OK, for future reference if someone finds this thread on the archives. I read this thread [1] and after debugging, I found out that I had one extra ZSK key on the directory server (explored with 389-console).
After I deleted the key that was *not* in the output of "ods-ksmutil key list --verbose" [2], the service started normally and didn't crash anymore. [1] https://pagure.io/freeipa/issue/5334 [2] http://www.freeipa.org/page/Troubleshooting#DNS_keys_are_not_generated_by_OpenDNSSEC _______________________________________________ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org