Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

pkispawn fails for CA during key backup with pki-server subsystem-cert-export #4992

Open
taherrin opened this issue Mar 11, 2025 · 0 comments

Comments

@taherrin
Copy link

taherrin commented Mar 11, 2025

Summary:

CA pkispawn fails with the below output:

Installation failed: Command failed: pki-server subsystem-cert-export ca -i topology-00-CA --pkcs12-file /var/lib/pki/topology-00-CA/conf/alias/ca_backup_keys.p12 --pkcs12-password-file /tmp/tmp9ez3szfa/password.txt

ca.cfg

Build:

OS: fedora-41
dogtag-pki-11.7.0-0.1.alpha1.20250311154011UTC.c331ad19.fc41.x86_64
COPR: @pki/master

Steps to reproduce:

  1. Install dogtag-pki packages
  2. Install CA with pkispawn command
# pkispawn -s CA -f /tmp/test_dir/ca.cfg --debug

Expected Result:

pkispawn for CA will be successful

Actual Result:

pkispawn fails during key backup using pki-server subsystem-cert-export with error below:

INFO: Loading external certs from /var/lib/pki/topology-00-CA/conf/external_certs.conf
INFO: File does not exist: /var/lib/pki/topology-00-CA/conf/external_certs.conf
INFO: Backing up keys into /var/lib/pki/topology-00-CA/conf/alias/ca_backup_keys.p12
DEBUG: Command: pki-server subsystem-cert-export ca -i topology-00-CA --pkcs12-file /var/lib/pki/topology-00-CA/conf/alias/ca_backup_keys.p12 --pkcs12-password-file /tmp/tmp9ez3szfa/password.txt
ERROR: Certificate not found: 
ERROR: CalledProcessError: Command '['pki-server', 'subsystem-cert-export', 'ca', '-i', 'topology-00-CA', '--pkcs12-file', '/var/lib/pki/topology-00-CA/conf/alias/ca_backup_keys.p12', '--pkcs12-password-file', '/tmp/tmp9ez3szfa/password.txt']' returned non-zero exit status 255.
  File "/usr/lib/python3.13/site-packages/pki/server/pkispawn.py", line 594, in main
    deployer.spawn()
    ~~~~~~~~~~~~~~^^
  File "/usr/lib/python3.13/site-packages/pki/server/deployment/__init__.py", line 5982, in spawn
    scriptlet.spawn(self)
    ~~~~~~~~~~~~~~~^^^^^^
  File "/usr/lib/python3.13/site-packages/pki/server/deployment/scriptlets/finalization.py", line 65, in spawn
    deployer.backup_keys(subsystem)
    ~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^
  File "/usr/lib/python3.13/site-packages/pki/server/deployment/__init__.py", line 4308, in backup_keys
    subprocess.run(cmd, check=True)
    ~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^
  File "/usr/lib64/python3.13/subprocess.py", line 579, in run
    raise CalledProcessError(retcode, process.args,
                             output=stdout, stderr=stderr)


Installation failed: Command failed: pki-server subsystem-cert-export ca -i topology-00-CA --pkcs12-file /var/lib/pki/topology-00-CA/conf/alias/ca_backup_keys.p12 --pkcs12-password-file /tmp/tmp9ez3szfa/password.txt

Additional Info:

pkispawn config file attached

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant