#5595 ipa-certupdate breaks Dogtag after CA-less to CA-full update
Closed: Fixed Opened by jcholast.

If ipa-certupdate is run after updating from CA-less to CA-full, it removes the CA-less CA certificate from the Dogtag NSS database, rendering Dogtag unable to connect to LDAP.

Fix ipa-certupdate to put all installed CA certificate to all relevant filesystem locations to avoid issues like this.


seen in https://bugzilla.redhat.com/show_bug.cgi?id=1256038

Linked to Bugzilla bug: https://bugzilla.redhat.com/show_bug.cgi?id=1301687 (Red Hat Enterprise Linux 7)

ipa-4-2:

  • 2314fa66fd7fe543209292660d4f7f9611cdedb2 cert renewal: import all external CA certs on IPA CA cert renewal

ipa-4-3:

  • 659c5ae7e649c1f03ac9f93c1b5369f037811d7d cert renewal: import all external CA certs on IPA CA cert renewal

Metadata Update from @jcholast:
- Issue assigned to jcholast
- Issue set to the milestone: FreeIPA 4.2.4

Metadata