[Freeipa-users] Re: ipa-server-certinstall -k

2022-06-21 Thread Rob Crittenden via FreeIPA-users
Fraser Tweedale >> Sent: Sunday, June 19, 2022 11:34 PM >> To: Charles Hedrick ; Rob Crittenden via FreeIPA-users >> >> Cc: Rob Crittenden >> Subject: Re: [Freeipa-users] Re: ipa-server-certinstall -k >> >> On Wed, Jun 15, 2022 at 04:23:30PM -0400,

[Freeipa-users] Re: ipa-server-certinstall -k

2022-06-20 Thread Charles Hedrick via FreeIPA-users
will not include that either. > > Thanks, > Fraser > >> >> From: Fraser Tweedale >> Sent: Sunday, June 19, 2022 11:34 PM >> To: Charles Hedrick ; Rob Crittenden via FreeIPA-users >> >> Cc: Rob Crittenden >>

[Freeipa-users] Re: ipa-server-certinstall -k

2022-06-20 Thread Fraser Tweedale via FreeIPA-users
lue. But public CAs will not include that either. Thanks, Fraser > > From: Fraser Tweedale > Sent: Sunday, June 19, 2022 11:34 PM > To: Charles Hedrick ; Rob Crittenden via FreeIPA-users > > Cc: Rob Crittenden > Subject: Re: [Freeipa-u

[Freeipa-users] Re: ipa-server-certinstall -k

2022-06-20 Thread Charles Hedrick via FreeIPA-users
it. From: Fraser Tweedale Sent: Sunday, June 19, 2022 11:34 PM To: Charles Hedrick ; Rob Crittenden via FreeIPA-users Cc: Rob Crittenden Subject: Re: [Freeipa-users] Re: ipa-server-certinstall -k On Wed, Jun 15, 2022 at 04:23:30PM -0400, Rob Crittenden via FreeIPA-users wrote: > Char

[Freeipa-users] Re: ipa-server-certinstall -k

2022-06-19 Thread Fraser Tweedale via FreeIPA-users
On Wed, Jun 15, 2022 at 04:23:30PM -0400, Rob Crittenden via FreeIPA-users wrote: > Charles Hedrick via FreeIPA-users wrote: > > the error is > > > > The KDC certificate in cert.pem, privkey.pem is not valid: invalid for a KDC > > A PKINIT certificate needs an EKU extension, >

[Freeipa-users] Re: ipa-server-certinstall -k

2022-06-15 Thread Rob Crittenden via FreeIPA-users
Charles Hedrick via FreeIPA-users wrote: > the error is > > The KDC certificate in cert.pem, privkey.pem is not valid: invalid for a KDC A PKINIT certificate needs an EKU extension, https://datatracker.ietf.org/doc/html/rfc4556 When generating the key with OpenSSL you need to include

[Freeipa-users] Re: ipa-server-certinstall -k

2022-06-15 Thread Charles Hedrick via FreeIPA-users
the error is The KDC certificate in cert.pem, privkey.pem is not valid: invalid for a KDC From: Charles Hedrick via FreeIPA-users Sent: Wednesday, June 15, 2022 3:39 PM To: freeipa-users@lists.fedorahosted.org Cc: Charles Hedrick Subject: [Freeipa-users]