[dogtag]# pki -d /opt/rhqa_pki/certs_db -n "PKI Administrator for XXXXXX.redhat.com" -c redhat123 user-add --fullName="Test ca_agent"  ClientResponseFailure: Error status 500 Internal Server Error returned
[06/04/2014] - Moving to Milestone 10.3 due to schedule restrictions.
Tested with the following pkgs, user gets added to ldap when CLI reponds with error. redhat-ds-10.0.0-1.el7dsrv.x86_64 pki-ca-10.2.6-8.el7pki.noarch pki-kra-10.2.6-8.el7pki.noarch # pki -d /opt/rhqa_pki/certs_db -n ROOTCA_adminV -c Secret123 -h XXXX.XXXX.XX.XXXX.XXX -p 30044 ca-user-add --fullName=test "ABCDEFQyzZn66aprnh7D9iZnPrelS9rEnSG96wHDUptqVbCNrWafdm33cKQ8YICA82K2e9Q3rKx0VRTmrEAAb6IzOPOWXrAM0ColdfbJNdkxGDQvudkCYkMOspTHsN1JQE5N9p0OCjm9dQ3mcOljxDAwYHuyAHARymdQsKGaxb6MDuMThN9cqTCvQrs2WGVoMmTCuYWaYxSHQFF9XdkZHDQfxi7mnwUU5NIm1ETnScBXaloSlkxOeP7EW7EUOZh6HVm7stQ03al5cvS5r2lGWySTa9ZSCUmljwPtSsFmm9GKv976q0PRjN5m3J84Vv96bbHpf6IOGPCmPmYeviwtkDxG0yw6GzRYjdTLSnhwwB90D2nUW9bXBlcpz7cmIgn1Cbw0XJEcIwjnD7JLqZoqmSO71APQeBmza9cm2gcTgSeUkkXOOYrG9qGc3S5n7LelFxk7qjtZYmHs5Af1PhrmND9psa5iuNl8zhYqKlb3xENXHdJPGoQ9w9chE1b6n7afu5xKtvdw6Bza9coyg04OhW6hecqKHiADX25XR9vsO1KwXR5YVbWcoCAB1t2hFUgGRXB3Fi6iNXCMHBZxvUtAcZC8q2dSBkevolzp3XUMdKaBwmLzVRn8f0S63dSh8N3xUC5K4c1uOnC9Rm082EW3M30mHDNwETDj9RfIJg070aNvW5fhhpb2qzh8jKyCfJeoSFYWISAlNvQ7ettjTZorXSEJtA3fg4MU5XhpIbxk3IlTrS9bRK50dfoPgYY4RjXVfyrT9TRzK63vM3CYYOCC05dvVVOtwY6Vk1FC97ShdE15StMUfzD3nG6Svu2FsfZ4sxVjzT43wkuFxqrAyXE4GI7u1AnlydKKnrnBo2AHON9nXhtZKB67R48huA4reNRqt3OJ1xWSUQPqqSSwR8Wls28X2PQ6OqGNSNSpj6E86IAS9jrOFxvriGGdsdukKymKyHBMF18BstSVKuQ3OyxJJpbP2T2X9zrH1RZtFoNEmIA5WEoTnrlNCBrqXDe8nNk9gNnP45c7tEuzeD56tJounncwtEgiMAGR1t5HF6jHrFFfSuUoHM8RgwhZ6DF43eeMChO18GacSoz3H2IeaNvrIpw66FL5K2wIMmUUwsLUutduGBTAwuKI6XbBe3mWgvAkm9i5obM0jWW4EHnNf9CpPA8wleuID2ysfS534WH3GbtDKjBqvRT4wXkHnjc7XeUXjhx5o3uaYhkzCYRSKrp8hvoERs8tOi84r4OQuxMxlvQEnddoqEFCTtYYmaxQKRXobtP1TWObym4v1MTrjm8BXtXChSlHkOAP9sMmXqdgslAvgx8NqkqEW6XRGWkZLMMM4QQYTTMbwgMxpqDv6PhJEt7xUTZpgQcgBVBm4RFkQolyt5rhbd9ifxz5092qYLa1kD4YFVapIZEGwmkqAQxm6DX5ogiSabuV9p7gEJQ33cIbBIMxl0tHRuoApH0lsSyngqyAAaSq7XNRQqbcj8TGmBw5zANEhMq8FCI9Pjl2552838PFBmOqUtBDKA83hzZcdYI5Y0dmIh2U80kGVA04bXiBwyJm9wFzjMXb1QxjHxjWuh4o0OCJyt21trPCHl8ZsdkZ1Sk1dPpkSmoI6kqpGOR3n0LdtWuFAKP5v0SAI8xF0Jw6ioFOmCtd2KxyMQx71hMqRaHT63g7iZu1F2K0BiumFgoV4HunWeQFBHZc0mL4kODEErSXWU5fZvIo3lkRDQF8XEwG08kKRMDeJxWhypfvQzEEQvyJQQr2lR0w0JX8T6mDwxz6ychFCPEJcJXbAd3Dr6pQfKFLKze7Df7fdyfrDIJ89iR8UScPTlayxedyve83S6S7pYHqZ928IhOysNyZRGWXL8st7gY8Dm80VJfzTLtn6JXhHj6LDKzDFHQFtfM0P5HMM9flyqNBJ9k0in4mdRQn8NsBOk8IIFqdBp6cpUeoYTnodBkMhw00U4EE8oua9S7rpAIMQAd7pZdiS9LLFyUBXFvg23fCcIvA8RLIeogB3RynYCz7G2sgZ0LQuO3RYHNkb9IYLlkxPP2FJy5EBeez61i7UHM5McNPf6ItEuPCEm3Z0Sg7LBEeNsm56I5CNaVs8B4K1oBEkXCGclAQcwUSkJeeki7ooejwskzwVItTT5tVnXj1JQ5akOroXoMaWJntegK3tKCXBSjkCxrRC0wK1v8X9qU4dVCNMFHsD2Ej7ADOP04Kxb3Z8fHtAuk4NVXQMny9a4AWyJNYIcNZ0G9awUYK3ibCOfUPbvRaxTUHo0IdmGy0LbSLDzNOWcPOG7BuiPiGYd8Yh5A6Dw92SxqqsENVq94JOiQGBh8mYILZAEnsXCgg7yt1gbOpkJbU1rMRcrPbTpDsEvrTR59qOLiFcgeLV55J6bEid15CBvExYFUz0rd5SmT1oZYKNfbdQRmuc8bIosBS0zHwx963igbqC7mz5ECu04pPncuq3NjeLmzWAG60QwVTsLGvsUZe6HMQWsBQX5LymklB2FgAxszE4j9N9UUk7HQQyELKTg52onR3dkP6vtJqc0CzmsKjTXYp2byi9D51p3Qc0ddnZrhV5eolFIw52zpxzcgdXxzKEeLEJAahCqxdy15lZSxsYvCCOjXmBT0eRaQ2vGW04LqjQwpcYnyPXyXg4nN2Y4qKjem5HirNdD0fLhjAev4OmJZZgQMxBShPkv78ZkBmdTDsR1DkHOLtowtU0XMr8HpYtRaj7xY4ii6LnN9kXfz69Ekt7ymclhcSI7GrLrZhKUbFvqSRPQrzci4iSHojIG5VqmZCuou5MjcKlKpGuWMWxchYtIDlEKw69ugHSABunI95jcAN8rYqINIo9jVTcKkZiHn9T92kRvci4E2lMYYhAop1LO5DVrYXfrYP9cbfpFGJUvoNvd2AWHMSbP8WwOBvV5xOD4nIHclK8QdM7u0NEKOBFkzNS9btN1BFz1aHYki3nPpwqNFy6OMRyEtQai0adnHyS2DC1RogiMVlcxzcSTBgYAH4ssETf69b7LDHTdHW4GZ96XyCPUnwMqSQaZ6NqORn8sAxLdw1VjlVjKvujnm5psHbHKDLycqBzBsztHRK00HPfO5BxhkSisll67uAjb8YsrRHtAJ81Ln3MHN3rpGw3gQELZiuT0l6heFLOP1gh1XDBaDSr1hmj5LX4C98yuxxB4D1gv8ttyYGhA9QnmZHDIbYpzVg6HYEhfbWWzKTnbDDkhyEvLv1vyNJlLLmmTC5aKtpOGjSbFVitnXuUp4HE08sAhnNcH1X1wd4oJrWbrWvDRrT22XdakI6S4C4tMD232iFzNh4CiRHJsgcNNWIGaXonbUA0Mbc088D7cmSMz7dxSKZuLK4U51R1WEA0UaRfnQUuxKMYmr8waaJRMUT8BjP8trTkGjjbpH3PHh3WCOwEj1lyfGJQ5UoiMSOpArR0OdufNOOyREZkwYhTyjdKzahmyiYifEczIftjECPhk3ptmvOl23JzroCQkKULGOnM3qCjFAUnKYK70GXMw32Otq6qdAULlEv9h1KLFdL40tpORWq9ToB2M0TH0mQTrFCyahZQdkhy9uxZurXrJbqe75AmTMvzUOCJH3gBRa5pqGa6jgGVLmMg6bb4i23lmSf6dMEnMcH3E9WvHac1gtmPGpq3vCo9YVNaypRbtLZh4LfV3haEOPaR0EQ7cr9I2bgIf6lrbfq8nxO3khmE7v1C1bmxBFPw7L9d8dJZLh4shGNjSBCEU8vnvERiG9eE9qJlK7yz3oVWG5lpbSWfI4lCfuE5q9DgfCfCXChtMd932WIZyohm7aHSHQkOIDoBqNhjU6IZBzt0VhdlT9ZLIn0c4vO1kVxY0mhNcTT7YRI5ysGtbY4CKbm9ENP4gkMGhHop6y4QlMJK85jt0dpEEc4w7cpnAhenAFJjrvbH1hIGdVNjftQT4lQfCpkKq79hzdewE2b9AwkvKHA7UGQi7bk3wfjP5z0Q1UhOp0IpSRvbPwdmTd1pfvMpj95sM5MEae7AYyTbq3FkKJfoXvu54pwMiMzRPd98rZlswPvLODIClQUgiVFpvfTgFBOUzbtdkArXCB9s50Mv9i6ELa3c2ol2Wah3rI12FBnvzMYrf6lCFtQ7sVLXIifvo59W9hZrNPHfe6BGvGZgsETpcOhn2RgUIBxwCBcawmLrYk8qSPC5R3p70LbYaCRO0lmLf5Wq05ZnU1hZrct4JqBf1qL6050wCZWJRnDkjBEeqBWoix1zuQfiWVJeNc1fIIHMZ0tdN09VeCcL8buDyE7GzVupw9kGtMAdI2eNyIQdF72ucDW0G9qmtyN7LVZZVhYfmote4aJDHV4el02zStEGWs5YnewV9On5yQdCauDVZQPXHS2cvrg7Ayy6LnzldAPQPlUMrPy08ZT0UVA3URRGJ3xy29YeEJeGlMKOfZ2yLhsJRqpAEzMcwizNrEDuQXqdN9k8Mzw3bJp7aCVNMWJKmaj3Y7bNdVTChP2TUgjp18GUhdyLf4II2gOBSAABb436rnsqX6PpfSz2HRDGjeYAQ0q1byU5Amn2SlX9q55f6z2awwKvqKCq2LrKPTjFkBpPluR6LnbPfaPqEbvQeaDNTLrBBbd2pn6t9aqbZwrRt1phgQ92zPqUDhH4el7v8FmlIoHnZfOTo53DUM4sBvviFTJFQUgRZoW5VmSxBNevUXbawZ7TjjRRegjcbO8s7LfANvzBUhe59KNDjzUK6uFPRBzzZU2jZOEECaPZd8gQckT7fegeNdhT7xQVsCKLXBAGbbTYtFjGbFuB88Gckp1A5EekQXPRpipdBPXGGB6Yb0PCzbEkNTBsWzZqYtTzkbUw9Ovdzr325ol46AT1hNaNIIuklx6IBozdGXw9aWDpRKAENvRxqPLuIKfi7ldfP6oN8E6Iw1tJtBRJ8oOf0fj2ISiAdqRkrpa0wPK6IoroFE4cDRsr9ImmvYZ48MWzOI6Hl7mLCVxDWwOcpQAgmtXYUFwTrlTTfiH8qVLqQKplwDCv40Q5ZBdmnMcaecZvdHPGtIDqLr1dy9KPFX0KEsfR4qSevvj2VQ1ZnDFeBh7y3OdLSHev5sLt9nBRMIjGX0bnUBD3wnbenFRnbP6a73DRrN09fFUHlfDO74x0kpkTUpaUtLsZOUr0inA6eryw21agWTmBw8BZ4VtmqzyePH0FCsOybZh4EG3Wc5bH9UvARqo7dsECoWi4HWGag7a7o1m24VZPXpogRq5Ri40dPts5V2mm9HROXlqdOJPybpceRnjUEjQXnRrWfaaFkqhN6QNIGip7nH497sYOBZW7Cro6zswamJTo31ZAQouW4NKhx7MXaixeq3AMd8WNgJtkUbuofcJzOCCHsQJ9VIBXh5fBVy0w6ex2NdBic7vZO08dSY6k1Aovw0aP1ppVhBhjgTn4AFxcsxe9O5E5oijNJSgUv52A5sEsZRSbtxscCZEzYBq0ttKNQbhfVOLa9zzkLwfHnswZwPDKeveohHNbtPlsVi8DM59yfvUKRXLRlYWTtFAdOH8spWv806qlt73FBlqaPcHmhdmWeKSICZtQN6OYJHKWb8LTFEy9JFme9ZRTQ79bROCXBtqsmRzP1f4hGlrKjsSTxDFwNXSvnkZkfkHWtVFmDcXMKbSlGrFxerwhb6ZyinLm68p36vjRPEhpGB4jCIpxVf0yXwq5OkQxx2ni1HX3JGkA6PPMDpVE4f2yYp9nB8GUmsUlJVgQHEMvaewzLdbvMFh7nj2KMH6XovsC8qOu2rpCTBCp54RKpNzYvLefYpRNDUDx3ZmCH28yMkLel2Ogg5rgDe7E92t2h9lu3UWXmMFohqPEiQfEC9l6iSRCEZSe7qT4OUCS97LSjSqTiYUjLnZcPOBEyHCZdi9qlRyprVSgpvSN7uPG3WmBrqT53MxoKPHklmP2KfwoYqrlpYczqinep48XTJXzbHKDIBG5NJzV7gwPFbo35ndNoxb9R8FXpWSacm3Lq5Lyi1xbpam7FPldMbbEYrdO4RzqJoj5S2gYpF1GJTfAVUvmyLX0NHF6d6SU2RAc9i8qBsCBxP3nNy9VICgqZxHq1pqsKDUzY1okeVzMJftAtL80hkrqxt0NenVSvswzG4IlvTfD8xybctmPNQmXXNnSv0CyT8IZlxG6eXBaA4ujSBq33efJHH5tDCPLJ2YLS0z0vljxRnpJOskmrs7ejQ96a1AudQyJrE3zYk2GuPTnRxSCiQFRvTbK9tsV9fa9rHpQqWnPFbBu8TGnYxF32YxmZHcteu4np9R6t1aFG2m5tGpTywhG8GeMKirXv6gtApACtOJ2aLZPoF2OY4MlBRSRrmZQluFeWSp94jelxph8tXaMTRHu1osMMFEMGGju7T75ucaLAOvPpL4flwUSaITTfP4tXTAwLIy9PTCH2Vk36jyIXsUxTy47tVCVuFY7epDWH8ZLGQsBNvNXp2sru0Aw5tk20cEXVSdkHGYpLcxJgpGzJ1dJLWcbrRD7S0xQDmiXMjbEPPqJBHq4rWQOlmw3dRzaI1jQP56kZ9HBlnRXNYmgEE6ochc4Sv2Yr4lZPe7OzfxrewLxAleP7w3dbUVt1MlKyFNzdspwvzGUim3fK9MSrqe3flDUnieIakoA8QSFWwqMvL5Jex53F9mBnOfoon6sFUdy1cS4nIGGa2Vj7wm38S5t2izE9Li7ezIVxhXHI46vuSq2FxqI1RE48WytiyWTkHRAij7SblGaP7Tm7U317rNtXZtqtIwuiWJMB8mdXJPteGSdEtTw9YWVxmOCa7EV6cfyAat75BJL4xgi6wsErQ456SRMkuZxW0p9x7ZZWIpqHBOgNKSo6MVfZC9ecMAqQt1HvbOP3YoVSJ9mEGbbMFWkqFEI3e3mvL59GnEFM7HnMtk68SRPPCkx0jcWO6XqqqyrQ8Vp9oJ6Wkfu6dyRwD6QVnOBA8HMSwJCS7QCtHaYD63EtrA7HzF4kueMjESp7PbAbyEOUU0GNlMGnkTKTAxiFViXiqJ4H5RTCqS9ey3zeSDVkX5NyyNkZQS6P9CNm3e1nN5nG5kLkxHI5QRzcDhRwsLXBjubVYX4c4MnYQ3yZB0DzAQWFR5SYfc8fD8UQR3ENL6G7jPXngirfWldyJuJIP5dO93Fo0V2CPOn2EOSTqJWkSehWqI1SXxNP5lv5yPzMvFb9iE80FxzUXaS5EHHMbrFrPlSAWkiVosTM64wVOK2qrQ3o0RpcXuwqL0C4senfQ3rihEua6KERMxtrMyJddp54wGrH9raUFlxHz1bfMGNiU9y3qoUbOZTDVD3NsPZkXpnqQrFmwa15gy4GZtFCmiSX5DkFlgTWRLawNzTgzQpPpSN0LXn8s7FxsRJlKSDJ40USF3XZIeANl3DdHosfIXLWu0B4qc8YcDFPGPBmbJZWXhHjItjD4i52kDJV3dB68M6PwldSjiRXELnWt4CQtZA1R7AQJ4u8dPftDl9LnMx4nNuFwCZeMYYXlsgHAFQQhnTcNlDbwRL4Cupug1WjKOK0aBnmRMzSx5VKIzCJo2aUHQJgoc6aEmps9I2VMriHJPG4AGuhzxTGj8b35Tm0007iGbOeFWv5Yjeb5gMdj0U5c9rfWSogyY1rg0Nd6dXCpCjv1eulMytYtIoIZRh9grp8MSzovIbXNocGaXqdlJnsxylhifYv3gGqKzMbW6gmVzOdDqcA83nJosgyEPOoMamj0L8ZqgV7bTJB3nK77fvNAlNeSNiZCXuR0cT7wJdp5cW5XyjOtvPby0J3Acb7JgEtJJRNJYN3b1OrPWpSXRczot8OSXk4B49jRrZNP3H54JciwUS15HKI0Pjd5yGz9vhEQA40LdUpI0EoRWA4kvziuJ1JccxeDtvpXyViyAi0Mz7oR0PBUHVxijpX57sQOafsNquB90jmalORKLbPZGYgM8ncILPeuxx9G3Obji8WKHlLGkR69UAerCNuoyzkZKKS1EN5n3f9NCXSmohsFGiDFS6OkJ2VJlQnZ2YWf4TH37vmnX6Kbjb4bDJxDSVRrd8U7nqcuUvgThfXcsbTlEhoKJNxhD3EIe8XCFf9nAJ7rBcZNaegzkSlCoD7P4xaThwHP4z9m8aQFOOGuBfLxfVoFPfePvjzJiIHo3th06oi6oR4CMO1998VZgTrx7HLe3BWp7mDq7sZ9c7xxh55NHp52jOsMQqqW0Z1oBaf30iQNROUUEtRi88NAR9tGriTI6LPQdzsaDoeMjWsHvbgdQ2E5PfaKcPiyXI2Z39Yb7zAHW9BcTI51kjeU68ldD0KFNOisQwec3QtnCKBO9LtklYYrXt9AB6aka5HEKmJgyA3Y7pavoY8nXnXjzSeFOtm0jhgYubCiu0j6zjZmQ4G2jcy6ccx3MDNnJalWeRxUPgCHAhnEPq9tQsbqEnXfSnG4sCCPSDbpzGr2YtXE5XOhwBFlV00Hg3cFqs4h6M5NRssGqzJMItfT1vVHMxj3Y98w18ABQ86MW6K3BbbuXr9UYUg2XQq3Gyz3r1Q4MRUzkCEJnxGf19NnLAZurNEdUdsji1m9y5GJrwdh7eSFYOb1pxQiE5qLBP788yx0kqtZ5mwNgeLts5k4v3zcTuZRk1PAM0mXOFRNJ8aShv8XdyN2QLT5Cgjk8QiX8vHP2AMbrNpk2sEYWxhz1Fztlpj2WeMzlnkEbrFlJ5uppbARfZQSmsSUIl7wyViFlyxyJ43OMLiaUNr9XZmmfm9prDffdx5MAqOOsrfE3HUEc4L8O4TE6QSF382BZCkUP5tk7o5FTRfJXN2wAv3pC1WDuA8nWOVPBvEEa3Pdk6smsv5EBsA06QJvsQs9Dq5FcHGUDKqBsl0ermfvoePhLDvqr6fNteJrLCDoEujGvYXDm7zBDOiX8y2CilEqDJZ4fCwwz3s8BQqpKyiuGm1pr8xxyQ24JmTh2rholWwJZUd9xjJrMDwpyK4q4NFAYg2gF9KtQSmPpbmljhyI2GQDDcvek4LQtkZ9X7oF7lYCFSgN320QpAsiolFSxTcoY78qcEvuLg46u7HF02Ub845Nxh257wCRwYoYrYL0QBCHc9Q6Ul4Nfc3zTZtPqnbnE9EIDNGOA1GkmQ6pTz3PDESKhtE1Pw5Fzrz6s9vSAVCB5VigFVij58QVOe4byNLFKBacyQSUQN8lNQD8XnrzHT4SxnXZ0shSmPV5W0USaqBnjrVBPcpHlFwg2Gy3Nd3aCAAdogD70IEqqlAcLL7HtNy2UzjIcpwwnGFSDrkM9FlorTmGn4VXpiqr9OXUhSfp7qZprxYQS39SCrsyzxcqNqo9ottuP4mwznZcUUzcWSX59PRgfAG79cZP5kSZks71yQ9y0UVSOdReodCQRgjI5lMhHvwPJ7BSkX42HfMwVu4vEssVgvWfsP8wMEi8oodKUawqZ2jcrTFrm6WmyZ5r6D1GdOG3d0OqvsprfIx4iaLh7lv2k6DLhq6jCNDpCszwkgNPcYpRCMFplfQelC6nB6McNAR5MMr9klYbPfpZRr3VH7UZBkbbBTkYkQbWgpZTUn8W2bMjna6KPP0JT7me2zvnnOe5bDGEyLDcnuiSUd1hXpFapan3rsMU68aKhvE4fYNHe3IDVSWqYAq1O2Bng4EESPEt9nNTflRqki5ggJ9RsFX6EB3tjXtHAttGEyzoAoRHDP2JKEF5vGZqDxET7KcHD5dwkwWq9gOaD3sqPquCq4q1F0TpOnfezAbeVwmb4bD8mpynJxsVwyESbg8S6Ztf8XKSgFTJ9oCNUfv2pi4RPj1uBXfct9BYRmipMqJckY2RbH20Tu6NpHq9KL0VYpQVPlD7TM2ndEUMCDdyggj7SWKJYIEXmLlOQybLBAE9lTdisqflS9VYgTmKlEHaGSJEntLMlvgSL5Vcw5S2RBeMzZPSysecRVJZvH0jRPQc0D6oo9zaMXsZtA083OG9NQtCKq2yzSxWQqYZo5lQHbucs6cjAgtzJI1CdufW8SfMSEdMvMngprFmKbYWWjocjKOJvww7is63lmQ3xn6CDIOdKMpted7" PKIException: Internal Server Error # echo $? 255 Actual results: CLI reponse is a error message "PKIException: Internal Server Error" and a return code of 255. The user got added to the ldap database. pki console display the user record. CA's Debug log shows this: [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: PKIRealm.logDebug: Authenticating certificate chain: [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: PKIRealm.getAuditUserfromCert: certUID=UID=ROOTCA_adminV, EMAILADDRESS=ROOTCA_adminV@example.com, CN=ROOTCA_Admin_ValidCert, OU=Engineering, O=Example, C=US [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: PKIRealm.logDebug: