Hi,
On Thu, May 16, 2024 at 4:42 AM Satish Patel via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote:
Folks,
I have Master freeIPA running on CentOS 7 and now trying to migrate it to RockyLinux 8.9 (because centos7 is EOL).
When I am running # ipa-replica-install --setup-ca I encounter following error
Custodia uses 'ldap-vx-010101-4.site5.example.com' as master peer.
Is the above node running the CA instance? You can check with # ipa config-show | grep CA IPA CA servers: server.ipa.test IPA CA renewal master: server.ipa.test
Then on this "master peer" machine, check that the custodia service is able to find all the keys: # /usr/libexec/ipa/ipa-custodia-check `hostname`
I would also check the redirection for ipa/keys that should be defined in /etc/httpd/conf.d/ipa.conf. You should see lines similar to the following on the "master peer": # Custodia stuff is redirected to the custodia daemon # after authentication <Location "/ipa/keys/"> ProxyPass "unix:/run/httpd/ipa-custodia.sock|http://localhost/keys/" RequestHeader set GSS_NAME %{GSS_NAME}s RequestHeader set REMOTE_USER %{REMOTE_USER}s </Location>
And check that the custodia service is running on this "master peer": # systemctl status ipa-custodia
flo
Configuring ipa-custodia
[1/4]: Generating ipa-custodia config file [2/4]: Generating ipa-custodia keys [3/4]: starting ipa-custodia [4/4]: configuring ipa-custodia to start on boot Done configuring ipa-custodia. Your system may be partly configured. Run /usr/sbin/ipa-server-install --uninstall to clean up.
502 Server Error: Proxy Error for url: https://ldap-vx-010101-4.site5.example.com/ipa/keys/ca/caSigningCert%20cert-...
I did google and found a similar issue but no solutions. Any idea what could be wrong here? I have checked and all certs are updated and not expired.
Above error isn't great to understand what is going on. I am able to use curls etc. That means cert is updated and valid. -- _______________________________________________ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahoste... Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue