Cert request fails with "Insufficient access: Insufficient 'write' privilege to the 'userCertificate' attribute of entry"
Issue
- 'Insufficient access' error when trying to issue a certificate with a service SAN:
ca-error: Server at https://ipaserver1.ipa.domain/ipa/xml denied our request, giving up: 2100 (RPC failed at server. Insufficient access: Insufficient 'write' privilege to the 'userCertificate' attribute of entry 'krbprincipalname=cert/webserver.ipa.domain@IPA.DOMAIN,cn=services,cn=accounts,dc=ipa,dc=domain'.).
Environment
- Red Hat Enterprise Linux (RHEL) 7, 8, 9
- Red Hat Identity Management (IPA) v4
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.