[Freeipa-users] Re: Problems after IPA upgrade: ipa-server-upgrade doesn't complete, pki-tomcatd won't start

2018-06-27 Thread Jokinen Eemeli via FreeIPA-users
Hi! No I haven't since my guide line didn't tell me to. I tried to set the date back, restart certmonger and then I did "ipactl restart" and then it got 2 certs renewed! One of the remaining two certificates was on "CA_UNREACHABLE" state, so I ran another certmonger restart and it did get

[Freeipa-users] Re: /etc/httpd/alias not getting renewed cert

2018-06-27 Thread Thomas Letherby via FreeIPA-users
Hello Florence, It was the Signing-Cert and the I.domain.NET IPA CA cert. By setting the clock back I managed to get those to renew, now it seems I just need to get tomcat-pki to start. The error is: Internal Database Error encountered: Could not connect to LDAP server host xipa1.i.xrs444.net

[Freeipa-users] Re: Server install fails on Ubuntu due to missing crypto.fips_enabled

2018-06-27 Thread John Morris via FreeIPA-users
On 06/27/2018 10:25 AM, Rob Crittenden wrote: John Morris via FreeIPA-users wrote: On 05/03/2018 08:27 AM, Kees Bakker via FreeIPA-users wrote: On 03-05-18 12:07, Kees Bakker via FreeIPA-users wrote: Hey, Trying to do a test installation of a FreeIPA server on Ubuntu 18.04. It fails

[Freeipa-users] Re: certmonger upgrade failure

2018-06-27 Thread Rob Crittenden via FreeIPA-users
Harald Dunkel wrote: > Hi Robert, > > On 6/26/18 4:45 PM, Rob Crittenden via FreeIPA-users wrote: >> Harald Dunkel wrote: >>> >>> I see several files with a key_pin or Key_pin_file inside. I would prefer >>> to send you these files in an encrypted EMail. What would you suggest? Do >>> you have

[Freeipa-users] Re: Server install fails on Ubuntu due to missing crypto.fips_enabled

2018-06-27 Thread Rob Crittenden via FreeIPA-users
John Morris via FreeIPA-users wrote: > > > On 05/03/2018 08:27 AM, Kees Bakker via FreeIPA-users wrote: >> On 03-05-18 12:07, Kees Bakker via FreeIPA-users wrote: >>> Hey, >>> >>> Trying to do a test installation of a FreeIPA server on Ubuntu 18.04. >>> It fails setting up the certificate server

[Freeipa-users] Re: Server install fails on Ubuntu due to missing crypto.fips_enabled

2018-06-27 Thread John Morris via FreeIPA-users
On 05/03/2018 08:27 AM, Kees Bakker via FreeIPA-users wrote: On 03-05-18 12:07, Kees Bakker via FreeIPA-users wrote: Hey, Trying to do a test installation of a FreeIPA server on Ubuntu 18.04. It fails setting up the certificate server (pki-tomcatd). Configuring certificate server

[Freeipa-users] Re: Problems after IPA upgrade: ipa-server-upgrade doesn't complete, pki-tomcatd won't start

2018-06-27 Thread Rob Crittenden via FreeIPA-users
Jokinen Eemeli via FreeIPA-users wrote: > Hi! > > -- > certutil -L -d /etc/pki/pki-tomcat/alias -n 'Server-Cert cert-pki-ca' |grep > "Not Before" > Not Before: Wed Feb 21 09:58:22 2018 > certutil -L -d /etc/dirsrv/slapd-<> -n Server-Cert | grep "Not Before" > Not Before:

[Freeipa-users] Re: Problems after IPA upgrade: ipa-server-upgrade doesn't complete, pki-tomcatd won't start

2018-06-27 Thread Jokinen Eemeli via FreeIPA-users
Hi! Checked access log for today date: -- <> - - [27/Jun/2018:10:57:38 +0300] "GET /ca/ee/ca/profileSubmit?profileId=caServerCert_num=4=true=true_name=IPA HTTP/1.1" 500 2208 <> - - [27/Jun/2018:10:57:41 +0300] "GET /ca/ee/ca/profileSubmit?profileId=caServerCert_num=7=true=true_name=IPA

[Freeipa-users] Re: Problems after IPA upgrade: ipa-server-upgrade doesn't complete, pki-tomcatd won't start

2018-06-27 Thread Florence Blanc-Renaud via FreeIPA-users
On 06/27/2018 08:56 AM, Jokinen Eemeli via FreeIPA-users wrote: Hi! -- certutil -L -d /etc/pki/pki-tomcat/alias -n 'Server-Cert cert-pki-ca' |grep "Not Before" Not Before: Wed Feb 21 09:58:22 2018 certutil -L -d /etc/dirsrv/slapd-<> -n Server-Cert | grep "Not Before"

[Freeipa-users] Re: /etc/httpd/alias not getting renewed cert

2018-06-27 Thread Florence Blanc-Renaud via FreeIPA-users
On 06/27/2018 07:02 AM, Thomas Letherby via FreeIPA-users wrote: After some fiddling with dates some more I seem to have the HTTPD cert in sync, however it appears the cert signing cert is expired. named also says it's starting, but doesn't seem to want to respond. I don't have time to dig

[Freeipa-users] Re: Problems after IPA upgrade: ipa-server-upgrade doesn't complete, pki-tomcatd won't start

2018-06-27 Thread Jokinen Eemeli via FreeIPA-users
Hi! -- certutil -L -d /etc/pki/pki-tomcat/alias -n 'Server-Cert cert-pki-ca' |grep "Not Before" Not Before: Wed Feb 21 09:58:22 2018 certutil -L -d /etc/dirsrv/slapd-<> -n Server-Cert | grep "Not Before" Not Before: Sun Mar 04 09:58:32 2018 certutil -L -d