Hi folks,

I had to replace the CA chain about 3 months ago, using
ipa-cacert-manage. Question:

Does this affect freeipa's NIS support? Is there a hidden
certificate somewhere I missed to renew?

The freeipa servers are running Centos 7.3 and 7.4. 

Every helpful comment is highly appreciated
