Thank you for your help Rob. I have changed the scripts and now I'm getting a 
other error:

The ipa-server-install command failed, exception: ScriptError: group '17' not 
found
group '17' not found
The ipa-server-install command failed. See /var/log/ipaserver-install.log for 
more information
 
Verify HSM:
input: 
pkcs11-tool --module /usr/safenet/lunaclient/lib/libCryptoki2_64.so --list-slots

output: 
Available slots:
Slot 0 (0x0): Net Token Slot
  token label        : a-hsm001-op-lipa-infra
  token manufacturer : Safenet, Inc.
  token model        : LunaSA 7.7.0
  token flags        : login required, PIN pad present, rng, token initialized, 
PIN initialized, other flags=0x20
  hardware version   : 0.0
  firmware version   : 7.7
  serial num         : 1522365206425
  pin min/max        : 7/255
Slot 1 (0x1): Net Token Slot
  token label        : b-hsm001-op-lipa-infra
  token manufacturer : Safenet, Inc.
  token model        : LunaSA 7.7.0
  token flags        : login required, PIN pad present, rng, token initialized, 
PIN initialized, other flags=0x20
  hardware version   : 0.0
  firmware version   : 7.7
  serial num         : 1522346579977
  pin min/max        : 7/255

Command to run:

input:
ipa-server-install --external-ca -r LINUX.OT.LOCAL   --random-serial-numbers   
--ds-password=XXXXXX   --admin-password=XXXXXX   
--token-name="a-hsm001-op-lipa-infra" --token-password="XXXXXX" 
--token-library-path /usr/safenet/lunaclient/lib/libCryptoki2_64.so --setup-kra 
--verbose
-- 
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to