[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
adding debug=true to /etc/ipa/default.conf and restarting apache gives debug output in apache error.log, and looks like it gets gzipped data from dogtag (which is fine) but somehow either the header is missing or it can't deflate it. -- You received this bug notification because you are a member

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
it's getting invalid xml from somewhere.. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa server -- problems with certificates Status in freeipa package in Ubuntu: Con

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
ok thanks for testing, I think it's on the dogtag side still.. hope there's something in the pki-tomcat logs -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa server -- pro

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread gianluca
I did a clean installation with all the new components and it works... at least more than before. "pki cert-find", "pki cert-show 1" and "ipa cert-show 1" all works. However, the "Authentication -> Certificates" tab in the web ui still returns error: Certificate operation cannot be completed: Unab

[Freeipa] [Bug 1772921] Re: freeipa web ui -- incorrect configuration for awesome fonts

2018-05-23 Thread gianluca
I confirm that it works! -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772921 Title: freeipa web ui -- incorrect configuration for awesome fonts Status in freeipa package in Ubuntu: In Pr

[Freeipa] [Bug 1772205] Re: freeipa install does not correctly setup krb5-admin-server

2018-05-23 Thread gianluca
I confirm that it works! -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772205 Title: freeipa install does not correctly setup krb5-admin-server Status in freeipa package in Ubuntu: In Pro

[Freeipa] [Bug 1772447] Re: freeipa installation - directory /var/lib/krb5kdc is not accessible by Apache

2018-05-23 Thread gianluca
Confirming that it works! -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772447 Title: freeipa installation - directory /var/lib/krb5kdc is not accessible by Apache Status in freeipa packa

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
and a new dogtag to depend on it and add the necessary links -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa server -- problems with certificates Status in freeipa packa

[Freeipa] [Bug 1772921] Re: freeipa web ui -- incorrect configuration for awesome fonts

2018-05-23 Thread Timo Aaltonen
oh man.. fixed in ~ppa2 -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772921 Title: freeipa web ui -- incorrect configuration for awesome fonts Status in freeipa package in Ubuntu: In Pro

[Freeipa] [Bug 1772921] Re: freeipa web ui -- incorrect configuration for awesome fonts

2018-05-23 Thread gianluca
I tried installing with 4.7.0.pre2, but I get an exception KeyError: 'FONT_AWESOME_DIR' I think you should add FONT_AWESOME_DIR=paths.FONT_AWESOME_DIR in the create_instance function in httpinstance.py -- You received this bug notification because you are a member of FreeIPA, which is subscri

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
interesting.. I'll push libjboss-annotations-1.2-api-java to the staging ppa to see how far you get with it -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa server -- prob

[Freeipa] [Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run

2018-05-23 Thread gianluca
Note that named-pkcs11 only crashes at startup when the section dyndb "ipa" "/usr/lib/bind/ldap.so" is present. If commented out, the daemon starts (although it becomes useless in this context). -- You received this bug notification because you are a member of FreeIPA, which is subscribed to fr

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread gianluca
In my case, with dogtag 10.6.1-0ubuntu0.1, giving the "pki cert-find" command returns tons of warning of the kind WARN: RESTEASY002145: NoClassDefFoundError: Unable to load builtin provider org.jboss.resteasy.plugins.providers.InputStreamProvider from jar:file:/usr/share/java/resteasy-jaxrs.jar!/M

[Freeipa] [Bug 1772205] Re: freeipa install does not correctly setup krb5-admin-server

2018-05-23 Thread Timo Aaltonen
** Changed in: freeipa (Ubuntu) Assignee: Timo Aaltonen (tjaalton) => (unassigned) -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772205 Title: freeipa install does not correctly setup k

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
pre2 uploaded to ppa:freeipa/staging I also uploaded tomcat8 there with a fixed (lower) version than what's in the updates ppa.. will take a while until these have been built -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. http

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
huh, ok.. could be that my test install is messed up somehow.. I'll reinstall ipa on it to see if things work then -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa server

[Freeipa] [Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run

2018-05-23 Thread Timo Aaltonen
** Changed in: freeipa (Ubuntu) Importance: Undecided => High -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1769440 Title: freeipa server install fails - named-pkcs11 fails to run Status

[Freeipa] [Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run

2018-05-23 Thread Andreas Hasenack
Thanks, he definitely knows more about bind than I do :) -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1769440 Title: freeipa server install fails - named-pkcs11 fails to run Status in bind9

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
** Changed in: freeipa (Ubuntu) Importance: Undecided => High -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa server -- problems with certificates Status in freeipa p

[Freeipa] [Bug 1772405] Re: freeipa dns install does not correctly configure reverse zones due to systemd-resolved

2018-05-23 Thread Timo Aaltonen
maybe I can modify ipa-server-install to disable systemd-resolved, but it feels fragile and I wish there was a way to make them work together... ** Changed in: freeipa (Ubuntu) Importance: Undecided => High ** Changed in: freeipa (Ubuntu) Status: New => Triaged -- You received this bu

