Re: [Freeipa-users] Certificate renewal issues for dogtag GUI (9443/9444/9445 ports)

2015-06-09 Thread Thibaut Pouzet
Le 09/06/2015 15:50, Rob Crittenden a écrit : > Thibaut Pouzet wrote: >> Le 05/06/2015 22:19, Endi Sukma Dewata a écrit : >>> Is this still a problem? Per discussion with Rob it doesn't seem to be >>> an issue with Dogtag itself. >>> >>> I su

Re: [Freeipa-users] Certificate renewal issues for dogtag GUI (9443/9444/9445 ports)

2015-06-09 Thread Thibaut Pouzet
Le 05/06/2015 22:19, Endi Sukma Dewata a écrit : > On 5/19/2015 3:54 AM, Thibaut Pouzet wrote: >> Hi, >> >> It appeared that the NSS DB had fips enabled due to the troubleshooting >> of an old problem : >> >> # modutil -dbdir /var/lib/pki-ca/alias/

[Freeipa-users] Status on Sub-CAs for FreeIPA v4.2

2015-06-01 Thread Thibaut Pouzet
ect for what I want to do. When I'm looking at the ticket, it seems that it is quietly sleeping somewhere, remaining not updated. I would love to see this feature in FreeIPA v4.2, has anyone a status on this RFE and it's current status ? Cheers, -- Thibaut Pouzet Lyra Network Ingénieur Sys

Re: [Freeipa-users] Certificate renewal issues for dogtag GUI (9443/9444/9445 ports)

2015-05-19 Thread Thibaut Pouzet
Le 13/05/2015 10:15, Thibaut Pouzet a écrit : > Le 12/05/2015 20:11, Nalin Dahyabhai a écrit : >> On Tue, May 12, 2015 at 06:39:13PM +0200, Thibaut Pouzet wrote: >>> After doing what you recommended, the CSR have changed in the debug log : >>> >>&g

Re: [Freeipa-users] Certificate renewal issues for dogtag GUI (9443/9444/9445 ports)

2015-05-13 Thread Thibaut Pouzet
Le 12/05/2015 20:11, Nalin Dahyabhai a écrit : > On Tue, May 12, 2015 at 06:39:13PM +0200, Thibaut Pouzet wrote: >> After doing what you recommended, the CSR have changed in the debug log : >> >> Certificate Request: >> Data: >> Version: 0 (0x0) >

Re: [Freeipa-users] Certificate renewal issues for dogtag GUI (9443/9444/9445 ports)

2015-05-12 Thread Thibaut Pouzet
Le 12/05/2015 18:09, Nalin Dahyabhai a écrit : > On Mon, May 11, 2015 at 05:14:16PM +0200, Thibaut Pouzet wrote: >> There is one that remains expired, despite all the efforts I put into >> renewing it. This is the one used for the pki-ca administration pages >> reachable on

[Freeipa-users] Certificate renewal issues for dogtag GUI (9443/9444/9445 ports)

2015-05-11 Thread Thibaut Pouzet
b:e6: 68:d6:e9:51:5b:9b:ec:d4:b3:e6:fd:e3:ee:7f:84:c3:e6:9b: cb:11:d8:48 And here I am, with this expired certificate still being served on my server... If anyone has any clue on what's going on, I would be really grateful ! Cheers, -- Thibaut Pouzet Lyra Network Ingé