注意:据我所知,我试图在这个问题中保持尽可能简单。任何形式的帮助表示赞赏
我是 FreeIPA 的新手,我很难从 FreeIPA 作为证书颁发机构请求 SSL 证书和密钥文件。
我使用Certificate Adminklist
的凭据验证我获得了 krbtgt 。
$ klist
Valid starting Expires Service principal
01/05/2022 5:35:35 01/06/2022 5:35:35 krbtgt/MYDOM@MYDOM
renew until 01/12/2022 5:35:35
sudo /usr/bin/ipa-getcert request -r -w -k /tmp/test.key \
-f /tmp/test.cert.pem \
-g 4096
-K HTTP/service.mydom \
-T caIPAserviceCert \
-D test.myDom -N CN=test.myDom,O=MYDOM
New signing request "20220105093346" added.
唯一被创建的是私钥:
$ ls /tmp
test.key
为什么不创建证书?权限不足。
错误:
$ sudo getcert list
Number of certificates and requests being tracked: 1.
Request ID '20220105093346':
status: CA_REJECTED
ca-error: Server at https://idm.myDom/ipa/xml denied our request, giving up: 2100 (RPC failed at server. Insufficient access: Insufficient 'write' privilege to the 'userCertificate' attribute of entry 'krbprincipalname=HTTP/service.mydom@MYDOM,cn=services,cn=accounts,dc=mydom'.).
stuck: yes
key pair storage: type=FILE,location='/tmp/test.key'
certificate: type=FILE,location='/tmp/test.cert.pem'
CA: IPA
issuer:
subject:
expires: unknown
pre-save command:
post-save command:
track: yes
auto-renew: yes
虽然我能跑
$ ipa service-mod HTTP/service.mydom --certificate=
可能重复freeipa-request-certificate-with-cname
有任何想法吗?