I've tried that actually, but then I'm also getting an error cannot connect to 'https://XXXX/ipa/json': [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate has expired (_ssl.c:1131) The ipa-certupdate command failed.
My certificate is still valid, so this must also be related to the expired root CA. Is there a manual way to update the NSS database? Our FreeIPA version is 4.8.10 by the way. I remember fixing the NSS db on an older installation at some time, but I haven't found the db location on this new installation yet. I guess I could reconfigure Apache to use a different certificate or even a self-signed one to get `ipa-certupdate` working again. _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected] Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure
