Red Hat Bugzilla – Bug 975431
IPA PKI cannot publish CRL after upgrade
Last modified: 2013-11-21 15:53:53 EST
This bug is created as a clone of upstream ticket: https://fedorahosted.org/freeipa/ticket/3727 The directory where IPA PKI publishes CRL (`/var/lib/ipa/pki-ca/publish/`) gets wrong ownership after freeipa-server package reinstall which leads to PKI not being able to update CRL in this directory: {{{ # ls -la /var/lib/ipa/pki-ca/publish/ total 244 drwxr-xr-x. 2 root pkiuser 12288 May 17 04:49 . <<< owned by pkiuser group drwxr-xr-x. 3 root root 4096 May 17 04:49 .. ... -rw-rw-r--. 1 pkiuser pkiuser 414 May 17 01:00 MasterCRL-20130517-010000.der lrwxrwxrwx. 1 pkiuser pkiuser 57 May 17 01:00 MasterCRL.bin -> /var/lib/ipa/pki-ca/publish/MasterCRL-20130517-010000.der }}} /var/lib/ipa/pki-ca/publish/ changes when freeipa-server package gets reinstalled or updated: {{{ # yum reinstall freeipa-server ... # ls -la /var/lib/ipa/pki-ca/publish/ total 244 drwxr-xr-x. 2 root root 12288 May 17 04:49 . <<< owned by root drwxr-xr-x. 3 root root 4096 May 17 04:49 .. ... -rw-rw-r--. 1 pkiuser pkiuser 414 May 17 01:00 MasterCRL-20130517-010000.der lrwxrwxrwx. 1 pkiuser pkiuser 57 May 17 01:00 MasterCRL.bin -> /var/lib/ipa/pki-ca/publish/MasterCRL-20130517-010000.der }}} PKI then logs errors like these: {{{ /var/log/pki-ca/system ... 1585.CRLIssuingPoint-MasterCRL - [13/Jun/2013:21:00:00 EDT] [20] [3] FileBasedPublisher: java.io.FileNotFoundException: /var/lib/ipa/pki-ca/publish/MasterCRL-20130613-210000.temp (Permission denied) 1585.CRLIssuingPoint-MasterCRL - [14/Jun/2013:01:00:00 EDT] [20] [3] FileBasedPublisher: java.io.FileNotFoundException: /var/lib/ipa/pki-ca/publish/MasterCRL-20130614-010000.temp (Permission denied) }}}
Re-assign to Tomas Babej.
Fixed upstream: master: 7a105604e265222cf6f96b0ac060d4f1b2504b6c Change group ownership of CRL publish directory ipa-3-2: 1a5daf0dcfeeec26a3869bf7d278b93f9716163d Change group ownership of CRL publish directory
Verified. Version :: ipa-server-3.0.0-34.el6.x86_64 Automated Test Results :: :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: [ LOG ] :: Checking ipa_upgrade_bz975431 - IPA PKI cannot publish CRL after upgrade :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: drwxrwxr-x. 2 root pkiuser 4096 Sep 5 14:11 /var/lib/ipa/pki-ca/publish :: [ PASS ] :: Running 'ls -ld /var/lib/ipa/pki-ca/publish' (Expected 0, got 0) :: [ PASS ] :: BZ 975431 not found
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2013-1651.html