I installed a master CA, a cloned CA, and a KRA in this order.
When the KRA was setup, it automatically setup the following connector information in the master CA's 'CS.cfg' file:
ca.connector.KRA.enable=true ca.connector.KRA.host=dogtag17.usersys.redhat.com ca.connector.KRA.local=false ca.connector.KRA.nickName=subsystemCert cert-pki-tomcat ca.connector.KRA.port=18443 ca.connector.KRA.timeout=30 ca.connector.KRA.transportCert=MIIDsTCCApmgAwIBAgIBCTANBgkqhkiG9w0BAQsFADBOMS swKQYDVQQKEyJ1c2Vyc3lzLnJlZGhhdC5jb20gU2VjdXJpdHkgRG9tYWluMR8wHQYDVQQDExZDQSB TaWduaW5nIENlcnRpZmljYXRlMB4XDTEyMDkxMjIzMzg0OVoXDTE0MDkwMjIzMzg0OVowUTErMCkG A1UEChMidXNlcnN5cy5yZWRoYXQuY29tIFNlY3VyaXR5IERvbWFpbjEiMCAGA1UEAxMZRFJNIFRyY W5zcG9ydCBDZXJ0aWZpY2F0ZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJm43nA2nV T9YWBNxzqy0rumad5wpl65SWPfASdf0egSDcdrrkj1gzlr+OnXtQIOkBRoPwYAsx2QJOlR9kLdRjz OHomzTgOnIpfG0+29g+KHxYKUZ1R4Do2+B1JwHiSh1QHCkUqw7BzUqolpAdd0kJLga2/oRBn8Vk7/ U1xhJykgkmihJHatwSFOp5ZHfb9xoyxXSpYNplTSatfnAXif+MiOctaHRhzh2QKJy3QfXiX5Qf1Wa lJ8rd37utP0hO6CnoO5EQWAWyhO2kDWn7EJF+K5HGqQzHmEYCaL+XDCOWrAK0Q8j6Qx6BuM4jg2o6 maek8FeCT61s+o7Tf/elZFGN0CAwEAAaOBljCBkzAfBgNVHSMEGDAWgBSC6Xkag1zjeWO4O32U+qe GhoHUOzBLBggrBgEFBQcBAQQ/MD0wOwYIKwYBBQUHMAGGL2h0dHA6Ly9kb2d0YWcxNy51c2Vyc3lz LnJlZGhhdC5jb206ODA4MC9jYS9vY3NwMA4GA1UdDwEB/wQEAwIE8DATBgNVHSUEDDAKBggrBgEFB QcDAjANBgkqhkiG9w0BAQsFAAOCAQEA1D9MliVNNgFaiu6p3XK48T/DD7QkmeoLDVgWkVozq9mw+U Gco5I6xdK/MA49MJqiYsv1wLaw4KunubPEET3KVc9qiXmM9IcIGYq4IVN9riPP9LaFimAeGV/1hVg xEx8sTfk8vLRpusL+mpc2i5Cm/5+OvMiLV8NCz9NwqCQj87NBGv0tHV09ehyeEEkRoOkl4bwoCNrJ TId8BC41sBkPeRZIz5VfHKKvqhZDr48eLmiczfr1ykOaZuBpa7IjNCfQLwNsshTBJrUU086QJscnS xcbNFQCTnqRQQpnkLK+39yobroOUqEWe1pYxE+VnbiOVfZhbp1kZARFIzX8WGS6/Q== ca.connector.KRA.uri=/kra/agent/kra/connector
I was able to use the 'Manual User Signing & Encryption Certificates Enrollment' profile from the master CA which successfully archived the key on the KRA.
However, although I was able to use the ' Manual User Signing & Encryption Certificates Enrollment' profile from the cloned CA, it was unable to archive the key on the KRA because this information had not been replicated in the cloned CA's 'CS.cfg' file.
I used the following procedure to manually rectify this situation:
# systemctl stop pki-tomcatd@pki-tomcat-ca-clone.service Edit '/var/lib/pki/pki-tomcat-ca-clone/conf/ca/CS.cfg' where I cut and pasted the KRA information listed above into this file. # systemctl start pki-tomcatd@pki-tomcat-ca-clone.service
The cloned CA will now successfully archive the keys when using this profile.
Metadata Update from @mharmsen: - Issue set to the milestone: UNTRIAGED
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/897
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.
Metadata Update from @dmoluguw: - Issue close_status updated to: migrated - Issue status updated to: Closed (was: Open)