[Freeipa-users] Invalid CA chain after ca chain renewal

2021-05-27 Thread Philipp Leusmann via FreeIPA-users
Hi, I have just renewed freeipas externally signed CA certificate using 'ipa-cacert-manage renew --external-ca' Given the new CSR contains the same key elements as the previous one, I already had to ignore the duplicate while signing. Maybe that's the cause for the issues following? After rene

[Freeipa-users] python3-ipaserver installutils.py missing IPA_MODULES list

2021-05-27 Thread iulian roman via FreeIPA-users
Hello everybody, I do not know if this is the right place to mentioned, but maybe there will be someone who can redirect me to the right list or support channel. On RHEL 8.3 , the latest python3-ipaserver package (python3-ipaserver-4.9.2-3.module+el8.4.0+10412+5ecb5b37) does not contain the

[Freeipa-users] custom tls certtificate for web UI

2021-05-27 Thread iulian roman via FreeIPA-users
Hello everybody, I tried to change the WEB UI certificate with a custom certificate signed by our internal CA. The custom certificate was provided as a bundle (certificate + intermediates). The root ca which signs the intermediate was added in the truststore with ipa-cacert-manage. Everything