Hide Forgot
This bug is created as a clone of upstream ticket: https://fedorahosted.org/freeipa/ticket/6288 With a CA-less ipa server, ipa-certupdate always fails with the following error: {{{ $ ipa-certupdate trying https://vm-180.abc.idm.lab.eng.brq.redhat.com/ipa/session/json Forwarding 'ca_is_enabled' to json server 'https://vm-180.abc.idm.lab.eng.brq.redhat.com/ipa/session/json' Forwarding 'ca_find/1' to json server 'https://vm-180.abc.idm.lab.eng.brq.redhat.com/ipa/session/json' CA is not configured The ipa-certupdate command failed. }}} The code is calling ca_find but not catching the exception returned because the CA is not configured.
Fixed upstream master: https://fedorahosted.org/freeipa/changeset/b36ee723b77a2721f4200d5df02268a9bd6a60b5 ipa-4-4: https://fedorahosted.org/freeipa/changeset/1b8f6ec58600ad4bbfb538ddcff659ea1ba2c324
Still i see same error message with ipa-server-4.4.0-10.el7.x86_64. Please find the attachment for console output.
Created attachment 1199296 [details] console output
On master branch, commit 08b768313020c45bfa82d67cd214afabf605f4b3 introduced a regression and overwrote the fix (on ipa-4-4, commit 99b0db0ebf090c9f60078e9ca9bf2aba665635f5). I'm making a new fix.
Fixed upstream master: https://fedorahosted.org/freeipa/changeset/cd75eb3b2557cbd97e93be3e1ceeef21b948a694 ipa-4-4: https://fedorahosted.org/freeipa/changeset/2eeab3acf43c8f33729b48779c12aea57e453075
Verified. IPA Version: ============ [root@dhcp207-129 ~]# rpm -q ipa-server ipa-server-4.4.0-11.el7.x86_64 [root@dhcp207-129 ~]# Please find the attached console output for verification.
Created attachment 1200486 [details] console output with verification steps
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2016-2404.html