On 11/11/20 8:22 AM, Thomas Boroske via FreeIPA-users wrote:
Hi Rob,

when I run

openssl x509 -text -in /var/kerberos/krb5kdc/kdc.crt

I get output containing the lines:

Certificate:
     Data:
         Version: 3 (0x2)
         Serial Number: 3 (0x3)
     Signature Algorithm: sha256WithRSAEncryption
         Issuer: O=NET.IDA, CN=ipa1.ida.ing.tu-bs.de
         Validity
             Not Before: Sep 28 09:51:09 2020 GMT
             Not After : Sep 28 09:51:09 2021 GMT
         Subject: O=NET.IDA, CN=ipa1.ida.ing.tu-bs.de
<...>

Looks ok to me.

Hi,

what are the permissions on the file /var/lib/ipa-client/pki/kdc-ca-bundle.pem ?
On a working system, I have:
# ls -l /var/lib/ipa-client/pki/kdc-ca-bundle.pem
-rw-r--r--. 1 root root 1399 Nov 10 16:56 /var/lib/ipa-client/pki/kdc-ca-bundle.pem

flo

_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org

_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org

Reply via email to