I reset system clock to a  proper point now IPA is working. 

Server-Cert cert-pki-ca was not tracked by certmonger somehow, I add it but it 
says

# output of getcert list.
-------------------------------------
Request ID '20191101102140':
        status: MONITORING
        ca-error: Server at 
"http://ipa.ipa.pthl.hk:8080/ca/ee/ca/profileSubmit"; replied: Certificate 
serial number {0} to be renewed is revoked. Cannot renew a revoked certificate
        stuck: no
----- --------------------

And it was not renewed.

So how to renew this certificate manually?

I also read 
https://frasertweedale.github.io/blog-redhat/posts/2019-02-28-dogtag-cert-fix.html
 but there is no 'cert-fix' command in my IPA.

Thanks.
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to