Open pki-bot opened 4 years ago
Comment from edewata (@edewata) at 2020-09-29 12:53:02
Did IPA import the ACME schema as documented here? https://github.com/dogtagpki/pki/blob/master/docs/installation/acme/Configuring_ACME_Database.md
The acmeNonce is defined in this file: https://github.com/dogtagpki/pki/blob/master/base/acme/database/ds/schema.ldif#L62-L64
Comment from edewata (@edewata) at 2020-09-29 12:53:03
Metadata Update from @edewata:
This issue was migrated from Pagure Issue #3214. Originally filed by frenaud (@flo-renaud) on 2020-09-29 12:45:46:
The nightly tests for FreeIPA fail in an ACME test when calling
certbot register
. See PR #439 that is using the copr repo @pki/master:pki-fedora/test_acme
: report and logs.Issue also logged on FreeIPA side as 8520
It looks like the schema for acme objects hcryptomilk't been loaded to the directory server:
/var/log/pki/pki-tomcat/acme/debug.log.gz contains:
Note that the nightly tests using pki 10.9.4-1.fc32.noarch don't have the failure. The issue is consistently reproduced with pki-server-10.10.0-0.1.alpha1.20200925212028UTC.040b5657.fc32.noarch