IPA: ipa-server-certinstall command is failing with error "Peer's Certificate issuer is not recognized."

Solution Verified - Updated -

Issue

  • IPA: ipa-server-certinstall command is failing with error
 # ipa-server-certinstall -w -d server-cert.pem server-cert.key -vvv
.
.
ipapython.ipautil: DEBUG: Starting external process
ipapython.ipautil: DEBUG: args=/usr/bin/certutil -d dbm:/tmp/tmpkZYCAF -V -n CN=server1.example.test,O=EXAMPLE.TEST -u V -f /tmp/tmpkZYCAF/pwdfile.txt
ipapython.ipautil: DEBUG: Process finished, return code=255
ipapython.ipautil: DEBUG: stdout=certutil: certificate is invalid: Peer's Certificate issuer is not recognized.

ipapython.ipautil: DEBUG: stderr=
ipapython.admintool: DEBUG:   File "/usr/lib/python2.7/site-packages/ipapython/admintool.py", line 178, in execute
    return_value = self.run()
  File "/usr/lib/python2.7/site-packages/ipaserver/install/ipa_server_certinstall.py", line 118, in run
    self.install_dirsrv_cert()
  File "/usr/lib/python2.7/site-packages/ipaserver/install/ipa_server_certinstall.py", line 144, in install_dirsrv_cert
    'restart_dirsrv %s' % serverid)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/ipa_server_certinstall.py", line 277, in import_cert
    self.check_chain(pkcs12_file.name, pin, cdb)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/ipa_server_certinstall.py", line 263, in check_chain
    "to install the CA certificate." % str(e))

ipapython.admintool: DEBUG: The ipa-server-certinstall command failed, exception: ScriptError: Peer's certificate issuer is not trusted (certutil: certificate is invalid: Peer's Certificate issuer is not recognized.
). Please run ipa-cacert-manage install and ipa-certupdate to install the CA certificate.
ipapython.admintool: ERROR: Peer's certificate issuer is not trusted (certutil: certificate is invalid: Peer's Certificate issuer is not recognized.
). Please run ipa-cacert-manage install and ipa-certupdate to install the CA certificate.

Environment

  • Red Hat Enterprise Linux 7
  • Red Hat Enterprise Linux 8
  • Red Hat Enterprise Linux 9
  • IPA 4.x

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content