[Freeipa-users] Re: How to get certificate containing full chain

2020-05-14 Thread Ian Pilcher via FreeIPA-users
On 5/8/20 4:00 PM, Leusmann, Philipp via FreeIPA-users wrote: Thanks for testing, here the same thing doesn’t work. I am using certmonger-0.78.4-12.el7.x86_64 on CentOS 7 post-save command is shown in the list of monitored certificates. Invoking manually works properly. Any further idea on

[Freeipa-users] Re: How to get certificate containing full chain

2020-05-12 Thread Rob Crittenden via FreeIPA-users
Leusmann, Philipp wrote: > rob, > > I finally found out what’s wrong: The local files for crt and key already > existed during my tests. Obviously they are not being overwritten when > stopping monitoring an old request for the certificate and requesting a new > one. > In result the

[Freeipa-users] Re: How to get certificate containing full chain

2020-05-11 Thread Leusmann, Philipp via FreeIPA-users
rob, I finally found out what’s wrong: The local files for crt and key already existed during my tests. Obviously they are not being overwritten when stopping monitoring an old request for the certificate and requesting a new one. In result the post-save-command is not triggered. When I delete

[Freeipa-users] Re: How to get certificate containing full chain

2020-05-11 Thread Rob Crittenden via FreeIPA-users
Leusmann, Philipp via FreeIPA-users wrote: > rob > > > CONET Solutions GmbH, Theodor-Heuss-Allee 19, 53773 Hennef. > Geschäftsführer/Managing Director: Dirk Lieder > > Registergericht/Registration Court: Amtsgericht Siegburg (HRB Nr. 9136) > >  

[Freeipa-users] Re: How to get certificate containing full chain

2020-05-09 Thread Leusmann, Philipp via FreeIPA-users
rob CONET Solutions GmbH, Theodor-Heuss-Allee 19, 53773 Hennef. Geschäftsführer/Managing Director: Dirk Lieder Registergericht/Registration Court: Amtsgericht Siegburg (HRB Nr. 9136) Datenschutzhinweise:

[Freeipa-users] Re: How to get certificate containing full chain

2020-05-08 Thread Rob Crittenden via FreeIPA-users
Leusmann, Philipp wrote: > > > CONET Solutions GmbH, Theodor-Heuss-Allee 19, 53773 Hennef. > Geschäftsführer/Managing Director: Dirk Lieder > > Registergericht/Registration Court: Amtsgericht Siegburg (HRB Nr. 9136) > >   > >   > >

[Freeipa-users] Re: How to get certificate containing full chain

2020-05-08 Thread Leusmann, Philipp via FreeIPA-users
CONET Solutions GmbH, Theodor-Heuss-Allee 19, 53773 Hennef. Geschäftsführer/Managing Director: Dirk Lieder Registergericht/Registration Court: Amtsgericht Siegburg (HRB Nr. 9136) Datenschutzhinweise:

[Freeipa-users] Re: How to get certificate containing full chain

2020-05-08 Thread Rob Crittenden via FreeIPA-users
Leusmann, Philipp via FreeIPA-users wrote: > Rob, > >> What command? The command should be a script or simple command. No pipes >> or redirects. > > I issue ipa-getcert request -I artifactory2 -f server.crt -k fullchain.key -C > 'cat server.crt /etc/ipa/ca.crt > fullchain.crt‘ > I also tried

[Freeipa-users] Re: How to get certificate containing full chain

2020-05-08 Thread Leusmann, Philipp via FreeIPA-users
Rob, > What command? The command should be a script or simple command. No pipes > or redirects. I issue ipa-getcert request -I artifactory2 -f server.crt -k fullchain.key -C 'cat server.crt /etc/ipa/ca.crt > fullchain.crt‘ I also tried calling a bash-script instead of the -C argument. Doesn’t

[Freeipa-users] Re: How to get certificate containing full chain

2020-05-08 Thread Rob Crittenden via FreeIPA-users
Philipp Leusmann via FreeIPA-users wrote: > Hi, > > I need to receive a certificate containing the full CA chain. > Since ipa-getcert doesn't seem to offer a prebuilt option to do so (or does > it?), I was looking at the post-save-command of ipa-getcert to merge the > received certificate and