Bug 817142 - Manual IPA client configuration misses a step
Manual IPA client configuration misses a step
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: doc-Identity_Management_Guide (Show other bugs)
Unspecified Unspecified
medium Severity medium
: rc
: ---
Assigned To: Deon Ballard
: Documentation
Depends On:
  Show dependency treegraph
Reported: 2012-04-27 15:42 EDT by Dmitri Pal
Modified: 2013-02-28 19:33 EST (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2013-02-28 19:33:44 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Dmitri Pal 2012-04-27 15:42:11 EDT
After the manual procedure described here is completed:

ipa command still does not work. Another step that is missing is the configuration of the NSSDB.

One needs to import the CA into the host certificate store
in /etc/pki/nssdb. You can import the CA with:

certutil -A -d /etc/pki/nssdb -n 'IPA CA' -t CT,C,C -a -i /etc/ipa/ca.crt

Also, make sure and generate a host cert for the machine (also in
/etc/pki/nssdb) and have IPA sign it.

For more details see thread: https://www.redhat.com/archives/freeipa-users/2012-April/msg00159.html
Comment 5 Rob Crittenden 2012-07-05 11:15:52 EDT
I think I'd want to make sure we have a PEM version of ca.crt in /etc/ipa, so I'd change the steps to:

11 a. wget -O /etc/ipa/ca.crt http://ipa.example.com/ipa/config/ca.crt

11 b. certutil -A -d /etc/pki/nssdb -n "IPA CA" -t CT,C,C -a -i /etc/ipa/ca.crt

The user may need to start the certmonger service for step 12:

# /sbin/service start certmonger

And make sure it is running by default:

# /sbin/chkconfig certmonger on
Comment 6 John Skeoch 2012-07-05 18:01:41 EDT
Moving to assigned to address SME comments#5
Comment 8 Deon Ballard 2013-02-28 19:33:44 EST
Mass closure.

Note You need to log in before you can comment on or make changes to this bug.