-
Notifications
You must be signed in to change notification settings - Fork 139
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Guidance Needed: Intermittent Unresponsiveness in Dogtag PKI Web Services in Podman Container Linked to 389ds Undefined Backend Issues #4728
Comments
It would be greatly appreciated if I could receive some assistance with this matter. In the meantime, we have made some additional findings. We have observed that the service becomes unresponsive due to the LDAP server failing to handle search queries properly. Upon examining the access logs on the LDAP server, the following warning message appears on the CA below: [CertStatusUpdateTask] WARNING: CertStatusUpdateTask: CertRecordPagedList: Error to get a new page In the LDAP server access log, we can see the following entries: [26/Apr/2024:19:11:17.634742447 +0200] conn=163 fd=157 slot=157 SSL connection from x.x.x.x to x.x.x.x The "B1 Closed Error" suggests issues with network problems or improper LDAP client operations, such as a client aborting before receiving all the results. However, it cannot be due to network problems, as spawning the PKI instance would not work, which is not the case here. Thanks in advance and Best Regards, |
Hi Joel, apologies for the delay, I am looking into this issue now |
Issue Description
We are experiencing intermittent unresponsiveness in Dogtag PKI web services affecting the Certificate Authority (CA) and Registration Authority (RA), running in a Podman container. These issues correlate with apparent crashes or non-responsive periods of the 389 Directory Server (ldap database), which these services depend on. We seek detailed guidance on troubleshooting and diagnosing the root causes of these 389ds disruptions.
Package Version and Platform:
Platform: AlmaLinux
Package and version: Dogtag PKI latest, 389-ds-base.x86_64 2.0.15-1.module_el8+14185+adb3f555
Steps to Reproduce
Since the unresponsiveness is intermittent and linked to the 389ds behavior, there are no deterministic steps to reproduce the issue. It can be typically observed:
Request for Guidance
Additional context
The text was updated successfully, but these errors were encountered: