On ke, 13 maalis 2019, Christopher Lamb via FreeIPA-users wrote:
30;47m Thanks Rob   My problem was which of the various server.xmls instances is pki-tomcat using. However I think I have worked it out:   "ps -ef | grep tomcat" shows that catalina.base=/var/lib/pki/pki-tomcat.   The directory /var/lib/pki/pki-tomcat/conf is a link to /etc/pki/pki-tomcat   i.e the "active" server.xml (and the one I need to edit) is /etc/pki/pki-tomcat/server.xml. Thankfully, this is the instance with the explicit list for sslRangeCiphers   Could you be more specific about "we don't recommend mixing packages between OS releases"?   Is one of the packages I listed not the expected version? We have not knowingly fiddled around with the package versions.
You listed ipa-server 4.6.4-10 and OL 7.2. I'm pretty sure there wasn't
any kind of ipa-server 4.6 in RHEL 7.2. This means you did individual
package updates instead of a distribution upgrade.




  However, looking at the yum history, when I last updated ipa-server in January 2019, the update aborted with "warning: %posttrans(ipa-server-4.6.4-10.0.1.el7.x86_64) scriptlet failed, signal 2", so this might account for a package not being upgraded as expected.

--
/ Alexander Bokovoy
Sr. Principal Software Engineer
Security / Identity Management Engineering
Red Hat Limited, Finland
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to