Closed pki-bot closed 4 years ago
Comment from frenaud (@flo-renaud) at 2020-08-17 09:41:33
Note: this is blocking our tests using the nightly dogtagpki copr repo @pki/master
Comment from cipherboy (@cipherboy) at 2020-08-17 10:30:07
@edewata -- Please take a look. Looks like a bug in the pki-acme
split.
Comment from cipherboy (@cipherboy) at 2020-08-17 10:30:08
Metadata Update from @cipherboy:
Comment from cipherboy (@cipherboy) at 2020-08-17 10:34:18
Or, since IPA merged ACME: https://github.com/freeipa/freeipa/pull/4723 -- might need to fix IPA.
Comment from cipherboy (@cipherboy) at 2020-08-24 15:22:01
One fix is being considered here: https://github.com/freeipa/freeipa/pull/5039
Comment from frenaud (@flo-renaud) at 2020-09-10 12:26:19
With a more recent build pki build (10.10.0-0.1.alpha1.20200909013458UTC.eac41b), ipa-server-install is failing later, in the pki-server acme-deploy
step. Please see PR #394, with logs:
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] Configuring certificate server (pki-tomcatd). Estimated time: 3 minutes
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] [1/31]: configuring certificate server instance
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] [2/31]: Add ipa-pki-wait-running
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] [3/31]: secure AJP connector
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] [4/31]: reindex attributes
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] [5/31]: exporting Dogtag certificate store pin
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] [6/31]: stopping certificate server instance to update CS.cfg
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] [7/31]: backing up CS.cfg
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] [8/31]: disabling nonces
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] [9/31]: set up CRL publishing
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] [10/31]: enable PKIX certificate path discovery and validation
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] [11/31]: deploying ACME service
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] [error] CalledProcessError: CalledProcessError(Command ['pki-server', 'acme-deploy'] returned non-zero exit status 1: 'ERROR: Error reading file \'/usr/share/pki/acme/conf/Catalina/localhost/acme.xml\': failed to load external entity "/usr/share/pki/acme/conf/Catalina/localhost/acme.xml"\n')
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] CalledProcessError(Command ['pki-server', 'acme-deploy'] returned non-zero exit status 1: 'ERROR: Error reading file \'/usr/share/pki/acme/conf/Catalina/localhost/acme.xml\': failed to load external entity "/usr/share/pki/acme/conf/Catalina/localhost/acme.xml"\n')
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] The ipa-server-install command failed. See /var/log/ipaserver-install.log for more information
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] Exit code: 1
Comment from frenaud (@flo-renaud) at 2020-09-24 04:03:37
Fixed with https://pagure.io/freeipa/c/c0461eb37ccf0b87b05f81380cf60dffdd26a3dc?branch=master on freeipa side: spec: require pki-acme if pki-ca >= 10.10
Comment from frenaud (@flo-renaud) at 2020-09-24 04:03:38
Metadata Update from @flo-renaud:
This issue was migrated from Pagure Issue #3206. Originally filed by frenaud (@flo-renaud) on 2020-08-17 09:38:42:
FreeIPA nightly tests are failing in ipa-server-install in the pkispawn step, when using pki nightly copr repo. See the PR #353, with the following report and logs.
ipa-server-install logs:
pki-ca-spawn logs:
Installed packages: