<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Sep 30, 2016 at 10:45 AM, Rob Crittenden <span dir="ltr"><<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Natxo Asenjo wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="gmail-">
<br>
<br>
On Thu, Sep 29, 2016 at 1:16 PM, Rob Crittenden <<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a><br></span><span class="gmail-">
<mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>>> wrote:<br>
<br>
    Natxo Asenjo wrote:<br>
<br>
<br>
<br>
        On Tue, Sep 27, 2016 at 1:42 PM, Rob Crittenden<br>
        <<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a> <mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>><br></span><span class="gmail-">
        <mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a> <mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>>>> wrote:<br>
<br>
<br>
             It's hard to say, it may in fact not be a problem.<br>
<br>
             It is really a matter of what service the certificate(s)<br>
        are related<br>
             to. I'd look at the serial numbers and then correlate those<br>
        to the<br>
             issued certificates.<br>
<br>
             I'd also do a service-find on the hostname to see if any<br>
        services<br>
             have certificates issued and with what serial numbers.<br>
<br>
<br>
        I agree, it could be that. But just for testing I have created a vm,<br>
        joined it to the domain and resubmitted the certificate.<br>
<br>
        Now there are two valid host certificates with the same subject:<br>
<br>
<br>
           $ ipa cert-find --subject=<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.irisz<wbr>org.nl</a><br>
        <<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>><br></span>
        <<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a><span class="gmail-"><br>
        <<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>>><br>
        ----------------------<br>
        2 certificates matched<br>
        ----------------------<br>
            Serial number (hex): 0x3FFE0002<br>
            Serial number: 1073610754<br>
            Status: VALID<br>
            Subject: CN=<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.iriszorg.nl</a><br>
        <<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>><br></span>
        <<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a><span class="gmail-"><br>
        <<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>>>,O=<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">UNIX.IRISZORG.NL</a><br>
        <<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">http://UNIX.IRISZORG.NL</a>><br>
        <<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">http://UNIX.IRISZORG.NL</a>><br>
<br>
            Serial number (hex): 0x3FFE0003<br>
            Serial number: 1073610755<br>
            Status: VALID<br>
            Subject: CN=<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.iriszorg.nl</a><br>
        <<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>><br></span>
        <<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a><span class="gmail-"><br>
        <<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>>>,O=<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">UNIX.IRISZORG.NL</a><br>
        <<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">http://UNIX.IRISZORG.NL</a>><br></span><span class="gmail-">
        <<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">http://UNIX.IRISZORG.NL</a>><br>
        ----------------------------<br>
        Number of entries returned 2<br>
        ----------------------------<br>
<br>
<br>
        So it certmonger in this centos 6.8 32bit host is renewing but not<br>
        having the old certificate revoked.<br>
<br>
<br>
    I'd check the Apache log to find the cert_request call to see if you<br>
    can see if there are any issues raised. It should be doing a<br>
    cert_revoke at the same time.<br>
<br>
    Can you should how this certificate is being tracked?<br>
<br>
<br>
sure:<br>
<br>
$ sudo getcert list<br>
Number of certificates and requests being tracked: 1.<br>
Request ID '20160929100945':<br>
     status: MONITORING<br>
     stuck: no<br>
     key pair storage:<br>
type=NSSDB,location='/etc/pki/<wbr>nssdb',nickname='IPA Machine Certificate -<br>
<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.iriszorg.nl</a><br></span>
<<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>>',token='NSS Certificate DB'<span class="gmail-"><br>
     certificate: type=NSSDB,location='/etc/pki/<wbr>nssdb',nickname='IPA<br>
Machine Certificate - <a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.iriszorg.nl</a><br></span>
<<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>>',token='NSS Certificate DB'<span class="gmail-"><br>
     CA: IPA<br>
