From amrivkin at gmail.com Fri Feb 16 17:29:05 2018 Content-Type: multipart/mixed; boundary="===============5014637481034017603==" MIME-Version: 1.0 From: Markovich To: freeipa-users at lists.fedorahosted.org Subject: [Freeipa-users] FreeIpa install failed on CA did not start in 300.0s Date: Fri, 16 Feb 2018 20:28:47 +0300 Message-ID: --===============5014637481034017603== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Hi FreeIPA users, Please help find wat's going wrong while reinstalling freeipa... 2018-02-16T16:41:30Z DEBUG response body '\n\n\nError 405 HTTP method POST is not supported by this URL:8080/ca/admin/ca/getStatus 2018-02-16T16:41:31Z DEBUG request body '' 2018-02-16T16:41:31Z DEBUG response status 405 2018-02-16T16:41:31Z DEBUG response headers Date: Fri, 16 Feb 2018 16:41:31 GMT Cache-Control: must-revalidate,no-cache,no-store Content-Type: text/html;charset=3Diso-8859-1 Content-Length: 408 Server: Jetty(9.3.z-SNAPSHOT) CA did not start in 300.0s CRITICAL Failed to restart the Dogtag instance.See the installation log for details. ERROR Unable to retrieve CA chain: Retrieving CA cert chain failed: list index out of range Also in log: 2018-02-16T16:35:12Z DEBUG stderr=3D 2018-02-16T16:35:12Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-16T16:35:12Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-16T16:35:12Z DEBUG Starting external process 2018-02-16T16:35:12Z DEBUG args=3D/bin/systemctl disable krb5kdc.service 2018-02-16T16:35:12Z DEBUG Process finished, return code=3D0 2018-02-16T16:35:12Z DEBUG stdout=3D 2018-02-16T16:35:12Z DEBUG stderr=3D 2018-02-16T16:35:12Z DEBUG duration: 0 seconds 2018-02-16T16:35:12Z DEBUG Done configuring Kerberos KDC (krb5kdc). 2018-02-16T16:35:12Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-16T16:35:12Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-16T16:35:12Z DEBUG Configuring kadmin 2018-02-16T16:35:12Z DEBUG [1/2]: starting kadmin 2018-02-16T16:35:12Z DEBUG Starting external process 2018-02-16T16:35:12Z DEBUG args=3D/bin/systemctl is-active kadmin.service 2018-02-16T16:35:12Z DEBUG Process finished, return code=3D3 2018-02-16T16:35:12Z DEBUG stdout=3Dfailed In /var/log/pki/pki-tomcat/ca/debug [16/Feb/2018:16:35:22][localhost-startStop-1]: LdapBoundConnFactory: init Property internaldb.ldapconn.port missing value ... [16/Feb/2018:16:36:20][http-bio-8443-exec-3]: