On 12/7/17 2:53 PM, Florence Blanc-Renaud wrote:


if you run:

ipa-cacert-manage install -t C,, <rootcert>

then the new root certificate will be installed in all the required NSS 
databases. Do not forget to run ipa-certupdate on all the FreeIPA machines.

This did not work:

[root@ipa1 ~]# ipa-cacert-manage install -t C,, pki2/root-ca.crt
Installing CA certificate, please wait
Not a valid CA certificate: (SEC_ERROR_UNTRUSTED_ISSUER) Peer's certificate 
issuer has been marked as not trusted by the user. (visit 
http://www.freeipa.org/page/Troubleshooting for troubleshooting guide)
The ipa-cacert-manage command failed.

FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org

Reply via email to