<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    On 10/17/2012 02:31 PM, Bret Wortman wrote:
    <blockquote
cite="mid:CACWq_ZmZtdSDn1N_0t3dqjpLUe8yfkBQejoyYmimGVU3Xi_T8g@mail.gmail.com"
      type="cite">Now it appears that whatever is supposed to be running
      on port 9445 (looks like mindarray-ca) isn't running, and I'm not
      sure how it gets started, exactly. I ran lsof -i:9445 on this
      server and on a FreeIPA test box I first set up, and it's running
      on the test box but not the new one. Where should I look next?<br>
    </blockquote>
    <br>
    You cert system component failed to start because its DS instance
    failed to start.<br>
    <br>
    Did the install fail again after cleanup?<br>
    If not it is better to start over with cleanup and if the install
    fails we will help you to troubleshoot.<br>
    <br>
    <br>
    <blockquote
cite="mid:CACWq_ZmZtdSDn1N_0t3dqjpLUe8yfkBQejoyYmimGVU3Xi_T8g@mail.gmail.com"
      type="cite">
      <br>
      <div class="gmail_quote">On Wed, Oct 17, 2012 at 2:07 PM, Bret
        Wortman <span dir="ltr"><<a moz-do-not-send="true"
            href="mailto:bret.wortman@damascusgrp.com" target="_blank">bret.wortman@damascusgrp.com</a>></span>
        wrote:<br>
        <blockquote class="gmail_quote" style="margin:0 0 0
          .8ex;border-left:1px #ccc solid;padding-left:1ex">
          Spot on. It was a fresh install of F17 and I neglected to #
          yum update first. I've done so, rebooted, and am trying again
          with better results.
          <div>
            <div class="h5"><br>
              <br>
              <div class="gmail_quote">On Wed, Oct 17, 2012 at 1:45 PM,
                John Dennis <span dir="ltr"><<a
                    moz-do-not-send="true"
                    href="mailto:jdennis@redhat.com" target="_blank">jdennis@redhat.com</a>></span>
                wrote:<br>
                <blockquote class="gmail_quote" style="margin:0 0 0
                  .8ex;border-left:1px #ccc solid;padding-left:1ex">
                  <div>On 10/17/2012 12:40 PM, Bret Wortman wrote:<br>
                  </div>
                  <blockquote class="gmail_quote" style="margin:0 0 0
                    .8ex;border-left:1px #ccc solid;padding-left:1ex">
                    <div>
                      I recently tried installing freeipa on a new
                      server, but<br>
                      ipa-server-install had problems around this point:<br>
                      <br>
                      Configuring certificate server: Estimated time 3
                      minutes 30 seconds<br>
                         [1/18]: creating certificate server user<br>
                         [2/18]: creating pki-ca instance<br>
                         [3/18]: configuring certificate server instance<br>
                      ipa         : CRITICAL failed to configure ca
                      instance Command<br>
                      '/usr/bin/perl /usr/bin/pkisilent ConfigureCA
                      -cs_hostname<br>
                    </div>
                    <a moz-do-not-send="true"
                      href="http://fs1.wedgeofli.me" target="_blank">fs1.wedgeofli.me</a>
                    <<a moz-do-not-send="true"
                      href="http://fs1.wedgeofli.me" target="_blank">http://fs1.wedgeofli.me</a>>
                    -cs_port 9445
                    <div><br>
                      -client_certdb_dir /tmp/tmp-UvBMbL
                      -client_certdb_pwd XXXXXXXX<br>
                      -preop_pin HHxKHUz5RRfzQ3OkFMlR -domain_name IPA
                      -admin_user admin<br>
                      -admin_email root@localhost -admin_XXXXXXXX
                      XXXXXXXX -agent_name<br>
                      ipa-ca-agent -agent_key_size 2048 -agent_key_type
                      rsa<br>
                    </div>
                    -agent_cert_subject CN=ipa-ca-agent,O=<a
                      moz-do-not-send="true" href="http://WEDGEOFLI.ME"
                      target="_blank">WEDGEOFLI.ME</a> <<a
                      moz-do-not-send="true" href="http://WEDGEOFLI.ME"
                      target="_blank">http://WEDGEOFLI.ME</a>><br>
                    -ldap_host <a moz-do-not-send="true"
                      href="http://fs1.wedgeofli.me" target="_blank">fs1.wedgeofli.me</a>
                    <<a moz-do-not-send="true"
                      href="http://fs1.wedgeofli.me" target="_blank">http://fs1.wedgeofli.me</a>>
                    -ldap_port 7389
                    <div><br>
                      -bind_dn cn=Directory Manager -bind_XXXXXXXX
