freeipa team mailing list archive
-
freeipa team
-
Mailing list archive
-
Message #00644
[Bug 1769440] [NEW] freeipa server install fails - Configuring the web interface, setting up ssl
Public bug reported:
Setting up FreeIPA server fails at "Configuring the web interface", step
12/21
It's in a cleanly started LXC Ubuntu Bionic container. The
ppa:freeipa/ppa is also used to get tomcat 8.5.30-1ubuntu1.2
Configuring the web interface (httpd)
[1/21]: stopping httpd
[2/21]: backing up ssl.conf
[3/21]: disabling nss.conf
[4/21]: configuring mod_ssl certificate paths
[5/21]: setting mod_ssl protocol list to TLSv1.0 - TLSv1.2
[6/21]: configuring mod_ssl log directory
[7/21]: disabling mod_ssl OCSP
[8/21]: adding URL rewriting rules
[9/21]: configuring httpd
[10/21]: setting up httpd keytab
[11/21]: configuring Gssproxy
[12/21]: setting up ssl
[error] RuntimeError: Certificate issuance failed (CA_REJECTED)
ipapython.admintool: ERROR Certificate issuance failed (CA_REJECTED)
ipapython.admintool: ERROR The ipa-server-install command failed. See /var/log/ipaserver-install.log for more information
and in the log there is
2018-05-05T20:37:29Z DEBUG stderr=
2018-05-05T20:37:29Z DEBUG step duration: httpd configure_gssproxy 1.09 sec
2018-05-05T20:37:29Z DEBUG [12/21]: setting up ssl
2018-05-05T20:37:33Z DEBUG certmonger request is in state dbus.String(u'GENERATING_KEY_PAIR', variant_level=1)
2018-05-05T20:37:38Z DEBUG certmonger request is in state dbus.String(u'CA_REJECTED', variant_level=1)
2018-05-05T20:37:42Z DEBUG Traceback (most recent call last):
File "/usr/lib/python2.7/dist-packages/ipaserver/install/service.py", line 555, in start_creation
run_step(full_msg, method)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/service.py", line 541, in run_step
method()
File "/usr/lib/python2.7/dist-packages/ipaserver/install/httpinstance.py", line 376, in __setup_ssl
passwd_fname=key_passwd_file
File "/usr/lib/python2.7/dist-packages/ipalib/install/certmonger.py", line 320, in request_and_wait_for_cert
raise RuntimeError("Certificate issuance failed ({})".format(state))
RuntimeError: Certificate issuance failed (CA_REJECTED)
2018-05-05T20:37:42Z DEBUG [error] RuntimeError: Certificate issuance failed (CA_REJECTED)
2018-05-05T20:37:42Z DEBUG File "/usr/lib/python2.7/dist-packages/ipapython/admintool.py", line 174, in exec
ute
...
** Affects: freeipa (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of FreeIPA,
which is subscribed to freeipa in Ubuntu.
https://bugs.launchpad.net/bugs/1769440
Title:
freeipa server install fails - Configuring the web interface, setting
up ssl
Status in freeipa package in Ubuntu:
New
Bug description:
Setting up FreeIPA server fails at "Configuring the web interface",
step 12/21
It's in a cleanly started LXC Ubuntu Bionic container. The
ppa:freeipa/ppa is also used to get tomcat 8.5.30-1ubuntu1.2
Configuring the web interface (httpd)
[1/21]: stopping httpd
[2/21]: backing up ssl.conf
[3/21]: disabling nss.conf
[4/21]: configuring mod_ssl certificate paths
[5/21]: setting mod_ssl protocol list to TLSv1.0 - TLSv1.2
[6/21]: configuring mod_ssl log directory
[7/21]: disabling mod_ssl OCSP
[8/21]: adding URL rewriting rules
[9/21]: configuring httpd
[10/21]: setting up httpd keytab
[11/21]: configuring Gssproxy
[12/21]: setting up ssl
[error] RuntimeError: Certificate issuance failed (CA_REJECTED)
ipapython.admintool: ERROR Certificate issuance failed (CA_REJECTED)
ipapython.admintool: ERROR The ipa-server-install command failed. See /var/log/ipaserver-install.log for more information
and in the log there is
2018-05-05T20:37:29Z DEBUG stderr=
2018-05-05T20:37:29Z DEBUG step duration: httpd configure_gssproxy 1.09 sec
2018-05-05T20:37:29Z DEBUG [12/21]: setting up ssl
2018-05-05T20:37:33Z DEBUG certmonger request is in state dbus.String(u'GENERATING_KEY_PAIR', variant_level=1)
2018-05-05T20:37:38Z DEBUG certmonger request is in state dbus.String(u'CA_REJECTED', variant_level=1)
2018-05-05T20:37:42Z DEBUG Traceback (most recent call last):
File "/usr/lib/python2.7/dist-packages/ipaserver/install/service.py", line 555, in start_creation
run_step(full_msg, method)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/service.py", line 541, in run_step
method()
File "/usr/lib/python2.7/dist-packages/ipaserver/install/httpinstance.py", line 376, in __setup_ssl
passwd_fname=key_passwd_file
File "/usr/lib/python2.7/dist-packages/ipalib/install/certmonger.py", line 320, in request_and_wait_for_cert
raise RuntimeError("Certificate issuance failed ({})".format(state))
RuntimeError: Certificate issuance failed (CA_REJECTED)
2018-05-05T20:37:42Z DEBUG [error] RuntimeError: Certificate issuance failed (CA_REJECTED)
2018-05-05T20:37:42Z DEBUG File "/usr/lib/python2.7/dist-packages/ipapython/admintool.py", line 174, in exec
ute
...
