Re: [Freeipa-users] External CA: Peer's certificate issuer has been marked as not trusted by the user

2016-10-02 Thread Matt .
Hi, No-one has any idea here ? My Root Cert is installed OK. # certutil -d /etc/pki/pki-tomcat/alias/ -L Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI ocspSigningCert cert-pki-ca

[Freeipa-users] External CA: Peer's certificate issuer has been marked as not trusted by the user

2016-10-01 Thread Matt .
Hi guys, I have installed successfully an external CA Certificate for https/LDAP but now I get this on my ipa-commands: ipa domainlevel-get ipa: ERROR: cert validation failed for "CN=*.mysubdomain.ipa.mydomain.tld,OU=PositiveSSL Wildcard,OU=Domain Control Validated"

Re: [Freeipa-users] External CA

2013-11-08 Thread Martin Kosek
Thanks for heads up. You mean by the difference between O=MW and O=MELTWATER.COM? Petr, is this possible? Can it be validated in the the installer if this is the root cause? Martin On 11/08/2013 01:55 AM, William Leese wrote: I was able to solve this by recreating my test CA. I believe the

Re: [Freeipa-users] External CA

2013-11-08 Thread William Leese
You mean by the difference between O=MW and O=MELTWATER.COM? Yes, but again I don't know for sure. I wasn't very diligent setting up my test CA. ___ Freeipa-users mailing list Freeipa-users@redhat.com

Re: [Freeipa-users] External CA

2013-11-08 Thread Petr Viktorin
On 11/08/2013 09:01 AM, Martin Kosek wrote: Thanks for heads up. You mean by the difference between O=MW and O=MELTWATER.COM? Petr, is this possible? Can it be validated in the the installer if this is the root cause? It is possible. It's hard to tell without the logs; looks like the failure

Re: [Freeipa-users] External CA

2013-11-08 Thread John Dennis
On 11/08/2013 04:56 AM, Petr Viktorin wrote: On 11/08/2013 09:01 AM, Martin Kosek wrote: Thanks for heads up. You mean by the difference between O=MW and O=MELTWATER.COM? Petr, is this possible? Can it be validated in the the installer if this is the root cause? Thats a good question.

Re: [Freeipa-users] External CA

2013-11-07 Thread Petr Viktorin
On 11/07/2013 08:34 AM, William Leese wrote: [root@vagrant-centos-6 CA]# cat /root/server.pem Certificate: Data: Version: 3 (0x2) Serial Number: 2 (0x2) Signature Algorithm: sha1WithRSAEncryption

Re: [Freeipa-users] External CA

2013-11-07 Thread William Leese
I was able to solve this by recreating my test CA. I believe the problem was with non-matching Organisation between the CSR and CA - but I dont have the knowledge to know if this is really required. Anyhow, things work, despite not having removed the -BEGIN CERTIFICATE- lines this time

Re: [Freeipa-users] External CA

2013-11-06 Thread Petr Viktorin
On 11/06/2013 06:32 AM, William Leese wrote: Hi, Trying to install freeIPA and have it a sub-ca of an existing one. Sadly I'm not getting anywhere. The version I have installed: ipa-server-3.0.0-26.el6_4.4.x86_64 This is what I run: ipa-server-install -U -a testtest -p testtest

[Freeipa-users] External CA

2013-11-05 Thread William Leese
Hi, Trying to install freeIPA and have it a sub-ca of an existing one. Sadly I'm not getting anywhere. The version I have installed: ipa-server-3.0.0-26.el6_4.4.x86_64 This is what I run: ipa-server-install -U -a testtest -p testtest --external_cert_file=/root/server.pem

Re: [Freeipa-users] external CA install problem

2013-07-25 Thread Martin Kosek
On 07/25/2013 04:06 PM, Armstrong, Kenneth Lawrence wrote: On Fri, 2013-07-19 at 17:44 -0400, Dmitri Pal wrote: On 07/19/2013 01:11 PM, Armstrong, Kenneth Lawrence wrote: I'm trying to install an IPA server using an external CA. I ran the ipa-server-install --external-ca command, and got my

Re: [Freeipa-users] external CA install problem

2013-07-25 Thread Rob Crittenden
Armstrong, Kenneth Lawrence wrote: On Thu, 2013-07-25 at 16:22 +0200, Martin Kosek wrote: On 07/25/2013 04:06 PM, Armstrong, Kenneth Lawrence wrote: On Fri, 2013-07-19 at 17:44 -0400, Dmitri Pal wrote: On 07/19/2013 01:11 PM, Armstrong, Kenneth Lawrence wrote: I'm trying to install an IPA

Re: [Freeipa-users] external CA install problem

2013-07-25 Thread Armstrong, Kenneth Lawrence
On Thu, 2013-07-25 at 11:51 -0400, Rob Crittenden wrote: Armstrong, Kenneth Lawrence wrote: On Thu, 2013-07-25 at 16:22 +0200, Martin Kosek wrote: On 07/25/2013 04:06 PM, Armstrong, Kenneth Lawrence wrote: On Fri, 2013-07-19 at 17:44 -0400, Dmitri Pal wrote: On 07/19/2013 01:11 PM,

Re: [Freeipa-users] external CA install problem

2013-07-25 Thread Martin Kosek
On 07/25/2013 06:53 PM, Armstrong, Kenneth Lawrence wrote: On Thu, 2013-07-25 at 11:51 -0400, Rob Crittenden wrote: Armstrong, Kenneth Lawrence wrote: On Thu, 2013-07-25 at 16:22 +0200, Martin Kosek wrote: On 07/25/2013 04:06 PM, Armstrong, Kenneth Lawrence wrote: On Fri, 2013-07-19 at

Re: [Freeipa-users] --external-ca is a bit confusing.

2013-02-21 Thread Dmitri Pal
On 02/20/2013 10:20 PM, Kendrick . wrote: I am trying to get cacert to sign the csr. I have tried searching about it and cant figure out what is what. some information i have found suggests it wont be possible. when I go to get the csr signed i get The following hostnames were rejected

Re: [Freeipa-users] --external-ca is a bit confusing.

2013-02-21 Thread Kendrick .
com - *Subject*: Re: [Freeipa-users] --external-ca is a bit confusing. - *Date*: Thu, 21 Feb 2013 03:30:45 -0500 -- On 02/20/2013 10:20 PM, Kendrick . wrote: I am trying to get cacert to sign the csr. I have tried searching about it and cant figure out what

Re: [Freeipa-users] --external-ca is a bit confusing.

2013-02-21 Thread John Dennis
On 02/21/2013 07:23 PM, Kendrick . wrote: It is part of my initial setup. I copied the ipa.csr in to cacert's signing system so that the certificates would be valid outside of my local domain. and it errors because the host information said certificate authority instead of the host name if I

[Freeipa-users] --external-ca is a bit confusing.

2013-02-20 Thread Kendrick .
I am trying to get cacert to sign the csr. I have tried searching about it and cant figure out what is what. some information i have found suggests it wont be possible. when I go to get the csr signed i get The following hostnames were rejected because the system couldn't link them to your