Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-54441

IPA replica installation could fail due to a large number of certificate entries.

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • rhel-8.10
    • pki-core
    • None
    • No
    • Moderate
    • rhel-idm-pki
    • ssg_idm
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • x86_64
    • None

      What were you trying to do that didn't work?

      Installation of an IPA replica is failing.

      Please provide the package NVR for which bug is seen:

      $ cat etc/redhat-release 
      Red Hat Enterprise Linux release 8.10 (Ootpa)
      $
      $ grep ^ipa ./installed-rpms 
      ipa-client-4.9.13-10.module+el8.10.0+21944+3943ad77.x86_64  Fri Jul 19 11:16:39 2024
      ipa-client-common-4.9.13-10.module+el8.10.0+21944+3943ad77.noarch Fri Jul 19 11:15:37 2024
      ipa-common-4.9.13-10.module+el8.10.0+21944+3943ad77.noarch  Fri Jul 19 11:16:10 2024
      ipa-healthcheck-0.12-3.module+el8.9.0+19634+c162f948.noarch Fri Jul 19 11:20:14 2024
      ipa-healthcheck-core-0.12-3.module+el8.9.0+19634+c162f948.noarch Fri Jul 19 11:19:45 2024
      ipa-selinux-4.9.13-10.module+el8.10.0+21944+3943ad77.noarch Fri Jul 19 11:15:38 2024
      ipa-server-4.9.13-10.module+el8.10.0+21944+3943ad77.x86_64  Fri Jul 19 11:20:14 2024
      ipa-server-common-4.9.13-10.module+el8.10.0+21944+3943ad77.noarch Fri Jul 19 11:20:13 2024
      ipa-server-dns-4.9.13-10.module+el8.10.0+21944+3943ad77.noarch Fri Jul 19 11:20:15 2024
      ipa-server-trust-ad-4.9.13-10.module+el8.10.0+21944+3943ad77.x86_64 Fri Jul 19 11:20:15 2024
      $
      
      

      How reproducible:

      Always at a customer site.

      Steps to reproduce

      1. Try to install an IPA replica using a source server that has lots of certificate entries.
      2. Reduce the number of certificate entries ( customer did purge the expired ones ).
      3. Retry the installation.

      Expected results

      Successful installation.

      Actual results

      The installation failed.

              rhcs-maint RHCS Maintenance
              rhn-support-tmihinto Têko Mihinto
              RHCS Maintenance RHCS Maintenance
              IdM CS QE IdM CS QE
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated: