<div dir="ltr"><div><div><div><div>Hello everyone.<br><br></div><div></div>I modified the /etc/selinux/config file :<br>#########################################################<br># This file controls the state of SELinux on the system.<br># SELINUX=disabled<br>#       enforcing - SELinux security policy is enforced.<br>#       permissive - SELinux prints warnings instead of enforcing.<br>#       disabled - SELinux is fully disabled.<br>SELINUX=permissive<br># SELINUXTYPE= type of policy in use. Possible values are:<br>#       targeted - Only targeted network daemons are protected.<br>#       strict - Full SELinux protection.<br>SELINUXTYPE=targeted<br>#########################################################<br><br></div>Then I rebooted.<br></div>#########################################################<br>reboot<br>#########################################################<br><br></div><div>Here is the result of getenforce :<br>#########################################################<br>Permissive<br>#########################################################<br><br></div><div>I removed the ipa-server that I had and I tried te 3.0.0-42 :<br>#########################################################<br>yum install ipa-server-3.0.0-42.el6.x86_64<br>Loaded plugins: security<br>Setting up Install Process<br>Resolving Dependencies<br>--> Running transaction check<br>---> Package ipa-server.x86_64 0:3.0.0-42.el6 will be installed<br>--> Processing Dependency: ipa-client = 3.0.0-42.el6 for package: ipa-server-3.0.0-42.el6.x86_64<br>--> Processing Dependency: ipa-admintools = 3.0.0-42.el6 for package: ipa-server-3.0.0-42.el6.x86_64<br>--> Processing Dependency: ipa-python = 3.0.0-42.el6 for package: ipa-server-3.0.0-42.el6.x86_64<br>--> Processing Dependency: ipa-server-selinux = 3.0.0-42.el6 for package: ipa-server-3.0.0-42.el6.x86_64<br>--> Running transaction check<br>---> Package ipa-admintools.x86_64 0:3.0.0-42.el6 will be installed<br>---> Package ipa-client.x86_64 0:3.0.0-42.el6 will be installed<br>---> Package ipa-python.x86_64 0:3.0.0-42.el6 will be installed<br>---> Package ipa-server-selinux.x86_64 0:3.0.0-42.el6 will be installed<br>--> Finished Dependency Resolution<br><br>Dependencies Resolved<br><br>======================================================================================================================================<br> Package                               Arch                      Version                            Repository                   Size<br>======================================================================================================================================<br>Installing:<br> ipa-server                            x86_64                    3.0.0-42.el6                       standard                    1.1 M<br>Installing for dependencies:<br> ipa-admintools                        x86_64                    3.0.0-42.el6                       standard                     67 k<br> ipa-client                            x86_64                    3.0.0-42.el6                       standard                    145 k<br> ipa-python                            x86_64                    3.0.0-42.el6                       standard                    928 k<br> ipa-server-selinux                    x86_64                    3.0.0-42.el6                       standard                     66 k<br><br>Transaction Summary<br>======================================================================================================================================<br>Install       5 Package(s)<br><br>Total download size: 2.3 M<br>Installed size: 9.2 M<br>Is this ok [y/N]: y<br>Downloading Packages:<br>(1/5): ipa-admintools-3.0.0-42.el6.x86_64.rpm                                                                  |  67 kB     00:00<br>(2/5): ipa-client-3.0.0-42.el6.x86_64.rpm                                                                      | 145 kB     00:00<br>(3/5): ipa-python-3.0.0-42.el6.x86_64.rpm                                                                      | 928 kB     00:00<br>(4/5): ipa-server-3.0.0-42.el6.x86_64.rpm                                                                      | 1.1 MB     00:00<br>(5/5): ipa-server-selinux-3.0.0-42.el6.x86_64.rpm                                                              |  66 kB     00:00<br>--------------------------------------------------------------------------------------------------------------------------------------<br>Total                                                                                                 6.8 MB/s | 2.3 MB     00:00<br>Running rpm_check_debug<br>Running Transaction Test<br>Transaction Test Succeeded<br>Running Transaction<br>  Installing : ipa-python-3.0.0-42.el6.x86_64                                                                                     1/5<br>  Installing : ipa-client-3.0.0-42.el6.x86_64                                                                                     2/5<br>  Installing : ipa-admintools-3.0.0-42.el6.x86_64                                                                                 3/5<br>  Installing : ipa-server-3.0.0-42.el6.x86_64                                                                                     4/5<br>  Installing : ipa-server-selinux-3.0.0-42.el6.x86_64                                                                             5/5<br>libsepol.print_missing_requirements: ipa_dogtag's global requirements were not met: type/attribute pki_ca_t (No such file or directory).<br>libsemanage.semanage_link_sandbox: Link packages failed (No such file or directory).<br>semodule:  Failed!<br>  Verifying  : ipa-server-3.0.0-42.el6.x86_64                                                                                     1/5<br>  Verifying  : ipa-server-selinux-3.0.0-42.el6.x86_64                                                                             2/5<br>  Verifying  : ipa-python-3.0.0-42.el6.x86_64                                                                                     3/5<br>  Verifying  : ipa-client-3.0.0-42.el6.x86_64                                                                                     4/5<br>  Verifying  : ipa-admintools-3.0.0-42.el6.x86_64                                                                                 5/5<br><br>Installed:<br>  ipa-server.x86_64 0:3.0.0-42.el6<br><br>Dependency Installed:<br>  ipa-admintools.x86_64 0:3.0.0-42.el6             ipa-client.x86_64 0:3.0.0-42.el6         ipa-python.x86_64 0:3.0.0-42.el6<br>  ipa-server-selinux.x86_64 0:3.0.0-42.el6<br><br>Complete!<br>#########################################################<br><br></div><div>The errors linked with dogtag is still there.<br></div><div></div>Now, when I tried to run the ipa-server-install command here is what I have :<br>#########################################################<br>Continue to configure the system with these values? [no]: yes<br><br>The following operations may take some minutes to complete.<br>Please wait until the prompt is returned.<br><br>Configuring NTP daemon (ntpd)<br>  [1/4]: stopping ntpd<br>  [2/4]: writing configuration<br>  [3/4]: configuring ntpd to start on boot<br>  [4/4]: starting ntpd<br>Done configuring NTP daemon (ntpd).<br>Configuring directory server for the CA (pkids): Estimated time 30 seconds<br>  [1/3]: creating directory server user<br>  [2/3]: creating directory server instance<br>  [3/3]: restarting directory server<br>Done configuring directory server for the CA (pkids).<br>Configuring certificate server (pki-cad): Estimated time 3 minutes 30 seconds<br>  [1/20]: creating certificate server user<br>  [2/20]: configuring certificate server instance<br>ipa         : CRITICAL failed to configure ca instance Command '/usr/bin/perl /usr/bin/pkisilent ConfigureCA -cs_hostname MYHOST -cs_port 9445 -client_certdb_dir /tmp/tmp-nbZ4fw -client_certdb_pwd XXXXXXXX -preop_pin WJUMtgRhyvooPs1kHhyQ -domain_name IPA -admin_user admin -admin_email root@localhost -admin_password XXXXXXXX -agent_name ipa-ca-agent -agent_key_size 2048 -agent_key_type rsa -agent_cert_subject CN=ipa-ca-agent,O=MYREALM -ldap_host MYHOST -ldap_port 7389 -bind_dn cn=Directory Manager -bind_password XXXXXXXX -base_dn o=ipaca -db_name ipaca -key_size 2048 -key_type rsa -key_algorithm SHA256withRSA -save_p12 true -backup_pwd XXXXXXXX -subsystem_name pki-cad -token_name internal -ca_subsystem_cert_subject_name CN=CA Subsystem,O=MYREALM -ca_subsystem_cert_subject_name CN=CA Subsystem,O=MYREALM -ca_ocsp_cert_subject_name CN=OCSP Subsystem,O=MYREALM -ca_server_cert_subject_name CN=MYHOST,O=MYREALM -ca_audit_signing_cert_subject_name CN=CA Audit,O=MYREALM -ca_sign_cert_subject_name CN=Certificate Authority,O=MYREALM -external false -clone false' returned non-zero exit status 255<br>Configuration of CA failed<br>#########################################################<br><div><div><br></div><div>And here is what I found in the ipasrever-install.log :<br>#########################################################<br>2015-06-01T07:38:43Z DEBUG stderr=Exception: Unable to Send Request:java.net.ConnectException: Connection refused<br>java.net.ConnectException: Connection refused<br>        at java.net.PlainSocketImpl.socketConnect(Native Method)<br>        at java.net.AbstractPlainSocketImpl.doConnect(AbstractPlainSocketImpl.java:327)<br>        at java.net.AbstractPlainSocketImpl.connectToAddress(AbstractPlainSocketImpl.java:193)<br>        at java.net.AbstractPlainSocketImpl.connect(AbstractPlainSocketImpl.java:180)<br>        at java.net.SocksSocketImpl.connect(SocksSocketImpl.java:385)<br>        at java.net.Socket.connect(Socket.java:546)<br>        at java.net.Socket.connect(Socket.java:495)<br>        at java.net.Socket.<init>(Socket.java:392)<br>        at java.net.Socket.<init>(Socket.java:235)<br>        at HTTPClient.sslConnect(HTTPClient.java:326)<br>        at ConfigureCA.LoginPanel(ConfigureCA.java:244)<br>        at ConfigureCA.ConfigureCAInstance(ConfigureCA.java:1157)<br>        at ConfigureCA.main(ConfigureCA.java:1672)<br>java.lang.NullPointerException<br>        at ConfigureCA.LoginPanel(ConfigureCA.java:245)<br>        at ConfigureCA.ConfigureCAInstance(ConfigureCA.java:1157)<br>        at ConfigureCA.main(ConfigureCA.java:1672)<br><br>2015-06-01T07:38:43Z CRITICAL failed to configure ca instance Command '/usr/bin/perl /usr/bin/pkisilent ConfigureCA -cs_hostname MYHOST -cs_port 9445 -client_certdb_dir /tmp/tmp-nbZ4fw -client_certdb_pwd XXXXXXXX -preop_pin WJUMtgRhyvooPs1kHhyQ -domain_name IPA -admin_user admin -admin_email root@localhost -admin_password XXXXXXXX -agent_name ipa-ca-agent -agent_key_size 2048 -agent_key_type rsa -agent_cert_subject CN=ipa-ca-agent,O=MYREALM -ldap_host MYHOST -ldap_port 7389 -bind_dn cn=Directory Manager -bind_password XXXXXXXX -base_dn o=ipaca -db_name ipaca -key_size 2048 -key_type rsa -key_algorithm SHA256withRSA -save_p12 true -backup_pwd XXXXXXXX -subsystem_name pki-cad -token_name internal -ca_subsystem_cert_subject_name CN=CA Subsystem,O=MYREALM -ca_subsystem_cert_subject_name CN=CA Subsystem,O=MYREALM -ca_ocsp_cert_subject_name CN=OCSP Subsystem,O=MYREALM -ca_server_cert_subject_name CN=MYHOST,O=MYREALM -ca_audit_signing_cert_subject_name CN=CA Audit,O=MYREALM -ca_sign_cert_subject_name CN=Certificate Authority,O=MYREALM -external false -clone false' returned non-zero exit status 255<br>2015-06-01T07:38:43Z INFO   File "/usr/lib/python2.6/site-packages/ipaserver/install/installutils.py", line 614, in run_script<br>    return_value = main_function()<br><br>  File "/usr/sbin/ipa-server-install", line 942, in main<br>    subject_base=options.subject)<br><br>  File "/usr/lib/python2.6/site-packages/ipaserver/install/cainstance.py", line 626, in configure_instance<br>    self.start_creation(runtime=210)<br><br>  File "/usr/lib/python2.6/site-packages/ipaserver/install/service.py", line 358, in start_creation<br>    method()<br><br>  File "/usr/lib/python2.6/site-packages/ipaserver/install/cainstance.py", line 888, in __configure_instance<br>    raise RuntimeError('Configuration of CA failed')<br><br>2015-06-01T07:38:43Z INFO The ipa-server-install command failed, exception: RuntimeError: Configuration of CA failed<br>#########################################################<br><br></div><div></div><div>I'm not really sure permissive mode with SELinux is helping in fact.<br><br></div><div>Best regards.<br><br></div><div>Bahan<br></div></div></div>