CertificateAuthority:initSigUnit: ca.signing.cert not found Property ca.signing.cacertnickname missing value ... [16/Feb/2018:16:36:20][http-bio-8443-exec-3]: CA signing unit inited [16/Feb/2018:16:36:20][http-bio-8443-exec-3]: cachainNum=3D 0 Could not get or build CA chain. Error java.security.cert.CertificateException: Certificate is not a PKCS #11 certificate ... [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: CertificateAuthority:initSigUnit: ca cert found [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: CertificateAuthority: initSigUnit 1- setting mIssuerObj and mSubjectObj [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: ca.signing Signing Unit nickname caSigningCert cert-pki-ca [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: Got token Internal Key Storage Token by name [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: Found cert by nickname: 'caSigningCert cert-pki-ca' with serial number: 1 [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: converted to x509CertImpl [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: Got private key from cert [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: Got public key from cert [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: got signing algorithm RSASignatureWithSHA256Digest [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: CA signing unit inited [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: cachainNum=3D 0 [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: in init - got CA chain from JSS. [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: ca.ocsp_signing Signing Unit nickname ocspSigningCert cert-pki-ca [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: Got token Internal Key Storage Token by name [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: Unable to find certificate ocspSigningCert cert-pki-ca [16/Feb/2018:16:36:23][http-bio-8443-exec-3]: SigningUnit: Certificate object not found Regards, Andrey --===============5014637481034017603== Content-Type: text/html MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="attachment.html" PGRpdiBkaXI9Imx0ciI+SGkgRnJlZUlQQSB1c2Vycyw8ZGl2Pjxicj48L2Rpdj48ZGl2PlBsZWFz ZSBoZWxwIGZpbmQgd2F0JiMzOTtzIGdvaW5nIHdyb25nIHdoaWxlIHJlaW5zdGFsbGluZyBmcmVl aXBhLi4uPC9kaXY+PGRpdj48YnI+PC9kaXY+PGRpdj48YnI+PC9kaXY+PGRpdj48ZGl2PjIwMTgt