Re: [Freeipa-users] invalid cn=CACert,cn=ipa,cn=etc entry

2015-01-22 Thread Bram Vandoren
Hi Martin, On 01/14/2015 02:14 PM, Martin Kosek wrote: Good investigation! You already found the root cause. You are most possibly hitting https://bugzilla.redhat.com/show_bug.cgi?id=948928 that is fixed in ipa-3.0.0-30.el6 or later. this was indeed the problem. I converted the certificate bac

Re: [Freeipa-users] invalid cn=CACert,cn=ipa,cn=etc entry

2015-01-14 Thread Martin Kosek
On 01/13/2015 04:53 PM, Bram Vandoren wrote: > Hi All, > We run a FreeIPA server (3.0.0) on SL6. Fedora 21 clients are unable to > complete freeipa-client-install. It fails due to a parsing error of the CA > certificate. I tracked down the error and it seems our cn=CACert,cn=ipa,cn=etc > entry is i

[Freeipa-users] invalid cn=CACert,cn=ipa,cn=etc entry

2015-01-13 Thread Bram Vandoren
Hi All, We run a FreeIPA server (3.0.0) on SL6. Fedora 21 clients are unable to complete freeipa-client-install. It fails due to a parsing error of the CA certificate. I tracked down the error and it seems our cn=CACert,cn=ipa,cn=etc entry is invalid. This is the ldif: dn: cn=CACert,cn=ipa,cn