Wound up taking this off-list as I wasn't subscribed and it appears the 
webservice where I could subscribe was down for a while.

I found my issue: I had a stray /etc/sysconfig/pki-tomcat that had 
PKI_VERSION=10.7.3; apparently an upgrade that needed to upgrade that 
file...didn't, somehow.

I updated that file with the tomcat.conf from /etc/pki/pki-tomcat/tomcat.conf 
(i.e. copied it over, but it's important that it be owned pkiuser:pkiuser and 
not have world read permissions), and now I can revoke certs again.

Thanks, Rob, for helping me through this!
--
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to