[Freeipa-users] Re: IPA install with custom CA fails at SSL: CERTIFICATE_VERIFY_FAILED

2019-03-11 Thread Jonny McCullagh via FreeIPA-users
Thank you Fraser - you hit the nail on the head! I had used openssl to create my Root CA and then an Intermediate CA following the guides at: https://jamielinux.com/docs/openssl-certificate-authority/ In that guide the extension for the intermediate is for pathlen:0 so I either need to change

[Freeipa-users] Re: IPA install with custom CA fails at SSL: CERTIFICATE_VERIFY_FAILED

2019-03-10 Thread Fraser Tweedale via FreeIPA-users
Hi Jonny, responses inline. On Fri, Mar 08, 2019 at 06:16:14PM -, Jonny McCullagh via FreeIPA-users wrote: > I can install freeipa with ipa-server-install and no parameters fine. However > I want to be able to use IPA as a sub-CA. I have created root and > intermediate CAs using openssl