[Freeipa-users] Re: CA Cert and CA Private key, or signing key.

2019-04-10 Thread Ralph Crongeyer via FreeIPA-users
That did the trick! Thanks for the info. Ralph ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct:

[Freeipa-users] Re: CA Cert and CA Private key, or signing key.

2019-04-09 Thread Ralph Crongeyer via FreeIPA-users
Hi Fraser, Sure thing. I was just pointing out that for testing we used the keys generated on the FW for testing. Now we would like to use FreeIPA as the CA for the FW's. So I am trying to figure out how best to go about this using FreeIPA. What I am trying to do is to create a sub CA cert and

[Freeipa-users] CA Cert and CA Private key, or signing key.

2019-04-08 Thread Ralph Crongeyer via FreeIPA-users
Hello List, I'm testing SSL decryption on a firewall. The self signed CA Cert and private signing key that I started testing with are generated on the firewall it self which works. So I am now trying to figure out how to generate a Sub CA with it's own private signing key to be imported to the

[Freeipa-users] CA Cert and CA Private key, or signing key.

2019-04-08 Thread Ralph Crongeyer via FreeIPA-users
Hello List, I'm testing SSL decryption on a firewall. The self signed CA Cert and private signing key that I started testing with are generated on the firewall it self which works. So I am now trying to figure out how to generate a Sub CA with it's own private signing key to be imported to the

[Freeipa-users] Re: ipa-replica-manage --force replica.server fails

2018-10-26 Thread Ralph Crongeyer via FreeIPA-users
at 5:43 PM Rob Crittenden wrote: > Ralph Crongeyer via FreeIPA-users wrote: > > So it does allow me to login, however there is a popup that says: > > "Some operations failed.", and a link "View details", when I click on > > that it shows: > > "in

[Freeipa-users] Re: ipa-replica-manage --force replica.server fails

2018-10-24 Thread Ralph Crongeyer via FreeIPA-users
https://ipaca-01.example.com/ipa/ui/js/libs/jquery.js?v=40504:6:9152 On Tue, Oct 23, 2018 at 4:07 PM Rob Crittenden wrote: > Ralph Crongeyer via FreeIPA-users wrote: > > Can this be manually removed? W currently can't login to the web portal > > due to this issue. > &

[Freeipa-users] Re: ipa-replica-manage --force replica.server fails

2018-10-23 Thread Ralph Crongeyer via FreeIPA-users
ecause of this. > > > On Thu, Oct 18, 2018 at 5:23 PM Rob Crittenden > wrote: > >> Ralph Crongeyer via FreeIPA-users wrote: >> > Hi List, >> > I have a master server that had a replica installed. The replica has >> > been uninstalled. When I try to run "i

[Freeipa-users] Re: Export CA from FreeIPA to new FreeIPA

2018-10-19 Thread Ralph Crongeyer via FreeIPA-users
Oct 18, 2018 at 10:00:20AM -0400, Ralph Crongeyer via > FreeIPA-users wrote: > > Hi Fraser, > > Actually my goal would be to have two identical stand alone servers. For > > instance maybe add a server as a replica and then separate them from each > > other, o

[Freeipa-users] Re: ipa-replica-manage --force replica.server fails

2018-10-19 Thread Ralph Crongeyer via FreeIPA-users
The goal is to remove the replica server from the master. No split brain. I need to remove this as we can't login to the portal because of this. On Thu, Oct 18, 2018 at 5:23 PM Rob Crittenden wrote: > Ralph Crongeyer via FreeIPA-users wrote: > > Hi List, > > I have a master

[Freeipa-users] ipa-replica-manage --force replica.server fails

2018-10-18 Thread Ralph Crongeyer via FreeIPA-users
Hi List, I have a master server that had a replica installed. The replica has been uninstalled. When I try to run "ipa-replica-manage del --force replica.server" it fails with: invalid 'PKINIT enabled server': all masters must have IPA master role enabled How can I delete this replica? Thanks,

[Freeipa-users] Remove a replica without DNS from a master with DNS

2018-10-18 Thread Ralph Crongeyer via FreeIPA-users
Hello List, I'm trying to remove a replica without the DNS component installed from a master with the DNS component installed. Every time I remove the replica from the master (ipa-replica-manage del replica.server.com) I can no longer log into the web UIof the replica. Additionally when I try to

[Freeipa-users] Re: Export CA from FreeIPA to new FreeIPA

2018-10-18 Thread Ralph Crongeyer via FreeIPA-users
login to the web portal. So i know I'm doing something wrong. Any advice would be helpful. Thanks, Ralph > On Tue, Oct 16, 2018 at 7:18 PM Fraser Tweedale > wrote: > >> On Tue, Oct 16, 2018 at 01:23:11PM -0400, Ralph Crongeyer via >> FreeIPA-users wrote: >> >

[Freeipa-users] Export CA from FreeIPA to new FreeIPA

2018-10-16 Thread Ralph Crongeyer via FreeIPA-users
Hello, I have a FreeIPA server that is currently running as a CA only, no clients connect, no LDAP entries have ever been made, no DNS etc... The original ipa CA is how it was setup during the initial install. A second CA was created, company.com CA, and certs have been created from this CA. I've