[Freeipa-devel] certificate renewal

Rob Crittenden rcritten at redhat.com
Wed Oct 30 18:30:20 UTC 2013


Vaede, Roger (Contractor) wrote:
> I have two IPA servers, one primary and one is backup.  (Redhat 5)

What version of ipa-server is this?

> The primary servers certificate has expired.
>
> I am not able to renew it.
>
> I turned off the ssl on the clients and now the users can login.
>
> I did a lot of research on certificate renewal and I am lost at this point.
>
> I am able to make changes using the backup IPA server.

This getcert output is quite strange. Did you start these tracking yourself?

Did you replace the IPA CA certificate at some point?

rob




More information about the Freeipa-devel mailing list