Formatting a token using tpsclient fails
How reproducible:
always
Steps to Reproduce:
Format a token using tpsclient
Actual results:
Format operation is failing
Expected results:
Format operation is successful
Additional info:
TPS debug log messages [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSProcessor.gp211GetSecureChannelProtocolDetails: totalLength: 0 [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSProcessor.acquireChannelPlatformProtocolInfo: Error getting gp211 protocol data, assume scp01 TPSProcessor.gp211GetSecureChannelProtocolDetails: Invalid return data. [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: In TPS_Processor.initializeUpdate. [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSMessage.write: Writing: s=71&msg_type=9&pdu_size=13&pdu_data=%80%50%00%00%08%67%18%EA%23%18%89%5C%3C [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSSession.process() about to call read on connection : org.dogtagpki.tps.TPSConnection@91ba163 [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSMessage read() [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSMessage.read: Reading: s=11 7&msg_type=10&pdu_data=%10%00%00%00%00%00%00%00%00S%01%01%B7%00%CFi%DF%25%1F%F2 %D1%A4%8F%1A%8A+%F0%19%90%00&pdu_size=30 [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSMessage.createMessage: message: s=117&msg_type=10&pdu_data=%10%00%00%00%00%00%00%00%00S%01%01%B7%00%CF i%DF%25%1F%F2%D1%A4%8F%1A%8A+%F0%19%90%00&pdu_size=30 [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSMessage msg_type: 10 [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSMessage operation: null [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSMessage extensions: null [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSSession.process() created message {msg_type=10, pdu_data=%10%00%00%00%00%00%00%00%00S%01%01%B7%00%CFi%DF% 25%1F%F2%D1%A4%8F%1A%8A+%F0%19%90%00, pdu_size=30} [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: APDUResponse.checkResult : sw1: 0x90 sw2: 0x0 [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSProcessor.setupSecureChannel: diversification data: 10%00%00%00%00%00%00%00%00%53% [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSProcessor.setupSecureChannel: key info data: 01%01% [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSProcessor.setupSecureChannel: card cryptogram: D1%A4%8F%1A%8A%20%F0%19% [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSProcessor.setupSecureChannel: card challenge: B7%00%CF%69%DF%25%1F%F2% [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSProcessor.generateSecureChannel: entering.. keyInfoData: 01%01% [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSProcessor.generateSecureChannel: isSCP02: false [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPsProcessor.checkCUIDMatchesKDD: CUID 10000000000000000053 KDD: 10000000000000000053 [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPsProcessor.checkCUIDMatchesKDD: config to check: op.format.tokenKey.cuidMustMatchKDD [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPsProcessor.checkCUIDMatchesKDD: config result: false [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPsProcessor.checkCUIDMatchesKDD: returning result: true [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: checkCardGPKeyVersionIsInRange: entering: keyInfoData: 0101 [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: checkCardGPKeyVersionIsInRange: config to check: op.format.tokenKey.enableBoundedGPKeyVersion [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: checkCardGPKeyVersionIsInRange: returning: true [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: checkCardGPKeyVersionIsInRange: config to check: minConfig: op.format.tokenKey.minimumGPKeyVersion maxConfig: op.format.tokenKey.maximumGPKeyVersion [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: checkCardGPKeyVersionIsInRange: minVersion: 01 maxVersion: FF [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: checkCardGPKeyVersionIsInRange: Version reported from key Info Data: 01 [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: checkCardGPKeyVersionIsInRange: versionMinCompare: 0 versionMaxCompare: -54 [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: checkCardGPKeyVersionIsInRange: Version : 01 is in range of: 01 and: FF [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: checkCardGPKeyVersionIsInRange: Returning result of: true [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: checkCardGPKeyVersionMatchesTokenDB: config to check: op.format.tokenKey.validateCardKeyInfoAgainstTokenDB [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSSession.process: Message processing failed: TPSProcessor.setupSecureChannel: Can't set up secure channel: checkCardGPKeyVersionMatchesTokenDB: error getting config value. [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSMessage.write: Writing: s=43&msg_type=13&operation=5&result=1&message=17 [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: TPSSession.process: leaving: result: 1 status: STATUS_ERROR_SECURE_CHANNEL [02/Apr/2015:17:40:42][http-bio-30044-exec-16]: After session.process() exiting ...
Per CS/DS Meeting of 04/13/2015: 10.2.3
Per Dogtag 10.2.x TRIAGE meeting of 04/28/2015: (Tech Preview Feature - tpsclient test tool only)
Per CS/DS meeting of 06/08/2015: 10.2.6
Per Dogtag 10.2.6 TRIAGE meeting of 06/30/2015: 10.3
rpattath tested this both with and without extensions=tokenType=userKey in the tpsclient format script and it works fine.
Metadata Update from @mharmsen: - Issue assigned to jmagne - Issue set to the milestone: 10.3.4
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/1892
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.