Score:1

CA Issues With getcert certmonger on 22.04

in flag

I have a puppet script that issues 802.1x certificates for networking, this process works fine on previous versions of Ubuntu LTS. However when the same process runs on 22.04, it reports an issue verifying the signature on the server to do with the CA.

Usually, the root and ca certs are added with getcert add-scep-ca, I then run getcert list-cas which shows the ca are present.

When I run my getcert request command to get the key pair, it only managed to create the client.key. When I run getcert list, I get the following:

Number of certificates and requests being tracked: 1.
Request ID '20230214151328':
    status: CA_UNREACHABLE
    ca-error: Error: failed to verify signature on server response. error:10800075:PKCS7 routines::certificate verify error
    stuck: no
    key pair storage: type=FILE,location='/etc/ssl/private/802/client.key',pin set
    certificate: type=FILE,location='/etc/ssl/private/802/client.pem'
    signing request thumbprint (MD5): F966FE33 9776517E 9E12C712 244780FF
    signing request thumbprint (SHA1): 7D0099AE B85C6CBB E5910E2B 98A52D9A BC347A5C
    CA: lboro-ca
    issuer: 
    subject: 
    issued: unknown
    expires: unknown
    pre-save command: 
    post-save command: 
    track: yes
    auto-renew: yes

Any help to fix this would be great, I'm not quite sure what has changed between the LTS releases. Any pointer would be great. Thanks!

Score:0
pw flag

I've had a similar problem and I've found it's wrong hostname of the requesting server. You need to have FQDN in hostname command output.

jamboNum5 avatar
in flag
Thanks for the suggestion Janci, it seems to kickout an error to the syslog... `Error: failed to verify signature on server response. error:10800075:PKCS7 routines::certificate verify error`
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.