Note: This bug is displayed in read-only format because
the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Comment 1richard.wiggins.ctr
2021-11-24 21:59:58 UTC
Seeing this error as well regardless of if I am performing a replica re-install or a new ipa-server install.
Review of the logs ( I will have to work on getting them ported from an airgapped network) shows in /var/log/pki/pki-tomcat/ca/debug.2021-11-24.log has repeated instances of
"java.security.AccessControlException: access denied: ("java.io.FilePermission" "/var/run/pki/tomcat/pki-tomcat.pid" "read")
so we are unable to either rebuild our replica or flat out build a new IDM server from fresh provision of VM system.
We are production so we've reinstalled RHEL 7.9 with ipa-server 4.6.8 which is working for now.
Rick
Comment 2Florence Blanc-Renaud
2021-11-25 14:37:21 UTC
(In reply to richard.wiggins.ctr from comment #1)
> Seeing this error as well regardless of if I am performing a replica
> re-install or a new ipa-server install.
>
> Review of the logs ( I will have to work on getting them ported from an
> airgapped network) shows in /var/log/pki/pki-tomcat/ca/debug.2021-11-24.log
> has repeated instances of
>
> "java.security.AccessControlException: access denied:
> ("java.io.FilePermission" "/var/run/pki/tomcat/pki-tomcat.pid" "read")
>
> so we are unable to either rebuild our replica or flat out build a new IDM
> server from fresh provision of VM system.
> We are production so we've reinstalled RHEL 7.9 with ipa-server 4.6.8 which
> is working for now.
>
> Rick
Hi,
the error described in this BZ is specific to a re-installation of the same replica. If you don't see this exact message in /var/log/ipareplica-install.log, then your issue is probably a different one:
com.netscape.certsrv.base.ConflictingOperationException: Entry already exists.
at com.netscape.certsrv.ldap.LDAPExceptionConverter.toPKIException(LDAPExceptionConverter.java:45)
at com.netscape.cmscore.usrgrp.UGSubsystem.addUser(UGSubsystem.java:720)
at org.dogtagpki.server.cli.SubsystemUserAddCLI.execute(SubsystemUserAddCLI.java:180)
at org.dogtagpki.cli.CommandCLI.execute(CommandCLI.java:58)
at org.dogtagpki.cli.CLI.execute(CLI.java:357)
at org.dogtagpki.cli.CLI.execute(CLI.java:357)
at org.dogtagpki.cli.CLI.execute(CLI.java:357)
at org.dogtagpki.server.cli.PKIServerCLI.execute(PKIServerCLI.java:93)
at org.dogtagpki.server.cli.PKIServerCLI.main(PKIServerCLI.java:123)
Caused by: netscape.ldap.LDAPException: error result (68); Already exists
at netscape.ldap.LDAPConnection.checkMsg(Unknown Source)
at netscape.ldap.LDAPConnection.add(Unknown Source)
at netscape.ldap.LDAPConnection.add(Unknown Source)
at netscape.ldap.LDAPConnection.add(Unknown Source)
at com.netscape.cmscore.usrgrp.UGSubsystem.addUser(UGSubsystem.java:717)
... 7 more
CalledProcessError: Command '['/usr/sbin/runuser', '-u', 'pkiuser', '--', '/usr/lib/jvm/jre-11-openjdk/bin/java', '-classpath', '/usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/*', '-Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory', '-Dcatalina.base=/var/lib/pki/pki-tomcat', '-Dcatalina.home=/usr/share/tomcat', '-Djava.endorsed.dirs=', '-Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp', '-Djava.util.logging.config.file=/etc/pki/pki-tomcat/logging.properties', '-Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager', '-Dcom.redhat.fips=false', 'org.dogtagpki.server.cli.PKIServerCLI', 'ca-user-add', '--full-name', 'CA-replica1.ipa.test-8443', '--type', 'agentType', '--state', '1', '--debug', 'CA-replica1.ipa.test-8443']' returned non-zero exit status 255.
Please check and open a different issue if the error is different.
Comment 3richard.wiggins.ctr
2021-11-25 20:17:37 UTC
Hi!
You are correct; I just performed various configuration testing and figured out this is a different issue than what I am experiencing.
Will open a new issue.
Rick
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory (pki-core:10.6 bug fix and enhancement update), and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://access.redhat.com/errata/RHBA-2022:0357
Seeing this error as well regardless of if I am performing a replica re-install or a new ipa-server install. Review of the logs ( I will have to work on getting them ported from an airgapped network) shows in /var/log/pki/pki-tomcat/ca/debug.2021-11-24.log has repeated instances of "java.security.AccessControlException: access denied: ("java.io.FilePermission" "/var/run/pki/tomcat/pki-tomcat.pid" "read") so we are unable to either rebuild our replica or flat out build a new IDM server from fresh provision of VM system. We are production so we've reinstalled RHEL 7.9 with ipa-server 4.6.8 which is working for now. Rick