When trying to submit request using caUserCert profile using IE 10 from Windows 7 , i get error "Invalid request" .
on CA debug logs i see below errors:
[26/Aug/2015:17:59:04][http-bio-30042-exec-24]: ProfileSelectServlet: SubId=profile [26/Aug/2015:17:59:04][http-bio-30042-exec-24]: ProfileSelectServlet: profileId=caUserCert [26/Aug/2015:17:59:04][http-bio-30042-exec-24]: ProfileSelectServlet: keyArchivalEnabled is true [26/Aug/2015:17:59:05][http-bio-30042-exec-24]: CMSServlet: curDate=Wed Aug 26 17:59:05 IST 2015 id=caProfileSelect time=36 [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet:service() uri = /ca/ee/ca/profileSubmit [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='cert_request_type' value='pkcs10' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='cert_request' value='' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='keyLength' value='1024' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='sn_uid' value='pki1' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='sn_e' value='pki1@example.org' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='sn_cn' value='pki1' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='sn_ou3' value='' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='sn_ou2' value='' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='sn_ou1' value='' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='sn_ou' value='' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='sn_o' value='' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='sn_c' value='' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='requestor_name' value='' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='requestor_email' value='' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='requestor_phone' value='' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='profileId' value='caUserCert' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='renewal' value='false' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet::service() param name='xmlOutput' value='false' [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet: caProfileSubmit start to service. [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: xmlOutput false [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: ProfileSubmitServlet: isRenewal false [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: according to ccMode, authorization for servlet: caProfileSubmit is LDAP based, not XML {1}, use default authz mgr: {2}. [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: Input Parameters: [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - sn_o: [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - sn_e: pki1@example.org [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - requestor_email: [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - requestor_phone: [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - cert_request: [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - remoteHost: 192.168.122.214 [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - requestor_name: [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - sn_ou3: [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - sn_ou2: [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - sn_uid: pki1 [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - sn_cn: pki1 [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - profileId: caUserCert [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - cert_request_type: pkcs10 [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - sn_c: [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - isRenewal: false [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - sn_ou1: [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - sn_ou: [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CAProcessor: - remoteAddr: 192.168.122.214 [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: EnrollmentProcessor: isRenewal false [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: EnrollmentProcessor: profileId caUserCert [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: EnrollmentProcessor: set Inputs into profile Context [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: EnrollmentProcessor: set sslClientCertProvider [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: Start parsePKCS10(): [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: EnrollProfile: parsePKCS10: signature verification enabled [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: EnrollProfile: parsePKCS10: use internal token [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: EnrollProfile: parsePKCS10 setting thread token [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: EnrollProfile: parsePKCS10 java.io.IOException: Sequence tag error -1 [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: EnrollProfile: parsePKCS10 restoring thread token [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: ProfileSubmitServlet: error in processing request: Invalid Request [26/Aug/2015:17:59:20][http-bio-30042-exec-24]: CMSServlet: curDate=Wed Aug 26 17:59:20 IST 2015 id=caProfileSubmit time=45
Steps to Reproduce:
1.Install pki-ca and configure CA instance 2. From I.E access EE and import the CA cert to "Trusted Root Certificates" 3. Access Profile "Manual Use Dual-Use Certificate Enrollment" and submit user cert request.
Actual results:
After submitting the request, the request fails with error "Invalid Request"
Expected results:
Should successfully submit the request for Approval.
Closing since we have a bugzilla with the instruction list included. The instructions to get the enrollment working have been tested as good. QE has also changed the bug into a doc bug.
Metadata Update from @mrniranjan: - Issue assigned to jmagne - Issue set to the milestone: 10.3.1
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/2147
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.