With sub-CAs feature it is necessary to call certificate revoke with CA which issued the certificate (--cacn option).
Ticket has been cloned to Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1367865
master:
ipa-4-4:
Metadata Update from @pvomacka: - Issue assigned to pvomacka - Issue set to the milestone: FreeIPA 4.4.2
Log in to comment on this ticket.