The installer (and replica prepare) are using the wrong profile when generating server certs. It should use the IPA profile and it is using the caRA profile.
This means we are still issuing 6 month certs for the IPA servers.
attachment freeipa-rcrit-864-profile.patch
master: f8d0688
ipa-2-1: ef63d2d
Metadata Update from @rcritten: - Issue assigned to rcritten - Issue set to the milestone: FreeIPA 2.1.1 (bug fixing)
Login to comment on this ticket.