I'm not sure if this is a user error or a bug. I didn't see a way to
tell OpenSSL to not require that Country be in the CSR.
Check that the request matches the signature
Signature ok
The Subject's Distinguished Name is as follows
organizationName :PRINTABLE:'MYREALM.COM'
commonName
On Mon, Jan 24, 2011 at 10:38 AM, Jeff B jeffb.l...@gmail.com wrote:
You are right. I changed:
[ policy_match ]
countryName = match
stateOrProvinceName = match
organizationName = match
organizationalUnitName = optional
commonName = supplied
I'm trying to do an ipa-server-install with an --external-ca but after
it generates the .csr and I sign a .crt I can't run the followup
ips-server-install to import the certificate.
I don't think I'm supposed to run an --uninstall between the
--external-ca and the --external_cert_file
the uninstall needs to clean up the .csr or the
installer needs to not assume so much just from the existence of a
.csr
On Mon, Jan 24, 2011 at 1:55 PM, Rob Crittenden rcrit...@redhat.com wrote:
Jeff B wrote:
I'm trying to do an ipa-server-install with an --external-ca but after
it generates
I don't know if this is a real bug or if I have a mis-configuration.
Any advice is appreciated.
I'm setting up a FreeIPA evaluation and I can't get the Web ui show
much of anything. It updates the top right to show the Username of
the user that I kinitted with but nothing else other than the