Thank you Fraser - you hit the nail on the head!
I had used openssl to create my Root CA and then an Intermediate CA following
the guides at: https://jamielinux.com/docs/openssl-certificate-authority/
In that guide the extension for the intermediate is for pathlen:0 so I either
need to change
I can install freeipa with ipa-server-install and no parameters fine. However I
want to be able to use IPA as a sub-CA. I have created root and intermediate
CAs using openssl and attempt to install ipa server with:
/usr/sbin/ipa-server-install