This service will be undergoing maintenance at 00:00 UTC, 2017-10-23 It is expected to last about 30 minutes
Bug 821644 - Create new CLI command admin crl_regen for recovery process
Create new CLI command admin crl_regen for recovery process
Product: Red Hat Satellite 6
Classification: Red Hat
Component: katello-agent (Show other bugs)
Unspecified Unspecified
unspecified Severity medium (vote)
: Unspecified
: --
Assigned To: Lukas Zapletal
Og Maciel
: Triaged, ZStream
Depends On:
Blocks: 828313 835161
  Show dependency treegraph
Reported: 2012-05-15 04:29 EDT by Lukas Zapletal
Modified: 2014-01-27 08:34 EST (History)
6 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Registered clients received errors when attempting to connect to System Engine during backup recovery. This was due to a CRL mismatch between the client and the server. This patch regenerates the CRL ensuring that the CRL subsystem is correctly setup after restoration.
Story Points: ---
Clone Of:
: 828313 (view as bug list)
Last Closed: 2012-12-04 14:45:43 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Lukas Zapletal 2012-05-15 04:29:24 EDT
When running backup recovery, there was one issue running the restore procedure though, my already-registered client was getting 403's in yum.  I think it may be the same symptom as another CRL issue I had earlier, so I'm going to req info from Ivan to see if restoring a several-day old CRL might cause this.

The solution is to create create new CLI command

katello admin crl_regen

and API method/proxy that calls this in Candlepin.

This change will need release note for the BackupRecovery.html chapter:

Once recovery is finished and all systems are running, run the following command to regenerate CRL lists. Otherwise, yum clients will be giving 403 errors when connecting to CloudForms.
Comment 2 Mike McCune 2012-05-30 18:47:04 EDT
This bug has no code modified for it, is there any reason it is ON_DEV?
Comment 3 Lukas Zapletal 2012-05-31 03:33:28 EDT

Merge pull request #151 from lzap/crl_regen_821644
Comment 10 Og Maciel 2012-10-04 12:53:16 EDT
Verified using:

* candlepin-0.7.8-1.el6cf.noarch
* candlepin-selinux-0.7.8-1.el6cf.noarch
* candlepin-tomcat6-0.7.8-1.el6cf.noarch
* katello-1.1.12-12.el6cf.noarch
* katello-all-1.1.12-12.el6cf.noarch
* katello-candlepin-cert-key-pair-1.0-1.noarch
* katello-certs-tools-1.1.8-1.el6cf.noarch
* katello-cli-1.1.8-6.el6cf.noarch
* katello-cli-common-1.1.8-6.el6cf.noarch
* katello-common-1.1.12-12.el6cf.noarch
* katello-configure-1.1.9-6.el6cf.noarch
* katello-glue-candlepin-1.1.12-12.el6cf.noarch
* katello-glue-pulp-1.1.12-12.el6cf.noarch
* katello-qpid-broker-key-pair-1.0-1.noarch
* katello-qpid-client-key-pair-1.0-1.noarch
* katello-selinux-1.1.1-1.el6cf.noarch
* pulp-1.1.12-1.el6cf.noarch
* pulp-common-1.1.12-1.el6cf.noarch
* pulp-selinux-server-1.1.12-1.el6cf.noarch
Comment 12 errata-xmlrpc 2012-12-04 14:45:43 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

Note You need to log in before you can comment on or make changes to this bug.