<div dir="ltr">Hello Guys,<div><br></div><div>I was able to resolve this today.<br>My webserver and dirsrv certificate were expired yesterday and trying to replace them gave me the same error "<span style="font-size:12.8000001907349px">ERROR: (SEC_ERROR_LIBRARY_FAILURE) security library failure."</span></div><div><span style="font-size:12.8000001907349px">So I tried some things to resolve this.<br>The trick was to replace /etc/ipa/ca.crt with the godaddy file "gdig2" which only has 1 certificare. This file you can get while downloading your certificate from godaddy. Then I had to add the bundle from godaddy, file gd_bundle-g2-g1 into my server cert.</span></div><div><span style="font-size:12.8000001907349px">This made both the command ipa-server-certinstall and ipa-replicate-prepare finish as expected!</span></div><div><span style="font-size:12.8000001907349px"><br></span></div><div><span style="font-size:12.8000001907349px">Hope this helps. I saw somebody else with a very similar issue.</span></div><div><span style="font-size:12.8000001907349px"><br></span></div><div><span style="font-size:12.8000001907349px">Kind Regards,</span></div><div><span style="font-size:12.8000001907349px"><br></span></div><div><span style="font-size:12.8000001907349px">D</span></div></div><div class="gmail_extra"><br><div class="gmail_quote">2015-04-23 7:40 GMT+02:00 Jan Cholasta <span dir="ltr"><<a href="mailto:jcholast@redhat.com" target="_blank">jcholast@redhat.com</a>></span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi,<br>
<br>
yes, you can definitely use a different certificate in the meantime, although it can't be self-signed.<br>
<br>
Honza<br>
<br>
Dne 20.4.2015 v 14:17 David Dejaeghere napsal(a):<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">
Hi,<br>
<br>
Let me know how I can assist.<br>
In the meantime could I setup a replica using a different certificate?<br>
Self signed or anything like that?<br>
<br>
Regards,<br>
<br>
D<br>
<br>
2015-04-17 15:27 GMT+02:00 Jan Cholasta <<a href="mailto:jcholast@redhat.com" target="_blank">jcholast@redhat.com</a><br></span>
<mailto:<a href="mailto:jcholast@redhat.com" target="_blank">jcholast@redhat.com</a>>>:<span class=""><br>
<br>
    Hi,<br>
<br>
    I don't have any new information. I'm trying to reproduce the<br>
    problem but had no luck so far.<br>
<br>
    Honza<br>
<br>
    Dne 17.4.2015 v 15:23 David Dejaeghere napsal(a):<br>
<br>
        Hi,<br>
<br>
        Any more things I can try out? How do we proceed?<br>
<br>
        Kind Regards,<br>
<br>
        D<br>
<br>
        2015-04-15 11:48 GMT+02:00 David Dejaeghere<br>
        <<a href="mailto:david.dejaeghere@gmail.com" target="_blank">david.dejaeghere@gmail.com</a> <mailto:<a href="mailto:david.dejaeghere@gmail.com" target="_blank">david.dejaeghere@gmail.com</a>><br></span>
        <mailto:<a href="mailto:david.dejaeghere@gmail.com" target="_blank">david.dejaeghere@gmail.com</a><span class=""><br>
        <mailto:<a href="mailto:david.dejaeghere@gmail.com" target="_blank">david.dejaeghere@gmail.com</a>>>>:<br>
<br>
             Hi Honza,<br>
<br>
             That gave me the exact same output.  Any ideas?<br>
<br>
             Regards,<br>
<br>
             D<br>
<br>
             2015-04-15 7:33 GMT+02:00 Jan Cholasta <<a href="mailto:jcholast@redhat.com" target="_blank">jcholast@redhat.com</a><br>
        <mailto:<a href="mailto:jcholast@redhat.com" target="_blank">jcholast@redhat.com</a>><br></span>
             <mailto:<a href="mailto:jcholast@redhat.com" target="_blank">jcholast@redhat.com</a> <mailto:<a href="mailto:jcholast@redhat.com" target="_blank">jcholast@redhat.com</a>>>>:<div><div class="h5"><br>
<br>
                 Hi,<br>
<br>
                 Dne 14.4.2015 v 19:47 Rob Crittenden napsal(a):<br>
<br>
                     David Dejaeghere wrote:<br>
<br>
                         Hi Rob,<br>
<br>
                         So you want to output of the command using pk12<br>
        with<br>
                         server cert and<br>
                         key? or with the ca chain in there too?<br>
<br>
<br>
                     Oddly enough it is failing in exactly the same<br>
        place. Those<br>
                     GoDaddy CA<br>
                     certs are still being loaded from somewhere, I'm<br>
        not sure<br>
                     where, and I<br>
                     suspect that is the source of the problem.<br>
<br>
<br>
                 They are in the default CA certificate bundle (in the<br>
                 ca-certificate package). I guess NSS loads it<br>
        automatically.<br>
<br>
<br>
                     I'm going to forward the log to a colleague who has<br>
        worked<br>
                     on this code<br>
                     more recently than I have. Maybe he will have an idea.<br>
<br>
<br>
                 Could you try if the following works?<br>
<br>
                      # mv<br>
        /usr/share/pki/ca-trust-__source/ca-bundle.trust.crt<br>
                 /root/ca-bundle.trust.crt<br>
<br>
                      # update-ca-trust<br>
<br>
                      # ipa-replica-prepare ...<br>
<br>
                      # mv /root/ca-bundle.trust.crt<br>
                 /usr/share/pki/ca-trust-__source/ca-bundle.trust.crt<br>
<br>
                      # update-ca-trust<br>
<br>
<br>
                     rob<br>
<br>
<br>
                 Honza<br>
<br>
                 --<br>
                 Jan Cholasta<br>
<br>
<br>
<br>
<br>
<br>
    --<br>
    Jan Cholasta<br>
<br>
<br>
</div></div></blockquote><span class="HOEnZb"><font color="#888888">
<br>
<br>
-- <br>
Jan Cholasta<br>
</font></span></blockquote></div><br></div>