This is because the issuer check always fails in CA-less install:
$ ipa host-add host.example.com --certificate=... ipa: ERROR: Certificate operation cannot be completed: Issuer "CN=CA,O=Example Organization" does not match the expected issuer
master: ec75348
ipa-3-2: 2628a59
Metadata Update from @jcholast: - Issue assigned to jcholast - Issue set to the milestone: FreeIPA 3.2.x - 2013/06 (bug fixing)
Login to comment on this ticket.