View Issue Details

IDProjectCategoryView StatusLast Update
0011419Rocky-Linux-9ipapublic2025-12-15 15:15
ReporterJacob Brandrup Assigned To 
PrioritynormalSeveritymajorReproducibilityalways
Status newResolutionopen 
PlatformvmwareOSRocky Linux 9OS Version9.7
Summary0011419: ipa-install-ca on replica fails due to existing log directory
Descriptionipa-install-ca when trying to install on replica

This seem to be because the installation creates /var/lib/pki/pki-tomcat/logs/acme on the following step

  [7/31]: configuring certificate server instance

This causes the "deploying ACME service" to fail

  [31/31]: deploying ACME service
  [error] CalledProcessError: CalledProcessError(Command ['pki-server', 'acme-create'] returned non-zero exit status 1: 'ERROR: [Errno 17] File exists: \'/var/lib/pki/pki-tomcat/logs/acme\'\nTraceback (most recent call last):\n File "/usr/lib/python3.9/site-packages/pki/server/pkiserver.py", line 41, in <module>\n cli.execute(sys.argv[1:])\n File "/usr/lib/python3.9/site-packages/pki/server/cli/__init__.py", line 183, in execute\n module.execute(module_args)\n File "/usr/lib/python3.9/site-packages/pki/server/cli/acme.py", line 104, in execute\n subsystem.create_logs(force=force)\n File "/usr/lib/python3.9/site-packages/pki/server/subsystem.py", line 3237, in create_logs\n self.instance.makedirs(self.logs_dir, exist_ok=exist_ok, force=force)\n File "/usr/lib/python3.9/site-packages/pki/server/__init__.py", line 686, in makedirs\n pki.util.makedirs(\n File "/usr/lib/python3.9/site-packages/pki/util.py", line 118, in makedirs\n os.makedirs(path, mode=mode, exist_ok=exist_ok)\n File "/usr/lib64/python3.9/os.py", line 225, in makedirs\n mkdir(name, mode)\nFileExistsError: [Errno 17] File exists: \'/var/lib/pki/pki-tomcat/logs/acme\'\n')

[root@ipa04 ~]# uname -a
Linux ipa04.adm.ngc.dk 5.14.0-611.13.1.el9_7.x86_64 #1 SMP PREEMPT_DYNAMIC Fri Dec 12 11:55:11 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux

[root@ipa04 ~]# cat /etc/redhat-release
Rocky Linux release 9.7 (Blue Onyx)

[root@ipa04 ~]# rpm -qa | grep ipa-server
ipa-server-common-4.12.2-22.el9_7.1.noarch
ipa-server-4.12.2-22.el9_7.1.x86_64
ipa-server-dns-4.12.2-22.el9_7.1.noarch


Steps To Reproduceipa-replica-install --setup-ca
or
ipa-replica-install
ipa-install-ca

Additional InformationRemoving /var/lib/pki/pki-tomcat/logs/acme after between step 7 and 31 seems to solve the problem
TagsNo tags attached.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2025-12-15 15:15 Jacob Brandrup New Issue