[IPA] Cannot sign CSRs with SAN:IP without the integrated DNS server
Issue
- I need to reissue my httpd.crt with SAN:IP so it meets our security standards.
- I can't issue certs with SAN:IP
- Attempt to issue the cert fails with:
'invalid 'csr': IP address in subjectAltName (xxx.xxx.xxx.xxx) unreachable from DNS names'
Environment
- Red Hat Enterprise Linux (RHEL) 9, 8, 7
- Red Hat Identity Management (IPA) v4 (Without integrated DNS)
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.