Re: [Freeipa-users] replica added, but clients still try renewing certificates with old master

2016-09-23 Thread Rob Crittenden
Petr Vobornik wrote: On 09/21/2016 05:06 PM, Natxo Asenjo wrote: hi Petr, On Wed, Sep 21, 2016 at 4:38 PM, Petr Vobornik > wrote: On 09/21/2016 10:50 AM, Natxo Asenjo wrote: > When I try to resubmit certificates from certmonger they

Re: [Freeipa-users] replica added, but clients still try renewing certificates with old master

2016-09-23 Thread Natxo Asenjo
On Fri, Sep 23, 2016 at 9:29 AM, Petr Vobornik wrote: > On 09/21/2016 05:06 PM, Natxo Asenjo wrote: > > > So, what should be the correct value for dns discovery for both > directives using > > dns discovery? > > I don't think there is a support for DNS discovery in

Re: [Freeipa-users] replica added, but clients still try renewing certificates with old master

2016-09-23 Thread Petr Vobornik
On 09/21/2016 05:06 PM, Natxo Asenjo wrote: > hi Petr, > > On Wed, Sep 21, 2016 at 4:38 PM, Petr Vobornik > wrote: > > On 09/21/2016 10:50 AM, Natxo Asenjo wrote: > > > When I try to resubmit certificates from certmonger they still hit

Re: [Freeipa-users] replica added, but clients still try renewing certificates with old master

2016-09-22 Thread Natxo Asenjo
On Wed, Sep 21, 2016 at 5:06 PM, Natxo Asenjo wrote: > ok, done. > > In fact, change both the domain as the xmlrpc_uri directives in the global > section was necessary. Now It worked :-) > I meant the server, not the domain options obviously. -- Groeten, natxo --

Re: [Freeipa-users] replica added, but clients still try renewing certificates with old master

2016-09-21 Thread Natxo Asenjo
hi Petr, On Wed, Sep 21, 2016 at 4:38 PM, Petr Vobornik wrote: > On 09/21/2016 10:50 AM, Natxo Asenjo wrote: > > > When I try to resubmit certificates from certmonger they still hit the > kdc01 web > > server, so the requests hang on an status: CA_UNREACHABLE > >

Re: [Freeipa-users] replica added, but clients still try renewing certificates with old master

2016-09-21 Thread Petr Vobornik
On 09/21/2016 10:50 AM, Natxo Asenjo wrote: > hi, > > I followed the instructions here: > https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/upgrading.html > > and now after some issues I have a replica with both

[Freeipa-users] replica added, but clients still try renewing certificates with old master

2016-09-21 Thread Natxo Asenjo
hi, I followed the instructions here: https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/upgrading.html and now after some issues I have a replica with both pki and dns data running centos 7. So now I have 3