#326 Dogtag 10: KRA connectors not automatically setup in CA clones
Closed: migrated by dmoluguw. Opened by mharmsen.

I installed a master CA, a cloned CA, and a KRA in this order.

When the KRA was setup, it automatically setup the following connector information in the master CA's 'CS.cfg' file:

ca.connector.KRA.enable=true
ca.connector.KRA.host=dogtag17.usersys.redhat.com
ca.connector.KRA.local=false
ca.connector.KRA.nickName=subsystemCert cert-pki-tomcat
ca.connector.KRA.port=18443
ca.connector.KRA.timeout=30
ca.connector.KRA.transportCert=MIIDsTCCApmgAwIBAgIBCTANBgkqhkiG9w0BAQsFADBOMS
swKQYDVQQKEyJ1c2Vyc3lzLnJlZGhhdC5jb20gU2VjdXJpdHkgRG9tYWluMR8wHQYDVQQDExZDQSB
TaWduaW5nIENlcnRpZmljYXRlMB4XDTEyMDkxMjIzMzg0OVoXDTE0MDkwMjIzMzg0OVowUTErMCkG
A1UEChMidXNlcnN5cy5yZWRoYXQuY29tIFNlY3VyaXR5IERvbWFpbjEiMCAGA1UEAxMZRFJNIFRyY
W5zcG9ydCBDZXJ0aWZpY2F0ZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJm43nA2nV
T9YWBNxzqy0rumad5wpl65SWPfASdf0egSDcdrrkj1gzlr+OnXtQIOkBRoPwYAsx2QJOlR9kLdRjz
OHomzTgOnIpfG0+29g+KHxYKUZ1R4Do2+B1JwHiSh1QHCkUqw7BzUqolpAdd0kJLga2/oRBn8Vk7/
U1xhJykgkmihJHatwSFOp5ZHfb9xoyxXSpYNplTSatfnAXif+MiOctaHRhzh2QKJy3QfXiX5Qf1Wa
lJ8rd37utP0hO6CnoO5EQWAWyhO2kDWn7EJF+K5HGqQzHmEYCaL+XDCOWrAK0Q8j6Qx6BuM4jg2o6
maek8FeCT61s+o7Tf/elZFGN0CAwEAAaOBljCBkzAfBgNVHSMEGDAWgBSC6Xkag1zjeWO4O32U+qe
GhoHUOzBLBggrBgEFBQcBAQQ/MD0wOwYIKwYBBQUHMAGGL2h0dHA6Ly9kb2d0YWcxNy51c2Vyc3lz
LnJlZGhhdC5jb206ODA4MC9jYS9vY3NwMA4GA1UdDwEB/wQEAwIE8DATBgNVHSUEDDAKBggrBgEFB
QcDAjANBgkqhkiG9w0BAQsFAAOCAQEA1D9MliVNNgFaiu6p3XK48T/DD7QkmeoLDVgWkVozq9mw+U
Gco5I6xdK/MA49MJqiYsv1wLaw4KunubPEET3KVc9qiXmM9IcIGYq4IVN9riPP9LaFimAeGV/1hVg
xEx8sTfk8vLRpusL+mpc2i5Cm/5+OvMiLV8NCz9NwqCQj87NBGv0tHV09ehyeEEkRoOkl4bwoCNrJ
TId8BC41sBkPeRZIz5VfHKKvqhZDr48eLmiczfr1ykOaZuBpa7IjNCfQLwNsshTBJrUU086QJscnS
xcbNFQCTnqRQQpnkLK+39yobroOUqEWe1pYxE+VnbiOVfZhbp1kZARFIzX8WGS6/Q==
ca.connector.KRA.uri=/kra/agent/kra/connector

I was able to use the 'Manual User Signing & Encryption Certificates Enrollment' profile from the master CA which successfully archived the key on the KRA.

However, although I was able to use the ' Manual User Signing & Encryption Certificates Enrollment' profile from the cloned CA, it was unable to archive the key on the KRA because this information had not been replicated in the cloned CA's 'CS.cfg' file.

I used the following procedure to manually rectify this situation:

# systemctl stop pki-tomcatd@pki-tomcat-ca-clone.service
Edit '/var/lib/pki/pki-tomcat-ca-clone/conf/ca/CS.cfg' where I cut and pasted
the KRA information listed above into this file.
# systemctl start pki-tomcatd@pki-tomcat-ca-clone.service

The cloned CA will now successfully archive the keys when using this profile.


Metadata Update from @mharmsen:
- Issue set to the milestone: UNTRIAGED

Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new
issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.

This issue has been cloned to GitHub and is available here:
https://github.com/dogtagpki/pki/issues/897

If you want to receive further updates on the issue, please navigate to the
GitHub issue and click on Subscribe button.

Thank you for understanding, and we apologize for any inconvenience.

Metadata Update from @dmoluguw:
- Issue close_status updated to: migrated
- Issue status updated to: Closed (was: Open)

Metadata