[Freeipa-users] freeipa 2.1.3-9 install with external CA failed

2012-05-21 Thread TChow
Hi, I am trying to install freeipa 2.1.3-9 with external CA and it failed. Any help is appreciated and thanks in advance! [r...@ipa.dev.example.com ~]# ipa-server-install --external_cert_file=/root/ipa.crt --external_ca_file=/root/ca.crt The log file for this installation can be found in /va

Re: [Freeipa-users] freeipa 2.1.3-9 install with external CA failed

2012-05-22 Thread TChow
First of all, thanks for the help! The /tmp/tmp-aZzm2V did not get remove. I am able to run the command per your suggestion. I do see the our CA cert and IPA CA cert. The /root/ca.crt is our root (private) ca cert (is not a chain). I have tested with a browser too and it could not verify the ce

Re: [Freeipa-users] freeipa 2.1.3-9 install with external CA failed

2012-05-23 Thread TChow
This is a fresh OS and IPA install. I did not create testnick, it was from the install. # certutil -V -u C -n ipa-ca-agent -d /tmp/tmp-aZzm2V certutil: certificate is invalid: Issuer certificate is invalid. # certutil -L -n ipa-ca-agent -d /tmp/tmp-aZzm2V Certificate: Data: Version: