The FreeIPA is 3.0.0 server is running on CentOS 6.5.

The CA subsystem certificates have all been renewed and will expire not
until 2016. In the

I think the problems come from "modifications" a colleague did to
/etc/httpd/ipa-pki-proxy.conf , /etc/httpd/nss.conf and
/var/lib/pki-ca/conf/server.xml (without dokumentation, but they have
different timestamps) when he wanted to enforce/enable higher level

I was able to reproduce some of his changes like StrictCypher and
sslOptions he did, but I am not sure with  the configuraion of the ports
of the connectors in /var/lib/pki-ca/conf/server.xml

  <Connector name="Agent" port="9443...

  <!-- Port Separation:  Admin Secure Port Connector -->
  <Connector name="Admin" port="9445" ...

  <!-- Port Separation:  EE Secure Port Connector -->
  <Connector name="EE" port="9444" ...

  <!-- Port Separation:  EE Secure Client Auth Port Connector -->
  <Connector  name="EEClientAuth" port="9446" ...

  <!-- Define an AJP 1.3 Connector on port 9447 -->
  <Connector port="9447" protocol="AJP/1.3" redirectPort="9444" />

and the /etc/httpd/conf.d/ipa-pki-proxy.conf


ProxyRequests Off

# matches for ee port
    NSSOptions +StdEnvVars +ExportCertData +StrictRequire +OptRenegotiate
    NSSVerifyClient none
#    ProxyPassMatch ajp://localhost:9443
#    ProxyPassReverse ajp://localhost:9443
    ProxyPassMatch ajp://localhost:9447
    ProxyPassReverse ajp://localhost:9447

# matches for admin port and installer
    NSSOptions +StdEnvVars +ExportCertData +StrictRequire +OptRenegotiate
    NSSVerifyClient none
#    ProxyPassMatch ajp://localhost:9443
#    ProxyPassReverse ajp://localhost:9443
    ProxyPassMatch ajp://localhost:9447
    ProxyPassReverse ajp://localhost:9447

# matches for agent port and eeca port
    NSSOptions +StdEnvVars +ExportCertData +StrictRequire +OptRenegotiate
    NSSVerifyClient require
#    ProxyPassMatch ajp://localhost:9443
#    ProxyPassReverse ajp://localhost:9443
    ProxyPassMatch ajp://localhost:9447
    ProxyPassReverse ajp://localhost:9447

# Only enable this on servers that are not generating a CRL
#RewriteRule ^/ipa/crl/MasterCRL.bin

Is there somewhere a example configuration? When I deployed the system it
was a rather default installation.

> Christof Schulze wrote:
>> Hello all,
>> i am running a FreeIPA server on CentOS for 2 years now with mostly
>> Ubuntu 12.04 and some Fedora 20 clients.
>> Since one week (or more) it is not possible any more to install new
>> clients (whether ubuntu nor fedora). The Host gets created on the
>> IPA-server but it can not create/exchange a Host-Certificate.
>> The only thing happened (except regular updates) was a complete
>> certificate renewal with no obvious problems some weeks ago.
>> Web-interface and certmonger show the same error.
>> ipa-getcert list on the new Hosts:
>>      status: CA_UNREACHABLE
>>      ca-error: Server failed request, will retry: 4301 (RPC failed at
>> server.  Certificate operation cannot be completed: FAILURE (Invalid
>> Request)).
>>      stuck: yes
> Given the timeline I'd guess that your CA subsystem certificates have
> expired.
> On the IPA master run: getcert list (not ipa-getcert)
> This will show the current status of things.
> What version of IPA is this?
> rob

Manage your subscription for the Freeipa-users mailing list:
Go To for more info on the project

Reply via email to