[Freeipa-devel] [freeipa PR#584][comment] Improve the implementation of PKINIT certificate retrieval

MartinBasti freeipa-github-notification at redhat.com
Tue Mar 14 17:35:02 UTC 2017


  URL: https://github.com/freeipa/freeipa/pull/584
Title: #584: Improve the implementation of PKINIT certificate retrieval

MartinBasti commented:
"""
Since I applied this PR, I cannot pass through failing client side installation:
```
Forwarding 'ping' to json server 'https://vm-024.abc.idm.lab.eng.brq.redhat.com/ipa/json'
Cannot connect to the server due to Kerberos error: No valid Negotiate header in server response. Trying with delegate=True
trying https://vm-024.abc.idm.lab.eng.brq.redhat.com/ipa/json
Forwarding 'ping' to json server 'https://vm-024.abc.idm.lab.eng.brq.redhat.com/ipa/json'
Second connect with delegate=True also failed: No valid Negotiate header in server response
Installation failed. As this is IPA server, changes will not be rolled back.
Cannot connect to the IPA server RPC interface: No valid Negotiate header in server response
The ipa-client-install command failed. See /var/log/ipaclient-install.log for more information
ipa.ipapython.install.cli.install_tool(CompatServerMasterInstall): ERROR    Configuration of client side components failed!
ipa.ipapython.install.cli.install_tool(CompatServerMasterInstall): ERROR    The ipa-server-install command failed. See /var/log/ipaserver-install.log for more information
```
"""

See the full comment at https://github.com/freeipa/freeipa/pull/584#issuecomment-286499793


More information about the Freeipa-devel mailing list