[Freeipa-users] FreeIPA 3 w/NO CA to version 4.3 with CA?
Martin Basti
mbasti at redhat.com
Thu May 26 17:08:46 UTC 2016
On 26.05.2016 17:31, Zak Wolfinger wrote:
> I’m following the instructions on how to migrate from FreeIPA version 3.0 to 4.3. Our 3.0 implementation does NOT have CA running. We want to enable CA Server with 4.3.
>
> Can we enable CA after the migration? Instructions to do so?
>
> or
>
> Can we enable CA during the isa-replica-install phase? The instructions say to use —dirsrv-cert-file —dirsrv-pin —http-cert-file —http-pin flags, but isa-replica-prepare in version 3 doesn’t seem to support —dirsrv-cert-file.
>
>
> Thanks for your help!
>
>
>
You cannot install CA together with ipa-replica-install. You have to
install replica first and then run ipa-ca-install on the new replica.
I'm not sure but it should be possible to use this options with
ipa-replica-install
Martin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20160526/67fcda11/attachment.htm>
More information about the Freeipa-users
mailing list