New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Cannot install LetsEncryptAuthorityX3 certificate #1
Comments
|
Having this problem as well - plain IPA install on standard VM (not containers), CentOS 7, IPA 4.2.0 |
|
I'm also able to reproduce this issue. This is caused due to incorrect root cert installed and incorrect trust flags for the certificate. |
The certificates in the repo are signed by DTS Root CA X3, not ISRG Root X1. This would cause issues with unknown issuer. Install DST Root CA X3 instead of ISRG Root X1 into nssdb to resolve this. The DST Root CA X3 also has to be marked as trusted CA in order for the verification of certutil to pass. Fixes freeipa#1
|
PR #3 fixes this issue. Please note that if you previously installed |
The certificates in the repo are signed by DTS Root CA X3, not ISRG Root X1. This would cause issues with unknown issuer. Install DST Root CA X3 instead of ISRG Root X1 into nssdb to resolve this. The DST Root CA X3 also has to be marked as trusted CA in order for the verification of certutil to pass. Fixes #1
|
It worked, thank you. If anyone wants to use Then modify |
|
@tomaskrizek I had previously installed
|
|
I stumbled on this today... any clue? |
I have FreeIPA docker container based on
adelton/freeipa-server. When I run thesetup-le.shscript, I am getting SEC_ERROR_UNKNOWN_ISSUER error.According to LetsEncrypt Chain of Trust,
LetsEncryptAuthorityX3is not cross signed byISGRoot X1.So I tried installing the
(IdentTrust) DST Root CA X3. Now I am getting SEC_ERROR_UNTRUSTED_ISSUER error.The text was updated successfully, but these errors were encountered: