getcert/cert-request are not working on 7.2 migrated IdM replica
Issue
- Requesting a new certificate on a RHEL-7.2 IdM server does not work
- One of the following errors are shown in
ipa-getcert listoutput:
Insufficient access: Principal 'host/foo.example.com@EXAMPLE.COM' is not permitted to use CA '.' with profile 'caIPAserviceCert' for certificate issuance.).
Certificate operation cannot be completed: FAILURE (Profile caIPAserviceCert Not Found)).
Environment
- Red Hat Enterprise Linux 7.2
- ipa-server-4.2
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.