Bug 2490607 - httpd gets stuck during FreeIPA replica enrolment with OpenSSL 4
Summary: httpd gets stuck during FreeIPA replica enrolment with OpenSSL 4
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: httpd
Version: 45
Hardware: All
OS: Linux
unspecified
high
Target Milestone: ---
Assignee: Luboš Uhliarik
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: openqa AcceptedBlocker
Depends On:
Blocks: BetaBlocker, F45BetaBlocker
TreeView+ depends on / blocked
 
Reported: 2026-06-18 22:47 UTC by Adam Williamson (Red Hat non-Fedora)
Modified: 2026-09-29 16:20 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-09-05 16:17:31 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github dogtagpki jss pull 1116 0 None open Integrate TLS 1.3 post-handshake authentication into the handshake state machine 2026-08-24 19:32:51 UTC

Description Adam Williamson (Red Hat non-Fedora) 2026-06-18 22:47:58 UTC
In testing of the OpenSSL 4.0 update - https://bodhi.fedoraproject.org/updates/FEDORA-2026-54c7ad647e - we have found that FreeIPA replica install fails. This is a real and reproducible bug. The underlying cause seems to be some kind of hang/block/loop/whatever in httpd: the FreeIPA setup process gets stuck running pkispawn as part of certificate configuration, but pkispawn appears to be waiting for a response from httpd which it never gets.

Manual reproduction steps from rcrit:

[10:42 PM]Start with 2 rawhide VMs with a good amount of disk. The updates are large.
[10:43 PM]On one: bodhi updates download --updateid=FEDORA-2026-54c7ad647e
[10:43 PM]use createrepo_c to generate a local copr repo of the contents
[10:43 PM]dnf -y update && dnf -y install freeipa-server-dns
[10:43 PM]If there is a kernel update in there I update. You do you.
[10:44 PM]I use hostnamectl to set the two hostnames to ipa.example.test and replica.example.test
[10:44 PM]ipa-server-install -a password -p password -r EXAMPLE.TEST -U -N --setup-dns --allow-zone-overlap --no-forwarders --auto-reverse
[10:45 PM]I next moved to the replica . I copied over the copr repo and set it up in a similar way. Then run the dnf cmds
[10:45 PM]ipa-replica-install --server ipa.example.test --domain example.test -w password -U --skip-mem-check --setup-ca
[10:45 PM]In step 7-ish of the CA install things will hang up, the CPU will go to 100%

[ed note there is nothing 'COPR' here, you're just creating a local dnf repo]

rcrit also got some httpd logs including an error "AH02008: SSL library error 1 in handshake (server ipa.example.test:443)" which may need investigation by jorton.

We are waiving this failure and making the tests temporarily non-gating on Rawhide to get the larger OpenSSL 4 update merged, but this is a high-priority issue and should be investigated and resolved ASAP, we need to fix this and start gating on the tests again quickly.

Also proposing as an F45 Beta blocker as a violation of https://fedoraproject.org/wiki/Basic_Release_Criteria#FreeIPA_server_requirements .

Comment 1 Jan Pazdziora 2026-06-19 16:21:53 UTC
Not sure if an instance of the same problem, but another broken thing about FreeIPA in rawhide is simple

# dnf install -y --setopt=install_weak_deps=False freeipa-server
# ipa-server-install -U -r EXAMPLE.TEST -n example.test -p Secret123 -a Secret123
# ipa-kra-install -p Secret123 -U

This will yield a 99+ % CPU looping of a java process:

Tasks: 183 total, 2 running, 181 sleep, 0 d-sleep, 0 stopped, 0 zombie
%Cpu(s): 44.1 us,  6.0 sy,  0.0 ni, 49.7 id,  0.0 wa,  0.2 hi,  0.0 si,  0.0 st 
MiB Mem :   2822.3 total,    615.9 free,   1550.7 used,    993.5 buff/cache     
MiB Swap:   2822.0 total,   2822.0 free,      0.0 used.   1271.5 avail Mem 

    PID USER      PR  NI    VIRT    RES    SHR S  %CPU  %MEM     TIME+ COMMAND  
  10151 root      20   0 2820520 125232  33328 S  99.7   4.3   4:54.15 java     
   7424 pkiuser   20   0 2935480 253684  39352 S   0.3   8.8   0:22.95 java     
      1 root      20   0   44144  25032  12812 S   0.0   0.9   0:12.15 systemd  
      2 root      20   0       0      0      0 S   0.0   0.0   0:00.01 kthreadd 

until I killed it.

Observed in the FreeIPA containerization CI: https://github.com/freeipa/freeipa-container/issues/745.

Comment 2 Joe Orton 2026-06-23 06:59:45 UTC
From the Slack discussion, this looked like a Post-Handshake Auth issue. I was unable to reproduce any PHA issue with simple testing against a Rawhide container, using a standard mod_ssl configuration requiring per-location client certificates.

Comment 5 Adam Williamson (Red Hat non-Fedora) 2026-07-07 15:13:39 UTC
+3 in https://forge.fedoraproject.org/quality/blocker-review/issues/2137 , marking accepted blocker.

Comment 7 Aoife Moloney 2026-08-17 14:55:55 UTC
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.

Comment 8 Adam Williamson (Red Hat non-Fedora) 2026-08-24 19:32:51 UTC
I've been told https://github.com/dogtagpki/jss/pull/1116 is the currently-proposed fix for this, or at least part of it, so linking that.

A reminder that we don't have long before Beta release now. Beta freeze is tomorrow and Go/No-Go is scheduled for Sept 10, which means we really need a candidate compose by Sept 7. Does it look like we will be able to address this by then?

Comment 9 Trivino 2026-08-27 10:30:45 UTC
Hey, Adam, the JSS fix addresses the OpenSSL 4 issue in IPA, which is the current blocker. There is a subsequent fix needed for mod_ssl due to a missing timeout, but that will be handled separately and later.

I’ll prioritize the JSS review and build so we can get this moving, and we should be able to have this addressed in time.

Comment 10 Fedora Update System 2026-09-02 19:12:37 UTC
FEDORA-2026-23de7c02f9 (jss-5.10.1-2.fc45) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-23de7c02f9

Comment 11 Fedora Update System 2026-09-03 02:13:19 UTC
FEDORA-2026-23de7c02f9 has been pushed to the Fedora 45 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-23de7c02f9`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-23de7c02f9

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 13 Jan Pazdziora 2026-09-03 13:06:22 UTC
I confirm that the jss-5.10.1-2.fc46 build (of https://bodhi.fedoraproject.org/updates/FEDORA-2026-7add23556a) fixes the problem for the FreeIPA containerization on Fedora rawhide.

Comment 14 Adam Williamson (Fedora) 2026-09-03 22:43:19 UTC
openQA tests also verified the fix.

Comment 16 Fedora Update System 2026-09-05 16:17:31 UTC
FEDORA-2026-23de7c02f9 (jss-5.10.1-2.fc45) has been pushed to the Fedora 45 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 17 Joe Orton 2026-09-29 16:20:10 UTC
I looked at the mod_ssl issue. In the pcap, mod_ssl sends the CertificateRequest message for PHA. TLS/1.3 §4.7.2 https://www.rfc-editor.org/info/rfc9846/#section-4.7.2 requires SOME response to that. mod_ssl waits for that, 60 seconds expire (default I/O timeout), nothing comes, and then it aborts the connection (unclean shutdown, TCP FIN). Apparently because the client is spinning it ignores that.

I'm not seeing a mod_ssl bug that we could/should test for - the I/O timeout was applied as expected by the server.


Note You need to log in before you can comment on or make changes to this bug.