Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
Red Hat Satellite engineering is moving the tracking of its product development work on Satellite to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "Satellite project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs will be migrated starting at the end of May. If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "Satellite project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/SAT-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 770066

Summary: Problem with certificates when accessing pulp repo
Product: Red Hat Satellite Reporter: Lukas Zapletal <lzap>
Component: katello-agentAssignee: Ivan Necas <inecas>
Status: CLOSED CURRENTRELEASE QA Contact: Garik Khachikyan <gkhachik>
Severity: high Docs Contact:
Priority: unspecified    
Version: 6.0.1CC: bkearney, gkhachik, mkoci
Target Milestone: UnspecifiedKeywords: Triaged
Target Release: Unused   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-08-22 18:16:13 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 747354    

Description Lukas Zapletal 2011-12-23 09:25:12 UTC
Description of problem:

Problem with certificates when accessing pulp repo

# yum info penguin
https://hp-dl580g7-02.xxx.com/pulp/repos/ACME_Corporation/testing/custom/product/repo/repodata/repomd.xml:
[Errno 14] PYCURL ERROR 77 - "Problem with the SSL CA cert (path? access rights?)"
Trying other mirror.


REPRODUCER SCRIPT:

#!/bin/bash
K="katello -u admin -p admin"
URL=http://lzap.fedorapeople.org/fakerepos/zoo4
export LC_ALL=en_US

# sync zoo
$K client remember --option org --value ACME_Corporation
$K provider create --name provider --url $URL
$K product create --provider provider --name product --url $URL --nodisc
$K repo create --product product --name repo --url $URL
$K repo synchronize --product product --name repo

# promote zoo
$K environment create --name testing --prior Locker
$K changeset create --name change --environment testing
$K changeset update --name change --environment testing --add_product product
$K changeset promote --name change --environment testing

# configure rhsm
sed -i "s/^hostname\s*=.*/hostname = $(hostname)/g" /etc/rhsm/rhsm.conf
sed -i 's/^prefix\s*=.*/prefix = \/katello\/api/g' /etc/rhsm/rhsm.conf
sed -i 's/^port\s*=.*/port = 443/g' /etc/rhsm/rhsm.conf
sed -i 's/^repo_ca_cert\s*=.*/repo_ca_cert = %(ca_cert_dir)scandlepin-ca.crt/g' /etc/rhsm/rhsm.conf
sed -i "s/^baseurl\s*=.*/baseurl=https:\/\/$(hostname)\/pulp\/repos\//g" /etc/rhsm/rhsm.conf
openssl x509 -outform pem -in /etc/candlepin/certs/candlepin-ca.crt -out /etc/rhsm/ca/candlepin-ca.pem

# self register and subscribe
POOLID=$(sudo subscription-manager list --available --all | grep PoolId | head -n1 | awk '{print $2}') # grab first pool
subscription-manager register --username=admin --password=admin --force --org=ACME_Corporation --environment=testing
subscription-manager subscribe --pool

yum info penguin

Comment 1 Lukas Zapletal 2011-12-23 09:28:04 UTC
More info: https://fedorahosted.org/pipermail/katello/2011-December/000247.html

Comment 2 Ivan Necas 2012-01-09 15:03:34 UTC
It is a bug on Pulp side - on Fedora 16 there is new version than mod_wsgi that is provided (and required) but Pulp. This new version does not include the patch required for correct functionality of the repo authentication. 

Filing a BZ for pulp: https://bugzilla.redhat.com/show_bug.cgi?id=772660

Comment 3 Mike McCune 2012-01-26 19:07:20 UTC
mass ON_QA move

Comment 5 Garik Khachikyan 2012-02-10 16:20:58 UTC
just a note: there is no need to do anything on the client side except:
cp /etc/candlepin/certs/candlepin-ca.crt ./candlepin-local.pem

doing all the steps with this in regard, I was able to fetch the penguin info without problem.

# VERIFIED

and the versions are:
---

katello-0.1.230-1.git.0.7ea815b.el6.noarch
katello-cli-0.1.54-1.git.0.2670189.el6.noarch
pulp-0.0.265-1.el6.noarch
candlepin-0.5.17-1.el6.noarch
subscription-manager-0.99.6-1.el6.x86_64
python-rhsm-0.99.3-1.el6.noarch

Comment 7 Mike McCune 2013-08-16 17:52:25 UTC
getting rid of 6.0.0 version since that doesn't exist