<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 TRANSITIONAL//EN">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="GENERATOR" content="GtkHTML/4.6.5">
</head>
<body>
On Mon, 2013-07-22 at 17:51 +0000, Armstrong, Kenneth Lawrence wrote:<br>
<blockquote type="CITE">On Mon, 2013-07-22 at 13:41 -0400, Rob Crittenden wrote:
<blockquote type="CITE">
<pre>
Armstrong, Kenneth Lawrence wrote:
<font color="#737373">> Hi all,</font>
<font color="#737373">></font>
<font color="#737373">> I have a RHEL 6 IdM test domain set up. In production, we have RHEL 5</font>
<font color="#737373">> and RHEL 4 clients as well, so I was going to test that out.</font>
<font color="#737373">></font>
<font color="#737373">> However, I can not get a RHEL 5.9 client to join the domain.</font>
<font color="#737373">></font>
<font color="#737373">> [root@r5-idmclient <<a href="mailto:root@r5-idmclient">mailto:root@r5-idmclient</a>> ~]# ipa-client-install</font>
<font color="#737373">> --server lnxrealmtest01.liberty.edu --domain lnxrealmtest.liberty.edu</font>
<font color="#737373">> root : ERROR LDAP Error: Connect error: error:14090086:SSL</font>
<font color="#737373">> routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed</font>
<font color="#737373">> Failed to verify that lnxrealmtest01.liberty.edu is an IPA Server.</font>
<font color="#737373">> This may mean that the remote server is not up or is not reachable</font>
<font color="#737373">> due to network or firewall settings.</font>
<font color="#737373">> Installation failed. Rolling back changes.</font>
<font color="#737373">> IPA client is not configured on this system.</font>
<font color="#737373">></font>
<font color="#737373">></font>
<font color="#737373">> Digging a little bit and I see that the ipa-client is an older version:</font>
<font color="#737373">></font>
<font color="#737373">> ipa-client-2.1.3-5.el5_9.2</font>
<font color="#737373">></font>
<font color="#737373">> Doing a yum update/upgrade doesn't show a newer version.</font>
<font color="#737373">></font>
<font color="#737373">> I was considering a manual installation, but the ipa-admintools don't</font>
<font color="#737373">> appear to be available for RHEL 5.9?</font>
<font color="#737373">></font>
<font color="#737373">> Is there a way to make this work?</font>
I'd first try removing /etc/ipa/ca.crt and try the enrollment again. It
should be possible to use the 2.1.3 client in EL 5 to enroll against a
3.x server.
Otherwise we probably need more context from
/var/log/ipaclient-install.log to see how the CA was retrieved.
rob
</pre>
</blockquote>
<br>
Thanks for the tip. I tried it again, and it still failed. End of the log:<br>
<br>
[<a href="mailto:root@r5-idmclient">root@r5-idmclient</a> ~]# tail -20 /var/log/ipaclient-install.log
<br>
lnxrealmtest.liberty.edu = LNXREALMTEST.LIBERTY.EDU<br>
<br>
<br>
2013-07-22 13:45:36,982 DEBUG args=kinit <a href="mailto:admin@LNXREALMTEST.LIBERTY.EDU">
admin@LNXREALMTEST.LIBERTY.EDU</a><br>
2013-07-22 13:45:36,983 DEBUG stdout=Password for <a href="mailto:admin@LNXREALMTEST.LIBERTY.EDU">
admin@LNXREALMTEST.LIBERTY.EDU</a>: <br>
<br>
2013-07-22 13:45:36,983 DEBUG stderr=<br>
2013-07-22 13:45:36,983 DEBUG trying to retrieve CA cert via LDAP from ldap://lnxrealmtest01.liberty.edu<br>
2013-07-22 13:45:37,181 INFO Successfully retrieved CA cert<br>
Subject: /O=LNXREALMTEST.LIBERTY.EDU/CN=Certificate Authority<br>
Issuer: /DC=edu/DC=liberty/CN=LUPKI01<br>
<br>
2013-07-22 13:45:37,344 DEBUG args=/usr/sbin/ipa-join -s lnxrealmtest01.liberty.edu -b dc=lnxrealmtest,dc=liberty,dc=edu<br>
2013-07-22 13:45:37,345 DEBUG stdout=<br>
2013-07-22 13:45:37,345 DEBUG stderr=libcurl failed to execute the HTTP POST transaction. SSL certificate problem, verify that the CA cert is OK. Details:<br>
error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed<br>
<br>
2013-07-22 13:45:37,490 DEBUG args=kdestroy<br>
2013-07-22 13:45:37,491 DEBUG stdout=<br>
2013-07-22 13:45:37,491 DEBUG stderr=
<pre>
_______________________________________________
Freeipa-users mailing list
<a href="mailto:Freeipa-users@redhat.com">Freeipa-users@redhat.com</a>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users">https://www.redhat.com/mailman/listinfo/freeipa-users</a>
</pre>
</blockquote>
<br>
I just stood up a brand new RHEL 6 client, and it works just fine, so there is something amiss with RHEL 5 on this. The time on the RHEL 5 client and the RHEL 6 IdM server is the same, and the cert is valid, so I don't know why the RHEL 5 system does not like
the cert. Could it be something with the versions of packages installed on it?<br>
<br>
libipa_hbac-1.5.1-58.el5<br>
ipa-client-2.1.3-5.el5_9.2<br>
curl-7.15.5-17.el5_9<br>
openssl-0.9.8e-26.el5_9.1
</body>
</html>