ipa-replica-install fails with RuntimeError: CA configuration failed and error result (68); Entry already exists
Issue
A RHEL IPA replica re-install using the command ipa-replica-install may fail with the error
[5/29]: configuring certificate server instance
Failed to configure CA instance
See the installation logs and the following files/directories for more information:
/var/log/pki/pki-tomcat
[error] RuntimeError: CA configuration failed.
Your system may be partly configured.
Run /usr/sbin/ipa-server-install --uninstall to clean up.
CA configuration failed.
The ipa-replica-install command failed. See /var/log/ipareplica-install.log for more information
And this message does show the underlying error and reason.
This may happen during migration or RHEL IdM upgrade scenarios from, RHEL-7 to RHEL-8
Environment
- Red Hat Enterprise Linux 8, RHEL-8.5
- Red Hat Identity Manager (IDM)
- IPA
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.