[Freeipa-users] FreeIPA HTTP Server-Cert expired.

2014-08-06 Thread ketan mehta
Hi All, I'm facing a strange problem, my IPA master server's HTTP Server-Cert got expired and i'm not able to renew it. would you please help me in resolve it. [root@ipa01 ~]# getcert list Number of certificates and requests being tracked: 9. Request ID '20120731123222': status: CA_UNREA

Re: [Freeipa-users] FreeIPA HTTP Server-Cert expired.

2014-08-06 Thread Rob Crittenden
ketan mehta wrote: > Hi All, > > I'm facing a strange problem, my IPA master server's HTTP Server-Cert > got expired and i'm not able to renew it. would you please help me in > resolve it. > > [root@ipa01 ~]# getcert list > Number of certificates and requests being tracked: 9. > Request ID '2012

Re: [Freeipa-users] FreeIPA HTTP Server-Cert expired.

2014-08-06 Thread ketan mehta
Hi Rob, I tried doing that earlier but it fails because of named error output of /var/log/messages Jul 31 14:06:04 ipa01 named[22866]: Failed to init credentials (Clock skew too great) Jul 31 14:06:04 ipa01 named[22866]: loading configuration: failure Jul 31 14:06:04 ipa01 named[22866]: exiting (

Re: [Freeipa-users] Replica Cert failed to renew ...

2014-08-06 Thread Martin Kosek
Right, the processing route may not seem obvious. certmonger uses the server from /etc/ipa/default.conf. This server does not necessarily need to also run CA, we count with that option. When certmonger wants to renew or request a certificate, it calls cert-request API call on that server. The API

Re: [Freeipa-users] RHEL 7 Upgrade experience so far

2014-08-06 Thread Ade Lee
Thanks for sticking in there with the debugging. Let us know if you run into any issues with the re-install. I will open a Dogtag ticket to look into the multiple certs issue for Dogtag. Ade On Tue, 2014-08-05 at 21:30 -0700, Erinn Looney-Triggs wrote: > Ok I am throwing up the white flag on thi

Re: [Freeipa-users] FreeIPA + Ipsilon

2014-08-06 Thread Luca Tartarini
Hi, Thanks for the replies. I updated the line with: plugins_by_name = dict((p.name, p) for p in self._site[FACILITY]['enabled']) and it works (the installation is completed succesfully). But now when I try to connect to: https://myidp.example.com/idp or I try to configure ipsilon-client (ip

Re: [Freeipa-users] FreeIPA + Ipsilon

2014-08-06 Thread Simo Sorce
On Wed, 2014-08-06 at 17:20 +0200, Luca Tartarini wrote: > Hi, > > Thanks for the replies. I updated the line with: > > plugins_by_name = dict((p.name, p) for p in self._site[FACILITY]['enabled']) > > and it works (the installation is completed succesfully). > > But now when I try to connect to