On ke, 13 maalis 2019, Christopher Lamb via FreeIPA-users wrote:
30;47m Thanks Rob My problem was which of the various server.xmls instances is pki-tomcat using. However I think I have worked it out: "ps -ef | grep tomcat" shows that catalina.base=/var/lib/pki/pki-tomcat. The directory /var/lib/pki/pki-tomcat/conf is a link to /etc/pki/pki-tomcat i.e the "active" server.xml (and the one I need to edit) is /etc/pki/pki-tomcat/server.xml. Thankfully, this is the instance with the explicit list for sslRangeCiphers Could you be more specific about "we don't recommend mixing packages between OS releases"? Is one of the packages I listed not the expected version? We have not knowingly fiddled around with the package versions.
You listed ipa-server 4.6.4-10 and OL 7.2. I'm pretty sure there wasn't any kind of ipa-server 4.6 in RHEL 7.2. This means you did individual package updates instead of a distribution upgrade.
However, looking at the yum history, when I last updated ipa-server in January 2019, the update aborted with "warning: %posttrans(ipa-server-4.6.4-10.0.1.el7.x86_64) scriptlet failed, signal 2", so this might account for a package not being upgraded as expected.
-- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected]
