On ma, 03 joulu 2018, 74cmonty via FreeIPA-users wrote:
This is true, the connect error is clear.

However, I don't understand why there's a connection error to the
replica-server?  Please note that command ipa-pkinit-manage enable is
executed on the replica-server, means the connection fails to itself.
And there's no instruction to open port 8443 on the server (for
whatever this port is used for).
I guess this is reincarnation of https://pagure.io/freeipa/issue/6016
(fixed in 4.3) as https://pagure.io/freeipa/issue/6878 which is fixed in
4.6.0 and above.  Installers talk to local CA directly on 8443 but
everything else should not. (See last set of comments in latter the ticket).

--
/ Alexander Bokovoy
Sr. Principal Software Engineer
Security / Identity Management Engineering
Red Hat Limited, Finland
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org

Reply via email to