My Oracle Support Banner

Unable To Deploy Configuration Changes Via the Oracle iPlanet Web Server Admin GUI When Using Solaris Cryptographic Framework (SCF) (Doc ID 2190819.1)

Last updated on OCTOBER 19, 2016

Applies to:

Oracle iPlanet Web Server - Version 7.0 and later
Information in this document applies to any platform.

Symptoms

The Solaris Cryptographic Framework has been added to network security services (NSS) and its keystore contains private key and certificate used by the web server.

root@QAsys # ../../bin/modutil -dbdir . -nocertdb -list

# ../../bin/modutil -dbdir . -nocertdb -list

Listing of PKCS #11 Modules
-----------------------------------------------------------
1. NSS Internal PKCS #11 Module
slots: 2 slots attached
status: loaded

slot: NSS Internal Cryptographic Services
token: NSS Generic Crypto Services

slot: NSS User Private Key and Certificate Services
token: NSS Certificate DB

2. Root Certs
library name: libnssckbi.so
slots: 1 slot attached
status: loaded

slot: NSS Builtin Objects
token: Builtin Object Token

3. SCF32
library name: /usr/lib/libpkcs11.so
slots: 1 slot attached
status: loaded

slot: Sun Metaslot
token: Sun Metaslot

4. SCF64
library name: /usr/lib/amd64/libpkcs11.so
slots: There are no slots attached to this module
status: Not loaded
-----------------------------------------------------------
#

 

root@QAsys # cd /webclnodes/https-ecsweb_HU/config

root@QAsys # ../../bin/certutil -L -d . -h "Sun Metaslot"

Certificate Nickname Trust Attributes
SSL,S/MIME,JAR/XPI

Enter Password or Pin for "Sun Metaslot":

Sun Metaslot:Server-Cert-HU u,u,u

 

server.xml has:

<http-listener>
<name>http-listener-1</name>
<ip>*</ip>
<port>443</port>
<acceptor-threads>4</acceptor-threads>
<listen-queue-size>81920</listen-queue-size>
<default-virtual-server-name>QAsys</default-virtual-server-name>
<ssl>
<server-cert-nickname>Sun Metaslot:Server-Cert-HU</server-cert-nickname>
</ssl>
</http-listener>

When deploying configuration changes via the admin GUI, the following error is thrown in the browser window:

ADMIN3011: The operation failed with errors on the following nodes:
QAsys: ADMIN3606: Error while reconfiguring the server.
config (3871): CORE1259: unable to find certificate Sun Metaslot:Server-Cert-HU

The admin server's error log has:

[29/Sep/2016:13:51:59] finest (13093): for host 10.231.234.12 trying to POST /admingui/admingui/instanceConfigPullDia
log, service-j2ee reports: Delegating to system classloader at end: sun.misc.Launcher$AppClassLoader@1784911
[29/Sep/2016:13:51:59] finest (13093): for host 10.231.234.12 trying to POST /admingui/admingui/instanceConfigPullDia
log, service-j2ee reports: Loading class from system
[29/Sep/2016:13:51:59] info (13093): for host 10.231.234.12 trying to POST /admingui/admingui/instanceConfigPullDialo
g, service-j2ee reports: Exception : ADMIN3606: Error while reconfiguring the server.
config (13021): CORE1259: unable to find certificate Sun Metaslot:testcert
[29/Sep/2016:13:51:59] fine (13093): for host 10.231.234.12 trying to POST /admingui/admingui/instanceConfigPullDialo
g, service-j2ee reports:
com.sun.web.admin.exceptions.AdminException: ADMIN3606: Error while reconfiguring the server.
config (13021): CORE1259: unable to find certificate Sun Metaslot:Server-Cert-HU
at com.sun.web.admin.mbeans.AgentMBean.reconfigServer(AgentMBean.java:243)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
at java.lang.reflect.Method.invoke(Method.java:606)
at com.sun.web.admin.mbeans.BaseAdminMBean.invoke(BaseAdminMBean.java:49)
at com.sun.jmx.interceptor.DefaultMBeanServerInterceptor.invoke(DefaultMBeanServerInterceptor.java:819)
at com.sun.jmx.mbeanserver.JmxMBeanServer.invoke(JmxMBeanServer.java:801)
at com.sun.web.admin.server.LocalMBeanServerConnection.invoke(LocalMBeanServerConnection.java:136)

 

Changes

 

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Symptoms
Changes
Cause
Solution
References


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.