On 02/02/2016 02:18 AM, Robert van Veelen wrote:
> Hi,
> I'm trying to create an ipa replica from
> ipa-server-3.0.0-47/pki-ca-9.0.3-45 to ipa-server-4.2.0-15/pki-ca-10.2.5-6
> and cannot get the install to complete. The CS is configured as a sub to an
> external CA. I keep getting the same error when running the
> replica-install. Digging into pki-ca's debug log, I find the following
> errors:
> 
>  java.lang.Exception: SystemCertsVerification: system certs verification
> failure
> &
>  CertUtils: verifySystemCertByNickname() failed: caSigningCert cert-pki-ca
> 
> I've tried regenerating the source cacert.p12, upgrading pki-ca to latest,
> etc. It just seems like the new replica is unable to verify the certs while
> running selftests. any good tips for a next step to work out whats going on?
> 
> Thanks,
> 
> -rob

Can this be the same problem as answered by Endi here:
https://www.redhat.com/archives/freeipa-users/2016-January/msg00564.html
?

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Reply via email to