Hi Rob,

any ideas here? it's a quite annoying when the system is not in a
stable state. Should I debug something? or easier to do full forced
replica sync?

Alex

ср, 12 авг. 2026 г. в 22:55, Rob Crittenden <[email protected]>:
>
> This is unexpected. So at least one other server can communicate with
> the IPA server with a CA but one in particular cannot?
>
> Are the system dates/times in sync with each other and correct?
>
> rob
>
> On 8/11/26 6:17 PM, alexey safonov via FreeIPA-users wrote:
> > so basically in my setup I have only one CA
> >
> > but you are right, on one replica executing this command provide the
> > error I mentioned earlier. And from that server only I'm getting that
> > error during uninstall.
> >
> > So what should I do? getcert list doesn't show any expired certificate
> > on that replica
> >
> > ср, 12 авг. 2026 г. в 05:16, Rob Crittenden <[email protected]>:
> >>
> >> This error originates on the IPA server. It is trying to search for any
> >> certificates associated with this client in order to revoke them. That
> >> search is failing with the expiration error.
> >>
> >> In other words, this isn't a problem unconfiguring the client, it's a
> >> problem on the IPA server (or servers).
> >>
> >> On each IPA server you can try something like: ipa cert-find --sizelimit 5
> >>
> >> If you get any error that then eliminates the client from the picture.
> >>
> >> rob
> >>
> >> On 8/11/26 4:13 PM, alexey safonov wrote:
> >>> don't have any expired here, but somehow all unenroll (--uninstall) is
> >>> causing this issue
> >>>
> >>> ipa-client-install --uninstall
> >>> Unenrolling client from IPA server
> >>> Unenrolling host failed: Certificate operation cannot be completed:
> >>> HTTPSConnectionPool(host='host01.domain.int', port=443): Max retries
> >>> exceeded with url: /ca/rest/certs/search?size=5000 (Caused by
> >>> SSLError(SSLError(1, '[SSL: SSLV3_ALERT_CERTIFICATE_EXPIRED] ssl/tls
> >>> alert certificate expired (_ssl.c:2651)')))
> >>>
> >>> вт, 11 авг. 2026 г. в 22:15, Rob Crittenden <[email protected]>:
> >>>>
> >>>> On 8/11/26 1:53 AM, alexey safonov via FreeIPA-users wrote:
> >>>>> Hi,
> >>>>>
> >>>>> previously I had strange situation, where one certificate had expired
> >>>>>
> >>>>> I've fixed this with ipa-cert-fix, but still have this:
> >>>>>
> >>>>> Number of certificates and requests being tracked: 7.
> >>>>> Request ID '20240815074547':
> >>>>> status: CA_UNREACHABLE
> >>>>> ca-error: Server at https://host01.int.domain/ipa/json failed request,
> >>>>> will retry: 4016 (503 Server Error: Service Unavailable for url:
> >>>>> https://host01.int.domain:443/ca/rest/account/login).
> >>>>> stuck: no
> >>>>> key pair storage: type=FILE,location='/var/lib/ipa/ra-agent.key'
> >>>>> certificate: type=FILE,location='/var/lib/ipa/ra-agent.pem'
> >>>>> CA: dogtag-ipa-ca-renew-agent
> >>>>> issuer: CN=Certificate Authority,O=INT.QUANTBOX.IN
> >>>>> subject: CN=IPA RA,O=INT.QUANTBOX.IN
> >>>>> issued: 2026-08-06 16:44:29 IST
> >>>>> expires: 2028-07-26 16:44:29 IST
> >>>>> key usage: digitalSignature,keyEncipherment,dataEncipherment
> >>>>> eku: id-kp-clientAuth
> >>>>> profile: caSubsystemCert
> >>>>> pre-save command: /usr/libexec/ipa/certmonger/renew_ra_cert_pre
> >>>>> post-save command: /usr/libexec/ipa/certmonger/renew_ra_cert
> >>>>> track: yes
> >>>>> auto-renew: yes
> >>>>>
> >>>>>
> >>>>> I feel that everything works fine, but today I see that on enrolling
> >>>>> have the following error.
> >>>>>
> >>>>> ipa-client-install --uninstall
> >>>>> Unenrolling client from IPA server
> >>>>> Unenrolling host failed: Certificate operation cannot be completed:
> >>>>> HTTPSConnectionPool(host='hos01.int.domain', port=443): Max retries
> >>>>> exceeded with url: /ca/rest/certs/search?size=5000 (Caused by
> >>>>> SSLError(SSLError(1, '[SSL: SSLV3_ALERT_CERTIFICATE_EXPIRED] ssl/tls
> >>>>> alert certificate expired (_ssl.c:2651)')))
> >>>>>
> >>>>> What should I check here and any ideas how to fix?
> >>>>
> >>>> It would seem some of your certificates are still expired. The "getcert
> >>>> list" output will tell you which one(s).
> >>>>
> >>>> rob
> >>
>
-- 
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to