[Freeipa-users] Re: ipa-healthcheck with fresh replica

2020-06-08 Thread Jochen Kellner via FreeIPA-users
Jochen Kellner via FreeIPA-users writes: > In IPA I have four certificates for "IPA RA" - one (the oldest) revoked, > two are expired in 2017 and 2019 and one valid until next year. > > The certificate in CS.cfg is expired: > > Serial Number: 268173317 (0xffc0005) > ... >

[Freeipa-users] Re: ipa-healthcheck with fresh replica

2020-06-07 Thread Jochen Kellner via FreeIPA-users
Rob Crittenden via FreeIPA-users writes: > Jochen Kellner via FreeIPA-users wrote: >> Topology: >> freeipa1 + freeipa2: CentOS Linux release 7.8.2003 (Core) (upgrade from >> older CentOS 7 releases) >> DNS, CA, KRA, AD trust >> freeipa1 is CA renewal master >> >> ERROR: >>

[Freeipa-users] Re: ipa-healthcheck with fresh replica

2020-06-07 Thread Rob Crittenden via FreeIPA-users
Jochen Kellner via FreeIPA-users wrote: > > Hi, > > I've been running IPA on CentOS 7 for some time on two servers with > integrated CA. With the release of CentOS 8.1 I tried upgrading with a > second replica - but scrapped that due to the problem with the wrong > samba libraries linked. Since