[Freeipa-users] Re: Chrome 58 Doesn't Trust SSL Certificates Signed by FreeIPA

2017-07-22 Thread Prasun Gera via FreeIPA-users
I tried to replicate every one of those on the replica, but I've hit a snag. The following CA only exists on the master, but not on the replica: CA 'dogtag-ipa-ca-renew-agent': is-default: no ca-type: EXTERNAL helper-location: /usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit I didn't

[Freeipa-users] Re: diskless workstations in an IPA domain

2017-07-22 Thread Lukas Slebodnik via FreeIPA-users
On (21/07/17 17:20), Jacquelin Charbonnel via FreeIPA-users wrote: >Hi everybody, > > At now, I enroll diskless Fedora26 workstations (with stateless Linux) > into >my IPA domain. > Inside the readonly root image, /etc/sysconfig/selinux points : > >SELINUX=disabled

[Freeipa-users] Fwd: Error during getcert request

2017-07-22 Thread John Obaterspok via FreeIPA-users
Hi, I need to create a new certificate for my Asus router. The router is not part of freeipa domain so I need to manually update the certificate when it expires. getcert request -k /etc/pki/router_private -f /etc/pki/router_cert -D router.my.lan -N "cn=router.my.lan" -K http/router.my.lan -c IPA