LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 12-06-2021, 01:47 PM   #1
Superspeed500
Member
 
Registered: Oct 2017
Distribution: Fedora, Ubuntu, Rocky Linux, Debian
Posts: 46

Rep: Reputation: Disabled
Question dogtag-pki: Tomcat instance crashes on Debian 11 when using certbot from other server


I have a Debian 11 server as a PKI soulution for my LAN. The server is setup with dogtag-pki with the following components:
  • CA
  • ACME Responder

The CA itself behaves nicely as far as I know. I can submit CSRs and aprove certificates. Renewal hasent been tested, since I have no need to renew any certificates as of now.

The ACME Responder however have some issues. The entire Tomcat instance running the CA and ACME Responder sometimes crashes if I from a different server runs the certbot command with http-01 validator and multiple domain names towards a webserver. The service have to be manually restarted everytime it crashes.

I have found out that the responder seems to stay stable if I use the --standalone parameter, but not all of my servers can spin up a temporary web server on port 80, since there already is a web server running on that port. I also noticed that I am usually able to use the --webroot parameter if i disable https redirect for .well-known on the web server.

The version of dogtag-pki is 10.10.2-3 on Debian 11.

Anyone knows any workarounds or if this bug should be reported somewhere?

Let me know if more info is needed, thanks in advance.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Certbot stopped working on my CentOS 6 server Red Squirrel Linux - Server 2 01-23-2021 03:49 PM
How to change the base url of ca susbsytem of dogtag pki? arhsagar Linux - Security 3 10-30-2018 11:36 AM
How to configure a CRL distribution point with Dogtag PKI arhsagar Linux - Security 2 10-28-2018 10:57 PM
LXer: Using certbot to secure your personal site LXer Syndicated Linux News 0 02-23-2017 02:01 PM
Fedora 14 Dogtag CA server Firgeis Linux - Server 6 05-06-2011 08:19 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 02:35 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration