[Freeipa-users] Expired Certificates, rolling back time didn't help

2020-03-16 Thread Bhavin Vaidya via FreeIPA-users
Hello, We had similar issue 2 yrs back, and resurface as it didn't auto-renew. Went back in time to 2016-06-11 as well as 2020-02-20, restarted "certmonger", didn't update. FreeIPA Master: CentOS 7.4.1708, FreeIPA Version: 4.5.0, API_VERSION: 2.228 while ipactl start, it will not start pki-tomc

[Freeipa-users] Expired Certificates, rolling back time didn't help

2020-03-16 Thread Bhavin Vaidya via FreeIPA-users
Hello, We had similar issue 2 yrs back, and resurface as it didn't auto-renew. Went back in time to 2016-06-11 as well as 2020-02-20, restarted "certmonger", didn't update. FreeIPA Master: CentOS 7.4.1708, FreeIPA Version: 4.5.0, API_VERSION: 2.228 while ipactl start, it will not start pki-tomc

[Freeipa-users] Expired Certificates.

2019-01-16 Thread Bhavin Vaidya via FreeIPA-users
Hello, We rebooted our Primary FreeIPA server (ds01) and then it will not start pki-tomcatd, Kerberos will also not work, though it starts. We realized that 2 certificates have expired. we tried stopped ipa, stopped NTP, going back to Dec 14th, 2018 and restarted certmonger, bring back date but

[Freeipa-users] expired certificates - pki-tomcat not running

2017-08-08 Thread Michael Gusek via FreeIPA-users
Hello, we run in a problem with expired certificates: > getcert list (sample show only one expired certificate) ... Request ID '20170202144747': status: MONITORING stuck: no key pair storage: type=NSSDB,location='/etc/httpd/alias',nickname='ipaCert',token='NSS Certificate DB',pinfile='/etc/

[Freeipa-users] Expired certificates

2017-06-20 Thread Ian Pilcher via FreeIPA-users
After rebooting my CentOS 7 IdM server, pki-tomcatd is failing to start. I see this (repeated many times) in the journal: WARNING: Exception processing realm com.netscape.cms.tomcat.ProxyRealm@383171f8 background process javax.ws.rs.ServiceUnavailableException: Subsystem unavailable at com.net

[Freeipa-users] Expired certificates

2017-06-20 Thread Ian Pilcher via FreeIPA-users
After rebooting my CentOS 7 IdM server, pki-tomcatd is failing to start. I see this (repeated many times) in the journal: WARNING: Exception processing realm com.netscape.cms.tomcat.ProxyRealm@383171f8 background process javax.ws.rs.ServiceUnavailableException: Subsystem unavailable at com.net