[Freeipa-users] Re: Use of certificates is failing

2019-02-05 Thread Labanowski Pierre via FreeIPA-users
Thx flo, Indeed you are right, I didn't have an ipaCert certificate store in my NSS databases. certutil: Could not find cert: ipaCert so I used your ldapsearch command to retrieve the certificate and was able to import it into the various NSS databases with certutil. I don't know why the ipaCer

[Freeipa-users] Remove and add a new CA autority

2018-03-11 Thread Labanowski Pierre via FreeIPA-users
Hello, I'm confused with my freeipa setup. Some details on the installation: - I use freeipa on only one server since 2012 (basic install with a self-signed certificate ... KO from then 2014). - meanwhile (a few years) I made a migration to switch to a version of freeipa v4 on 7.1 centos, which i

[Freeipa-users] Re: Remove and add a new CA autority

2018-03-22 Thread Labanowski Pierre via FreeIPA-users
Hi Fraser, thank you in advance for the help. ipa-server-upgrade ends on this message : '' Migrating certificate profiles to LDAP] cert validation failed for "CN=freeipa4..fr,O=.FR" ((SEC_ERROR_EXPIRED_CERTIFICATE) Peer's Certificate has expired.) IPA server upgrade failed: Inspect /var/