-PPRINCIPAL, --principal-of-request=PRINCIPAL
Identifies the principal name of the service for which the certificate is being issued. This
setting is required by IPA and must always be specified.
-XNAME, --issuer=NAME
Requests that the certificate be processed by the specified certificate issuer. By default, if
this flag is not specified, and the CERTMONGER_CA_ISSUER variable is set in the environment, then
the value of the environment variable will be used. This setting is optional, and if a server
returns error 3005, indicating that it does not understand multiple profiles, the request will be
re-submitted without specifying an issuer name.
-TNAME, --profile=NAME
Requests that the certificate be processed using the specified certificate profile. By default,
if this flag is not specified, and the CERTMONGER_CA_PROFILE variable is set in the environment,
then the value of the environment variable will be used. This setting is optional, and if a
server returns error 3005, indicating that it does not understand multiple profiles, the request
will be re-submitted without specifying a profile.
-hHOSTNAME, --host=HOSTNAME
Submit the request to the IPA server running on the named host. The default is to read the
location of the host from /etc/ipa/default.conf. If no server is configured, or the configured
server cannot be reached, the client will attempt to use DNS discovery to locate LDAP servers for
the IPA domain. If servers are found, they will be searched for entries pointing to IPA masters
running the "CA" service, and the client will attempt to contact each of those in turn.
-HURL, --xmlrpc-url=URL
Submit the request to the IPA server at the specified location. The default is to read the
location of the host from /etc/ipa/default.conf. If no server is configured, or the configured
server cannot be reached, the client will attempt to use DNS discovery to locate LDAP servers for
the IPA domain. If servers are found, they will be searched for entries pointing to IPA masters
running the "CA" service, and the client will attempt to contact each of those in turn.
-LURL, --ldap-url=URL
Provide the IPA LDAP service location rather than using DNS discovery. The default is to read the
location of the host from /etc/ipa/default.conf and use DNS discovery to find the set of
_ldap._tcp.DOMAIN values and pick one for use.
-dDOMAIN, --domain=DOMAIN
Use this domain when doing DNS discovery to locate LDAP servers for the IPA installation. The
default is to read the location of the host from /etc/ipa/default.conf.
-bBASEDN, --basedn=BASEDN
Use this basedn to search for an IPA installation in LDAP. The default is to read the location of
the host from /etc/ipa/default.conf.
-cFILE, --cafile=FILE
The server's certificate was issued by the CA whose certificate is in the named file. The default
value is /etc/ipa/ca.crt.
-CPATH, --capath=DIR
Trust the server if its certificate was issued by a CA whose certificate is in a file in the named
directory. There is no default for this option, and it is not expected to be necessary.
-tKEYTAB, --keytab=KEYTAB
Authenticate to the IPA server using Kerberos with credentials derived from keys stored in the
named keytab. The default value can vary, but it is usually /etc/krb5.keytab. This option
conflicts with the -K, -u, -W, and -w options.
-kPRINCIPAL, --submitter-principal=PRINCIPAL
Authenticate to the IPA server using Kerberos with credentials derived from keys stored in the
named keytab for this principal name. The default value is the host service for the local host in
the local realm. This option conflicts with the -K, -u, -W, and -w options.
-K, --use-ccache-creds
Authenticate to the IPA server using Kerberos with credentials derived from the default credential
cache rather than a keytab. This option conflicts with the -k, -u, -W, and -w options.
-uUSERNAME, --uid=USERNAME
Authenticate to the IPA server using a user name and password, using the specified value as the
user name. This option conflicts with the -k, -K, and -t options.
-WPASSWORD, --pwd=PASSWORD
Authenticate to the IPA server using a user name and password, using the specified value as the
password. This option conflicts with the -k, -K, -t, and -w options.
-wFILE, --pwdfile=FILE
Authenticate to the IPA server using a user name and password, reading the password from the
specified file. This option conflicts with the -k, -K, -t, and -W options.