Most of the jobs in FreeIPA's [testing_master_pki] Nightly PR 4557 failed: report
[ipatests.pytest_ipa.integration.host.Host.master.cmd29] Configuring certificate server (pki-tomcatd). Estimated time: 3 minutes [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [1/30]: configuring certificate server instance [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [2/30]: Add ipa-pki-wait-running [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [3/30]: secure AJP connector [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [4/30]: reindex attributes [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [5/30]: exporting Dogtag certificate store pin [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [6/30]: stopping certificate server instance to update CS.cfg [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [7/30]: backing up CS.cfg [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [8/30]: disabling nonces [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [9/30]: set up CRL publishing [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [10/30]: enable PKIX certificate path discovery and validation [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [11/30]: starting certificate server instance [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [12/30]: configure certmonger for renewals [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [13/30]: requesting RA certificate from CA [ipatests.pytest_ipa.integration.host.Host.master.cmd29] [error] RuntimeError: Certificate issuance failed (CA_REJECTED: Server at "http://master.ipa.test:8080/ca/ee/ca//profileSubmit" replied: Request 7 Rejected - Signing Algorithm Not Matched SHA256withRSA ) [ipatests.pytest_ipa.integration.host.Host.master.cmd29] Certificate issuance failed (CA_REJECTED: Server at "http://master.ipa.test:8080/ca/ee/ca//profileSubmit" replied: Request 7 Rejected - Signing Algorithm Not Matched SHA256withRSA )
certmonger logs:
Apr 19 21:01:54 master.ipa.test certmonger[28447]: 2020-04-19 21:01:54 [28447] Certificate submission still ongoing. Apr 19 21:01:54 master.ipa.test certmonger[28447]: 2020-04-19 21:01:54 [28447] Certificate submission attempt complete. Apr 19 21:01:54 master.ipa.test certmonger[28447]: 2020-04-19 21:01:54 [28447] Child status = 2. Apr 19 21:01:54 master.ipa.test certmonger[28447]: 2020-04-19 21:01:54 [28447] Child output: Apr 19 21:01:54 master.ipa.test certmonger[28447]: "Server at "http://master.ipa.test:8080/ca/ee/ca//profileSubmit" replied: Request 7 Rejected - Signing Algorithm Not Matched SHA256withRSA " Apr 19 21:01:54 master.ipa.test certmonger[28447]: 2020-04-19 21:01:54 [28447] Server at "http://master.ipa.test:8080/ca/ee/ca//profileSubmit" replied: Request 7 Rejected - Signing Algorithm Not Matched SHA256withRSA 2020-04-19 21:01:54 [28447] Certificate not (yet?) issued. Apr 19 21:01:54 master.ipa.test certmonger[28551]: Request for certificate to be stored in file "/var/lib/ipa/ra-agent.pem" rejected by CA.
