Bug 496692 - CS 8.0 Beta. At the end of enrollment, double verification of PIN is requested with the second one throwing an
Summary: CS 8.0 Beta. At the end of enrollment, double verification of PIN is request...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Dogtag Certificate System
Classification: Retired
Component: ESC
Version: 1.0
Hardware: All
OS: Linux
medium
high
Target Milestone: ---
Assignee: Jack Magne
QA Contact: Chandrasekar Kannan
URL:
Whiteboard:
Depends On:
Blocks: 443788
TreeView+ depends on / blocked
 
Reported: 2009-04-20 18:32 UTC by Sean Veale
Modified: 2015-01-04 23:37 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-07-22 23:34:34 UTC
Embargoed:


Attachments (Terms of Use)
Debug logs and screen shot of the error message (1.55 MB, application/zip)
2009-04-20 18:45 UTC, Sean Veale
no flags Details

Description Sean Veale 2009-04-20 18:32:17 UTC
Description of problem:


Version-Release number of selected component (if applicable):


How reproducible:
Always

Steps to Reproduce:
1.
2.
3.
  
Actual results:


Expected results:


Additional info:

Comment 1 Sean Veale 2009-04-20 18:44:59 UTC
Description of problem: 

Version-Release number of selected component (if applicable):
After a token is enrolled, the ESC displays the dialog asking for Pin Verification twice. The second time a CoolKey PKCS #11 CSP Error is displayed. 

If you click ok, you will then get the pop-up saying the token was enrolled successfully. 

Potentially related.  In fire fox (running 3.0.7 anyway) in the alpha if I slotted or removed the token from the system I could see the certificates associated with the card being added or removed from the list the browser knows about.  This no longer happens!

How reproducible:
Always

Steps to Reproduce:
1. Enroll a User. 
2. See the error
3.

Actual results:

Error when enrolling
Expected results:

Able to enroll with no errors. Only asked once.
Additional info:  
Zip File includes tail of TPS debug and error logs, as well as CA debug  and a screen shot of the 2nd verification with it's error.

Comment 2 Sean Veale 2009-04-20 18:45:30 UTC
Created attachment 340405 [details]
Debug logs and screen shot of the error message

Comment 3 Jack Magne 2009-04-20 18:50:20 UTC
I've not seen this myself, but will take a look at the logs...

So, when this happens do the certificates make it over to CAPI thus you can see them in IE when doing internet options/content/certificates?

Comment 4 Sean Veale 2009-04-20 19:46:53 UTC
They do make it to the CAPI as I see them in I.E. Also It appears the PKS module isn't loaded into the firefox though "Managing Smart Cards with the ESC" doc section 5.1 says this is automatic.

Comment 5 Jack Magne 2009-06-04 21:16:04 UTC
Moving to medium, intermittent.

Comment 6 Jack Magne 2009-06-06 00:33:41 UTC
The fix for this bug is contained in the fix for the following bug:

https://bugzilla.redhat.com/show_bug.cgi?id=496759

Comment 7 Jack Magne 2009-06-06 00:33:57 UTC
Fixed in next build.

Comment 8 Asha Akkiangady 2009-06-11 17:35:41 UTC
Verified.

In Firefox (3.0.7) the token insertion and removal events adds and removes the certificates. Do not have any problem of double pin verification with Gemalto 64 K or Safenet cards, pin verification is requested once.


Note You need to log in before you can comment on or make changes to this bug.