[Freeipa-users] Error on "Setting up Multi-Master Replication"

Rob Crittenden rcritten at redhat.com
Wed Aug 19 20:22:45 UTC 2009


Fu-Jyh Luo wrote:
>> What version of IPA are you using and what Linux
>> distribution?
> IPA 1.2.1 and CentOS 5.3 64Bits
> 
>> Can you attach /var/log/ipareplica-install.log? You might
>> want to check that log real quick before sending to ensure
>> it doesn't have any private information you might not want
>> to disclose (IP addresses, hostnames, passwords, etc).
> See attachment.
>

Ok, there are 2 problems. The first is that an index already exists for 
some reason so creating the indices in the ldif is failing. Not a fatal 
issue really but looks like a bug.

The bigger issue is that the PKCS#12 file for the DS that it is trying 
to load either doesn't contain the CA or isn't trusting it for some 
reason. Did you provide your own PKCS#12 files for IPA or are you using 
the default, self-signed CA?

rob
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3245 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20090819/0e32358a/attachment.bin>


More information about the Freeipa-users mailing list