UID=ROOTCA_adminV, EMAILADDRESS=ROOTCA_adminV@example.com, CN=ROOTCA_Admin_ValidCert, OU=Engineering, O=Example, C=US [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: CertUserDBAuth: started [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: CertUserDBAuth: Retrieving client certificate [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: CertUserDBAuth: Got client certificate [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: In LdapBoundConnFactory::getConn() [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: masterConn is connected: true [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: getConn: conn is connected true [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: getConn: mNumConns now 2 [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: returnConn: mNumConns now 3 [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: Authentication: client certificate found [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: In LdapBoundConnFactory::getConn() [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: masterConn is connected: true [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: getConn: conn is connected true [23/Sep/2015:12:22:11][http-bio-30042-exec-1]: getConn: mNumConns now 2 [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: returnConn: mNumConns now 3 [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: Authentication: mapped certificate to user [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: authenticated uid=ROOTCA_adminV,ou=people,dc=pki-ca [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: PKIRealm.logDebug: User ID: ROOTCA_adminV [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: SignedAuditEventFactory: create() message=[AuditEvent=AUTH_SUCCESS][SubjectID=ROOTCA_adminV][Outcome=Success][AuthMgr=certUserDBAuthMgr] authentication success [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: In LdapBoundConnFactory::getConn() [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: masterConn is connected: true [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: getConn: conn is connected true [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: getConn: mNumConns now 2 [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: returnConn: mNumConns now 3 [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: PKIRealm.logDebug: User DN: uid=ROOTCA_adminV,ou=people,dc=pki-ca [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: In LdapBoundConnFactory::getConn() [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: masterConn is connected: true [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: getConn: conn is connected true [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: getConn: mNumConns now 2 [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: returnConn: mNumConns now 3 [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: PKIRealm.logDebug: Roles: [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: PKIRealm.logDebug: Administrators [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: SessionContextInterceptor: principal: ROOTCA_adminV [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: AuthMethodInterceptor: AccountResource.login() [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: AuthMethodInterceptor: mapping: account [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: AuthMethodInterceptor: required auth methods: [passwdUserDBAuthMgr, certUserDBAuthMgr] [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: AuthMethodInterceptor: authentication manager: certUserDBAuthMgr [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: AuthMethodInterceptor: access granted [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: ACLInterceptor: AccountResource.login() [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: ACLInterceptor: principal: ROOTCA_adminV [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: ACLInterceptor: mapping: account.login [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: ACLInterceptor: ACL: certServer.ca.account,login [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: checkACLS(): ACLEntry expressions= user="anybody" [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: evaluating expressions: user="anybody" [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: evaluated expression: user="anybody" to be true [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: DirAclAuthz: authorization passed [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: ACLInterceptor: access granted [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: SignedAuditEventFactory: create() message=[AuditEvent=AUTHZ_SUCCESS][SubjectID=ROOTCA_adminV][Outcome=Success][aclResource=certServer.ca.account][Op=login][Info=AccountResource.login] authorization success [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: MessageFormatInterceptor: AccountResource.login() [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: MessageFormatInterceptor: content-type: null [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: MessageFormatInterceptor: accept: [application/xml] [23/Sep/2015:12:22:12][http-bio-30042-exec-1]: MessageFormatInterceptor: response format: application/xml [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: SessionContextInterceptor: principal: ROOTCA_adminV [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: AuthMethodInterceptor: UserResource.addUser() [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: AuthMethodInterceptor: mapping: users [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: AuthMethodInterceptor: required auth methods: [certUserDBAuthMgr] [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: AuthMethodInterceptor: authentication manager: certUserDBAuthMgr [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: AuthMethodInterceptor: access granted [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: ACLInterceptor: UserResource.addUser() [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: ACLInterceptor: principal: ROOTCA_adminV [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: ACLInterceptor: mapping: users [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: ACLInterceptor: ACL: certServer.ca.users,execute [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: checkACLS(): ACLEntry expressions= group="Administrators" [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: evaluating expressions: group="Administrators" [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: GroupAccessEvaluator: evaluate: uid=ROOTCA_adminV value="Administrators" [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: GroupAccessEvaluator: evaluate: no groups in authToken [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: In LdapBoundConnFactory::getConn() [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: masterConn is connected: true [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: getConn: conn is connected true [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: getConn: mNumConns now 2 [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: returnConn: mNumConns now 3 [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: UGSubsystem.isMemberOf() using new lookup code [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: In LdapBoundConnFactory::getConn() [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: masterConn is connected: true [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: getConn: conn is connected true [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: getConn: mNumConns now 2 [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: authorization search base: cn=Administrators,ou=groups,dc=pki-ca [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: authorization search filter: (uniquemember=uid=ROOTCA_adminV,ou=people,dc=pki-ca) [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: authorization result: true [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: returnConn: mNumConns now 3 [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: evaluated expression: group="Administrators" to be true [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: DirAclAuthz: authorization passed [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: ACLInterceptor: access granted [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: SignedAuditEventFactory: create() message=[AuditEvent=AUTHZ_SUCCESS][SubjectID=ROOTCA_adminV][Outcome=Success][aclResource=certServer.ca.users][Op=execute][Info=UserResource.addUser] authorization