Re: [Freeipa-users] IPA replica without CA, how to become CA

2015-07-07 Thread Matt .
Hi Rob, OK, I had difficulties with that and try it. What I actually did is: Turned off IPA1 (to act it like a dead one) and removed it from ipa2. Now when I install a new replica with ipa2 as it's master/source I get complains there is no CA. So my ipa2 needs to become ca in some way. I need

Re: [Freeipa-users] IPA replica without CA, how to become CA

2015-07-06 Thread Matt .
Rob, Isn't it impossible to install a CA on a replica when it's master died ? I know there is normally one CA, but this is kinda confusing me so I'm testing out scenarios. Thanks, Matt 2015-07-06 18:10 GMT+02:00 Matt . yamakasi@gmail.com: Hi Rob, OK, I had difficulties with that and

Re: [Freeipa-users] IPA replica without CA, how to become CA

2015-07-06 Thread Matt .
Small update on this. The replica without CA is not going to find any CA as the master is dead so we need a CA. The question is how to approach, you have a replica with only ldap information and no CA. Is it possible to create a split-brain like, install IPA1 as a normal ipa server, so it

Re: [Freeipa-users] IPA replica without CA, how to become CA

2015-07-06 Thread Rob Crittenden
Matt . wrote: Hi All, I'm cleaning up and playing around with some old dev setups and reviewing these tests. This is a replica setup but the replica is no CA. Now I'm testing out how to manage cluster when I remove the ipa1 (CA) and create a new replica with CA from the ipa2. IPA2 should