                      XXXXXXXX -base_dn o=ipaca<br>
                      -db_name ipaca -key_size 2048 -key_type rsa
                      -key_algorithm SHA256withRSA<br>
                      -save_p12 true -backup_pwd XXXXXXXX
                      -subsystem_name pki-cad -token_name<br>
                      internal -ca_subsystem_cert_subject_name CN=CA
                      Subsystem,O=<a moz-do-not-send="true"
                        href="http://WEDGEOFLI.ME" target="_blank">WEDGEOFLI.ME</a><br>
                    </div>
                    <<a moz-do-not-send="true"
                      href="http://WEDGEOFLI.ME" target="_blank">http://WEDGEOFLI.ME</a>>
                    -ca_ocsp_cert_subject_name CN=OCSP<br>
                    Subsystem,O=<a moz-do-not-send="true"
                      href="http://WEDGEOFLI.ME" target="_blank">WEDGEOFLI.ME</a>
                    <<a moz-do-not-send="true"
                      href="http://WEDGEOFLI.ME" target="_blank">http://WEDGEOFLI.ME</a>><br>
                    -ca_server_cert_subject_name CN=<a
                      moz-do-not-send="true"
                      href="http://fs1.wedgeofli.me" target="_blank">fs1.wedgeofli.me</a><br>
                    <<a moz-do-not-send="true"
                      href="http://fs1.wedgeofli.me" target="_blank">http://fs1.wedgeofli.me</a>>,O=<a
                      moz-do-not-send="true" href="http://WEDGEOFLI.ME"
                      target="_blank">WEDGEOFLI.ME</a> <<a
                      moz-do-not-send="true" href="http://WEDGEOFLI.ME"
                      target="_blank">http://WEDGEOFLI.ME</a>><br>
                    -ca_audit_signing_cert_subject_name CN=CA Audit,O=<a
                      moz-do-not-send="true" href="http://WEDGEOFLI.ME"
                      target="_blank">WEDGEOFLI.ME</a><br>
                    <<a moz-do-not-send="true"
                      href="http://WEDGEOFLI.ME" target="_blank">http://WEDGEOFLI.ME</a>>
                    -ca_sign_cert_subject_name CN=Certificate<br>
                    Authority,O=<a moz-do-not-send="true"
                      href="http://WEDGEOFLI.ME" target="_blank">WEDGEOFLI.ME</a>
                    <<a moz-do-not-send="true"
                      href="http://WEDGEOFLI.ME" target="_blank">http://WEDGEOFLI.ME</a>>
                    -external false -clone
                    <div><br>
                      false' returned non-zero exit status 255<br>
                      Unexpected error - see ipaserver-install.log for
                      details:<br>
                        Configuration of CA failed<br>
                      [root@fs1 ~]#<br>
                      <br>
                      The logfile revealed the following stack trace:<br>
                      <br>
                      #############################################<br>
                      Attempting to connect to: <a
                        moz-do-not-send="true"
                        href="http://fs1.wedgeofli.me:9445"
                        target="_blank">fs1.wedgeofli.me:9445</a><br>
                    </div>
                    <<a moz-do-not-send="true"
                      href="http://fs1.wedgeofli.me:9445"
                      target="_blank">http://fs1.wedgeofli.me:9445</a>>
                    <div>
                      <div><br>
                        Exception in LoginPanel():
                        java.lang.NullPointerException<br>
                        ERROR: ConfigureCA: LoginPanel() failure<br>
                        ERROR: unable to create CA<br>
                        <br>
                        #######################################################################<br>
                        <br>
                        2012-10-17T16:24:53Z DEBUG stderr=Exception:
                        Unable to Send<br>
                        Request:<a moz-do-not-send="true"
                          href="http://java.net" target="_blank">java.net</a>.ConnectException:
                        Connection refused<br>
                        java.net.ConnectException: Connection refused<br>
                        at java.net.PlainSocketImpl.socketConnect(Native
                        Method)<br>
                        at<br>
                        <a moz-do-not-send="true" href="http://java.net"
                          target="_blank">java.net</a>.AbstractPlainSocketImpl.doConnect(AbstractPlainSocketImpl.java:339)<br>
                        at<br>
                        <a moz-do-not-send="true" href="http://java.net"
                          target="_blank">java.net</a>.AbstractPlainSocketImpl.connectToAddress(AbstractPlainSocketImpl.java:200)<br>
                        at<br>
                        <a moz-do-not-send="true" href="http://java.net"
                          target="_blank">java.net</a>.AbstractPlainSocketImpl.connect(AbstractPlainSocketImpl.java:182)<br>
                        at java.net.SocksSocketImpl.connect(SocksSocketImpl.java:391)<br>
                        at java.net.Socket.connect(Socket.java:579)<br>
                        at java.net.Socket.connect(Socket.java:528)<br>
                        at java.net.Socket.<init>(Socket.java:425)<br>
                        at java.net.Socket.<init>(Socket.java:241)<br>
                        at HTTPClient.sslConnect(HTTPClient.java:326)<br>
                        at ConfigureCA.LoginPanel(ConfigureCA.java:244)<br>
                        at ConfigureCA.ConfigureCAInstance(ConfigureCA.java:1157)<br>
                        at ConfigureCA.main(ConfigureCA.java:1672)<br>
                        java.lang.NullPointerException<br>
                        at ConfigureCA.LoginPanel(ConfigureCA.java:245)<br>
                        at ConfigureCA.ConfigureCAInstance(ConfigureCA.java:1157)<br>
                        at ConfigureCA.main(ConfigureCA.java:1672)<br>
                        <br>
                        Now I seem to be stuck. I tried uninstalling the
                        freeipa-server package<br>
                        with # yum remove freeipa-server and then
                        reinstalled it the same way,<br>
                        but ipa-server-install won't run no matter what
                        I attempt.<br>
                        <br>
                        Any thoughts? I'm pretty new to IPA.<br>
                      </div>
                    </div>
                  </blockquote>
                  <br>
                  There is a good chance this is due to a version
                  mismatch between the IPA packages and the dogtag
                  packages. You didn't mention which OS you're using nor
                  the versions of the relevant packages, that would have
                  been helpful. In any event I would make sure all your
                  packages are up to date.<span><font color="#888888"><br>
                      <br>
                      <br>
                      -- <br>
                      John Dennis <<a moz-do-not-send="true"
                        href="mailto:jdennis@redhat.com" target="_blank">jdennis@redhat.com</a>></font></span>
                  <div>
                    <div><br>
                      <br>
                      Looking to carve out IT costs?<br>
                      <a moz-do-not-send="true"
                        href="http://www.redhat.com/carveoutcosts/"
                        target="_blank">www.redhat.com/carveoutcosts/</a><br>
                    </div>
                  </div>
                </blockquote>
              </div>
              <br>
              <br clear="all">
              <div><br>
              </div>
            </div>
          </div>
          <div class="im">-- <br>
            <div>Bret Wortman</div>
            <div>The Damascus Group</div>
            <div>Fairfax, VA</div>
          </div>
          <div><a moz-do-not-send="true" href="http://bretwortman.com/"
              target="_blank">http://bretwortman.com/</a></div>
          <div><a moz-do-not-send="true"
              href="http://twitter.com/BretWortman" target="_blank">http://twitter.com/BretWortman</a></div>
          <br>
        </blockquote>
      </div>
      <br>
      <br clear="all">
      <div><br>
      </div>
      -- <br>
      <div>Bret Wortman</div>
      <div>The Damascus Group</div>
      <div>Fairfax, VA</div>
      <div><a moz-do-not-send="true" href="http://bretwortman.com/"
          target="_blank">http://bretwortman.com/</a></div>
      <div><a moz-do-not-send="true"
          href="http://twitter.com/BretWortman" target="_blank">http://twitter.com/BretWortman</a></div>
      <br>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Freeipa-users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Freeipa-users@redhat.com">Freeipa-users@redhat.com</a>
<a class="moz-txt-link-freetext" href="https://www.redhat.com/mailman/listinfo/freeipa-users">https://www.redhat.com/mailman/listinfo/freeipa-users</a></pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
Thank you,
Dmitri Pal

Sr. Engineering Manager for IdM portfolio
Red Hat Inc.


-------------------------------
Looking to carve out IT costs?
<a class="moz-txt-link-abbreviated" href="http://www.redhat.com/carveoutcosts/">www.redhat.com/carveoutcosts/</a>


</pre>
  </body>
</html>