success [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: MessageFormatInterceptor: UserResource.addUser() [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: MessageFormatInterceptor: content-type: application/xml [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: MessageFormatInterceptor: accept: [application/xml] [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: MessageFormatInterceptor: request format: application/xml [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: MessageFormatInterceptor: response format: application/xml [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: UserService.addUser() [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: User ID:  [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: Full name: test [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: Email: null [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: Password: null [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: Phone: null [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: Type: null [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: State: null [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: TPS profiles: null [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: In LdapBoundConnFactory::getConn() [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: masterConn is connected: true [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: getConn: conn is connected true [23/Sep/2015:12:22:13][http-bio-30042-exec-2]: getConn: mNumConns now 2 [23/Sep/2015:12:22:16][http-bio-30042-exec-2]: returnConn: mNumConns now 3 [23/Sep/2015:12:22:16][http-bio-30042-exec-2]: SignedAuditEventFactory: create() message=[AuditEvent=CONFIG_ROLE][SubjectID=ROOTCA_adminV][Outcome=Success][ParamNameValPairs=Scope;;users+Operation;;OP_ADD+Resource;;;;<null>+phone;;<null>+fullname;;test+state;;<null>+userType;;<null>+email;;<null>] role configuration parameter(s) change [23/Sep/2015:12:22:16][http-bio-30042-exec-2]: In LdapBoundConnFactory::getConn() [23/Sep/2015:12:22:16][http-bio-30042-exec-2]: masterConn is connected: true [23/Sep/2015:12:22:16][http-bio-30042-exec-2]: getConn: conn is connected true [23/Sep/2015:12:22:16][http-bio-30042-exec-2]: getConn: mNumConns now 2 [23/Sep/2015:12:22:16][http-bio-30042-exec-2]: returnConn: mNumConns now 3 Expected results: User record should not be added to ldap.
I think this is the same issue as ticket #2295. The error is caused by maxHttpHeaderSize configuration in server.xml, not schema limit.
Metadata Update from @aakkiang: - Issue set to the milestone: 10.3.2
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/1409
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.
Log in to comment on this ticket.