We are currently dead in the water. Our OCSP, CA Audit, CA Subsystem, and IPA 
RA certs expired as of 7/23/16. I found and followed the instructions to the 
 however the CA Subsystem and IPA RA certs will not renew. I've backdated the 
server to make sure the system was within the renewal window, but that has not 

When I run getcert list it reports:
Ca-error: Sever at "https://<fqdn>:9443/ca/agent/ca/profileProcess" replied: 1: 
Authentication Error
for both the IPA RA and CA Subsystem certs

The debug log shows:
SignedAuditEventFactory: create() 
 RA,O=MISS.ION] authentication failure
ReviewReqServlet: Invalid Credential.

We are kind of in deep doo-doo until this gets resolved.

We are running ipa-server-3.0.0-47.el6_7.2 on RHEL 6.5

Any thoughts?


Adam M. Lewis

Attachment: smime.p7s
Description: S/MIME cryptographic signature

Manage your subscription for the Freeipa-users mailing list:
Go to http://freeipa.org for more info on the project

Reply via email to