Can someone explain how can i fix this issue and the way forward in getting this working?.


Can you give us some more information on your set up? Are you using the built-in IPA CA for your SSL certificates or did you replace them at some point?

Can you confirm that ports 636 and 389 are open in the firewall on each of your IPA servers?

My bad it was indeed "iptables". Fixed them and replication is working properly.

Now i have another question regarding "referrals" does FreeIPA allow to add "referrals" for a configured for an already configured master.

I saw the "replication" itself internally does "referral"
but adding "nsslapd-referrals" URL in ldif file. But i just want to understand is that really so how it works?.



