Roberto Cornacchia wrote:
> UPDATE:
> 
> ipa01 had non-matching secrets
> between /etc/httpd/conf.d/ipa-pki-proxy.conf
> and /etc/pki/pki-tomcat/server.xml (I don't know how that happened. The
> latest upgrade log was successful).
> 
> I modified /etc/pki/pki-tomcat/server.xml to use the secret found in
> /etc/httpd/conf.d/ipa-pki-proxy.conf and now the "Unable to communicate
> with CMS (403)" issue on ipa01 is solved. Health-check only shows minor
> issues now.
> 
> Now I'm back to ipa02 with
> 
> # getcert list
> Number of certificates and requests being tracked: 0.

Running ipa-server-upgrade to fix the missing certificate tracking.

rob

> 
> 
> 
> On Wed, 16 Nov 2022 at 12:38, Roberto Cornacchia
> <[email protected] <mailto:[email protected]>> wrote:
> 
>     It turns out that also ipa01 (the CA renewal master) has
>     issue: Unable to communicate with CMS (403)
> 
>     I found
>     this: 
> https://www.mail-archive.com/[email protected]/msg12594.html
> 
>     which mentions both "secret" and "requiredSecret" should be
>     in /etc/pki/pki-tomcat/server.xml and match.
> 
>     on ipa01 (VERSION: 4.9.8, API_VERSION: 2.246), I see only "secret"
>     on ipa02 (VERSION: 4.9.8, API_VERSION: 2.245) I see only
>     "requiredSecret"
> 
>     Can this be important?
> 
>     Besides this, I ran ipa-healthcheck on both, the result is in attachment
> 
> 
> 
>     On Wed, 16 Nov 2022 at 10:46, Roberto Cornacchia
>     <[email protected] <mailto:[email protected]>>
>     wrote:
> 
>         I also found in the journal:
> 
>         Nov 16 07:40:11 ipa02.hq.spinque.com
>         <http://ipa02.hq.spinque.com> certmonger[10967]: 2022-11-16
>         07:40:11 [10967] Running enrollment/cadata helper
>         "/usr/libexec/certmonger/dogtag-ipa-renew-agent-submit".
>         Nov 16 07:40:11 ipa02.hq.spinque.com
>         <http://ipa02.hq.spinque.com> certmonger[10967]: Error opening
>         "/etc/httpd/alias/pwdfile.txt": No such file or directory.
> 
> 
>         On Wed, 16 Nov 2022 at 10:34, Roberto Cornacchia
>         <[email protected]
>         <mailto:[email protected]>> wrote:
> 
>             No luck with that, unfortunately:
> 
>             # getcert resubmit -d /etc/pki/pki-tomcat/alias -n
>             'subsystemCert cert-pki-ca' -v -w
>             No request found that matched arguments.
> 
>             # getcert list
>             Number of certificates and requests being tracked: 0.
> 
> 
>             On Wed, 16 Nov 2022 at 01:40, Rob Crittenden
>             <[email protected] <mailto:[email protected]>> wrote:
> 
>                 Roberto Cornacchia via FreeIPA-users wrote:
>                 >
>                 >     I'm not sure why it was not renewed, but now that
>                 it is in this
>                 >     state, what would be the correct procedure to
>                 renew it?
>                 >
>                 >
>                 > The other IPA server is the CA renewal master and it
>                 does have a valid
>                 > certificate. 
> 
>                 The CA subsystem certificates are renewed on the renewal
>                 master server
>                 and put into LDAP. The CA clones will pick up the
>                 certificates from
>                 there. You can force it to try to fetch it with:
> 
>                 # getcert resubmit -d /etc/pki/pki-tomcat/alias -n
>                 'subsystemCert
>                 cert-pki-ca' -v -w
> 
>                 With -v and -w you'll be able to follow along with the
>                 progress.
> 
>                 rob
> 
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to