Red Hat Bugzilla – Bug 973195
CA-less install fails when intermediate CA is used
Last modified: 2016-02-02 06:34:10 EST
This bug is created as a clone of upstream ticket: https://fedorahosted.org/freeipa/ticket/3668 This is because wrong trust flags are assigned to the intermediate CA certificate when importing the PKCS!#12 file: {{{ $ certutil -L <dbdir> Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI The Root CA CT,C,C ca1/subca/server u,u,u ca1/subca ,, }}} This in turn causes certutil to return an incomplete trust chain: {{{ $ certutil -O -d <dbdir> -n ca1/subca/server "ca1/subca/server" [CN=vm-131.idm.lab.bos.redhat.com,O=Subsidiary Example Organization] }}} Trust flags of intermediate CA certificates should be set to "c,c,c" to fix this.
If this feature or issue should be documented in the Release or Technical Notes for RHEL 7.0 Beta, please select the correct Doc Type from the drop-down menu and enter a description in Doc Text. For info about the differences between known issues, driver updates, deprecated functionality, release notes and Technology Previews, see: https://engineering.redhat.com/docs/en-US/Policy/70.ecs/html-single/Describing_Errata_Release_and_Technical_Notes_for_Engineers/index.html#bh-known_issue If you have questions, please email rhel-notes@redhat.com.
Filling Known Issue doc text for 7.0
Will this be fixed in the recent 7.3 fixes focused on CA-less to CA-full installation?
IIRC this has been fixed since 7.1.
Ah, closing as fixed then. Please reopen the bug if this happens again.