#5598 ipa-replica-install fails after CA-less to CA-full update
Closed: Fixed Opened by jcholast.

If ipa-replica-install is run with replica file prepared on master which has been updated from CA-less to CA-full, it fails with:

...
  [16/35]: enabling referential integrity plugin
  [17/35]: configuring ssl for ds instance
  [error] RuntimeError: Could not find a CA cert in /tmp/tmpR7owOmipa/realm_info/dscert.p12
Your system may be partly configured.
Run /usr/sbin/ipa-server-install --uninstall to clean up.
Could not find a CA cert in /tmp/tmpR7owOmipa/realm_info/dscert.p12

I can't reproduce the ipa-client-install anymore, removing it from the description.

seen in https://bugzilla.redhat.com/show_bug.cgi?id=1256038

Linked to Bugzilla bug: https://bugzilla.redhat.com/show_bug.cgi?id=1301687 (Red Hat Enterprise Linux 7)

master:

  • 465ce82a4d098c4c419913f30a1a028afc7ae445 replica install: validate DS and HTTP server certificates

ipa-4-3:

  • 15357aea39eb9e496439e4ef711b97616ef7ee9a replica install: validate DS and HTTP server certificates

ipa-4-2:

  • c2ade68df88e440cd969bede298f0c1feae59fcc replica install: validate DS and HTTP server certificates

Metadata Update from @jcholast:
- Issue assigned to jcholast
- Issue set to the milestone: FreeIPA 4.2.4

Metadata