On 26.05.2016 17:31, Zak Wolfinger wrote:
I’m following the instructions on how to migrate from FreeIPA version 3.0 to
4.3. Our 3.0 implementation does NOT have CA running. We want to enable CA
Server with 4.3.
Can we enable CA after the migration? Instructions to do so?
or
Can we enable CA during the isa-replica-install phase? The instructions say to
use —dirsrv-cert-file —dirsrv-pin —http-cert-file —http-pin flags, but
isa-replica-prepare in version 3 doesn’t seem to support —dirsrv-cert-file.
Thanks for your help!
You cannot install CA together with ipa-replica-install. You have to
install replica first and then run ipa-ca-install on the new replica.
I'm not sure but it should be possible to use this options with
ipa-replica-install
Martin
--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project