MDItMTZUMTY6NDE6MzBaIERFQlVHIHJlc3BvbnNlIGJvZHkgJiMzOTsmbHQ7aHRtbCZndDtcbiZs dDtoZWFkJmd0O1xuJmx0O21ldGEgaHR0cC1lcXVpdj0mcXVvdDtDb250ZW50LVR5cGUmcXVvdDsg Y29udGVudD0mcXVvdDt0ZXh0L2h0bWw7Y2hhcnNldD11dGYtOCZxdW90Oy8mZ3Q7XG4mbHQ7dGl0 bGUmZ3Q7RXJyb3IgNDA1IEhUVFAgbWV0aG9kIFBPU1QgaXMgbm90IHN1cHBvcnRlZCBieSB0aGlz IFVSTCZsdDsvdGl0bGUkPC9kaXY+PGRpdj4yMDE4LTAyLTE2VDE2OjQxOjMwWiBERUJVRyBUaGUg Q0Egc3RhdHVzIGlzOiBjaGVjayBpbnRlcnJ1cHRlZCBkdWUgdG8gZXJyb3I6IFJldHJpZXZpbmcg Q0Egc3RhdHVzIGZhaWxlZCB3aXRoIHN0YXR1cyA0MDU8L2Rpdj48ZGl2PjIwMTgtMDItMTZUMTY6 NDE6MzBaIERFQlVHIFdhaXRpbmcgZm9yIENBIHRvIHN0YXJ0Li4uPC9kaXY+PGRpdj4yMDE4LTAy LTE2VDE2OjQxOjMxWiBERUJVRyByZXF1ZXN0IFBPU1QgaHR0cDovLyZsdDtob3N0bmFtZSZndDs6 ODA4MC9jYS9hZG1pbi9jYS9nZXRTdGF0dXM8L2Rpdj48ZGl2PjIwMTgtMDItMTZUMTY6NDE6MzFa IERFQlVHIHJlcXVlc3QgYm9keSAmIzM5OyYjMzk7PC9kaXY+PGRpdj4yMDE4LTAyLTE2VDE2OjQx OjMxWiBERUJVRyByZXNwb25zZSBzdGF0dXMgNDA1PC9kaXY+PGRpdj4yMDE4LTAyLTE2VDE2OjQx OjMxWiBERUJVRyByZXNwb25zZSBoZWFkZXJzIERhdGU6IEZyaSwgMTYgRmViIDIwMTggMTY6NDE6 MzEgR01UPC9kaXY+PGRpdj5DYWNoZS1Db250cm9sOiBtdXN0LXJldmFsaWRhdGUsbm8tY2FjaGUs bm8tc3RvcmU8L2Rpdj48ZGl2PkNvbnRlbnQtVHlwZTogdGV4dC9odG1sO2NoYXJzZXQ9aXNvLTg4 NTktMTwvZGl2PjxkaXY+Q29udGVudC1MZW5ndGg6IDQwODwvZGl2PjxkaXY+U2VydmVyOiBKZXR0 eSg5LjMuei1TTkFQU0hPVCk8L2Rpdj48ZGl2Pjxicj48L2Rpdj48ZGl2Pjxicj48L2Rpdj48ZGl2 PkNBIGRpZCBub3Qgc3RhcnQgaW4gMzAwLjBzPGJyPjwvZGl2PjxkaXY+Q1JJVElDQUwgRmFpbGVk IHRvIHJlc3RhcnQgdGhlIERvZ3RhZyBpbnN0YW5jZS5TZWUgdGhlIGluc3RhbGxhdGlvbiBsb2cg Zm9yIGRldGFpbHMuPGJyPjwvZGl2PjxkaXY+RVJST1IgVW5hYmxlIHRvIHJldHJpZXZlIENBIGNo YWluOiBSZXRyaWV2aW5nIENBIGNlcnQgY2hhaW4gZmFpbGVkOiBsaXN0IGluZGV4IG91dCBvZiBy YW5nZTxicj48L2Rpdj48ZGl2Pjxicj48L2Rpdj48ZGl2Pjxicj48L2Rpdj48ZGl2Pjxicj48L2Rp dj48ZGl2Pjxicj48L2Rpdj48ZGl2Pjxicj48L2Rpdj48ZGl2PkFsc28gaW4gbG9nOjwvZGl2Pjxk aXY+PGJyPjwvZGl2PjxkaXY+PGJyPjwvZGl2PjxkaXY+PGRpdj4yMDE4LTAyLTE2VDE2OjM1OjEy WiBERUJVRyBzdGRlcnI9PC9kaXY+PGRpdj4yMDE4LTAyLTE2VDE2OjM1OjEyWiBERUJVRyBMb2Fk aW5nIFN0YXRlRmlsZSBmcm9tICYjMzk7L3Zhci9saWIvaXBhL3N5c3Jlc3RvcmUvc3lzcmVzdG9y ZS5zdGF0ZSYjMzk7PC9kaXY+PGRpdj4yMDE4LTAyLTE2VDE2OjM1OjEyWiBERUJVRyBTYXZpbmcg U3RhdGVGaWxlIHRvICYjMzk7L3Zhci9saWIvaXBhL3N5c3Jlc3RvcmUvc3lzcmVzdG9yZS5zdGF0 ZSYjMzk7PC9kaXY+PGRpdj4yMDE4LTAyLTE2VDE2OjM1OjEyWiBERUJVRyBTdGFydGluZyBleHRl cm5hbCBwcm9jZXNzPC9kaXY+PGRpdj4yMDE4LTAyLTE2VDE2OjM1OjEyWiBERUJVRyBhcmdzPS9i aW4vc3lzdGVtY3RsIGRpc2FibGUga3JiNWtkYy5zZXJ2aWNlPC9kaXY+PGRpdj4yMDE4LTAyLTE2 