[Freeipa-users] FreeIPA 3 w/NO CA to version 4.3 with CA?

Martin Basti mbasti at redhat.com
Thu May 26 17:08:46 UTC 2016



On 26.05.2016 17:31, Zak Wolfinger wrote:
> I’m following the instructions on how to migrate from FreeIPA version 3.0 to 4.3.  Our 3.0 implementation does NOT have CA running.  We want to enable CA Server with 4.3.
>
> Can we enable CA after the migration?  Instructions to do so?
>
> or
>
> Can we enable CA during the isa-replica-install phase?  The instructions say to use —dirsrv-cert-file —dirsrv-pin —http-cert-file —http-pin flags, but isa-replica-prepare in version 3 doesn’t seem to support —dirsrv-cert-file.
>
>
> Thanks for your help!
>
>
>
You cannot install CA together with ipa-replica-install. You have to 
install replica first and then run ipa-ca-install on the new replica.

I'm not sure but it should be possible to use this options with 
ipa-replica-install

Martin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20160526/67fcda11/attachment.htm>


More information about the Freeipa-users mailing list