Re: [Freeipa-users] Recovering from messed-up certs

2014-10-28 Thread Rob Crittenden
Eric McCoy wrote: > You're right. When I deleted the puppetmaster certs and reran > newcert.py, it worked like a champ. Presumably this is how the main > cert disappeared in the first place: NSS silently overwrote it. This > does mean that I won't be able to run puppet on this server, but... > W

Re: [Freeipa-users] Recovering from messed-up certs

2014-10-28 Thread Eric McCoy
You're right. When I deleted the puppetmaster certs and reran newcert.py, it worked like a champ. Presumably this is how the main cert disappeared in the first place: NSS silently overwrote it. This does mean that I won't be able to run puppet on this server, but... Well, even when I was doing i

Re: [Freeipa-users] Recovering from messed-up certs

2014-10-28 Thread Rob Crittenden
Eric McCoy wrote: > Sorry it took me so long to try this and get back to you. I tried > modifying that Python script and running it, and this is what I get: > > Initializing API > Setting up NSS databases > Untracking existing Apache Server-Cert > Issuing new cert > Tracking Server-Cert > ipa: ER

Re: [Freeipa-users] Recovering from messed-up certs

2014-10-28 Thread Eric McCoy
Sorry it took me so long to try this and get back to you. I tried modifying that Python script and running it, and this is what I get: Initializing API Setting up NSS databases Untracking existing Apache Server-Cert Issuing new cert Tracking Server-Cert ipa: ERROR: certmonger failed starting to t

Re: [Freeipa-users] Recovering from messed-up certs

2014-10-23 Thread Rob Crittenden
Eric McCoy wrote: > Some nicknames changed to protect the innocent. The > puppetmaster/hostname cert is nominally unrelated, though its creation > was contemporaneous with the disappearance of server-cert so I can't > entirely rule it out. > > Certificate Nickname

Re: [Freeipa-users] Recovering from messed-up certs

2014-10-23 Thread Eric McCoy
Some nicknames changed to protect the innocent. The puppetmaster/hostname cert is nominally unrelated, though its creation was contemporaneous with the disappearance of server-cert so I can't entirely rule it out. Certificate Nickname Trust Attributes SSL,

Re: [Freeipa-users] Recovering from messed-up certs

2014-10-23 Thread Rob Crittenden
Eric McCoy wrote: > Hi all, > > I somehow destroyed my primary IPA server's Server-Cert in > /etc/httpd/alias. I don't understand how or why it happened, all I know > is that I went to restart Apache and it was gone. Apache won't start, > of course, because the cert is missing. I can't issue a

[Freeipa-users] Recovering from messed-up certs

2014-10-23 Thread Eric McCoy
Hi all, I somehow destroyed my primary IPA server's Server-Cert in /etc/httpd/alias. I don't understand how or why it happened, all I know is that I went to restart Apache and it was gone. Apache won't start, of course, because the cert is missing. I can't issue a new cert on the primary becaus