VDE2OjM1OjEyWiBERUJVRyBQcm9jZXNzIGZpbmlzaGVkLCByZXR1cm4gY29kZT0wPC9kaXY+PGRp dj4yMDE4LTAyLTE2VDE2OjM1OjEyWiBERUJVRyBzdGRvdXQ9PC9kaXY+PGRpdj4yMDE4LTAyLTE2 VDE2OjM1OjEyWiBERUJVRyBzdGRlcnI9PC9kaXY+PGRpdj4yMDE4LTAyLTE2VDE2OjM1OjEyWiBE RUJVR8KgIMKgZHVyYXRpb246IDAgc2Vjb25kczwvZGl2PjxkaXY+MjAxOC0wMi0xNlQxNjozNTox MlogREVCVUcgRG9uZSBjb25maWd1cmluZyBLZXJiZXJvcyBLREMgKGtyYjVrZGMpLjwvZGl2Pjxk aXY+MjAxOC0wMi0xNlQxNjozNToxMlogREVCVUcgTG9hZGluZyBTdGF0ZUZpbGUgZnJvbSAmIzM5 Oy92YXIvbGliL2lwYS9zeXNyZXN0b3JlL3N5c3Jlc3RvcmUuc3RhdGUmIzM5OzwvZGl2PjxkaXY+ MjAxOC0wMi0xNlQxNjozNToxMlogREVCVUcgTG9hZGluZyBJbmRleCBmaWxlIGZyb20gJiMzOTsv dmFyL2xpYi9pcGEvc3lzcmVzdG9yZS9zeXNyZXN0b3JlLmluZGV4JiMzOTs8L2Rpdj48ZGl2PjIw MTgtMDItMTZUMTY6MzU6MTJaIERFQlVHIENvbmZpZ3VyaW5nIGthZG1pbjwvZGl2PjxkaXY+MjAx OC0wMi0xNlQxNjozNToxMlogREVCVUfCoCDCoFsxLzJdOiBzdGFydGluZyBrYWRtaW48L2Rpdj48 ZGl2PjIwMTgtMDItMTZUMTY6MzU6MTJaIERFQlVHIFN0YXJ0aW5nIGV4dGVybmFsIHByb2Nlc3M8 L2Rpdj48ZGl2PjIwMTgtMDItMTZUMTY6MzU6MTJaIERFQlVHIGFyZ3M9L2Jpbi9zeXN0ZW1jdGwg aXMtYWN0aXZlIGthZG1pbi5zZXJ2aWNlPC9kaXY+PGRpdj4yMDE4LTAyLTE2VDE2OjM1OjEyWiBE RUJVRyBQcm9jZXNzIGZpbmlzaGVkLCByZXR1cm4gY29kZT0zPC9kaXY+PGRpdj4yMDE4LTAyLTE2 VDE2OjM1OjEyWiBERUJVRyBzdGRvdXQ9ZmFpbGVkPC9kaXY+PC9kaXY+PGRpdj48YnI+PC9kaXY+ PGRpdj48YnI+PC9kaXY+PGRpdj5JbsKgL3Zhci9sb2cvcGtpL3BraS10b21jYXQvY2EvZGVidWc8 L2Rpdj48ZGl2Pjxicj48L2Rpdj48ZGl2Pjxicj48L2Rpdj48ZGl2PjxkaXY+WzE2L0ZlYi8yMDE4 OjE2OjM1OjIyXVtsb2NhbGhvc3Qtc3RhcnRTdG9wLTFdOiBMZGFwQm91bmRDb25uRmFjdG9yeTog aW5pdDwvZGl2PjxkaXY+UHJvcGVydHkgaW50ZXJuYWxkYi5sZGFwY29ubi5wb3J0IG1pc3Npbmcg dmFsdWU8L2Rpdj48L2Rpdj48ZGl2Pi4uLjwvZGl2PjxkaXY+PGJyPjwvZGl2PjxkaXY+PGRpdj5b MTYvRmViLzIwMTg6MTY6MzY6MjBdW2h0dHAtYmlvLTg0NDMtZXhlYy0zXTogQ2VydGlmaWNhdGVB dXRob3JpdHk6aW5pdFNpZ1VuaXQ6IGNhLnNpZ25pbmcuY2VydCBub3QgZm91bmQ8L2Rpdj48ZGl2 PlByb3BlcnR5IGNhLnNpZ25pbmcuY2FjZXJ0bmlja25hbWUgbWlzc2luZyB2YWx1ZTwvZGl2Pjwv ZGl2PjxkaXY+PGJyPjwvZGl2PjxkaXY+Li4uPC9kaXY+PGRpdj48ZGl2PlsxNi9GZWIvMjAxODox NjozNjoyMF1baHR0cC1iaW8tODQ0My1leGVjLTNdOiBDQSBzaWduaW5nIHVuaXQgaW5pdGVkPC9k aXY+PGRpdj5bMTYvRmViLzIwMTg6MTY6MzY6MjBdW2h0dHAtYmlvLTg0NDMtZXhlYy0zXTogY2Fj aGFpbk51bT0gMDwvZGl2PjxkaXY+Q291bGQgbm90IGdldCBvciBidWlsZCBDQSBjaGFpbi4gRXJy b3IgamF2YS5zZWN1cml0eS5jZXJ0LkNlcnRpZmljYXRlRXhjZXB0aW9uOiBDZXJ0aWZpY2F0ZSBp cyBub3QgYSBQS0NTICMxMSBjZXJ0aWZpY2F0ZTwvZGl2PjwvZGl2PjxkaXY+Li4uPC9kaXY+PGRp