As <persona, e.g. admin> , I want <what?> so that <why?>.
I installed freeIPA on centos 7 with external DNS and internal CA server. It finished successfully but with a failed message about installing client components! Anyway i open a web browser and browse freeipa page. It showed and i add exception for certificate. Then login page appeared. I inserted admin user and password but it showed error. "Invalid CA renewal master. All masters must have CA server role enabled"
$ rpm -q freeipa-server 4.6.4
i attached ipaclient-install.log file becouse at the end of ipa-server-install i got the error "configuration of the client components is failed"
<img alt="ipaclient-install.log" src="/freeipa/issue/raw/files/3f59a5de9e8dd9b668b6eec82ea4289b3fe1f86d629891bb7a882574caef726c-ipaclient-install.log" />
From the reporter on freeipa-user:
My pam files had read only attribute and i changed with chattr and it fixed.
Metadata Update from @rcritten: - Issue close_status updated to: invalid - Issue status updated to: Closed (was: Open)
Login to comment on this ticket.