(I think) final update:

I was getting too many issues on ipa02.

I did a ipa-replica-manage del ipa02 and now I'm going to reinstall it from
scratch.

Thanks for the help so far!
Best, Roberto


On Wed, 16 Nov 2022 at 14:15, Roberto Cornacchia <
[email protected]> wrote:

> UPDATE:
>
> ipa01 had non-matching secrets
> between /etc/httpd/conf.d/ipa-pki-proxy.conf
> and /etc/pki/pki-tomcat/server.xml (I don't know how that happened. The
> latest upgrade log was successful).
>
> I modified /etc/pki/pki-tomcat/server.xml to use the secret found in
> /etc/httpd/conf.d/ipa-pki-proxy.conf and now the "Unable to communicate
> with CMS (403)" issue on ipa01 is solved. Health-check only shows minor
> issues now.
>
> Now I'm back to ipa02 with
>
> # getcert list
> Number of certificates and requests being tracked: 0.
>
>
>
> On Wed, 16 Nov 2022 at 12:38, Roberto Cornacchia <
> [email protected]> wrote:
>
>> It turns out that also ipa01 (the CA renewal master) has issue: Unable to
>> communicate with CMS (403)
>>
>> I found this:
>> https://www.mail-archive.com/[email protected]/msg12594.html
>>
>> which mentions both "secret" and "requiredSecret" should be
>> in /etc/pki/pki-tomcat/server.xml and match.
>>
>> on ipa01 (VERSION: 4.9.8, API_VERSION: 2.246), I see only "secret"
>> on ipa02 (VERSION: 4.9.8, API_VERSION: 2.245) I see only "requiredSecret"
>>
>> Can this be important?
>>
>> Besides this, I ran ipa-healthcheck on both, the result is in attachment
>>
>>
>>
>> On Wed, 16 Nov 2022 at 10:46, Roberto Cornacchia <
>> [email protected]> wrote:
>>
>>> I also found in the journal:
>>>
>>> Nov 16 07:40:11 ipa02.hq.spinque.com certmonger[10967]: 2022-11-16
>>> 07:40:11 [10967] Running enrollment/cadata helper
>>> "/usr/libexec/certmonger/dogtag-ipa-renew-agent-submit".
>>> Nov 16 07:40:11 ipa02.hq.spinque.com certmonger[10967]: Error opening
>>> "/etc/httpd/alias/pwdfile.txt": No such file or directory.
>>>
>>>
>>> On Wed, 16 Nov 2022 at 10:34, Roberto Cornacchia <
>>> [email protected]> wrote:
>>>
>>>> No luck with that, unfortunately:
>>>>
>>>> # getcert resubmit -d /etc/pki/pki-tomcat/alias -n 'subsystemCert
>>>> cert-pki-ca' -v -w
>>>> No request found that matched arguments.
>>>>
>>>> # getcert list
>>>> Number of certificates and requests being tracked: 0.
>>>>
>>>>
>>>> On Wed, 16 Nov 2022 at 01:40, Rob Crittenden <[email protected]>
>>>> wrote:
>>>>
>>>>> Roberto Cornacchia via FreeIPA-users wrote:
>>>>> >
>>>>> >     I'm not sure why it was not renewed, but now that it is in this
>>>>> >     state, what would be the correct procedure to renew it?
>>>>> >
>>>>> >
>>>>> > The other IPA server is the CA renewal master and it does have a
>>>>> valid
>>>>> > certificate.
>>>>>
>>>>> The CA subsystem certificates are renewed on the renewal master server
>>>>> and put into LDAP. The CA clones will pick up the certificates from
>>>>> there. You can force it to try to fetch it with:
>>>>>
>>>>> # getcert resubmit -d /etc/pki/pki-tomcat/alias -n 'subsystemCert
>>>>> cert-pki-ca' -v -w
>>>>>
>>>>> With -v and -w you'll be able to follow along with the progress.
>>>>>
>>>>> rob
>>>>>
>>>>>
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to