Chris Mohler via FreeIPA-users wrote: > Sorry for the delay and multiple posts. I'm having some trouble with my > mail client. > > thanks again for all the help > > As requested Here is the output from getcert list on the CA renewal master:
So these errors are from today, when the certs are expired. Can you go back in time and get the errors from back then? They are likely to be different. To do this you need to do something like: # ipactl stop # date <some time in Dec 2018> # systemctl start dirsrv@DOMAIN-COM httpd krb5kdc pki-tomcatd@pki-tomcat (if you are running DNS add named-pkcs11 right after dirsrv # systemctl restart certmonger Then gather the data. You can return to current time now if you want as well, ipactl stop, date <now>, ipactl --ignore-service-failures start rob > > Number of certificates and requests being tracked: 9. > Request ID '20180131032610': > status: CA_UNREACHABLE > ca-error: Error 58 connecting to > https://ipa1.domain.com:8443/ca/agent/ca/profileReview: Problem with the > local SSL certificate. > stuck: no > key pair storage: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='auditSigningCert > cert-pki-ca',token='NSS Certificate DB',pin set > certificate: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='auditSigningCert > cert-pki-ca',token='NSS Certificate DB' > CA: dogtag-ipa-ca-renew-agent > issuer: CN=Certificate Authority,O=domain.com > subject: CN=CA Audit,O=domain.com > expires: 2018-12-31 13:28:03 UTC > key usage: digitalSignature,nonRepudiation > pre-save command: /usr/libexec/ipa/certmonger/stop_pkicad > post-save command: /usr/libexec/ipa/certmonger/renew_ca_cert > "auditSigningCert cert-pki-ca" > track: yes > auto-renew: yes > Request ID '20180131032614': > status: CA_UNREACHABLE > ca-error: Error 58 connecting to > https://ipa1.domain.com:8443/ca/agent/ca/profileReview: Problem with the > local SSL certificate. > stuck: no > key pair storage: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='ocspSigningCert > cert-pki-ca',token='NSS > Certificate DB',pin set > certificate: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='ocspSigningCert > cert-pki-ca',token='NSS > Certificate DB' > CA: dogtag-ipa-ca-renew-agent > issuer: CN=Certificate Authority,O=domain.com > subject: CN=OCSP Subsystem,O=domain.com > expires: 2018-12-31 13:26:43 UTC > eku: id-kp-OCSPSigning > pre-save command: /usr/libexec/ipa/certmonger/stop_pkicad > post-save command: /usr/libexec/ipa/certmonger/renew_ca_cert > "ocspSigningCert cert-pki-ca" > track: yes > auto-renew: yes > Request ID '20180131032615': > status: CA_UNREACHABLE > ca-error: Error 58 connecting to > https://ipa1.domain.com:8443/ca/agent/ca/profileReview: Problem with the > local SSL certificate. > stuck: no > key pair storage: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='subsystemCert > cert-pki-ca',token='NSS Certificate DB',pin set > certificate: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='subsystemCert > cert-pki-ca',token='NSS Certificate DB' > CA: dogtag-ipa-ca-renew-agent > issuer: CN=Certificate Authority,O=domain.com > subject: CN=CA Subsystem,O=domain.com > expires: 2018-12-31 13:26:53 UTC > key usage: > digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment > eku: id-kp-serverAuth,id-kp-clientAuth > pre-save command: /usr/libexec/ipa/certmonger/stop_pkicad > post-save command: /usr/libexec/ipa/certmonger/renew_ca_cert > "subsystemCert cert-pki-ca" > track: yes > auto-renew: yes > Request ID '20180131032616': > status: MONITORING > stuck: no > key pair storage: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='caSigningCert > cert-pki-ca',token='NSS Certificate DB',pin set > certificate: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='caSigningCert > cert-pki-ca',token='NSS Certificate DB' > CA: dogtag-ipa-ca-renew-agent > issuer: CN=Certificate Authority,O=domain.com > subject: CN=Certificate Authority,O=domain.com > expires: 2038-12-31 03:18:40 UTC > key usage: digitalSignature,nonRepudiation,keyCertSign,cRLSign > pre-save command: /usr/libexec/ipa/certmonger/stop_pkicad > post-save command: /usr/libexec/ipa/certmonger/renew_ca_cert > "caSigningCert cert-pki-ca" > track: yes > auto-renew: yes > Request ID '20180131032623': > status: CA_UNREACHABLE > ca-error: Error 58 connecting to > https://ipa1.domain.com:8443/ca/agent/ca/profileReview: Problem with the > local SSL certificate. > stuck: no > key pair storage: type=FILE,location='/var/lib/ipa/ra-agent.key' > certificate: type=FILE,location='/var/lib/ipa/ra-agent.pem' > CA: dogtag-ipa-ca-renew-agent > issuer: CN=Certificate Authority,O=domain.com > subject: CN=IPA RA,O=domain.com > expires: 2018-12-31 13:27:15 UTC > key usage: > digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment > eku: id-kp-serverAuth,id-kp-clientAuth > pre-save command: /usr/libexec/ipa/certmonger/renew_ra_cert_pre > post-save command: /usr/libexec/ipa/certmonger/renew_ra_cert > track: yes > auto-renew: yes > Request ID '20180131032624': > status: MONITORING > stuck: no > key pair storage: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='Server-Cert > cert-pki-ca',token='NSS Certificate DB',pin set > certificate: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='Server-Cert > cert-pki-ca',token='NSS Certificate DB' > CA: dogtag-ipa-ca-renew-agent > issuer: CN=Certificate Authority,O=domain.com > subject: CN=ipa1.domain.com,O=domain.com > expires: 2019-06-25 15:44:03 UTC > key usage: > digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment > eku: id-kp-serverAuth,id-kp-clientAuth,id-kp-emailProtection > pre-save command: /usr/libexec/ipa/certmonger/stop_pkicad > post-save command: /usr/libexec/ipa/certmonger/renew_ca_cert > "Server-Cert cert-pki-ca" > track: yes > auto-renew: yes > Request ID '20180131032626': > status: MONITORING > stuck: no > key pair storage: > type=NSSDB,location='/etc/dirsrv/slapd-CS-OBERLIN-EDU',nickname='Server-Cert',token='NSS > Certificate DB',pinfile='/etc/dirsrv/slapd-CS-OBERLIN-EDU/pwdfile.txt' > certificate: > type=NSSDB,location='/etc/dirsrv/slapd-CS-OBERLIN-EDU',nickname='Server-Cert',token='NSS > Certificate DB' > CA: IPA > issuer: CN=Certificate Authority,O=domain.com > subject: CN=ipa1.domain.com,O=domain.com > expires: 2019-07-06 15:22:41 UTC > key usage: > digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment > eku: id-kp-serverAuth,id-kp-clientAuth > pre-save command: > post-save command: /usr/libexec/ipa/certmonger/restart_dirsrv > CS-OBERLIN-EDU > track: yes > auto-renew: yes > Request ID '20180131032637': > status: MONITORING > stuck: no > key pair storage: > type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS > Certificate DB',pinfile='/etc/httpd/alias/pwdfile.txt' > certificate: > type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS > Certificate DB' > CA: IPA > issuer: CN=Certificate Authority,O=domain.com > subject: CN=ipa1.domain.com,O=domain.com > expires: 2019-07-06 15:22:43 UTC > key usage: > digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment > eku: id-kp-serverAuth,id-kp-clientAuth > pre-save command: > post-save command: /usr/libexec/ipa/certmonger/restart_httpd > track: yes > auto-renew: yes > Request ID '20180131032703': > status: MONITORING > stuck: no > key pair storage: > type=FILE,location='/var/kerberos/krb5kdc/kdc.key' > certificate: type=FILE,location='/var/kerberos/krb5kdc/kdc.crt' > CA: SelfSign > issuer: CN=ipa1.domain.com,O=domain.com > subject: CN=ipa1.domain.com,O=domain.com > expires: 2020-02-05 02:11:51 UTC > principal name: krbtgt/[email protected] > certificate template/profile: KDCs_PKINIT_Certs > pre-save command: > post-save command: /usr/libexec/ipa/certmonger/renew_kdc_cert > track: yes > auto-renew: yes > > > Now the output from journalctl -u certmonger: > > > -- Logs begin at Sun 2018-12-30 22:18:38 EST, end at Fri 2019-02-08 > 11:34:16 EST. -- > Dec 30 22:18:46 ipa1.domain.com systemd[1]: Starting Certificate > monitoring and PKI enrollment... > Dec 30 22:18:47 ipa1.domain.com systemd[1]: Started Certificate > monitoring and PKI enrollment. > Dec 30 22:19:06 ipa1.domain.com dogtag-ipa-ca-renew-agent-submit[4483]: > Traceback (most recent call last): > File "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit", line > 541, in <module> > sys.exit(main()) > File "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit", line > 515, in main > kinit_keytab(principal, paths.KRB5_KEYTAB, ccache_filename) > File "/usr/lib/python2.7/site-packages/ipalib/install/kinit.py", line > 47, in kinit_keytab > cred = gssapi.Credentials(name=name, store=store, usage='initiate') > File "/usr/lib64/python2.7/site-packages/gssapi/creds.py", line 64, in > __new__ > store=store) > File "/usr/lib64/python2.7/site-packages/gssapi/creds.py", line 148, in > acquire > usage) > File "ext_cred_store.pyx", line 182, in > gssapi.raw.ext_cred_store.acquire_cred_from (gssapi/raw/ext_cred_store.c > GSSError: Major (851968): Unspecified GSS failure. Minor code may > provide more information, Minor (2529639068): C > Dec 30 22:19:06 ipa1.domain.com dogtag-ipa-ca-renew-agent-submit[4496]: > Traceback (most recent call last): > File "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit", line > 541, in <module> > sys.exit(main()) > File "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit", line > 515, in main > kinit_keytab(principal, paths.KRB5_KEYTAB, ccache_filename) > File "/usr/lib/python2.7/site-packages/ipalib/install/kinit.py", line > 47, in kinit_keytab > cred = gssapi.Credentials(name=name, store=store, usage='initiate') > File "/usr/lib64/python2.7/site-packages/gssapi/creds.py", line 64, in > __new__ > store=store) > File "/usr/lib64/python2.7/site-packages/gssapi/creds.py", line 148, in > acquire > usage) > File "ext_cred_store.pyx", line 182, in > gssapi.raw.ext_cred_store.acquire_cred_from (gssapi/raw/ext_cred_store.c > GSSError: Major (851968): Unspecified GSS failure. Minor code may > provide more information, Minor (2529639068): C > Dec 30 22:19:06 ipa1.domain.com dogtag-ipa-ca-renew-agent-submit[4473]: > Traceback (most recent call last): > File "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit", line > 541, in <module> > sys.exit(main()) > File "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit", line > 515, in main > kinit_keytab(principal, paths.KRB5_KEYTAB, ccache_filename) > File "/usr/lib/python2.7/site-packages/ipalib/install/kinit.py", line > 47, in kinit_keytab > cred = gssapi.Credentials(name=name, store=store, usage='initiate') > File "/usr/lib64/python2.7/site-packages/gssapi/creds.py", line 64, in > __new__ > store=store) > File "/usr/lib64/python2.7/site-packages/gssapi/creds.py", line 148, in > acquire > usage) > File "ext_cred_store.pyx", line 182, in > gssapi.raw.ext_cred_store.acquire_cred_from (gssapi/raw/ext_cred_store.c > GSSError: Major (851968): Unspecified GSS failure. Minor code may > provide more information, Minor (2529639068): C > Dec 30 22:19:06 ipa1.domain.com certmonger[3631]: 2018-12-30 22:19:06 > [3631] Internal error > Dec 30 22:19:06 ipa1.domain.com certmonger[3631]: 2018-12-30 22:19:06 > [3631] Internal error > Dec 30 22:19:06 ipa1.domain.com dogtag-ipa-ca-renew-agent-submit[4460]: > Traceback (most recent call last): > File "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit", line > 541, in <module> > sys.exit(main()) > File "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit", line > 515, in main > kinit_keytab(principal, paths.KRB5_KEYTAB, ccache_filename) > File "/usr/lib/python2.7/site-packages/ipalib/install/kinit.py", line > 47, in kinit_keytab > cred = gssapi.Credentials(name=name, store=store, usage='initiate') > File "/usr/lib64/python2.7/site-packages/gssapi/creds.py", line 64, in > __new__ > store=store) > File "/usr/lib64/python2.7/site-packages/gssapi/creds.py", line 148, in > acquire > usage) > File "ext_cred_store.pyx", line 182, in > gssapi.raw.ext_cred_store.acquire_cred_from (gssapi/raw/ext_cred_store.c > GSSError: Major (851968): Unspecified GSS failure. Minor code may > provide more information, Minor (2529639068): C > Dec 30 22:19:06 ipa1.domain.com certmonger[3631]: 2018-12-30 22:19:06 > [3631] Internal error > Dec 30 22:19:06 ipa1.domain.com certmonger[3631]: 2018-12-30 22:19:06 > [3631] Internal error > Feb 05 02:50:09 ipa1.domain.com ipa-submit[16915]: GSSAPI client step 1 > > > Lastly a few lines from /var/log/messages: > > Feb 8 11:24:16 ipa1 dogtag-ipa-ca-renew-agent-submit: Forwarding > request to dogtag-ipa-renew-agent > Feb 8 11:24:16 ipa1 dogtag-ipa-ca-renew-agent-submit: > dogtag-ipa-renew-agent returned 3 > Feb 8 11:24:16 ipa1 certmonger: 2019-02-08 11:24:16 [3631] Error 58 > connecting to https://ipa1.domain.com:8443/ca/agent/ca/profileReview: > Problem with the local SSL certificate. > Feb 8 11:24:20 ipa1 dogtag-ipa-ca-renew-agent-submit: Forwarding > request to dogtag-ipa-renew-agent > Feb 8 11:24:20 ipa1 dogtag-ipa-ca-renew-agent-submit: > dogtag-ipa-renew-agent returned 3 > Feb 8 11:24:21 ipa1 certmonger: 2019-02-08 11:24:21 [3631] Error 58 > connecting to https://ipa1.domain.com:8443/ca/agent/ca/profileReview: > Problem with the local SSL certificate. > Feb 8 11:24:24 ipa1 dogtag-ipa-ca-renew-agent-submit: Forwarding > request to dogtag-ipa-renew-agent > Feb 8 11:24:25 ipa1 dogtag-ipa-ca-renew-agent-submit: > dogtag-ipa-renew-agent returned 3 > Feb 8 11:24:25 ipa1 certmonger: 2019-02-08 11:24:25 [3631] Error 58 > connecting to https://ipa1.domain.com:8443/ca/agent/ca/profileReview: > Problem with the local SSL certificate. > Feb 8 11:24:31 ipa1 dogtag-ipa-ca-renew-agent-submit: Forwarding > request to dogtag-ipa-renew-agent > Feb 8 11:24:31 ipa1 dogtag-ipa-ca-renew-agent-submit: > dogtag-ipa-renew-agent returned 3 > Feb 8 11:24:31 ipa1 certmonger: 2019-02-08 11:24:31 [3631] Error 58 > connecting to https://ipa1.domain.com:8443/ca/agent/ca/profileReview: > Problem with the local SSL certificate. > Feb 8 11:25:34 ipa1 ns-slapd: [08/Feb/2019:11:25:34.227979399 -0500] - > ERR - slapi_ldap_bind - Error: could not send startTLS request: error -1 > (Can't contact LDAP server) errno 107 (Transport endpoint is not connected) > > _______________________________________________ > FreeIPA-users mailing list -- [email protected] > To unsubscribe send an email to [email protected] > Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedorahosted.org/archives/list/[email protected] > _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected]
