On 1/28/2016 2:45 PM, Endi Sukma Dewata wrote:

If you're cloning from an IPA running on RHEL/CentOS 6 with CA signed by 
another CA you are likely hitting this issue:

The bug has been fixed in this package: pki-ca-9.0.3-45. You'll need to install 
it on the master, then restart the server, then try cloning again.

The latest PKI available on RHEL/CentOS 7 is version 10.2.5, but it's patched 
with relevant bug fixes from newer versions.

If you're still having a problem, try enabling the debug log on the master and 
clone by setting the following property in CS.cfg:

See also: http://pki.fedoraproject.org/wiki/PKI_Server_Logs

Endi S. Dewata

Just a note, I believe the fix is already available on CentOS 6:

Endi S. Dewata

Manage your subscription for the Freeipa-users mailing list:
Go to http://freeipa.org for more info on the project

Reply via email to