-
Bug
-
Resolution: Unresolved
-
Minor
-
certsys-11.0
Description of problem:
/var/log/pki/pki-ca-spawn or /var/log/pki/pki-ca-destroy logs are not generated at PKI subsystem installation and removal
Version-Release number of selected component (if applicable):
pki-core-11.2.0-0.4.beta3.el9.src.rpm
jss-5.2.0-0.3.beta2.el9.src.rpm
nss-3.71.0-7.el9.src.rpm
How reproducible:
Always
Steps to Reproduce:
1. Install CA:
- cat /tmp/test_dir/ca.cfg
[DEFAULT]
pki_instance_name = topology-00-CA
pki_https_port = 20443
pki_http_port = 20080
pki_token_password = SECret.123
pki_admin_password = SECret.123
pki_admin_key_type=rsa
pki_admin_key_size=2048
pki_admin_key_algorithm=SHA512withRSA
pki_hostname = pki1.example.com
pki_security_domain_name = topology-00_Foobarmaster.org
pki_security_domain_password = SECret.123
pki_client_dir = /opt/topology-00-CA
pki_client_pkcs12_password = SECret.123
pki_backup_keys = True
pki_backup_password = SECret.123
pki_ds_password = SECret.123
pki_ds_ldap_port = 3389
pki_sslserver_key_algorithm=SHA512withRSA
pki_sslserver_key_size=2048
pki_sslserver_key_type=rsa
pki_subsystem_key_type=rsa
pki_subsystem_key_size=2048
pki_subsystem_key_algorithm=SHA512withRSA
pki_audit_signing_key_algorithm=SHA512withRSA
pki_audit_signing_key_size=2048
pki_audit_signing_key_type=rsa
pki_audit_signing_signing_algorithm=SHA512withRSA
[Tomcat]
pki_ajp_port = 20009
pki_tomcat_server_port = 20005
[CA]
pki_import_admin_cert = False
pki_ds_hostname = pki1.example.com
pki_admin_nickname = PKI CA Administrator for Example.Org
pki_ca_signing_key_algorithm=SHA512withRSA
pki_ca_signing_key_size=2048
pki_ca_signing_key_type=rsa
pki_ca_signing_signing_algorithm=SHA512withRSA
pki_ocsp_signing_key_algorithm=SHA512withRSA
pki_ocsp_signing_key_size=2048
pki_ocsp_signing_key_type=rsa
pki_ocsp_signing_signing_algorithm=SHA512withRSA
- pkispawn -s CA -f /tmp/test_dir/ca.cfg --debug
Actual results:
DEBUG: Command: chown 17:17 /var/log/pki/topology-00-CA/ca/archive/spawn_manifest.20220516071541
==========================================================================
INSTALLATION SUMMARY
==========================================================================
Administrator's username: caadmin
Administrator's PKCS #12 file:
/opt/topology-00-CA/ca_admin_cert.p12
To check the status of the subsystem:
systemctl status pki-tomcatd@topology-00-CA.service
To restart the subsystem:
systemctl restart pki-tomcatd@topology-00-CA.service
The URL for the subsystem is:
https://pki1.example.com:20443/ca
PKI instances will be enabled upon system boot
==========================================================================
- ls -l /var/lib/pki/pki-ca-spawn*
ls: cannot access '/var/lib/pki/pki-ca-spawn*': No such file or directory
Expected results:
The pki-ca-spawn file should be supposed to generate at /var/log/pki/ location.
Additional info:
https://bugzilla.redhat.com/show_bug.cgi?id=1960146#c11 Bugzilla reproducer automation is failing for RHEL91 pipeline job.
https://gitlab.cee.redhat.com/prisingh/pki-pytest-ansible/-/jobs/6591783