#5359 IPA upgrade fails for server with CA cert signed by external CA
Closed: Fixed None Opened 8 years ago by jcholast.

Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 7): Bug 1270608

Please note that this Bug is private and may not be accessible as it contains confidential Red Hat customer information.

Description of problem:

Upgrading from IPA on RHEL7.0 to IPA on RHEL7.2, I see failures and dirsrv
won't start.

I see this during yum update:

773/773
2619 blocks
IPA server upgrade failed: Inspect /var/log/ipaupgrade.log and run command
ipa-server-upgrade manually.
Unexpected error - see /var/log/ipaupgrade.log for details:
CalledProcessError: Command ''/bin/systemctl' 'start'
'dirsrv@EXAMPLE-COM.service'' returned non-zero exit status 1
rhel-7.2-server/productid
| 1.6 kB  00:00:00


Version-Release number of selected component (if applicable):
From: ipa-server-3.3.3-28.el7.x86_64
To: ipa-server-4.2.0-12.el7.x86_64

How reproducible:
Unknown

Steps to Reproduce:
1.  Install IPA on rhel7.0 with external-ca signed cert
2.  Point server to RHEL7.2 repos
3.  yum update

Actual results:
fails

Expected results:


Additional info:

master:

  • 275e148 schema: do not derive ipaVaultPublicKey from ipaPublicKey

ipa-4-2:

  • e92da55 schema: do not derive ipaVaultPublicKey from ipaPublicKey

Metadata Update from @jcholast:
- Issue assigned to jcholast
- Issue set to the milestone: FreeIPA 4.2.3

7 years ago

Login to comment on this ticket.

Metadata