Hi,
> On 26 Jan 2023, at 13:12, MM MM via FreeIPA-users > <[email protected]> wrote: > > Hello Antonio, > > ipa getcert-list doesn't show the outdated certificate. ipa getcert-list displays only a subset of certificates, the ones handled by IPA CA helper. What is the full output of “getcert list” on the master? Are all the certs up to date? > The replica is failing with the following certificates: > - CA Subsystem > - OCSP Subsystem > - CA Audit > The replica installer downloads those certs from the master (they are identical on all servers/replicas), and this is why I suspect that some of them were not properly renewed on the master. flo > Thanks in advance! > > Best regards > _______________________________________________ > FreeIPA-users mailing list -- [email protected] > To unsubscribe send an email to [email protected] > Fedora Code of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedorahosted.org/archives/list/[email protected] > Do not reply to spam, report it: > https://pagure.io/fedora-infrastructure/new_issue _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected] Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