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/freeipa/+bug/1769440/+subscriptions
Follow ups
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Nicolás Pinochet, 2018-12-26
-
[Bug 1769440] Update Released
From: Łukasz Zemczak, 2018-11-19
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Launchpad Bug Tracker, 2018-11-19
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: gianluca, 2018-11-17
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Meluco, 2018-10-30
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-10-26
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Timo Aaltonen, 2018-10-23
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-10-23
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: keestux, 2018-10-23
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-10-15
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Launchpad Bug Tracker, 2018-10-10
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-10-10
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: gianluca, 2018-10-06
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Launchpad Bug Tracker, 2018-09-23
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: keestux, 2018-09-06
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: David Britton, 2018-09-05
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Gabriel Devenyi, 2018-09-05
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Launchpad Bug Tracker, 2018-09-05
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Karl Stenerud, 2018-08-29
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Karl Stenerud, 2018-08-29
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Launchpad Bug Tracker, 2018-08-29
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Karl Stenerud, 2018-08-28
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Timo Aaltonen, 2018-08-24
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-08-24
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-08-24
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-08-24
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-08-24
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Timo Aaltonen, 2018-08-14
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-08-14
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Robie Basak, 2018-08-13
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Gabriel Devenyi, 2018-08-08
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: garyx, 2018-08-08
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Gabriel Devenyi, 2018-08-02
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-08-02
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Robie Basak, 2018-08-02
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Gabriel Devenyi, 2018-08-01
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Timo Aaltonen, 2018-07-31
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Timo Aaltonen, 2018-07-31
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Gabriel Devenyi, 2018-07-30
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Gabriel Devenyi, 2018-07-30
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: gianluca, 2018-06-26
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Alexey Krasilnikov, 2018-06-26
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Timo Aaltonen, 2018-06-26
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Timo Aaltonen, 2018-06-26
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Harry Coin, 2018-06-25
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Harry Coin, 2018-06-24
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Harry Coin, 2018-06-24
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Harry Coin, 2018-06-23
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-06-20
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-06-20
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-06-19
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: gianluca, 2018-06-18
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: gianluca, 2018-05-23
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-05-23
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Timo Aaltonen, 2018-05-23
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Timo Aaltonen, 2018-05-23
-
[Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run
From: Andreas Hasenack, 2018-05-23
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: Timo Aaltonen, 2018-05-23
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: gianluca, 2018-05-23
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: Norman Kabir, 2018-05-21
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: gianluca, 2018-05-21
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: Timo Aaltonen, 2018-05-21
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: gianluca, 2018-05-21
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: Timo Aaltonen, 2018-05-20
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: gianluca, 2018-05-20
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: Launchpad Bug Tracker, 2018-05-19
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: Timo Aaltonen, 2018-05-08
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: keestux, 2018-05-08
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: keestux, 2018-05-08
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: keestux, 2018-05-08
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: Timo Aaltonen, 2018-05-08
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: keestux, 2018-05-08
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: Stan R, 2018-05-07
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: Timo Aaltonen, 2018-05-07
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: keestux, 2018-05-07
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: keestux, 2018-05-07
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: Timo Aaltonen, 2018-05-06
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: keestux, 2018-05-06
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: keestux, 2018-05-06
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: Timo Aaltonen, 2018-05-06
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: keestux, 2018-05-06
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: Timo Aaltonen, 2018-05-06
-
[Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl
From: keestux, 2018-05-06