Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-13 Thread Gronde, Christopher (Contractor)
om: Gronde, Christopher (Contractor) Sent: Thursday, October 08, 2015 2:06 PM To: 'Rob Crittenden' <rcrit...@redhat.com> Cc: freeipa-users@redhat.com Subject: RE: [Freeipa-users] Certmonger and dogtag not workingissues manually renewing Server-Cert # ldapsearch -x -b cn=ca_renewal,cn=ipa,c

Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-13 Thread Gronde, Christopher (Contractor)
: Tuesday, October 13, 2015 10:50 AM To: Rob Crittenden <rcrit...@redhat.com> Cc: freeipa-users@redhat.com Subject: Re: [Freeipa-users] Certmonger and dogtag not workingissues manually renewing Server-Cert Still having issues...if I can still have assistance with this getcert list

Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-08 Thread Alexander Bokovoy
On Wed, 07 Oct 2015, Gronde, Christopher (Contractor) wrote: I am new to FreeIPA and have inherited two IPA servers not sure if one is a master/slave or how they are different. I will try to give some pertinent outputs below of some of the things I am seeing. I know the Server-Cert is expired

Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-08 Thread Rob Crittenden
> > > -Original Message- > From: Alexander Bokovoy [mailto:aboko...@redhat.com] > Sent: Thursday, October 08, 2015 9:00 AM > To: Gronde, Christopher (Contractor) <christopher.gro...@fincen.gov> > Cc: freeipa-users@redhat.com > Subject: Re: [Freeipa-users]

Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-08 Thread Alexander Bokovoy
ent: Thursday, October 08, 2015 2:22 AM To: Gronde, Christopher (Contractor) <christopher.gro...@fincen.gov> Cc: freeipa-users@redhat.com Subject: Re: [Freeipa-users] Certmonger and dogtag not workingissues manually renewing Server-Cert On Wed, 07 Oct 2015, Gronde, Christopher (Contractor

Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-08 Thread Gronde, Christopher (Contractor)
ut >renewing it? > ># certutil -V -u V -n Server-Cert -d /etc/httpd/alias >certutil: certificate is invalid: Peer's Certificate has expired. > > > >-Original Message- >From: Alexander Bokovoy [mailto:aboko...@redhat.com] >Sent: Thursday, October 08, 2015 2:22 AM >To

Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-08 Thread Gronde, Christopher (Contractor)
(Contractor) <christopher.gro...@fincen.gov>; Alexander Bokovoy <aboko...@redhat.com> Cc: freeipa-users@redhat.com Subject: Re: [Freeipa-users] Certmonger and dogtag not workingissues manually renewing Server-Cert Gronde, Christopher (Contractor) wrote: > Now I am getting

Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-08 Thread Gronde, Christopher (Contractor)
istopher (Contractor) <christopher.gro...@fincen.gov>; Alexander Bokovoy <aboko...@redhat.com> Cc: freeipa-users@redhat.com Subject: Re: [Freeipa-users] Certmonger and dogtag not workingissues manually renewing Server-Cert Gronde, Christopher (Contractor) wrote: > Currently run

Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-08 Thread Rob Crittenden
issuer: CN=Certificate Authority,O=EXAMPLE.COM > subject: CN=ipa.example.com,O=EXAMPLE.COM > expires: 2017-01-02 14:36:32 UTC > key usage: > digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment > eku: id-kp-serverAuth,id-kp-clientAuth >

Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-08 Thread Gronde, Christopher (Contractor)
11:37 AM To: Gronde, Christopher (Contractor) <christopher.gro...@fincen.gov>; Alexander Bokovoy <aboko...@redhat.com> Cc: freeipa-users@redhat.com Subject: Re: [Freeipa-users] Certmonger and dogtag not workingissues manually renewing Server-Cert Gronde, Christopher (Contractor) w

Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-08 Thread Rob Crittenden
<aboko...@redhat.com> > Cc: freeipa-users@redhat.com > Subject: Re: [Freeipa-users] Certmonger and dogtag not workingissues > manually renewing Server-Cert > > Gronde, Christopher (Contractor) wrote: >> When I ran "getcert list" rather than "ipa-getcert li

Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-08 Thread Gronde, Christopher (Contractor)
) <christopher.gro...@fincen.gov> Cc: freeipa-users@redhat.com Subject: Re: [Freeipa-users] Certmonger and dogtag not workingissues manually renewing Server-Cert Gronde, Christopher (Contractor) wrote: > First commend came back: > > ]# grep internal= /var/lib/pki-ca/conf/password.conf &

[Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-07 Thread Gronde, Christopher (Contractor)
I am new to FreeIPA and have inherited two IPA servers not sure if one is a master/slave or how they are different. I will try to give some pertinent outputs below of some of the things I am seeing. I know the Server-Cert is expired but can't figure out how to renew it. There also appears to