ca-certificates 20110502+nmu1ubuntu3 (and ca-certificates-java 20110912ubuntu2): Exception in thread "main" java.security.ProviderException: Could not initialize NSS

Bug #855246 reported by Stenten on 2011-09-21
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
ca-certificates-java (Ubuntu)
High
Steve Langasek
Oneiric
High
Steve Langasek

Bug Description

The following packages will be upgraded:
  ca-certificates ca-certificates-java google-chrome-beta
3 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
Need to get 27.7 MB of archives.
After this operation, 0 B of additional disk space will be used.
Do you want to continue [Y/n]?
Get:1 http://dl.google.com/linux/chrome/deb/ stable/main google-chrome-beta i386 14.0.835.186-r101821 [27.5 MB]
Get:2 http://us.archive.ubuntu.com/ubuntu/ oneiric/main ca-certificates-java all 20110912ubuntu2 [8,070 B]
Get:3 http://us.archive.ubuntu.com/ubuntu/ oneiric/main ca-certificates i386 20110502+nmu1ubuntu3 [164 kB]
Fetched 27.7 MB in 48s (571 kB/s)
Preconfiguring packages ...
(Reading database ... 146120 files and directories currently installed.)
Preparing to replace ca-certificates-java 20110912ubuntu1 (using .../ca-certificates-java_20110912ubuntu2_all.deb) ...
Unpacking replacement ca-certificates-java ...
Preparing to replace ca-certificates 20110502+nmu1 (using .../ca-certificates_20110502+nmu1ubuntu3_i386.deb) ...
Unpacking replacement ca-certificates ...
Preparing to replace google-chrome-beta 14.0.835.163-r101024 (using .../google-chrome-beta_14.0.835.186-r101821_i386.deb) ...
Unpacking replacement google-chrome-beta ...
Processing triggers for man-db ...
Processing triggers for desktop-file-utils ...
Setting up ca-certificates (20110502+nmu1ubuntu3) ...
Clearing symlinks in /etc/ssl/certs...done.
Updating certificates in /etc/ssl/certs... WARNING: Skipping duplicate certificate cert_igca_rsa.pem
WARNING: Skipping duplicate certificate cert_igca_rsa.pem
156 added, 0 removed; done.
Running hooks in /etc/ca-certificates/update.d....
Exception in thread "main" java.security.ProviderException: Could not initialize NSS
 at sun.security.pkcs11.SunPKCS11.<init>(SunPKCS11.java:201)
 at sun.security.pkcs11.SunPKCS11.<init>(SunPKCS11.java:103)
 at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)
 at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:57)
 at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45)
 at java.lang.reflect.Constructor.newInstance(Constructor.java:532)
 at sun.security.jca.ProviderConfig$3.run(ProviderConfig.java:262)
 at sun.security.jca.ProviderConfig$3.run(ProviderConfig.java:244)
 at java.security.AccessController.doPrivileged(Native Method)
 at sun.security.jca.ProviderConfig.doLoadProvider(ProviderConfig.java:244)
 at sun.security.jca.ProviderConfig.getProvider(ProviderConfig.java:224)
 at sun.security.jca.ProviderList.getProvider(ProviderList.java:232)
 at sun.security.jca.ProviderList.getService(ProviderList.java:330)
 at sun.security.jca.GetInstance.getInstance(GetInstance.java:157)
 at java.security.Security.getImpl(Security.java:696)
 at java.security.AlgorithmParameters.getInstance(AlgorithmParameters.java:130)
 at sun.security.x509.AlgorithmId.decodeParams(AlgorithmId.java:121)
 at sun.security.x509.AlgorithmId.<init>(AlgorithmId.java:114)
 at sun.security.x509.AlgorithmId.parse(AlgorithmId.java:381)
 at sun.security.x509.X509Key.parse(X509Key.java:168)
 at sun.security.x509.CertificateX509Key.<init>(CertificateX509Key.java:75)
 at sun.security.x509.X509CertInfo.parse(X509CertInfo.java:705)
 at sun.security.x509.X509CertInfo.<init>(X509CertInfo.java:169)
 at sun.security.x509.X509CertImpl.parse(X509CertImpl.java:1747)
 at sun.security.x509.X509CertImpl.<init>(X509CertImpl.java:196)
 at sun.security.provider.X509Factory.engineGenerateCertificate(X509Factory.java:107)
 at java.security.cert.CertificateFactory.generateCertificate(CertificateFactory.java:322)
 at sun.security.provider.JavaKeyStore.engineLoad(JavaKeyStore.java:763)
 at sun.security.provider.JavaKeyStore$JKS.engineLoad(JavaKeyStore.java:55)
 at java.security.KeyStore.load(KeyStore.java:1201)
 at UpdateCertificates.createKeyStore(UpdateCertificates.java:65)
 at UpdateCertificates.main(UpdateCertificates.java:51)
Caused by: java.io.FileNotFoundException: /usr/lib/i386-linux-gnu/libnss3.so
 at sun.security.pkcs11.Secmod.initialize(Secmod.java:186)
 at sun.security.pkcs11.SunPKCS11.<init>(SunPKCS11.java:197)
 ... 31 more
E: /etc/ca-certificates/update.d/jks-keystore exited with code 1.
done.
Setting up ca-certificates-java (20110912ubuntu2) ...
Installing new version of config file /etc/ca-certificates/update.d/jks-keystore ...
Setting up google-chrome-beta (14.0.835.186-r101821) ...

Steve Langasek (vorlon) on 2011-09-21
affects: ca-certificates (Ubuntu) → ca-certificates-java (Ubuntu)
Changed in ca-certificates-java (Ubuntu):
assignee: nobody → Steve Langasek (vorlon)
importance: Undecided → High
status: New → Fix Committed
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package ca-certificates-java - 20110912ubuntu3

---------------
ca-certificates-java (20110912ubuntu3) oneiric; urgency=low

  * debian/preinst, debian/postinst: when upgrading from version
    20110912ubuntu1, disable the buggy hook script early to prevent it from
    being run before our new version is configured; and re-enable the script
    in the postinst. LP: #855246.
 -- Steve Langasek <email address hidden> Tue, 20 Sep 2011 22:04:33 -0700

Changed in ca-certificates-java (Ubuntu Oneiric):
status: Fix Committed → Fix Released
Jamie Pocas (pocas-jamie) wrote :

I was hitting this bug as well so I filed a bug report not knowing that you had already opened this one. Now I can't find my bug (maybe someone deleted it?). Anyway, on a hunch I figured that this had something to do with the NSS package. So I did the following.

$ sudo apt-get install --reinstall libnss3:i386 libnss3

Then when I reinstalled the ca-certificates packages with the following command

$ sudo apt-get install --reinstall ca-certificates ca-certificates-java

The installation succeeds with no exception thrown. So I suspect that some package dependencies are screwed up such that nss was removed during a recent upgrade, even though ca-certificates-java clearly depends on it.

To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers