[Freeipa-users] Re: Another pki-tomcatd failing to start due to expired certs

2021-12-01 Thread Florence Renaud via FreeIPA-users
Hi, Please find inline answers. > On 30 Nov 2021, at 06:02, Jacob Block wrote: > >  > Thank you flo! Those are very good leads. I also found your blog with some > very helpful posts, thanks! I see the Server-Cert must be after 2021-03-08 > now, but also the IPA certs need to be after

[Freeipa-users] Re: Another pki-tomcatd failing to start due to expired certs

2021-11-29 Thread Jacob Block via FreeIPA-users
Thank you flo! Those are very good leads. I also found your blog with some very helpful posts, thanks! I see the Server-Cert must be after 2021-03-08 now, but also the IPA certs need to be after 2021-09-01. Few questions: 1. Also strangely we have 7 IPA certs issued, all identical except

[Freeipa-users] Re: Another pki-tomcatd failing to start due to expired certs

2021-11-29 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, The error "Peer's certificate issuer has been marked as not trusted by the user." points to PKI not trusting the LDAP certificate. 1. When moving the date back, you need to carefully pick the date. As the HTTP and LDAP certs have already been renewed, their "valid from" date is probably