Red Hat Bugzilla – Bug 1358457
ipa installer SecurityWarning certificate has no subjectAltName
Last modified: 2018-10-15 07:23:22 EDT
Description of problem: When Installing a second KRA on an IPA Replica, I see this warning: /usr/lib/python2.7/site-packages/urllib3/connection.py:251: SecurityWarning: Certificate has no `subjectAltName`, falling back to check for a `commonName` for now. This feature is being removed by major browsers and deprecated by RFC 2818. (See https://github.com/shazow/urllib3/issues/497 for details.) SecurityWarning Version-Release number of selected component (if applicable): ipa-server-4.4.0-2.1.el7.x86_64 python-urllib3-1.10.2-2.el7_1.noarch How reproducible: unknown Steps to Reproduce: on Master: 1. ipa-server-install 2. ipa-kra-install on Replica: 3. ipa-replica-install 4. ipa-ca-install 5. ipa-kra-install Actual results: appears to work but, throws above warning Expected results: No warning was expected so I'm raising this here. Additional info: If this is a non-issue, we may still want to document this as expected behavior in release notes.
FYI, I saw the same on ipa-ca-install and ipa-replica-install. I missed that before but, looking back through an install, I do see it in both places as well.
Upstream ticket: https://fedorahosted.org/freeipa/ticket/4970
This issue was fixed with the fix for https://bugzilla.redhat.com/show_bug.cgi?id=1562423 SAN in internal SSL server certificate in pkispawn configuration step The fix was done on 7.6 and backported to 7.5 z-stream. Closing as CURRENTRELEASE.