PKI logs:
2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: Parsing PKCS #10 request: 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: - 1.2.840.113549.1.9.20: Generic Extension 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: - 1.2.840.113549.1.9.14: extensions 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: Repository: Getting last serial number in range 1..10000000 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: DBVirtualList: Searching ou=ca,ou=requests,o=ipaca 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: DBVirtualList: filter: (requestState=*) 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: DBVirtualList: dn: cn=1,ou=ca,ou=requests,o=ipaca 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: DBVirtualList: dn: cn=2,ou=ca,ou=requests,o=ipaca 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: DBVirtualList: dn: cn=3,ou=ca,ou=requests,o=ipaca 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: DBVirtualList: dn: cn=4,ou=ca,ou=requests,o=ipaca 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: DBVirtualList: dn: cn=5,ou=ca,ou=requests,o=ipaca 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: DBVirtualList: dn: cn=6,ou=ca,ou=requests,o=ipaca 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: createEnrollmentRequest 7 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: Filling PKCS #10 data 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: Key algorithm: RSA 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: Subject name: CN=IPA RA,O=IPA.TEST 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: Subject CN: IPA RA 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: Subject UID: 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: Attributes: 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: - 1.2.840.113549.1.9.20 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: - 1.2.840.113549.1.9.14 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: - 1.3.6.1.4.1.311.20.2 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: - SubjectKeyIdentifier 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: - SubjectAlternativeName 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: EnrollProfile: - BasicConstraints 2020-04-19 21:01:53 [http-nio-8080-exec-16] INFO: UserSubjectNameDefault: Subject: CN=IPA RA,O=IPA.TEST 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: Processing certificate request: 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - profileapprovedby: admin 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - cert_request: -----BEGIN NEW CERTIFICATE REQUEST----- MIIDgDCCAmgCAQAwJDERMA8GA1UECgwISVBBLlRFU1QxDzANBgNVBAMTBklQQSBS QTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANMIzpLg8Zf9nxPROAz7 YsHzJqR/tOhX22LiVkE85b/ZfB8FXcbeOKS18cZzOlIq69JuTE3MTVCr1Awj3foQ j2voHrsztk/uta5ziD3EBCwIPNvRJBSasF96gz5dIGCRn9BPzHsVDxzUVfwQ3kGC N148DTc5YioFvjljfkxaggQMMlSi+KT/du/gKSi6N3vDSKAnZnOpFSM6f4eXxvht fFPlUb1oUTAlU1QDZafQZYoDuxgDWDBJh8acpB0vfRL6nKQPLN4E4IV7wmU+3/FP 7koIbG+VxjsNiJLkPd6eyYvIN7Wb+ghLBYgX+dsGcD5ds8C8vMgMt1dbURlTEmND Pa8CAwEAAaCCARUwKwYJKoZIhvcNAQkUMR4eHAAyADAAMgAwADAANAAxADkAMgAx ADAAMQA0ADYwgeUGCSqGSIb3DQEJDjGB1zCB1DBwBgNVHREBAQAEZjBkoCQGCisG AQQBgjcUAgOgFgwUaG9zdC9tYXN0ZXIuaXBhLnRlc3SgPAYGKwYBBQICoDIwMKAK