[Freeipa-users] SEC_ERROR_LEGACY_DATABASE

Martin Kosek mkosek at redhat.com
Fri May 29 08:02:55 UTC 2015


On 05/29/2015 01:27 AM, David Lin wrote:
> Hi,
> When I try to add multiple hosts, on the web UI, when I go to the host tab, I get
> Certificate format error: (SEC_ERROR_LEGACY_DATABASE) The certificate/key database is in an old, unsupported format.
>
> What does this mean?

That's strange. CCIng Petr. Maybe /etc/httpd/alias NSS database was somehow 
damaged? Although I doubt that, in that case Apache would not be able to serve 
https even.

> On one of the hosts, I do notice that when i do
>
> ipa host-show
>
> there is no certificate listed.

If you are using FreeIPA 4.1+, this is expected:

https://fedorahosted.org/freeipa/ticket/4449

Martin




More information about the Freeipa-users mailing list