[Freeipa-users] Re: How to grant CSR from command line

2019-04-12 Thread Alexander Bokovoy via FreeIPA-users
On to, 11 huhti 2019, Rob Crittenden via FreeIPA-users wrote: Alexander Bokovoy via FreeIPA-users wrote: On to, 11 huhti 2019, Rob Crittenden via FreeIPA-users wrote: Bret Wortman via FreeIPA-users wrote: Thanks, Rob. I'm a lot closer now. What I'm getting now looks like: #

[Freeipa-users] Re: How to grant CSR from command line

2019-04-11 Thread Rob Crittenden via FreeIPA-users
Alexander Bokovoy via FreeIPA-users wrote: > On to, 11 huhti 2019, Rob Crittenden via FreeIPA-users wrote: >> Bret Wortman via FreeIPA-users wrote: >>> Thanks, Rob. I'm a lot closer now. >>> >>> What I'm getting now looks like: >>> >>> # KRB5_CLIENT_KTNAME=/etc/krb5.keytab ipa cert-request --add

[Freeipa-users] Re: How to grant CSR from command line

2019-04-11 Thread Alexander Bokovoy via FreeIPA-users
On to, 11 huhti 2019, Rob Crittenden via FreeIPA-users wrote: Bret Wortman via FreeIPA-users wrote: Thanks, Rob. I'm a lot closer now. What I'm getting now looks like: # KRB5_CLIENT_KTNAME=/etc/krb5.keytab ipa cert-request --add --principal=HTTP/$HOST $DB/$HOST.csr IPA: error: tHE SERVICE

[Freeipa-users] Re: How to grant CSR from command line

2019-04-11 Thread Bret Wortman via FreeIPA-users
I should have realized that. We'll just stick with FQDNs from now on. I adjusted my wrapper and now it runs to completion and does what we expect. Thanks, Rob! Bret Wortman Founder, Damascus Products, LLC 855-644-2783 (tel:855-644-2783) | b...@wrapbuddies.co

[Freeipa-users] Re: How to grant CSR from command line

2019-04-11 Thread Rob Crittenden via FreeIPA-users
Bret Wortman via FreeIPA-users wrote: > Thanks, Rob. I'm a lot closer now. > > What I'm getting now looks like: > > # KRB5_CLIENT_KTNAME=/etc/krb5.keytab ipa cert-request --add > --principal=HTTP/$HOST $DB/$HOST.csr > IPA: error: tHE SERVICE PRINCIPAL FOR SUBJECT ALT NAME myhost in > certificate

[Freeipa-users] Re: How to grant CSR from command line

2019-04-11 Thread Bret Wortman via FreeIPA-users
Thanks, Rob. I'm a lot closer now. What I'm getting now looks like: # KRB5_CLIENT_KTNAME=/etc/krb5.keytab ipa cert-request --add --principal=HTTP/$HOST $DB/$HOST.csr IPA: error: tHE SERVICE PRINCIPAL FOR SUBJECT ALT NAME myhost in certificate request does not exist What we've done before is