[Freeipa-users] "Could not locate issuing CA" when querying OCSP responder

2016-07-25 Thread Anthony Joseph Messina
After upgrading to FreeIPA 4.3.1, I am getting "Error querying OCSP responder" with the following command. I can confirm certificate with serial 0x14 is present in the system and is not expired/revoked, etc. I'm a bit nervous about the "OCSPServlet: Could not locate issuing CA" in the Dogtag o

Re: [Freeipa-users] "Could not locate issuing CA" when querying OCSP responder

2016-07-26 Thread Anthony Joseph Messina
On Tuesday, July 26, 2016 2:40:38 PM CDT Fraser Tweedale wrote: > On Tue, Jul 26, 2016 at 01:45:19PM +1000, Fraser Tweedale wrote: > > On Mon, Jul 25, 2016 at 05:23:31PM -0500, Anthony Joseph Messina wrote: > > > After upgrading to FreeIPA 4.3.1, I am getting "Error queryi

Re: [Freeipa-users] bind crashes on rndc reload

2016-09-12 Thread Anthony Joseph Messina
On Monday, September 12, 2016 10:31:10 AM CDT Jochen Demmer wrote: > Hi, > > I have a major issue with my setup: > Fedora 24 > freeipa-common-4.3.2-2.fc24.noarch > freeipa-admintools-4.3.2-2.fc24.noarch > freeipa-server-dns-4.3.2-2.fc24.noarch > freeipa-client-common-4.3.2-2.fc24.noarch > freeipa-

Re: [Freeipa-users] bind crashes on rndc reload

2016-09-19 Thread Anthony Joseph Messina
On Monday, September 19, 2016 2:16:55 PM CDT Petr Spacek wrote: > On 12.9.2016 11:55, Anthony Joseph Messina wrote: > > On Monday, September 12, 2016 10:31:10 AM CDT Jochen Demmer wrote: > >> Hi, > >> > >> I have a major issue with my setup: > >> Fedo

Re: [Freeipa-users] bind crashes on rndc reload

2016-09-25 Thread Anthony Joseph Messina
On Tuesday, September 20, 2016 8:53:58 AM CDT Petr Spacek wrote: > On 20.9.2016 00:33, Anthony Joseph Messina wrote: > > On Monday, September 19, 2016 2:16:55 PM CDT Petr Spacek wrote: > >> On 12.9.2016 11:55, Anthony Joseph Messina wrote: > >>> On Monday, September 1

Re: [Freeipa-users] RFE: Documentation for creating OpenVPN certificates.

2017-01-18 Thread Anthony Joseph Messina
On Tuesday, January 17, 2017 2:09:08 PM CST Phil Ingram wrote: > To whom this may concern, > > I use FreeIPA and I would like to create certificates for peer-to-peer and > remote-access VPNs. In speaking with Fraser Tweedale, we agree that the > best way forward is to create a secondary CA for ins

[Freeipa-users] FreeIPA default_ccache_name in systemd-nspawn container

2017-03-17 Thread Anthony Joseph Messina
I've been running freeipa-server-4.x.x.fc25.x86_64 in systemd-nspawn selinux- wrapped full OS containers for a while. After upgrading to F25 on the host, systemd disabled access to the KEYRING ccache type from nspawn containers since the kernel keyring isn't namespaced. So anything that needs to

Re: [Freeipa-users] FreeIPA default_ccache_name in systemd-nspawn container

2017-03-17 Thread Anthony Joseph Messina
On Saturday, March 18, 2017 1:24:13 AM CDT Alexander Bokovoy wrote: > On la, 18 maalis 2017, Anthony Joseph Messina wrote: > >I've been running freeipa-server-4.x.x.fc25.x86_64 in systemd-nspawn > >selinux- wrapped full OS containers for a while. > > > >After upgra