Bug 973195
| Summary: | CA-less install fails when intermediate CA is used | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Dmitri Pal <dpal> |
| Component: | ipa | Assignee: | Martin Kosek <mkosek> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Namita Soman <nsoman> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 7.0 | CC: | arubin, jcholast, mkosek |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | ipa-4.1.0-18.el7 | Doc Type: | Known Issue |
| Doc Text: |
There are multiple problems across different tools used in the identity manager (IdM) installation, which prevents installation of CA-less with intermediate certificate authority (CA). One of the errors is that incorrect trust flags are assigned to the intermediate CA certificate when importing the PKCS#12 file. Consequently, the IdM server installer fails due to an incomplete trust chain that is returned for IdM services. There is no known workaround, CA-less certificates must not contain intermediate CA in their trust chain.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2016-02-02 11:34:10 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Dmitri Pal
2013-06-11 12:54:35 UTC
If this feature or issue should be documented in the Release or Technical Notes for RHEL 7.0 Beta, please select the correct Doc Type from the drop-down menu and enter a description in Doc Text. For info about the differences between known issues, driver updates, deprecated functionality, release notes and Technology Previews, see: https://engineering.redhat.com/docs/en-US/Policy/70.ecs/html-single/Describing_Errata_Release_and_Technical_Notes_for_Engineers/index.html#bh-known_issue If you have questions, please email rhel-notes. Filling Known Issue doc text for 7.0 Will this be fixed in the recent 7.3 fixes focused on CA-less to CA-full installation? IIRC this has been fixed since 7.1. Ah, closing as fixed then. Please reopen the bug if this happens again. |