Re: [Freeipa-users] Upgrade form Centos to Fedora (3.0.0 -> 3.3.3)

2014-02-05 Thread Will Sheldon
On 2/5/2014, 1:35 AM, Rob Crittenden wrote: > Will Sheldon wrote: > > > > Hello IPA users :) > > > > We have implemented IPA using the packaged version in centos 6.5 (which > > is 3.0.0-37.el6), but have been playing with the more recent version in > > Fedora 19 (3.3.3-2.fc19) and are q

Re: [Freeipa-users] Upgrade form Centos to Fedora (3.0.0 -> 3.3.3)

2014-02-05 Thread Martin Kosek
The installation part is indeed that simple, but you will also want to additionally turn the new CA to be the "master CA" so that it properly generates the CRL and renews the CA subsystem certificates when the old "master CA" is decommissioned. See [1] and [2] for more information. Martin [1]

Re: [Freeipa-users] Upgrade form Centos to Fedora (3.0.0 -> 3.3.3)

2014-02-05 Thread Bret Wortman
Rob, To add the second master-with-CA, is it as simple as doing this on one of the replicas? # ipa-ca-install /path/to/replica-info-hostname.foo.net.gpg Bret On 02/05/2014 04:35 AM, Rob Crittenden wrote: Will Sheldon wrote: Hello IPA users :) We have implemented IPA using the packaged

Re: [Freeipa-users] Upgrade form Centos to Fedora (3.0.0 -> 3.3.3)

2014-02-05 Thread Rob Crittenden
Will Sheldon wrote: Hello IPA users :) We have implemented IPA using the packaged version in centos 6.5 (which is 3.0.0-37.el6), but have been playing with the more recent version in Fedora 19 (3.3.3-2.fc19) and are quite keen to take advantage of the shiny new features, so are thinking about m