dj48YnI+PC9kaXY+PGRpdj48ZGl2PlsxNi9GZWIvMjAxODoxNjozNjoyM11baHR0cC1iaW8tODQ0 My1leGVjLTNdOiBDZXJ0aWZpY2F0ZUF1dGhvcml0eTppbml0U2lnVW5pdDogY2EgY2VydCBmb3Vu ZDwvZGl2PjxkaXY+WzE2L0ZlYi8yMDE4OjE2OjM2OjIzXVtodHRwLWJpby04NDQzLWV4ZWMtM106 IENlcnRpZmljYXRlQXV0aG9yaXR5OiBpbml0U2lnVW5pdCAxLSBzZXR0aW5nIG1Jc3N1ZXJPYmog YW5kIG1TdWJqZWN0T2JqPC9kaXY+PGRpdj5bMTYvRmViLzIwMTg6MTY6MzY6MjNdW2h0dHAtYmlv LTg0NDMtZXhlYy0zXTogY2Euc2lnbmluZyBTaWduaW5nIFVuaXQgbmlja25hbWUgY2FTaWduaW5n Q2VydCBjZXJ0LXBraS1jYTwvZGl2PjxkaXY+WzE2L0ZlYi8yMDE4OjE2OjM2OjIzXVtodHRwLWJp by04NDQzLWV4ZWMtM106IEdvdCB0b2tlbiBJbnRlcm5hbCBLZXkgU3RvcmFnZSBUb2tlbiBieSBu YW1lPC9kaXY+PGRpdj5bMTYvRmViLzIwMTg6MTY6MzY6MjNdW2h0dHAtYmlvLTg0NDMtZXhlYy0z XTogRm91bmQgY2VydCBieSBuaWNrbmFtZTogJiMzOTtjYVNpZ25pbmdDZXJ0IGNlcnQtcGtpLWNh JiMzOTsgd2l0aCBzZXJpYWwgbnVtYmVyOiAxPC9kaXY+PGRpdj5bMTYvRmViLzIwMTg6MTY6MzY6 MjNdW2h0dHAtYmlvLTg0NDMtZXhlYy0zXTogY29udmVydGVkIHRvIHg1MDlDZXJ0SW1wbDwvZGl2 PjxkaXY+WzE2L0ZlYi8yMDE4OjE2OjM2OjIzXVtodHRwLWJpby04NDQzLWV4ZWMtM106IEdvdCBw cml2YXRlIGtleSBmcm9tIGNlcnQ8L2Rpdj48ZGl2PlsxNi9GZWIvMjAxODoxNjozNjoyM11baHR0 cC1iaW8tODQ0My1leGVjLTNdOiBHb3QgcHVibGljIGtleSBmcm9tIGNlcnQ8L2Rpdj48ZGl2Plsx Ni9GZWIvMjAxODoxNjozNjoyM11baHR0cC1iaW8tODQ0My1leGVjLTNdOiBnb3Qgc2lnbmluZyBh bGdvcml0aG0gUlNBU2lnbmF0dXJlV2l0aFNIQTI1NkRpZ2VzdDwvZGl2PjxkaXY+WzE2L0ZlYi8y MDE4OjE2OjM2OjIzXVtodHRwLWJpby04NDQzLWV4ZWMtM106IENBIHNpZ25pbmcgdW5pdCBpbml0 ZWQ8L2Rpdj48ZGl2PlsxNi9GZWIvMjAxODoxNjozNjoyM11baHR0cC1iaW8tODQ0My1leGVjLTNd OiBjYWNoYWluTnVtPSAwPC9kaXY+PGRpdj5bMTYvRmViLzIwMTg6MTY6MzY6MjNdW2h0dHAtYmlv LTg0NDMtZXhlYy0zXTogaW4gaW5pdCAtIGdvdCBDQSBjaGFpbiBmcm9tIEpTUy48L2Rpdj48ZGl2 PlsxNi9GZWIvMjAxODoxNjozNjoyM11baHR0cC1iaW8tODQ0My1leGVjLTNdOiBjYS5vY3NwX3Np Z25pbmcgU2lnbmluZyBVbml0IG5pY2tuYW1lIG9jc3BTaWduaW5nQ2VydCBjZXJ0LXBraS1jYTwv ZGl2PjxkaXY+WzE2L0ZlYi8yMDE4OjE2OjM2OjIzXVtodHRwLWJpby04NDQzLWV4ZWMtM106IEdv dCB0b2tlbiBJbnRlcm5hbCBLZXkgU3RvcmFnZSBUb2tlbiBieSBuYW1lPC9kaXY+PGRpdj5bMTYv RmViLzIwMTg6MTY6MzY6MjNdW2h0dHAtYmlvLTg0NDMtZXhlYy0zXTogVW5hYmxlIHRvIGZpbmQg Y2VydGlmaWNhdGUgb2NzcFNpZ25pbmdDZXJ0IGNlcnQtcGtpLWNhPC9kaXY+PGRpdj5bMTYvRmVi LzIwMTg6MTY6MzY6MjNdW2h0dHAtYmlvLTg0NDMtZXhlYy0zXTogU2lnbmluZ1VuaXQ6IENlcnRp ZmljYXRlIG9iamVjdCBub3QgZm91bmQ8L2Rpdj48L2Rpdj48ZGl2Pjxicj48L2Rpdj48ZGl2Pjxi cj48L2Rpdj48ZGl2PlJlZ2FyZHMsPC9kaXY+PGRpdj5BbmRyZXk8L2Rpdj48ZGl2Pjxicj48L2Rp dj48L2Rpdj48L2Rpdj4K --===============5014637481034017603==--