Re: [Freeipa-users] CA: IPA certificates not renewing

2016-06-22 Thread Marc Wiatrowski
Thank you Rob! I now have two years till everything expires... On Tue, Jun 21, 2016 at 1:33 PM, Rob Crittenden wrote: > Marc Wiatrowski wrote: > >> Thanks for the reply Rob, >> >> So should fixing replication be more than running a re-initialize? >> I've tried this with no

Re: [Freeipa-users] CA: IPA certificates not renewing

2016-06-21 Thread Rob Crittenden
Marc Wiatrowski wrote: Thanks for the reply Rob, So should fixing replication be more than running a re-initialize? I've tried this with no luck. Still the same errors in renewing the IPA certs. re-init drops one database and replaces it with another. If you really did that then you have

Re: [Freeipa-users] CA: IPA certificates not renewing

2016-06-20 Thread Marc Wiatrowski
Thanks for the reply Rob, So should fixing replication be more than running a re-initialize? I've tried this with no luck. Still the same errors in renewing the IPA certs. status: CA_UNREACHABLE ca-error: Server at https://spider01a.iglass.net/ipa/xml failed request, will retry: 4301 (RPC

Re: [Freeipa-users] CA: IPA certificates not renewing

2016-06-16 Thread Rob Crittenden
Marc Wiatrowski wrote: Thanks Rob, Any suggestions on how make the CA aware of the current serial number? Serial numbers are dolled out like uid numbers, by the 389-ds DNA Plugin. So each CA that has ever issued a certificate has its own range, hence the quite different serial number

Re: [Freeipa-users] CA: IPA certificates not renewing

2016-06-16 Thread Marc Wiatrowski
Thanks Rob, Any suggestions on how make the CA aware of the current serial number? Also started seeing the following error from two of the servers, spider01b and spider01o, but not spider01a when to navigate in the web gui. Though it doesn't appear to stop me from doing anything. IPA Error

Re: [Freeipa-users] CA: IPA certificates not renewing

2016-06-14 Thread Rob Crittenden
Marc Wiatrowski wrote: Hello, I'm having issues with the 3 ipa certificates of type CA: IPA renewing on 2 of 3 replicas. Particularly on the 2 that are not the CA master. The other 5 certificates from getcert list do renew and all certificates on the CA master do look to renew. Both servers