rcritten, tscherf |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2020-04-01 12:19:22 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Lukas Slebodnik
2020-04-01 09:28:19 UTC
Tail of /var/log/pki/pki-tomcat/ca/debug [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: In LdapBoundConnFactory::getConn() [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: masterConn is connected: true [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: getConn: conn is connected true [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: getConn: mNumConns now 2 [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: returnConn: mNumConns now 3 [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: AAclAuthz.checkPermission(certServer.ca.request.profile, approve) [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: checkAllowEntries(): expressions: group="Certificate Manager Agents" [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: evaluating expressions: group="Certificate Manager Agents" [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: GroupAccessEvaluator: evaluate: uid=admin value="Certificate Manager Agents" [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: GroupAccessEvaluator: evaluate: no groups in authToken [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: In LdapBoundConnFactory::getConn() [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: masterConn is connected: true [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: getConn: conn is connected true [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: getConn: mNumConns now 2 [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: returnConn: mNumConns now 3 [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: UGSubsystem.isMemberOf() using new lookup code [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: In LdapBoundConnFactory::getConn() [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: masterConn is connected: true [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: getConn: conn is connected true [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: getConn: mNumConns now 2 [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: authorization search base: cn=Certificate Manager Agents,ou=groups,o=ipaca [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: authorization search filter: (uniquemember=uid=admin,ou=People,o=ipaca) [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: authorization result: true [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: returnConn: mNumConns now 3 [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: evaluated expression: group="Certificate Manager Agents" to be true [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: DirAclAuthz: authorization passed [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: SignedAuditLogger: event AUTHZ [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: SignedAuditLogger: event ROLE_ASSUME [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: RequestProcessor: processRequest: start serving [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: RequestProcessor: requestId=27 [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: Setting AUTH_TOKEN-userid=admin [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: Setting AUTH_TOKEN-user=uid=admin,ou=People,o=ipaca [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: Setting AUTH_TOKEN-sslClientCert(0)=null [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: Setting AUTH_TOKEN-uid=admin [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: Setting AUTH_TOKEN-userdn=uid=admin,ou=People,o=ipaca [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: Setting AUTH_TOKEN-authTime=1585687750192 [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: Setting AUTH_TOKEN-authMgrInstName=certUserDBAuthMgr [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: RequestProcessor: profileId=caServerCert [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: UserSubjectNameDefault: setValue: name = name [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: UserSubjectNameDefault: setValue: value = CN=IPA RA,O=TESTRELM.TEST [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: UserSubjectNameDefault: getX500Name: use system encoding: false [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: UserSubjectNameDefault: getX500Name: subjectDN exists in CSR. [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: UserSubjectNameDefault: getX500Name: new Subject DN has same string representation as current value; retaining current value. [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: UserSubjectNameDefault: setValue: setting name=CN=IPA RA,O=TESTRELM.TEST [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: parseRecords: Record0 [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: SigningAlgDefault: setValue java.security.NoSuchAlgorithmException: unrecognized algorithm name: SHA256withRSA [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: ProfileProcessServlet: execution error Invalid Property signingAlg [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: CMSServlet: curDate=Tue Mar 31 16:49:10 EDT 2020 id=caProfileProcess time=51 [31/Mar/2020:16:49:10][http-bio-8443-exec-9]: SignedAuditLogger: event ACCESS_SESSION_TERMINATED [31/Mar/2020:16:49:10][http-bio-8443-exec-12]: SignedAuditLogger: event ACCESS_SESSION_TERMINATED Fraser, Endi, could you please look at this? SHA256withRSA is the default signing in Dogtag. I can confirm that installation fails with pki-server 10.5.18-1.el7, but is successful with the more recent nightly build 10.5.18-2.el7. Closing as WORKSFORME. There is just a single change between 10.5.18-1 and 10.5.8-2. * Mon Mar 30 2020 Dogtag Team <pki-devel> 10.5.18-2 - Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne) Maybe it can be closed as a duplicate instead of works for me Hi Lukas, thanks for the pointer, I updated the Close reason. *** This bug has been marked as a duplicate of bug 1710109 *** |