[Freeipa-users] Re: Why is ipa-ods-exporter broken after running ipa-dns-install? (Was - Unable to start directory server after updates)

2021-09-13 Thread Jeremy Tourville via FreeIPA-users
Last week I ran the command: > [root@utility ~]# ipa-certupdate > > cannot connect to 'https://utility.idm.nac-issa.org/ipa/json': [SSL: > CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:897) > The ipa-certupdate command failed. We tested the root CA cert and server cert. Both were

[Freeipa-users] Re: ipahealthcheck.ipa.certs.IPACertmongerExpirationCheck - Request ID expires in....

2021-09-13 Thread Russell Jones via FreeIPA-users
Thank you! It resolved itself before I got a chance to try resubmitting the ID's. :-) On Mon, Sep 13, 2021 at 9:17 AM Rob Crittenden wrote: > Russell Jones via FreeIPA-users wrote: > > Hi all, > > > > I am not sure what to do with these below errors. Are they related to my > > failed replica

[Freeipa-users] Re: [Freeipa-users] ipahealthcheck.ipa.certs.IPACertmongerExpirationCheck - Request ID expires in....

2021-09-13 Thread Rob Crittenden via FreeIPA-users
Russell Jones via FreeIPA-users wrote: > Hi all, > > I am not sure what to do with these below errors. Are they related to my > failed replica that I rebuilt and resynced, and as a result can be > ignored? All the current certificates seem to be healthy. According to ipa-healthcheck they will be

[Freeipa-users] ipahealthcheck.ipa.certs.IPACertmongerExpirationCheck - Request ID expires in....

2021-09-13 Thread Russell Jones via FreeIPA-users
Hi all, I am not sure what to do with these below errors. Are they related to my failed replica that I rebuilt and resynced, and as a result can be ignored? All the current certificates seem to be healthy. Thanks for the insight! WARNING:

[Freeipa-users] Re: Waiting for CA subsystem to start (round 2)

2021-09-13 Thread MERCIER Jonathan via FreeIPA-users
For records that works if I remove these lines in /etc/crypto-policies/back-ends/nss.config name=p11-kit-proxy library=p11-kit-proxy.so ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] [BUG?] Host Alias DNS

2021-09-13 Thread Buckley Ross via FreeIPA-users
Hello, I'm trying to provision an HTTP service principal for a containerized service. The host on which the container is running also has a kerberized HTTP service running on it with a separate service principal (both services are highly critical, but for different systems, and thus should

[Freeipa-users] Re: Add second SSL to host

2021-09-13 Thread Per Qvindesland via FreeIPA-users
Hi Rob The SAN would also work really well since we are only using subdomains and hardly ever a new domain. I tried the following: ipa-getcert resubmit -D HTTP/sub2.example.com -i 20210910082436 But when I check ipa-getcert lis it says:         ca-error: Server at

[Freeipa-users] Re: CA errors after update, server.xml desync?

2021-09-13 Thread Dirk Silkenbaeumer via FreeIPA-users
I ran into similar issues after upgrading from FreeIPA 4.9.3 to 4.9.6 on Centos Stream 8 last week. You could check /var/log/httpd/error_log - I had trouble with TLS 1.3 (leading to error "Request failed with status 403: Non-2xx response from CA REST API: 403.") which could be solved by