22.3. CA installation error log files on an IdM replica
Installing the Certificate Authority (CA) service on an Identity Management (IdM) replica appends debugging information to several locations on the replica and the IdM server the replica communicates with.
| Location | Description |
|---|---|
|
|
High-level issues and Python traces for the |
|
|
Errors from the |
|
| Large JAVA stacktraces of activity in the core of the Public Key Infrastructure (PKI) product |
|
| Audit log of the PKI product |
| Low-level debug data of certificate operations for service principals, hosts, and other entities that use certificates |
- On the server contacted by the replica
/var/log/httpd/error_loglog fileInstalling the CA service on an existing IdM replica also writes debugging information to the following log file:
-
/var/log/ipareplica-ca-install.loglog file
If a full IdM replica installation fails while installing the optional CA component, no details about the CA are logged; a message is logged in the /var/log/ipareplica-install.log file indicating that the overall installation process failed. Review the log files listed above for details specific to the CA installation failure.
The only exception to this behavior is when you are installing the CA service and the root CA is an external CA. If there is an issue with the certificate from the external CA, errors are logged in /var/log/ipareplica-install.log.