[Freeipa-users] FreeIPA 3.3.* bug with external-ca?

2013-11-08 Thread Andrea Bontempi
Hi, i'm trying to install FreeIPA with external CA (again) Now i use FreeIPA 3.3.* and i found a strange error on [17/22]: requesting RA certificate from CA: 2013-11-08T11:07:38Z DEBUG File /usr/lib/python2.7/site-packages/ipaserver/install/installutils.py, line 622, in run_script

Re: [Freeipa-users] FreeIPA 3.3.* bug with external-ca?

2013-11-08 Thread Rob Crittenden
Andrea Bontempi wrote: Hi, i'm trying to install FreeIPA with external CA (again) Now i use FreeIPA 3.3.* and i found a strange error on [17/22]: requesting RA certificate from CA: 2013-11-08T11:07:38Z DEBUG File /usr/lib/python2.7/site-packages/ipaserver/install/installutils.py, line

Re: [Freeipa-users] FreeIPA 3.3.* bug with external-ca?

2013-11-08 Thread Andrea Bontempi
Here the log /var/log/pki/pki-tomcat/ca/debug [08/nov/2013:13:40:43][http-bio-8080-exec-2]: according to ccMode, authorization for servlet: caProfileSubmit is LDAP based, not XML {1}, use default authz mgr: {2}. [08/nov/2013:13:40:43][http-bio-8080-exec-2]: according to ccMode, authorization

Re: [Freeipa-users] FreeIPA 3.3.* bug with external-ca?

2013-11-08 Thread Andrea Bontempi
/usr/share/pki/ca/profiles/ca/caServerCert.cfg exist? Yes Does rpm -V pki-ca pass? No response Can openssl x509 -text -in /path/to/ca.crt show the cert ok? Certificate: Data: Version: 3 (0x2) Serial Number: 1383914316 (0x527cdb4c) Signature Algorithm:

Re: [Freeipa-users] FreeIPA 3.3.* bug with external-ca?

2013-11-08 Thread Rob Crittenden
Andrea Bontempi wrote: Here the log /var/log/pki/pki-tomcat/ca/debug [08/nov/2013:13:40:43][http-bio-8080-exec-2]: according to ccMode, authorization for servlet: caProfileSubmit is LDAP based, not XML {1}, use default authz mgr: {2}. [08/nov/2013:13:40:43][http-bio-8080-exec-2]: according to