Hello all.
I'm trying to understand the use of the certificates in the communication
between an IPA client and server.
The documentation describes the retrieval of CA certificate while client
"Retrieve the CA certificate for the IdM CA"

And retrieval of SSL server certificate:
"Enable certmonger, retrieve an SSL server certificate, and install the
certificate in /etc/pki/nssdb"


>From my understanding the authentication in IPA environment is kerberos
based, therefore the client and server share a "secret" that allows the
user to authenticate himself to the server and vice versa.
Where comes the need for certificate? Some of the IPA server services are
not kerberized?

Thanks in advance.
