Hi, On Thu, Jun 4, 2026 at 3:36 AM Duc Tran Ngoc via FreeIPA-users < [email protected]> wrote:
> Hello all, > > When I run "getcert list" cmd, I see these 4 certs that will be expired on > 20 days and cannot be renewed automatically. Can anyone help me? > > Request ID '20260309084023': > status: MONITORING > ca-error: Server at https://hostname.domain.com/ipa/json denied > our request, giving up: 3009 (invalid 'csr': hostname in subject of request > 'IPA RA' does not match name or aliases of principal 'host/ > [email protected]'). > This certificate (the RA Agent) and the 3 others should not contain a hostname because they are shared among all the servers. Did you change the profile caSubsystemCert? Can you check if there is a CSR in the file /var/lib/certmonger/requests/20260309084023 and show us the value? flo > stuck: no > key pair storage: type=FILE,location='/var/lib/ipa/ra-agent.key' > certificate: type=FILE,location='/var/lib/ipa/ra-agent.pem' > CA: dogtag-ipa-ca-renew-agent > issuer: CN=Certificate Authority,O=DOMAIN.COM > subject: CN=IPA RA,O=DOMAIN.COM > issued: 2024-07-02 08:47:04 UTC > expires: 2026-06-22 08:47:04 UTC > key usage: digitalSignature,keyEncipherment,dataEncipherment > eku: id-kp-clientAuth > profile: caSubsystemCert > pre-save command: /usr/libexec/ipa/certmonger/renew_ra_cert_pre > post-save command: /usr/libexec/ipa/certmonger/renew_ra_cert > track: yes > auto-renew: yes > Request ID '20260309084024': > status: MONITORING > ca-error: Server at https://hostname.domain.com/ipa/json denied > our request, giving up: 3009 (invalid 'csr': hostname in subject of request > 'CA Audit' does not match name or aliases of principal 'host/ > [email protected]'). > stuck: no > key pair storage: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='auditSigningCert > cert-pki-ca',token='NSS Certificate DB',pin set > certificate: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='auditSigningCert > cert-pki-ca',token='NSS Certificate DB' > CA: dogtag-ipa-ca-renew-agent > issuer: CN=Certificate Authority,O=DOMAIN.COM > subject: CN=CA Audit,O=DOMAIN.COM > issued: 2024-07-02 08:46:01 UTC > expires: 2026-06-22 08:46:01 UTC > key usage: digitalSignature,nonRepudiation > profile: caSignedLogCert > pre-save command: /usr/libexec/ipa/certmonger/stop_pkicad > post-save command: /usr/libexec/ipa/certmonger/renew_ca_cert > "auditSigningCert cert-pki-ca" > track: yes > auto-renew: yes > Request ID '20260309084025': > status: MONITORING > ca-error: Server at https://hostname.domain.com/ipa/json denied > our request, giving up: 3009 (invalid 'csr': hostname in subject of request > 'OCSP Subsystem' does not match name or aliases of principal 'host/ > [email protected]'). > stuck: no > key pair storage: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='ocspSigningCert > cert-pki-ca',token='NSS Certificate DB',pin set > certificate: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='ocspSigningCert > cert-pki-ca',token='NSS Certificate DB' > CA: dogtag-ipa-ca-renew-agent > issuer: CN=Certificate Authority,O=DOMAIN.COM > subject: CN=OCSP Subsystem,O=DOMAIN.COM > issued: 2024-07-02 08:45:43 UTC > expires: 2026-06-22 08:45:43 UTC > eku: id-kp-OCSPSigning > profile: caOCSPCert > pre-save command: /usr/libexec/ipa/certmonger/stop_pkicad > post-save command: /usr/libexec/ipa/certmonger/renew_ca_cert > "ocspSigningCert cert-pki-ca" > track: yes > auto-renew: yes > Request ID '20260309084026': > status: MONITORING > ca-error: Server at https://hostname.domain.com/ipa/json denied > our request, giving up: 3009 (invalid 'csr': hostname in subject of request > 'CA Subsystem' does not match name or aliases of principal 'host/ > [email protected]'). > stuck: no > key pair storage: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='subsystemCert > cert-pki-ca',token='NSS Certificate DB',pin set > certificate: > type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='subsystemCert > cert-pki-ca',token='NSS Certificate DB' > CA: dogtag-ipa-ca-renew-agent > issuer: CN=Certificate Authority,O=DOMAIN.COM > subject: CN=CA Subsystem,O=DOMAIN.COM > issued: 2024-07-02 08:45:55 UTC > expires: 2026-06-22 08:45:55 UTC > key usage: > digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment > eku: id-kp-clientAuth > profile: caSubsystemCert > pre-save command: /usr/libexec/ipa/certmonger/stop_pkicad > post-save command: /usr/libexec/ipa/certmonger/renew_ca_cert > "subsystemCert cert-pki-ca" > track: yes > auto-renew: yes > -- > _______________________________________________ > FreeIPA-users mailing list -- [email protected] > To unsubscribe send an email to [email protected] > Fedora Code of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedorahosted.org/archives/list/[email protected] > Do not reply to spam, report it: > https://forge.fedoraproject.org/infra/tickets/issues/new >
-- _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
