Looking for better logging for detecting issue faster.Audit and debug doesn't have much information to troubleshoot the issue. As a user they mind need it.
<debug logs> [03/Oct/2017:02:29:50][http-bio-8443-exec-23]: ProfileSubmitCMCServlet: authenticate: Invalid Credential. [03/Oct/2017:02:29:50][http-bio-8443-exec-23]: SignedAuditEventFactory: create() message created for eventType=AUTH_FAIL </debug logs>
<audit logs> 0.http-bio-8443-exec-19 - [03/Oct/2017:02:24:22 EDT] [14] [6] [AuditEvent=ACCES S_SESSION_ESTABLISH_SUCCESS][ClientIP=10.12.28.208][ServerIP=10.12.28.208][Subj ectID=UID=testing,E=Geetikakk@redhat.com,OU=Test2,C=IN][Outcome=Success] access session establish success 0.http-bio-8443-exec-19 - [03/Oct/2017:02:24:22 EDT] [14] [6] [AuditEvent=CMC_S IGNED_REQUEST_SIG_VERIFY][SubjectID=$NonRoleUser$][Outcome=Failure][ReqType=$Un identified$][CertSubject=$Unidentified$][SignerInfo=$Unidentified$] agent pre-approved CMC request signature verification 0.http-bio-8443-exec-19 - [03/Oct/2017:02:24:22 EDT] [14] [6] [AuditEvent=CMC_S IGNED_REQUEST_SIG_VERIFY][SubjectID=$NonRoleUser$][Outcome=Failure][ReqType=$Un identified$][CertSubject=$Unidentified$][SignerInfo=$Unidentified$] agent pre-approved CMC request signature verification 0.http-bio-8443-exec-19 - [03/Oct/2017:02:24:22 EDT] [14] [6] [AuditEvent=AUTH_ FAIL][SubjectID=null][Outcome=Failure][AuthMgr=CMCAuth][AttemptedCred=null] authentication failure </audit logs>
Steps to Reproduce:
1.Try to sign a SubCA certificate with a user certificate
Actual results:
Reason of failure is never listed in logs.
Expected results:
Reason should be visible in logs . example: user certificate not have permissions to sign a subCA certificate
Additional info:
Debug logs with user certificate: ================================= [03/Oct/2017:02:29:50][http-bio-8443-exec-23]: CertUserDBAuthentication: cannot map certificate to any userUser not found [03/Oct/2017:02:29:50][http-bio-8443-exec-23]: CMCAuth: Invalid Credential. [03/Oct/2017:02:29:50][http-bio-8443-exec-23]: SignedAuditEventFactory: create() message created for eventType=CMC_SIGNED_REQUEST_SIG_VERIFY [03/Oct/2017:02:29:50][http-bio-8443-exec-23]: SignedAuditEventFactory: create() message created for eventType=CMC_SIGNED_REQUEST_SIG_VERIFY [03/Oct/2017:02:29:50][http-bio-8443-exec-23]: ProfileSubmitCMCServlet: authenticate: Invalid Credential. [03/Oct/2017:02:29:50][http-bio-8443-exec-23]: SignedAuditEventFactory: create() message created for eventType=AUTH_FAIL [03/Oct/2017:02:29:50][http-bio-8443-exec-23]: CMCOutputTemplate: getContentInfo: begins [03/Oct/2017:02:29:50][http-bio-8443-exec-23]: CMCOutputTemplate: getContentInfo: - done [03/Oct/2017:02:29:50][http-bio-8443-exec-23]: ProfileSubmitCMCServlet: authentication error Invalid Credential. [03/Oct/2017:02:29:50][http-bio-8443-exec-23]: CMSServlet: curDate=Tue Oct 03 02:29:50 EDT 2017 id=caProfileSubmitCMCFull time=26 Debug logs with CA certificate: =============================== [03/Oct/2017:02:34:54][http-bio-8443-exec-18]: SignedAuditEventFactory: create() message created for eventType=CMC_SIGNED_REQUEST_SIG_VERIFY [03/Oct/2017:02:34:54][http-bio-8443-exec-18]: ProfileSubmitCMCServlet: authenticate: setting auditSubjectID in SessionContext:caadmin [03/Oct/2017:02:34:54][http-bio-8443-exec-18]: SignedAuditEventFactory: create() message created for eventType=AUTH_SUCCESS [03/Oct/2017:02:34:54][http-bio-8443-exec-18]: ProfileSubmitCMCServlet authToken not null [03/Oct/2017:02:34:54][http-bio-8443-exec-18]: CMSServlet: in auditSubjectID [03/Oct/2017:02:34:54][http-bio-8443-exec-18]: CMSServlet: auditSubjectID auditContext {sslClientCertProvider=com.netscape.cms.servlet.profile.SSLClientC ertProvider@328ac2ac, userid=caadmin,
Metadata Update from @mharmsen: - Custom field component adjusted to None - Custom field feature adjusted to None - Custom field origin adjusted to None - Custom field proposedmilestone adjusted to None - Custom field proposedpriority adjusted to None - Custom field reviewer adjusted to None - Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1497920 - Custom field type adjusted to None - Custom field version adjusted to None - Issue assigned to cfu - Issue priority set to: blocker - Issue set to the milestone: 10.5
commit 26deac305c5be8c2294fbeb537388711acc9450c (HEAD -> master, origin/master, origin/HEAD) Author: Christina Fu cfu@redhat.com Date: Thu Oct 19 15:53:31 2017 -0700
Ticket #2834-Missing CN causing NPE in CMCAuth This patch eliminates the wrong assumption that all subjectDN contains the CN component. Change-Id: I2a9dafe073be0562d1356012fb517b146251523e
Metadata Update from @cfu: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)
Metadata Update from @mharmsen: - Issue set to the milestone: 10.5.1 (was: 10.5)
Metadata Update from @mharmsen: - Custom field fixedinversion adjusted to pki-core-10.5.1-1.fc27
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/2954
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.