#5598 ipa-replica-install fails after CA-less to CA-full update
Closed: Fixed None Opened 8 years ago by jcholast.

If ipa-replica-install is run with replica file prepared on master which has been updated from CA-less to CA-full, it fails with:

...
  [16/35]: enabling referential integrity plugin
  [17/35]: configuring ssl for ds instance
  [error] RuntimeError: Could not find a CA cert in /tmp/tmpR7owOmipa/realm_info/dscert.p12

Your system may be partly configured.
Run /usr/sbin/ipa-server-install --uninstall to clean up.

Could not find a CA cert in /tmp/tmpR7owOmipa/realm_info/dscert.p12

I can't reproduce the ipa-client-install anymore, removing it from the description.

master:

  • 465ce82 replica install: validate DS and HTTP server certificates

ipa-4-3:

  • 15357ae replica install: validate DS and HTTP server certificates

ipa-4-2:

  • c2ade68 replica install: validate DS and HTTP server certificates

Metadata Update from @jcholast:
- Issue assigned to jcholast
- Issue set to the milestone: FreeIPA 4.2.4

7 years ago

Login to comment on this ticket.

Metadata