This might have been fixed on the main branch (PKI 11.0): * https://github.com/dogtagpki/pki/commit/c2f88ba3d40bf1a03548ad6d5c70794c532db473 So we just need to cherry-pick it to v10.11 branch.
Chandan, does this scenario work without HSM? If it does we probably can move this ticket to RHCS instead of RHEL since IPA does not use HSM.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Red Hat Certificate System 10.3 General Availability), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHEA-2022:0398
Issue migration from Bugzilla to Jira is in process at this time. This will be the last message in Jira copied from the Bugzilla bug.