Because 'Server-Cert cert-pki-ca' is part of '/etc/pki/pki-tomcat/alias' and 
should be unique, it needs to be regenerated on this machine.  Whether that 
regeneration is by pulling it from the backup of cert8.db or a new creation, 
I'm not exactly sure.  Obviously, I'm also not versed well enough to export it 
out of the backed up cert8.db and then re-install it into the new copy of 
cert8.db.  I suspect that it's three to four commands.  One that exports it, 
one or two that massage the export into or out of pk12, and then an import.
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure

Reply via email to