Make sure in the OCSP's pkispawn config file, the security domain configured for the CA, and make sure that CA and its LDAP server are up.
Or may be something is missing in that OCSP's pkispawn config file, or incorrect.
There may be more hints into the /var/log/pki/pki-ocsp/ocsp/debug file, like may be a private key could not be unlocked (file or hsm)
Thanks,
M.

On Fri, Mar 1, 2019 at 5:24 AM Jonathan Montero <jmrxto@gmail.com> wrote:
Hi Guys, i have a case that i haven't been able to solve. I'm not too experienced in dogtag, but believe me, i'm doing my best. I installed a CA in server1 and OSCP in server2. Server1 is working fine as CA. When i "pkispawn -s OCSP -vvv" in server 2, things go fine until the last moment.

pkispawn    : INFO     ....... executing 'systemctl daemon-reload'
pkispawn    : INFO     ....... executing 'systemctl start pki-tomcatd@testinstance.service'
pkispawn    : DEBUG    ........... No connection - server may still be down
pkispawn    : DEBUG    ........... No connection - exception thrown: ('Connection aborted.', error(111, 'Connection refused'))
pkispawn    : DEBUG    ........... No connection - server may still be down
pkispawn    : DEBUG    ........... No connection - exception thrown: ('Connection aborted.', error(111, 'Connection refused'))
pkispawn    : DEBUG    ........... No connection - server may still be down
pkispawn    : DEBUG    ........... No connection - exception thrown: ('Connection aborted.', error(111, 'Connection refused'))
pkispawn    : DEBUG    ........... No connection - server may still be down
pkispawn    : DEBUG    ........... No connection - exception thrown: 500 Server Error: Internal Server Error
pkispawn    : DEBUG    ........... No connection - server may still be down

firewalld is down and disabled, same with iptables, same with selinux in both servers


I'm using default values (most of them) before going to production.

what am i missing here?

Jonathan Montero
 
IT Professional | IT Trainer
A: Santo Domingo, DR
 
 

_______________________________________________
Pki-users mailing list
Pki-users@redhat.com
https://www.redhat.com/mailman/listinfo/pki-users