The pki-tomcat service stopped: SEVERE: Unable to start CA engine: Unable to initialize LogFile: /var/lib/pki/pki-tomcat/logs/ca/signedAudit/ca_audit (Permission denied)

Solution Verified - Updated -

Issue

The pki-tomcat service stops and can't be initialized:

● pki-tomcatd@pki-tomcat.service - PKI Tomcat Server pki-tomcat
   Loaded: loaded (/lib/systemd/system/pki-tomcatd@.service; enabled; vendor preset: disabled)
  Drop-In: /etc/systemd/system/pki-tomcatd@pki-tomcat.service.d
  Process: 3479169 ExecStartPre=/usr/bin/pkidaemon start pki-tomcat (code=exited, status=0/SUCCESS)
  Process: 3479096 ExecStartPre=/usr/sbin/pki-server migrate pki-tomcat (code=exited, status=0/SUCCESS)
  Process: 3479093 ExecStartPre=/usr/sbin/pki-server upgrade pki-tomcat (code=exited, status=0/SUCCESS)
Mar 19 09:05:43 idm-server01 systemd[1]: pki-tomcatd@pki-tomcat.service: Start-post operation timed out. Stopping.
Mar 19 09:07:13 idm-server01 systemd[1]: pki-tomcatd@pki-tomcat.service: State 'stop-sigterm' timed out. Killing.
Mar 19 09:07:13 idm-server01 systemd[1]: pki-tomcatd@pki-tomcat.service: Killing process 3479180 (java) with signal SIGKILL.
Mar 19 09:07:13 idm-server01 systemd[1]: pki-tomcatd@pki-tomcat.service: Main process exited, code=killed, status=9/KILL
Mar 19 09:07:13 idm-server01 systemd[1]: pki-tomcatd@pki-tomcat.service: Failed with result 'timeout'.
Mar 19 09:07:13 idm-server01 systemd[1]: Failed to start PKI Tomcat Server pki-tomcat.

From the /var/log/pki/pki-tomcat/ca/debug.log :

2025-03-19 08:40:16 [main] INFO: PluginRegistry: Loading plugin registry from /var/lib/pki/pki-tomcat/conf/ca/registry.cfg
2025-03-19 08:40:17 [main] SEVERE: Unable to start CA engine: Unable to initialize LogFile: /var/lib/pki/pki-tomcat/logs/ca/signedAudit/ca_audit (Permission denied)
Unable to initialize LogFile: /var/lib/pki/pki-tomcat/logs/ca/signedAudit/ca_audit (Permission denied)
        at com.netscape.cms.logging.LogFile.init(LogFile.java:327)

Environment

  • Red Hat Enterprise Linux 7
  • Red Hat Enterprise Linux 8
  • Red Hat Enterprise Linux 9
  • IPA server

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content