Uploaded image for project: 'Dogtag PKI'
  1. Dogtag PKI
  2. DOGTAG-537

[DOC] Add manual steps to verify cert import into HSM in FIPS mode

    • None
    • rhel-idm-cs
    • rc
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • 42

      When installing PKI with HSM in FIPS mode, pkispawn might generate the following warning message:

      certutil: could not change trust on certificate: SEC_ERROR_TOKEN_NOT_LOGGED_IN: The operation failed because the PKCS#11 token is not logged in.

      The message is actually generated by certutil (bug #1393668) but a workaround has been implemented in PKI (bug #1395817), so it's no longer a problem in PKI.

      However, the warning message still appears and may cause some concerns to customers, so some manual steps need to be provided to verify that the certificate was imported properly.

              rhn-support-fdelehay Florian Delehaye (Inactive)
              edewata Endi Dewata
              RH Bugzilla Integration RH Bugzilla Integration
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: