The pki-tomcat service stopped: SEVERE: Unable to start CA engine: Unable to initialize LogFile: /var/lib/pki/pki-tomcat/logs/ca/signedAudit/ca_audit (Permission denied)
Issue
The pki-tomcat service stops and can't be initialized:
● pki-tomcatd@pki-tomcat.service - PKI Tomcat Server pki-tomcat
Loaded: loaded (/lib/systemd/system/pki-tomcatd@.service; enabled; vendor preset: disabled)
Drop-In: /etc/systemd/system/pki-tomcatd@pki-tomcat.service.d
Process: 3479169 ExecStartPre=/usr/bin/pkidaemon start pki-tomcat (code=exited, status=0/SUCCESS)
Process: 3479096 ExecStartPre=/usr/sbin/pki-server migrate pki-tomcat (code=exited, status=0/SUCCESS)
Process: 3479093 ExecStartPre=/usr/sbin/pki-server upgrade pki-tomcat (code=exited, status=0/SUCCESS)
Mar 19 09:05:43 idm-server01 systemd[1]: pki-tomcatd@pki-tomcat.service: Start-post operation timed out. Stopping.
Mar 19 09:07:13 idm-server01 systemd[1]: pki-tomcatd@pki-tomcat.service: State 'stop-sigterm' timed out. Killing.
Mar 19 09:07:13 idm-server01 systemd[1]: pki-tomcatd@pki-tomcat.service: Killing process 3479180 (java) with signal SIGKILL.
Mar 19 09:07:13 idm-server01 systemd[1]: pki-tomcatd@pki-tomcat.service: Main process exited, code=killed, status=9/KILL
Mar 19 09:07:13 idm-server01 systemd[1]: pki-tomcatd@pki-tomcat.service: Failed with result 'timeout'.
Mar 19 09:07:13 idm-server01 systemd[1]: Failed to start PKI Tomcat Server pki-tomcat.
From the /var/log/pki/pki-tomcat/ca/debug.log :
2025-03-19 08:40:16 [main] INFO: PluginRegistry: Loading plugin registry from /var/lib/pki/pki-tomcat/conf/ca/registry.cfg
2025-03-19 08:40:17 [main] SEVERE: Unable to start CA engine: Unable to initialize LogFile: /var/lib/pki/pki-tomcat/logs/ca/signedAudit/ca_audit (Permission denied)
Unable to initialize LogFile: /var/lib/pki/pki-tomcat/logs/ca/signedAudit/ca_audit (Permission denied)
at com.netscape.cms.logging.LogFile.init(LogFile.java:327)
Environment
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- IPA server
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.