Bug 696816 - certmonger crash : triggered by "ipa-getcert request -d /etc/pki/nssdb/ -n -"
Summary: certmonger crash : triggered by "ipa-getcert request -d /etc/pki/nssdb/ -n -"
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: certmonger
Version: 6.1
Hardware: Unspecified
OS: Linux
unspecified
high
Target Milestone: rc
: ---
Assignee: Nalin Dahyabhai
QA Contact: BaseOS QE Security Team
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-04-14 22:14 UTC by Yi Zhang
Modified: 2011-12-06 17:37 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-12-06 17:37:30 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2011:1708 0 normal SHIPPED_LIVE certmonger bug fix update 2011-12-06 01:02:28 UTC

Description Yi Zhang 2011-04-14 22:14:38 UTC
Description of problem:
certmonger crashed when i run the following command 
[i386.a root@dhcp-118 /etc/pki/nssdb] ipa-getcert request -d /etc/pki/nssdb/ -n -
Apr 14 15:08:46 dhcp-118 kernel: certmonger[6626]: segfault at 0 ip 0072c23a sp bfcc04ac error 4 in libc-2.12.so[6b5000+18a000]
Apr 14 15:08:46 dhcp-118 abrt[6630]: saved core dump of pid 6626 (/usr/sbin/certmonger) to /var/spool/abrt/ccpp-1302818926-6626.new/coredump (679936 bytes)
Apr 14 15:08:46 dhcp-118 abrtd: Directory 'ccpp-1302818926-6626' creation detected
Please verify that the certmonger service is still running.
[i386.a root@dhcp-118 /etc/pki/nssdb] Apr 14 15:08:46 dhcp-118 abrtd: New crash /var/spool/abrt/ccpp-1302818926-6626, processing

Version-Release number of selected component (if applicable):
[i386.a root@dhcp-118 /etc/pki/nssdb] rpm -qa | grep certmonger
certmonger-0.42-1.20110413T1643z.el6.i686

[i386.a root@dhcp-118 /etc/pki/nssdb] rpm -qa | grep ipa-client
ipa-client-2.0.0-20.20110413T1714zgit9cac1d8.el6.i686

How reproducible: always


Steps to Reproduce:
1. install ipa-client
2. run above ipa-getcert command  : don't forget the "-" after -n
the full command is
"ipa-getcert request -d /etc/pki/nssdb/ -n -"

Actual results:


Expected results:
at least not crash

Additional info:

Comment 2 RHEL Program Management 2011-04-15 06:00:11 UTC
Since RHEL 6.1 External Beta has begun, and this bug remains
unresolved, it has been rejected as it is not proposed as
exception or blocker.

Red Hat invites you to ask your support representative to
propose this request, if appropriate and relevant, in the
next release of Red Hat Enterprise Linux.

Comment 3 Nalin Dahyabhai 2011-04-15 14:29:48 UTC
Do we have a backtrace from the core file?

Comment 4 Namita Soman 2011-04-15 14:49:17 UTC
Using:
certmonger-0.42-1.el6.x86_64
ipa-client-2.0.0-21.el6.x86_64

Ran:
# ipa-getcert request -d /etc/pki/nssdb/ -n -
New signing request "20110415144621" added.

Didn't see the behaviour described above.

Comment 5 Dmitri Pal 2011-04-25 18:22:31 UTC
It might be an nss issue then. Can you confirm the version of NSS?

Comment 6 Yi Zhang 2011-07-19 17:40:16 UTC
It seems fixed in daily build. My test is below:

[x86_64.b root@dhcp-122 /etc/pki/nssdb] ipa-getcert request -d /etc/pki/nssdb/ -n -
New signing request "20110719173620" added


cert list below:
Request ID '20110719173620':
	status: MONITORING
	stuck: no
	key pair storage: type=NSSDB,location='/etc/pki/nssdb',nickname='-',token='NSS Certificate DB'
	certificate: type=NSSDB,location='/etc/pki/nssdb',nickname='-'
	CA: IPA
	issuer: 
	subject: 
	expires: unknown
	track: yes
	auto-renew: yes


NO error msg detected in /var/log/message (as it used to be)
I can now close it as verified

Comment 7 errata-xmlrpc 2011-12-06 17:37:30 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2011-1708.html


Note You need to log in before you can comment on or make changes to this bug.