GwhJUEEuVEVTVKEiMCCgAwIBAaEZMBcbBGhvc3QbD21hc3Rlci5pcGEudGVzdDAM BgNVHRMBAf8EAjAAMCAGA1UdDgEBAAQWBBTENwGEigmIcLjOHtfit/blP/xVxzAw BgkrBgEEAYI3FAIBAQAEIB4eAGMAYQBTAHUAYgBzAHkAcwB0AGUAbQBDAGUAcgB0 MA0GCSqGSIb3DQEBCwUAA4IBAQCS0mhd0k8ta51N+HBOZ1KQXItWOHKcISU1C8zd k+le1tCe3RmUhtcb9UbIzrktP+GAv83eub2F/9UUxMx81kvRkbSp0sxuQ4RI43AW tSjNOi0HtJ505r93fdL/A487MyG5vJX77/JG6Z9XtISb9SnQrjkfN8YGrkvaeHkl PRDxOGxrXvzA+CdIuz6AeomYF7UGvJ/znhuAs0bBxiOGcioIpZvLxMy1cevQqaJO wtgchkdcmRFpfA/8FN2Y9fSydzeZ91c558W7EXSofSfuSty+FaTQlo0c6ZbFLDMb YJYf3jjZ+3pA1o9AMNr3NkHlxsmyQMaSKyOpDbBlxEKD0Kgl -----END NEW CERTIFICATE REQUEST----- 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - profile: true 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - cert_request_type: pkcs10 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - requestversion: 1.0.0 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - req_subject_name.cn: IPA RA 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - req_locale: en 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - dbstatus: NOT_UPDATED 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - requeststatus: begin 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - req_key: MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0wjOkuDxl/2fE9E4DPtiwfMmpH+06Ffb YuJWQTzlv9l8HwVdxt44pLXxxnM6Uirr0m5MTcxNUKvUDCPd+hCPa+geuzO2T+61rnOIPcQELAg8 29EkFJqwX3qDPl0gYJGf0E/MexUPHNRV/BDeQYI3XjwNNzliKgW+OWN+TFqCBAwyVKL4pP927+Ap KLo3e8NIoCdmc6kVIzp/h5fG+G18U+VRvWhRMCVTVANlp9BligO7GANYMEmHxpykHS99EvqcpA8s 3gTghXvCZT7f8U/uSghsb5XGOw2IkuQ93p7Ji8g3tZv6CEsFiBf52wZwPl2zwLy8yAy3V1tRGVMS Y0M9rwIDAQAB 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - profileid: caSubsystemCert 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - requestid: 7 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - req_x509info: MIICQKADAgECAgEAMA0GCSqGSIb3DQEBCwUAMDMxETAPBgNVBAoMCElQQS5URVNUMR4wHAYDVQQD DBVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcNMjAwNDE5MjEwMTUzWhcNMjIwNDA5MjEwMTUzWjAk MREwDwYDVQQKDAhJUEEuVEVTVDEPMA0GA1UEAxMGSVBBIFJBMIIBIjANBgkqhkiG9w0BAQEFAAOC AQ8AMIIBCgKCAQEA0wjOkuDxl/2fE9E4DPtiwfMmpH+06FfbYuJWQTzlv9l8HwVdxt44pLXxxnM6 Uirr0m5MTcxNUKvUDCPd+hCPa+geuzO2T+61rnOIPcQELAg829EkFJqwX3qDPl0gYJGf0E/MexUP HNRV/BDeQYI3XjwNNzliKgW+OWN+TFqCBAwyVKL4pP927+ApKLo3e8NIoCdmc6kVIzp/h5fG+G18 U+VRvWhRMCVTVANlp9BligO7GANYMEmHxpykHS99EvqcpA8s3gTghXvCZT7f8U/uSghsb5XGOw2I kuQ93p7Ji8g3tZv6CEsFiBf52wZwPl2zwLy8yAy3V1tRGVMSY0M9rwIDAQABo4GFMIGCMB8GA1Ud IwQYMBaAFKmuyXK2OFdwmHOmufNK2gWKJbAMMDoGCCsGAQUFBwEBBC4wLDAqBggrBgEFBQcwAYYe aHR0cDovL2lwYS1jYS5pcGEudGVzdC9jYS9vY3NwMA4GA1UdDwEB/wQEAwIEsDATBgNVHSUEDDAK BggrBgEFBQcDAg== 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - req_seq_num: 0 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - profilesetid: serverCertSet 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - req_subject_name.uid: 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - profileremoteaddr: 192.168.122.128 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - requesttype: enrollment 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - req_extensions: o4HOMIHLMG0GA1UdEQRmMGSgJAYKKwYBBAGCNxQCA6AWDBRob3N0L21hc3Rlci5pcGEudGVzdKA8 BgYrBgEFAgKgMjAwoAobCElQQS5URVNUoSIwIKADAgEBoRkwFxsEaG9zdBsPbWFzdGVyLmlwYS50 ZXN0MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFMQ3AYSKCYhwuM4e1+K39uU//FXHMC0GCSsGAQQB gjcUAgQgHh4AYwBhAFMAdQBiAHMAeQBzAHQAZQBtAEMAZQByAHQ= 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - req_subject_name: MCQxETAPBgNVBAoMCElQQS5URVNUMQ8wDQYDVQQDEwZJUEEgUkE= 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: - profileremotehost: 192.168.122.128 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: CertProcessor: Submitting certificate request to caSubsystemCert profile 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: KeyConstraint: Key algorithnm: RSA 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: KeyConstraint: Key type: RSA 2020-04-19 21:01:54 [http-nio-8080-exec-16] WARNING: Certificate request rejected: Signing Algorithm Not Matched SHA256withRSA Signing Algorithm Not Matched SHA256withRSA at com.netscape.cms.profile.constraint.SigningAlgConstraint.validate(SigningAlgConstraint.java:125) at com.netscape.cms.profile.constraint.EnrollConstraint.validate(EnrollConstraint.java:165) at com.netscape.cms.profile.common.Profile.validate(Profile.java:1329) at com.netscape.cms.profile.common.EnrollProfile.validate(EnrollProfile.java:2727) at com.netscape.cms.profile.common.EnrollProfile.submit(EnrollProfile.java:668) at com.netscape.cms.servlet.cert.CertProcessor.submitRequests(CertProcessor.java:246) at com.netscape.cms.servlet.cert.EnrollmentProcessor.processEnrollment(EnrollmentProcessor.java:207) at com.netscape.cms.servlet.cert.EnrollmentProcessor.processEnrollment(EnrollmentProcessor.java:97) at com.netscape.cms.servlet.profile.ProfileSubmitServlet.processEnrollment(ProfileSubmitServlet.java:242) at com.netscape.cms.servlet.profile.ProfileSubmitServlet.process(ProfileSubmitServlet.java:128) at com.netscape.cms.servlet.base.CMSServlet.service(CMSServlet.java:493) at javax.servlet.http.HttpServlet.service(HttpServlet.java:741) at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62) at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke(Method.java:498) at org.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:282) at org.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:279) at java.security.AccessController.doPrivileged(Native Method) at javax.security.auth.Subject.doAsPrivileged(Subject.java:549) at org.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:314) at org.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:170) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:225) at org.apache.catalina.core.ApplicationFilterChain.access$000(ApplicationFilterChain.java:47) at org.apache.catalina.core.ApplicationFilterChain$1.run(ApplicationFilterChain.java:149) at org.apache.catalina.core.ApplicationFilterChain$1.run(ApplicationFilterChain.java:145) at java.security.AccessController.doPrivileged(Native Method) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:144) at org.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:53) at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62) at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke(Method.java:498) at org.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:282) at org.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:279) at java.security.AccessController.doPrivileged(Native Method) at javax.security.auth.Subject.doAsPrivileged(Subject.java:549) at org.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:314) at org.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:253) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:191) at org.apache.catalina.core.ApplicationFilterChain.access$000(ApplicationFilterChain.java:47) at org.apache.catalina.core.ApplicationFilterChain$1.run(ApplicationFilterChain.java:149) at org.apache.catalina.core.ApplicationFilterChain$1.run(ApplicationFilterChain.java:145) at java.security.AccessController.doPrivileged(Native Method) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:144) at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:202) at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:96) at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:541) at com.netscape.cms.tomcat.ExternalAuthenticationValve.invoke(ExternalAuthenticationValve.java:82) at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:139) at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:92) at org.apache.catalina.valves.AbstractAccessLogValve.invoke(AbstractAccessLogValve.java:688) at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:74) at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:343) at org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:367) at org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:65) at org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:868) at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1639) at org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49) at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61) at java.lang.Thread.run(Thread.java:748) 2020-04-19 21:01:54 [http-nio-8080-exec-16] INFO: Updating certificate request
I have dumped the CSR:
-----BEGIN NEW CERTIFICATE REQUEST----- MIIDgDCCAmgCAQAwJDERMA8GA1UECgwISVBBLlRFU1QxDzANBgNVBAMTBklQQSBS QTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANMIzpLg8Zf9nxPROAz7 YsHzJqR/tOhX22LiVkE85b/ZfB8FXcbeOKS18cZzOlIq69JuTE3MTVCr1Awj3foQ j2voHrsztk/uta5ziD3EBCwIPNvRJBSasF96gz5dIGCRn9BPzHsVDxzUVfwQ3kGC N148DTc5YioFvjljfkxaggQMMlSi+KT/du/gKSi6N3vDSKAnZnOpFSM6f4eXxvht fFPlUb1oUTAlU1QDZafQZYoDuxgDWDBJh8acpB0vfRL6nKQPLN4E4IV7wmU+3/FP 7koIbG+VxjsNiJLkPd6eyYvIN7Wb+ghLBYgX+dsGcD5ds8C8vMgMt1dbURlTEmND Pa8CAwEAAaCCARUwKwYJKoZIhvcNAQkUMR4eHAAyADAAMgAwADAANAAxADkAMgAx ADAAMQA0ADYwgeUGCSqGSIb3DQEJDjGB1zCB1DBwBgNVHREBAQAEZjBkoCQGCisG AQQBgjcUAgOgFgwUaG9zdC9tYXN0ZXIuaXBhLnRlc3SgPAYGKwYBBQICoDIwMKAK GwhJUEEuVEVTVKEiMCCgAwIBAaEZMBcbBGhvc3QbD21hc3Rlci5pcGEudGVzdDAM BgNVHRMBAf8EAjAAMCAGA1UdDgEBAAQWBBTENwGEigmIcLjOHtfit/blP/xVxzAw BgkrBgEEAYI3FAIBAQAEIB4eAGMAYQBTAHUAYgBzAHkAcwB0AGUAbQBDAGUAcgB0 MA0GCSqGSIb3DQEBCwUAA4IBAQCS0mhd0k8ta51N+HBOZ1KQXItWOHKcISU1C8zd k+le1tCe3RmUhtcb9UbIzrktP+GAv83eub2F/9UUxMx81kvRkbSp0sxuQ4RI43AW tSjNOi0HtJ505r93fdL/A487MyG5vJX77/JG6Z9XtISb9SnQrjkfN8YGrkvaeHkl PRDxOGxrXvzA+CdIuz6AeomYF7UGvJ/znhuAs0bBxiOGcioIpZvLxMy1cevQqaJO wtgchkdcmRFpfA/8FN2Y9fSydzeZ91c558W7EXSofSfuSty+FaTQlo0c6ZbFLDMb YJYf3jjZ+3pA1o9AMNr3NkHlxsmyQMaSKyOpDbBlxEKD0Kgl -----END NEW CERTIFICATE REQUEST-----
And the text version is:
Certificate Request: Data: Version: 1 (0x0) Subject: O = IPA.TEST, CN = IPA RA Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:d3:08:ce:92:e0:f1:97:fd:9f:13:d1:38:0c:fb: 62:c1:f3:26:a4:7f:b4:e8:57:db:62:e2:56:41:3c: e5:bf:d9:7c:1f:05:5d:c6:de:38:a4:b5:f1:c6:73: 3a:52:2a:eb:d2:6e:4c:4d:cc:4d:50:ab:d4:0c:23: dd:fa:10:8f:6b:e8:1e:bb:33:b6:4f:ee:b5:ae:73: 88:3d:c4:04:2c:08:3c:db:d1:24:14:9a:b0:5f:7a: 83:3e:5d:20:60:91:9f:d0:4f:cc:7b:15:0f:1c:d4: 55:fc:10:de:41:82:37:5e:3c:0d:37:39:62:2a:05: be:39:63:7e:4c:5a:82:04:0c:32:54:a2:f8:a4:ff: 76:ef:e0:29:28:ba:37:7b:c3:48:a0:27:66:73:a9: 15:23:3a:7f:87:97:c6:f8:6d:7c:53:e5:51:bd:68: 51:30:25:53:54:03:65:a7:d0:65:8a:03:bb:18:03: 58:30:49:87:c6:9c:a4:1d:2f:7d:12:fa:9c:a4:0f: 2c:de:04:e0:85:7b:c2:65:3e:df:f1:4f:ee:4a:08: 6c:6f:95:c6:3b:0d:88:92:e4:3d:de:9e:c9:8b:c8: 37:b5:9b:fa:08:4b:05:88:17:f9:db:06:70:3e:5d: b3:c0:bc:bc:c8:0c:b7:57:5b:51:19:53:12:63:43: 3d:af Exponent: 65537 (0x10001) Attributes: friendlyName :unable to print attribute Requested Extensions: X509v3 Subject Alternative Name: othername:<unsupported>, othername:<unsupported> X509v3 Basic Constraints: critical CA:FALSE X509v3 Subject Key Identifier: C4:37:01:84:8A:09:88:70:B8:CE:1E:D7:E2:B7:F6:E5:3F:FC:55:C7 1.3.6.1.4.1.311.20.2: ...c.a.S.u.b.s.y.s.t.e.m.C.e.r.t Signature Algorithm: sha256WithRSAEncryption 92:d2:68:5d:d2:4f:2d:6b:9d:4d:f8:70:4e:67:52:90:5c:8b: 56:38:72:9c:21:25:35:0b:cc:dd:93:e9:5e:d6:d0:9e:dd:19: 94:86:d7:1b:f5:46:c8:ce:b9:2d:3f:e1:80:bf:cd:de:b9:bd: 85:ff:d5:14:c4:cc:7c:d6:4b:d1:91:b4:a9:d2:cc:6e:43:84: 48:e3:70:16:b5:28:cd:3a:2d:07:b4:9e:74:e6:bf:77:7d:d2: ff:03:8f:3b:33:21:b9:bc:95:fb:ef:f2:46:e9:9f:57:b4:84: 9b:f5:29:d0:ae:39:1f:37:c6:06:ae:4b:da:78:79:25:3d:10: f1:38:6c:6b:5e:fc:c0:f8:27:48:bb:3e:80:7a:89:98:17:b5: 06:bc:9f:f3:9e:1b:80:b3:46:c1:c6:23:86:72:2a:08:a5:9b: cb:c4:cc:b5:71:eb:d0:a9:a2:4e:c2:d8:1c:86:47:5c:99:11: 69:7c:0f:fc:14:dd:98:f5:f4:b2:77:37:99:f7:57:39:e7:c5: bb:11:74:a8:7d:27:ee:4a:dc:be:15:a4:d0:96:8d:1c:e9:96: c5:2c:33:1b:60:96:1f:de:38:d9:fb:7a:40:d6:8f:40:30:da: f7:36:41:e5:c6:c9:b2:40:c6:92:2b:23:a9:0d:b0:65:c4:42: 83:d0:a8:25
the signature algorithm is sha256WithRSAEncryption. note the raw error is: Certificate request rejected: Signing Algorithm Not Matched SHA256withRSA
Certificate request rejected: Signing Algorithm Not Matched SHA256withRSA
@dmoluguw could you please have a look, time permitting?
This is identical to the issue @frenaud reported at https://pagure.io/dogtagpki/issue/3170#comment-641632 and should be fixed by the PRs referenced in https://pagure.io/dogtagpki/issue/3170#comment-641701
I merged this. SSLEngine still isn't yet finished, so these tests will continue to fail for the time being.
Metadata Update from @cipherboy: - Custom field component adjusted to None - Custom field feature adjusted to None - Custom field origin adjusted to None - Custom field proposedmilestone adjusted to None - Custom field proposedpriority adjusted to None - Custom field reviewer adjusted to None - Custom field type adjusted to None - Custom field version adjusted to None
I believe JSSEngine should be fixed with:
When @jmagne reviews them, we can merge and nightly builds should be fixed.
The latest run shows that the issue was fixed: PR 207 Versions: pki-base-10.9.0-0.1.20200523021925.617a3c1d.fc32.noarch tomcatjss-7.5.0-1.20200518183820.23655272.fc32.noarch jss-4.7.0-1.20200522211756.4791c10f.fc32.x86_64
@cipherboy you can close this issue.
Metadata Update from @cipherboy: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/3289
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.