service pki-ca stop
cd /var/lib/pki-ca/conf
CS.cfg file to configure the replica's CA as a master.
ca.crl. prefix.
ca.crl. prefix from the CA CS.cfg file on the master server into the replica server's CA CS.cfg file.
600.
ca.certStatusUpdateInterval=600
ca.listenToCloneModifications=true
ca.crl.IssuingPointId.enableCRLCache=trueca.crl.IssuingPointId.enableCRLUpdates=truemaster.ca.agent.host=hostnamemaster.ca.agent.port=port number
service pki-ca start
/var/lib/ipa/ca_serialno file from the master server to the replica.
# cd /etc/dirsrv/slapd-REALM # pk12util -i /path/to/cacert.p12 -d .
PKCS#12 file is stored as /etc/dirsrv/slapd-REALM/pwdfile.txt on the original server.
# ipa-replica-manage del master.example.com