I'm looking at the following link for recovering expired certificates on 
FreeeIPA 3.0.0:
Problem is when Iook inside my /etc/pki-ca/CS.cfg file for a subsystemCert I do 
not find one.  I see the other three:
auditSigningCert cert-pki-ca =>  updatedocspSigningCert cert-pki-ca => 
updatedServer-Cert cert-pki-ca  => no cert heresubsystemCert cert-pki-ca => 
Has anyone ever run across this?  Any suggestions or hints would be 
appreciated.  If I role the clock back on my system I can login to IPA, but if 
the time is updated, I cannot login.
Please help. 

Manage your subscription for the Freeipa-users mailing list:
Go to http://freeipa.org for more info on the project

Reply via email to