Hi Rob, any ideas here? it's a quite annoying when the system is not in a stable state. Should I debug something? or easier to do full forced replica sync?
Alex ср, 12 авг. 2026 г. в 22:55, Rob Crittenden <[email protected]>: > > This is unexpected. So at least one other server can communicate with > the IPA server with a CA but one in particular cannot? > > Are the system dates/times in sync with each other and correct? > > rob > > On 8/11/26 6:17 PM, alexey safonov via FreeIPA-users wrote: > > so basically in my setup I have only one CA > > > > but you are right, on one replica executing this command provide the > > error I mentioned earlier. And from that server only I'm getting that > > error during uninstall. > > > > So what should I do? getcert list doesn't show any expired certificate > > on that replica > > > > ср, 12 авг. 2026 г. в 05:16, Rob Crittenden <[email protected]>: > >> > >> This error originates on the IPA server. It is trying to search for any > >> certificates associated with this client in order to revoke them. That > >> search is failing with the expiration error. > >> > >> In other words, this isn't a problem unconfiguring the client, it's a > >> problem on the IPA server (or servers). > >> > >> On each IPA server you can try something like: ipa cert-find --sizelimit 5 > >> > >> If you get any error that then eliminates the client from the picture. > >> > >> rob > >> > >> On 8/11/26 4:13 PM, alexey safonov wrote: > >>> don't have any expired here, but somehow all unenroll (--uninstall) is > >>> causing this issue > >>> > >>> ipa-client-install --uninstall > >>> Unenrolling client from IPA server > >>> Unenrolling host failed: Certificate operation cannot be completed: > >>> HTTPSConnectionPool(host='host01.domain.int', port=443): Max retries > >>> exceeded with url: /ca/rest/certs/search?size=5000 (Caused by > >>> SSLError(SSLError(1, '[SSL: SSLV3_ALERT_CERTIFICATE_EXPIRED] ssl/tls > >>> alert certificate expired (_ssl.c:2651)'))) > >>> > >>> вт, 11 авг. 2026 г. в 22:15, Rob Crittenden <[email protected]>: > >>>> > >>>> On 8/11/26 1:53 AM, alexey safonov via FreeIPA-users wrote: > >>>>> Hi, > >>>>> > >>>>> previously I had strange situation, where one certificate had expired > >>>>> > >>>>> I've fixed this with ipa-cert-fix, but still have this: > >>>>> > >>>>> Number of certificates and requests being tracked: 7. > >>>>> Request ID '20240815074547': > >>>>> status: CA_UNREACHABLE > >>>>> ca-error: Server at https://host01.int.domain/ipa/json failed request, > >>>>> will retry: 4016 (503 Server Error: Service Unavailable for url: > >>>>> https://host01.int.domain:443/ca/rest/account/login). > >>>>> stuck: no > >>>>> key pair storage: type=FILE,location='/var/lib/ipa/ra-agent.key' > >>>>> certificate: type=FILE,location='/var/lib/ipa/ra-agent.pem' > >>>>> CA: dogtag-ipa-ca-renew-agent > >>>>> issuer: CN=Certificate Authority,O=INT.QUANTBOX.IN > >>>>> subject: CN=IPA RA,O=INT.QUANTBOX.IN > >>>>> issued: 2026-08-06 16:44:29 IST > >>>>> expires: 2028-07-26 16:44:29 IST > >>>>> key usage: digitalSignature,keyEncipherment,dataEncipherment > >>>>> eku: id-kp-clientAuth > >>>>> profile: caSubsystemCert > >>>>> pre-save command: /usr/libexec/ipa/certmonger/renew_ra_cert_pre > >>>>> post-save command: /usr/libexec/ipa/certmonger/renew_ra_cert > >>>>> track: yes > >>>>> auto-renew: yes > >>>>> > >>>>> > >>>>> I feel that everything works fine, but today I see that on enrolling > >>>>> have the following error. > >>>>> > >>>>> ipa-client-install --uninstall > >>>>> Unenrolling client from IPA server > >>>>> Unenrolling host failed: Certificate operation cannot be completed: > >>>>> HTTPSConnectionPool(host='hos01.int.domain', port=443): Max retries > >>>>> exceeded with url: /ca/rest/certs/search?size=5000 (Caused by > >>>>> SSLError(SSLError(1, '[SSL: SSLV3_ALERT_CERTIFICATE_EXPIRED] ssl/tls > >>>>> alert certificate expired (_ssl.c:2651)'))) > >>>>> > >>>>> What should I check here and any ideas how to fix? > >>>> > >>>> It would seem some of your certificates are still expired. The "getcert > >>>> list" output will tell you which one(s). > >>>> > >>>> rob > >> > -- _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
