IPA: ipa-server-certinstall command is failing with error "Peer's Certificate issuer is not recognized."
Issue
- IPA: ipa-server-certinstall command is failing with error
# ipa-server-certinstall -w -d server-cert.pem server-cert.key -vvv
.
.
ipapython.ipautil: DEBUG: Starting external process
ipapython.ipautil: DEBUG: args=/usr/bin/certutil -d dbm:/tmp/tmpkZYCAF -V -n CN=server1.example.test,O=EXAMPLE.TEST -u V -f /tmp/tmpkZYCAF/pwdfile.txt
ipapython.ipautil: DEBUG: Process finished, return code=255
ipapython.ipautil: DEBUG: stdout=certutil: certificate is invalid: Peer's Certificate issuer is not recognized.
ipapython.ipautil: DEBUG: stderr=
ipapython.admintool: DEBUG: File "/usr/lib/python2.7/site-packages/ipapython/admintool.py", line 178, in execute
return_value = self.run()
File "/usr/lib/python2.7/site-packages/ipaserver/install/ipa_server_certinstall.py", line 118, in run
self.install_dirsrv_cert()
File "/usr/lib/python2.7/site-packages/ipaserver/install/ipa_server_certinstall.py", line 144, in install_dirsrv_cert
'restart_dirsrv %s' % serverid)
File "/usr/lib/python2.7/site-packages/ipaserver/install/ipa_server_certinstall.py", line 277, in import_cert
self.check_chain(pkcs12_file.name, pin, cdb)
File "/usr/lib/python2.7/site-packages/ipaserver/install/ipa_server_certinstall.py", line 263, in check_chain
"to install the CA certificate." % str(e))
ipapython.admintool: DEBUG: The ipa-server-certinstall command failed, exception: ScriptError: Peer's certificate issuer is not trusted (certutil: certificate is invalid: Peer's Certificate issuer is not recognized.
). Please run ipa-cacert-manage install and ipa-certupdate to install the CA certificate.
ipapython.admintool: ERROR: Peer's certificate issuer is not trusted (certutil: certificate is invalid: Peer's Certificate issuer is not recognized.
). Please run ipa-cacert-manage install and ipa-certupdate to install the CA certificate.
Environment
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- IPA 4.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.