[Freeipa-users] Traceback starting pki-cad - ca.subsystem.certreq missing?
Martin Kosek
mkosek at redhat.com
Mon Feb 22 14:25:46 UTC 2016
On 02/20/2016 05:58 PM, Ian Pilcher wrote:
> I am running IPA 3.0.0 on CentOS 6 (32-bit x86), and I am getting a
> traceback every time pki-cad starts:
>
> Traceback (most recent call last):
> File "/usr/sbin/pki-server", line 89, in <module>
> cli.execute(sys.argv)
> File "/usr/sbin/pki-server", line 84, in execute
> super(PKIServerCLI, self).execute(args)
> File "/usr/lib/python2.6/site-packages/pki/cli.py", line 195, in execute
> module.execute(module_args)
> File "/usr/lib/python2.6/site-packages/pki/server/cli/upgrade.py", line 103,
> in execute
> scriptlet.execute()
> File "/usr/lib/python2.6/site-packages/pki/server/upgrade/__init__.py", line
> 50, in execute
> cert = self.subsystem.get_system_cert('subsystem')
> File "/usr/lib/python2.6/site-packages/pki/server/__init__.py", line 93, in
> get_system_cert
> cert['request'] = base64.b64decode(self.config['%s.%s.certreq' %
> (self.prefix, tag)])
> KeyError: 'ca.subsystem.certreq'
> Starting pki-ca: [ OK ]
>
> As you can see, the daemon does still start successfully, and the
> traceback doesn't appear in any of the pki-cad logs.
>
> It seems that it is looking for a ca.subsystem.certreq entry in
> /etc/pki-ca/CS.cfg, and sure enough it isn't there. Nor is it present
> in CS.cfg.bak.
>
> How can I create this entry (or otherwise fix this)?
>
> Thanks!
This looks as something PKI specific (given it is in /usr/sbin/pki-server),
CCing Endi from Dogtag team.
More information about the Freeipa-users
mailing list