# ipa-server-install -p secret123 -a secret123 ... Configuring certificate server: Estimated time 6 minutes [1/17]: creating certificate server user [2/17]: creating pki-ca instance [3/17]: restarting certificate server [4/17]: configuring certificate server instance [5/17]: restarting certificate server [6/17]: creating CA agent PKCS#12 file in /root [7/17]: creating RA agent certificate database [8/17]: importing CA chain to RA certificate database Unexpected error - see ipaserver-install.log for details: Unable to retrieve CA chain: request failed with HTTP status 500
This is really bad. We need to look into this ASAP.
It is. I have prepared a VM with reproduction and Ade Lee is now investigating this issue.
Red Hat BZ:
https://bugzilla.redhat.com/show_bug.cgi?id=698796
The bug is located in pki-ca, a fix is proposed.
pki-ca
Fedora 15 BZ:
https://bugzilla.redhat.com/show_bug.cgi?id=698885
New version of pki-ca has been pushed to updates-testing. I was able to successfully install FreeIPA with pki-core-9.0.7-1.fc15.
Metadata Update from @mkosek: - Issue assigned to mkosek - Issue set to the milestone: FreeIPA 2.1 - 2011/08 (Final)
Login to comment on this ticket.