Uploaded image for project: 'Dogtag PKI'
  1. Dogtag PKI
  2. DOGTAG-4038

/var/log/pki/pki-ca-spawn logs are not generated at PKI subsystem installation and removal

    • None
    • rhel-idm-cs
    • rc
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • 42

      Description of problem:
      /var/log/pki/pki-ca-spawn or /var/log/pki/pki-ca-destroy logs are not generated at PKI subsystem installation and removal

      Version-Release number of selected component (if applicable):
      pki-core-11.2.0-0.4.beta3.el9.src.rpm
      jss-5.2.0-0.3.beta2.el9.src.rpm
      nss-3.71.0-7.el9.src.rpm

      How reproducible:
      Always

      Steps to Reproduce:
      1. Install CA:

      1. cat /tmp/test_dir/ca.cfg
        [DEFAULT]
        pki_instance_name = topology-00-CA
        pki_https_port = 20443
        pki_http_port = 20080

      pki_token_password = SECret.123

      pki_admin_password = SECret.123
      pki_admin_key_type=rsa
      pki_admin_key_size=2048
      pki_admin_key_algorithm=SHA512withRSA

      pki_hostname = pki1.example.com
      pki_security_domain_name = topology-00_Foobarmaster.org
      pki_security_domain_password = SECret.123

      pki_client_dir = /opt/topology-00-CA
      pki_client_pkcs12_password = SECret.123
      pki_backup_keys = True
      pki_backup_password = SECret.123
      pki_ds_password = SECret.123
      pki_ds_ldap_port = 3389

      pki_sslserver_key_algorithm=SHA512withRSA
      pki_sslserver_key_size=2048
      pki_sslserver_key_type=rsa

      pki_subsystem_key_type=rsa
      pki_subsystem_key_size=2048
      pki_subsystem_key_algorithm=SHA512withRSA

      pki_audit_signing_key_algorithm=SHA512withRSA
      pki_audit_signing_key_size=2048
      pki_audit_signing_key_type=rsa
      pki_audit_signing_signing_algorithm=SHA512withRSA

      [Tomcat]
      pki_ajp_port = 20009
      pki_tomcat_server_port = 20005

      [CA]
      pki_import_admin_cert = False
      pki_ds_hostname = pki1.example.com
      pki_admin_nickname = PKI CA Administrator for Example.Org

      pki_ca_signing_key_algorithm=SHA512withRSA
      pki_ca_signing_key_size=2048
      pki_ca_signing_key_type=rsa
      pki_ca_signing_signing_algorithm=SHA512withRSA

      pki_ocsp_signing_key_algorithm=SHA512withRSA
      pki_ocsp_signing_key_size=2048
      pki_ocsp_signing_key_type=rsa
      pki_ocsp_signing_signing_algorithm=SHA512withRSA

      1. pkispawn -s CA -f /tmp/test_dir/ca.cfg --debug

      Actual results:

      DEBUG: Command: chown 17:17 /var/log/pki/topology-00-CA/ca/archive/spawn_manifest.20220516071541

      ==========================================================================
      INSTALLATION SUMMARY
      ==========================================================================

      Administrator's username: caadmin
      Administrator's PKCS #12 file:
      /opt/topology-00-CA/ca_admin_cert.p12

      To check the status of the subsystem:
      systemctl status pki-tomcatd@topology-00-CA.service

      To restart the subsystem:
      systemctl restart pki-tomcatd@topology-00-CA.service

      The URL for the subsystem is:
      https://pki1.example.com:20443/ca

      PKI instances will be enabled upon system boot

      ==========================================================================

      1. ls -l /var/lib/pki/pki-ca-spawn*
        ls: cannot access '/var/lib/pki/pki-ca-spawn*': No such file or directory

      Expected results:
      The pki-ca-spawn file should be supposed to generate at /var/log/pki/ location.

      Additional info:

      https://bugzilla.redhat.com/show_bug.cgi?id=1960146#c11 Bugzilla reproducer automation is failing for RHEL91 pipeline job.
      https://gitlab.cee.redhat.com/prisingh/pki-pytest-ansible/-/jobs/6591783

              jira-bugzilla-migration RH Bugzilla Integration
              prisingh@redhat.com Pritam Singh
              RH Bugzilla Integration RH Bugzilla Integration
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: