When ldap server is not reachable (behind the firewall or ldap port is forbidden access) the Directory Authenticated profile requests from CA EE page hangs.
Steps to Reproduce:
1. set-up a TLS enabled ldap on host1. Create user testuser. uid=testuser,ou=People,dc=pki-ldap-test1 2. Set-up CS subsystems on host2. 3. Goto the ca's admin console. goto the configuration/authentication tab. 4. Select add and add 'uidpwddirauth' and fill in the reqd fields dnpattern: UID=$attr.uid, OU=$dn.ou, ldap host: host1 ldap port: someport [ make sure you specify the LDAPS port ]. ldapStringAttrs: mail ldapbasedn: dc=pki-test-ldap2 5.Then goto the ca's eeSSL page and select the profile 'caDirUserCert' for enrollment. fill in the user id and password and click submit. userid = testuser password = netscape { make sure this user exists in the directory server } 6. Enrollment should succeed. 7. Now forbidden the ldap port on host1 iptables -A INPUT -p tcp --dport <ssl-port> -j REJECT 8. Then goto the ca's eeSSL page and select the profile 'caDirUserCert' for enrollment. fill in the user id and password and click submit. userid = testuser password = netscape
Actual results:
You can see the spinning icon. UI hangs. Same problem observed when host1 has firewall turned on.
Expected results:
Enrollment should fail with message 'Authentication Error'.
Additional info:
No log messages found on ldap logs as expected. CA's debug log has this: [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet:service() uri = /ca/ee/ca/profileSubmit [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param name='uid' value='testuser' [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param name='pwd' value='(sensitive)' [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param name='cert_request_type' value='keygen' [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param name='cert_request' value='MIICQDCCASgwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCkrWIo5Yve jDZFBs5iddrIYglvM0Ze0atuElwCN7259ezByZV1zh32r2jfYYhCtqorrIC7zDbq KBRbSl4FJ7TA6vA/gP9H7ktLSmF0CeejTUUE0oRj1x0kwoZpBxzUNH9nbt2ImTZR MCtHy/66BfwG2uxfnUU6vSaf7FI450XZp5TQPQoracPYJwYZbS7dMwZYQAxGpB/j hs0CUzWfDqWRTzQVETo5sHNzF4Lg/o3ZEM90P+dkHSfkzgoM9tSz/p/i8/xnD5r7 n/2FkoKvxie+JAMFwpxcI5YIzunhBtKY+0H3dAas/4d/CqcMi288kMpnWw6MoKty f3uejFjw2JAzAgMBAAEWADANBgkqhkiG9w0BAQQFAAOCAQEAcRYlpx9V+iG3UPbR ngavJAL5+dMRA9KVo8iphA/EhO7uONwrNP2KjmlIUpgfkbDRV321tMtsQZy4DiBI P6dpf6QYErQyHPJcuYedhN5zAQFkns8198e7EK9OULFHpqdUJ6Wx+RaMkkYN3fEk k9WDCDfAjn4I12+dg6Qfjb++0B5TNBVP2ifV33GXL14cms6ufGeMLT0rQNYivb5x UxPsGoMLvQRVu2V6zhN9Be2EdWZr259Rp9MhpMco0tyT6Xg72weF8pBQbCx2Oo7s 8ZjWW4J4B46QGDyK2zuCJ6cBOr4GdURQA/OMFDM62I7kOzByZEoo8lCvW1e5Ruo6 30bSBQ==' [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param name='selectKeyType' value='RSA' [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param name='profileId' value='caDirUserCert' [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param name='renewal' value='false' [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param name='xmlOutput' value='false' [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet: caProfileSubmit start to service. [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: xmlOutput false [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: ProfileSubmitServlet: isRenewal false [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: according to ccMode, authorization for servlet: caProfileSubmit is LDAP based, not XML {1}, use default authz mgr: {2}. [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: Input Parameters: [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: - profileId: caDirUserCert [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: - cert_request_type: keygen [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: - isRenewal: false [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: - cert_request: MIICQDCCASgwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCkrWIo5Yve jDZFBs5iddrIYglvM0Ze0atuElwCN7259ezByZV1zh32r2jfYYhCtqorrIC7zDbq KBRbSl4FJ7TA6vA/gP9H7ktLSmF0CeejTUUE0oRj1x0kwoZpBxzUNH9nbt2ImTZR MCtHy/66BfwG2uxfnUU6vSaf7FI450XZp5TQPQoracPYJwYZbS7dMwZYQAxGpB/j hs0CUzWfDqWRTzQVETo5sHNzF4Lg/o3ZEM90P+dkHSfkzgoM9tSz/p/i8/xnD5r7 n/2FkoKvxie+JAMFwpxcI5YIzunhBtKY+0H3dAas/4d/CqcMi288kMpnWw6MoKty f3uejFjw2JAzAgMBAAEWADANBgkqhkiG9w0BAQQFAAOCAQEAcRYlpx9V+iG3UPbR ngavJAL5+dMRA9KVo8iphA/EhO7uONwrNP2KjmlIUpgfkbDRV321tMtsQZy4DiBI P6dpf6QYErQyHPJcuYedhN5zAQFkns8198e7EK9OULFHpqdUJ6Wx+RaMkkYN3fEk k9WDCDfAjn4I12+dg6Qfjb++0B5TNBVP2ifV33GXL14cms6ufGeMLT0rQNYivb5x UxPsGoMLvQRVu2V6zhN9Be2EdWZr259Rp9MhpMco0tyT6Xg72weF8pBQbCx2Oo7s 8ZjWW4J4B46QGDyK2zuCJ6cBOr4GdURQA/OMFDM62I7kOzByZEoo8lCvW1e5Ruo6 30bSBQ== [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: - remoteAddr: 10.8.0.85 [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: - remoteHost: 10.8.0.85 [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: EnrollmentProcessor: isRenewal false [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: EnrollmentProcessor: profileId caDirUserCert [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: EnrollmentProcessor: set Inputs into profile Context [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: EnrollmentProcessor: authenticator UserDirEnrollment found [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CertRequestSubmitter:setCredentialsIntoContext() authNames not null [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CertRequestSubmitter:setCredentialsIntoContext() authName:uid [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CertRequestSubmitter:setCredentialsIntoContext() authName found in request [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CertRequestSubmitter:setCredentialsIntoContext() authName:pwd [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CertRequestSubmitter:setCredentialsIntoContext() authName found in request [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: EnrollmentProcessor: set sslClientCertProvider [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: authenticate: authentication required. [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet: in auditSubjectID [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet: auditSubjectID auditContext {sslClientCertProvider=com.netscape.cms.servlet.profile.SSLClientC ertProvider@eaf3bef, profileContext=com.netscape.cms.profile.common.ProfileContext@1287cf71} [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet auditSubjectID: subjectID: null [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: DirBasedAuthentication: authenticate: begins...mBoundConnEnable=false [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: DirBasedAuthentication: authenticate: mConnFactory class name = com.netscape.cmscore.ldapconn.LdapAnonConnFactory [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: DirBasedAuthentication: authenticate: mConnFactory not null, calling getConn [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: LdapAnonConnFactory::getConn [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: LdapAnonConnFactory.getConn(): num avail conns now 0 [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: DirBasedAuthentication: authenticate: before authenticate() call [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: Authenticating UID=testuser [20/Aug/2015:14:08:34][http-bio-30042-exec-17]: UidPwdDirAuthentication: Authenticating: Searching for uid=testuser base DN=dc=pki-test-ldap2
Per CS/DS Meeting of 08/24/2015: 10.3, low priority
Per Bug Triage of 05/05/2016: 10.4
Metadata Update from @aakkiang: - Issue set to the milestone: UNTRIAGED
Metadata Update from @mharmsen: - Custom field feature adjusted to None - Custom field proposedmilestone adjusted to None - Custom field proposedpriority adjusted to None - Custom field reviewer adjusted to None - Custom field version adjusted to None - Issue close_status updated to: None - Issue set to the milestone: FUTURE (was: UNTRIAGED)
Per 10.5.x/10.6 Triage: FUTURE
mharmsen: sounds more irritating than anything else, although a proper error should be returned if possible
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/2140
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.
Metadata Update from @dmoluguw: - Issue close_status updated to: migrated - Issue status updated to: Closed (was: Open)