[Freeipa-devel] Recovering from expired CA subsystem certificates in IPA 2.x

Rob Crittenden rcritten at redhat.com
Mon Nov 11 20:08:19 UTC 2013


There have been a number of questions about expiring CA subsystem 
certificates for users running 2.x and unable to upgrade to 3.x where 
this is handled automatically, so I wrote 
http://www.freeipa.org/page/IPA_2x_Certificate_Renewal

Now you'll see why we automated it. It can cause premature baldness, so 
beware. I ran through it twice, once to write it and once to verify that 
it actually did what I said and it WORKSFORME. YMMV.

rob




More information about the Freeipa-devel mailing list