[Freeipa] [Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run

2018-05-23 Thread Timo Aaltonen
I can ask Ondrej too -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1769440 Title: freeipa server install fails - named-pkcs11 fails to run Status in bind9 package in Ubuntu: Triaged Status

[Freeipa] [Bug 1769485] Re: freeipa install server fails - cannot start apache server with SSL

2018-05-23 Thread Timo Aaltonen
fixed in git unassigning myself so that bug email end up in the correct folder ** Changed in: freeipa (Ubuntu) Status: Triaged => In Progress ** Changed in: freeipa (Ubuntu) Assignee: Timo Aaltonen (tjaalton) => (unassigned) ** Changed in: freeipa (Ubuntu) Importance: Undecided =

[Freeipa] [Bug 1772447] Re: freeipa installation - directory /var/lib/krb5kdc is not accessible by Apache

2018-05-23 Thread Timo Aaltonen
fixed in git ** Changed in: freeipa (Ubuntu) Importance: Undecided => High ** Changed in: freeipa (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/17

[Freeipa] [Bug 1772921] Re: freeipa web ui -- incorrect configuration for awesome fonts

2018-05-23 Thread Timo Aaltonen
hah, fixed in git ** Changed in: freeipa (Ubuntu) Status: New => In Progress ** Changed in: freeipa (Ubuntu) Importance: Undecided => High -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bu

[Freeipa] [Bug 1772205] Re: freeipa install does not correctly setup krb5-admin-server

2018-05-23 Thread Timo Aaltonen
fixed in git ** Changed in: freeipa (Ubuntu) Importance: Undecided => High ** Changed in: freeipa (Ubuntu) Status: Confirmed => In Progress -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/b

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Norman Kabir
At this stage, I am just trying to make it work so apologies for the hacks. For context: * I am using your PPAs for FreeIPA and dogtag * I linked named-pkcs11 to named * /etc/hostname is set to fqdn (kvm-10.ipa.kvm) And the following script for installation: #!/usr/bin/env bash sudo ipa-server

[Freeipa] [Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run

2018-05-23 Thread Andreas Hasenack
I'll take a look -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1769440 Title: freeipa server install fails - named-pkcs11 fails to run Status in bind9 package in Ubuntu: Triaged Status in

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Launchpad Bug Tracker
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: freeipa (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Titl

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Norman Kabir
So far, the only clue I can find in the logs is a 'null' value for authType and principal: [ajp-nio-127.0.0.1-8009-exec-1] INFO com.netscape.cms.tomcat.ExternalAuthenticationValve - ExternalAuthenticationValve: authType: null [ajp-nio-127.0.0.1-8009-exec-1] INFO com.netscape.cms.tomcat.Externa

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Norman Kabir
Strange. I am able to execute 'pki cert-find' without error. $ pki cert-find SLF4J: Class path contains multiple SLF4J bindings. SLF4J: Found binding in [jar:file:/usr/share/java/slf4j-jdk14.jar!/org/slf4j/impl/StaticLoggerBinder.class] SLF4J: Found binding in [jar:file:/usr/share/java/slf4j-sim

[Freeipa] [Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl

2018-05-23 Thread Timo Aaltonen
no, bind9 needs to be fixed instead, the way it's build got revamped in 9.11.3+dfsg-1 and I believe that's what broke it.. ** Also affects: bind9 (Ubuntu) Importance: Undecided Status: New ** Changed in: bind9 (Ubuntu) Status: New => Triaged ** Summary changed: - freeipa server

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Norman Kabir
I would like to help debug this. Like gianluca, I've managed to sort out the other bugs and am hitting this certificate issue. Where can I find the Git repository for 4.7.0-pre2? The associated repos only seem to contain 4.7.0-pre1 https://code.launchpad.net/ubuntu/+source/freeipa/+git -- You r

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
I haven't finished it yet.. Dogtag needs jboss-annotations-1.2-api which isn't even in the archive yet :/ Running 'pki cert-find' would show some errors when it's missing, but even with it installed it still fails with 'internal server error' and I've no idea where that comes from. Upstream irc ch

[Freeipa] [Bug 1772921] [NEW] freeipa web ui -- incorrect configuration for awesome fonts

2018-05-23 Thread gianluca
Public bug reported: Hi, another bug for FreeIPA, but this is quite trivial and not very important either. The file /usr/share/ipa/ipa.conf.template containw the line Alias /ipa/ui/fonts/fontawesome "${FONTS_DIR}/fontawesome" for providing the Awesome font to web browsers. $FONTS_DIR si correctl

[Freeipa] [Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl

2018-05-23 Thread gianluca
I think the my trick (copy /usr/sbin/named into /usr/sbin/named-pkcs11) works quite well. Not sure about the differences between named and named-pkcs11, but I think it is essentially the fact that named-pkcs11 supports cryptographic devices while plain named doesn't. In order to avoid /usr/sbin/nam

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread gianluca
I tried the new dogtag but there is no difference. What about 4.7.0-pre2? -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa server -- problems with certificates Status in