Hello,
I'm testing Dogtag PKI integration with softHSM. Versions used for integration are the
following :
dogtag-pki-10.10.6-1.fc34.x86_64
softhsm-2.6.1-5.fc34.1.x86_64
On Fedora 34.
I used the very standard config file and pkispawn fails as shown below (hsm is emptied
before every run) :
==============================================
DEBUG: Command: certutil -A -d /etc/pki/pki-tomcat/alias -h test -P test -f
/tmp/tmpirkyntkt/password.txt -n sslserver -a -i /tmp/tmp9_q5qm_b/sslserver.crt -t
certutil: could not decode certificate: SEC_ERROR_REUSED_ISSUER_AND_SERIAL: You are
attempting to import a cert with the same issuer/serial as an existing cert, but that is
not the same cert.
WARNING: certutil returned non-zero exit code (bug #1393668)
INFO: Starting server
DEBUG: Command: systemctl start pki-tomcatd(a)pki-tomcat.service
Job for pki-tomcatd(a)pki-tomcat.service failed because the control process exited with
error code.
See "systemctl status pki-tomcatd(a)pki-tomcat.service" and "journalctl -xeu
pki-tomcatd(a)pki-tomcat.service" for details.
ERROR: CalledProcessError: Command '['systemctl', 'start',
'pki-tomcatd(a)pki-tomcat.service']' returned non-zero exit status 1.
File "/usr/lib/python3.9/site-packages/pki/server/pkispawn.py", line 577, in
main
scriptlet.spawn(deployer)
File
"/usr/lib/python3.9/site-packages/pki/server/deployment/scriptlets/configuration.py",
line 1178, in spawn
instance.start()
File "/usr/lib/python3.9/site-packages/pki/server/__init__.py", line 263, in
start
subprocess.check_call(cmd)
File "/usr/lib64/python3.9/subprocess.py", line 373, in check_call
raise CalledProcessError(retcode, cmd)
===============================================
Does this sounds familiar to anyone ?
Thanks in advance.
A.
Show replies by date
Following ca.cfg was used, just in case :
======================
[DEFAULT]
pki_server_database_password=Password2021
pki_hsm_enable=True
pki_hsm_libfile=/usr/lib64/pkcs11/libsofthsm2.so
#pki_hsm_libfile=/usr/lib64/softhsm/libsofthsm.so
pki_hsm_modulename=softhsm
pki_token_name=test
pki_token_password=Password2021
[CA]
pki_admin_email=caadmin(a)example.com
pki_admin_name=caadmin
pki_admin_nickname=caadmin
pki_admin_password=Thales2021
pki_admin_uid=caadmin
pki_client_database_password=Password2021
pki_client_database_purge=False
pki_client_pkcs12_password=Password2021
pki_ds_base_dn=dc=ca,dc=pki,dc=thales,dc=com
pki_ds_database=ca
pki_ds_password=Password2021
pki_security_domain_name=EXAMPLE
pki_ca_signing_nickname=ca_signing
pki_ocsp_signing_nickname=ca_ocsp_signing
pki_audit_signing_nickname=ca_audit_signing
pki_sslserver_nickname=sslserver
pki_subsystem_nickname=subsystem
======================