     issuer: CN=Certificate Authority,O=<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">UNIX.IRISZORG.NL</a><br></span>
<<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">http://UNIX.IRISZORG.NL</a>><br>
     subject: CN=<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.iriszorg.nl</a><span class="gmail-"><br>
<<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>>,O=<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">UNIX.IRISZORG.NL</a><br>
<<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">http://UNIX.IRISZORG.NL</a>><br></span><span class="gmail-">
     expires: 2018-09-30 10:13:17 UTC<br>
     principal name: host/<a href="mailto:throwaway.unix.iriszorg.nl@UNIX.IRISZORG.NL" target="_blank">throwaway.unix.iriszorg.n<wbr>l@UNIX.IRISZORG.NL</a><br></span>
<mailto:<a href="mailto:throwaway.unix.iriszorg.nl@UNIX.IRISZORG.NL" target="_blank">throwaway.unix.iriszor<wbr>g.nl@UNIX.IRISZORG.NL</a>><span class="gmail-"><br>
     key usage:<br>
digitalSignature,nonRepudiatio<wbr>n,keyEncipherment,dataEncipher<wbr>ment<br>
     eku: id-kp-serverAuth,id-kp-clientA<wbr>uth<br>
     pre-save command:<br>
     post-save command:<br>
     track: yes<br>
     auto-renew: yes<br>
<br>
now, let's resubmit:<br>
<br>
$ sudo ipa-getcert resubmit -i 20160929100945<br>
Resubmitting "20160929100945" to "IPA".<br>
[jose.admin@throwaway ~]$ sudo getcert list<br>
Number of certificates and requests being tracked: 1.<br>
Request ID '20160929100945':<br>
     status: MONITORING<br>
     stuck: no<br>
     key pair storage:<br>
type=NSSDB,location='/etc/pki/<wbr>nssdb',nickname='IPA Machine Certificate -<br>
<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.iriszorg.nl</a><br></span>
<<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>>',token='NSS Certificate DB'<span class="gmail-"><br>
     certificate: type=NSSDB,location='/etc/pki/<wbr>nssdb',nickname='IPA<br>
Machine Certificate - <a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.iriszorg.nl</a><br></span>
<<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>>',token='NSS Certificate DB'<span class="gmail-"><br>
     CA: IPA<br>
     issuer: CN=Certificate Authority,O=<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">UNIX.IRISZORG.NL</a><br></span>
<<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">http://UNIX.IRISZORG.NL</a>><br>
     subject: CN=<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.iriszorg.nl</a><span class="gmail-"><br>
<<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>>,O=<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">UNIX.IRISZORG.NL</a><br>
<<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">http://UNIX.IRISZORG.NL</a>><br></span><span class="gmail-">
     expires: 2018-09-30 20:41:28 UTC<br>
     principal name: host/<a href="mailto:throwaway.unix.iriszorg.nl@UNIX.IRISZORG.NL" target="_blank">throwaway.unix.iriszorg.n<wbr>l@UNIX.IRISZORG.NL</a><br></span>
<mailto:<a href="mailto:throwaway.unix.iriszorg.nl@UNIX.IRISZORG.NL" target="_blank">throwaway.unix.iriszor<wbr>g.nl@UNIX.IRISZORG.NL</a>><span class="gmail-"><br>
     key usage:<br>
digitalSignature,nonRepudiatio<wbr>n,keyEncipherment,dataEncipher<wbr>ment<br>
     eku: id-kp-serverAuth,id-kp-clientA<wbr>uth<br>
     pre-save command:<br>
     post-save command:<br>
     track: yes<br>
     auto-renew: yes<br>
<br>
so it has been successfully renewed.<br>
<br>
In the access_log of the kdc I see this:<br>
<br>
172.20.4.228 - - [29/Sep/2016:22:41:27 +0200] "POST<br>
<a href="https://kdc03.unix.iriszorg.nl:443/ca/eeca/ca/profileSubmitSSLClient" rel="noreferrer" target="_blank">https://kdc03.unix.iriszorg.nl<wbr>:443/ca/eeca/ca/profileSubmitS<wbr>SLClient</a><br>
HTTP/1.1" 200 1913<br>
172.20.6.81 - host/<a href="mailto:throwaway.unix.iriszorg.nl@UNIX.IRISZORG.NL" target="_blank">throwaway.unix.iriszorg.n<wbr>l@UNIX.IRISZORG.NL</a><br></span>
<mailto:<a href="mailto:throwaway.unix.iriszorg.nl@UNIX.IRISZORG.NL" target="_blank">throwaway.unix.iriszor<wbr>g.nl@UNIX.IRISZORG.NL</a>><span class="gmail-"><br>
[29/Sep/2016:22:41:27 +0200] "POST /ipa/xml HTTP/1.1" 200 2929<br>
<br>
and in the error_log:<br>
[Thu Sep 29 22:41:28.<a href="tel:626669%202016" value="+16266692016" target="_blank">626669 2016</a>] [:error] [pid 4617] ipa: INFO:<br>
[xmlserver] host/<a href="mailto:throwaway.unix.iriszorg.nl@UNIX.IRISZORG.NL" target="_blank">throwaway.unix.iriszorg.n<wbr>l@UNIX.IRISZORG.NL</a><br></span>
<mailto:<a href="mailto:throwaway.unix.iriszorg.nl@UNIX.IRISZORG.NL" target="_blank">throwaway.unix.iriszor<wbr>g.nl@UNIX.IRISZORG.NL</a>>:<br>
cert_request(u'MIID6DCCAtACAQA<wbr>wQDEZMBcGA1UEChMQVU5JWC5JUklTW<wbr>k9SRy5OTDEjMCEGA1UEAxMadGhyb3d<wbr>hd2F5LnVuaXguaXJpc3pvcmcubmwwg<wbr>gEiMA0GCSqGSIb3DQEBAQUAA4IBDwA<wbr>wggEKAoIBAQC4jBk7V2D5pX12kYrr+<wbr>+lwsWq1UWHy6PM9O+B/GvxaI0JoARB<wbr>rhR6MKI1Ev+DV2r5ukNNWHj5+/kKbt<wbr>W9XI2XMZ9pIBSwG3SG4m9s3gQV3dGQ<wbr>jlRCcU+MgXiDxRtRy2Vdzd1fZ9xdB1<wbr>txH3ZnZfceTosNw4Jp3bm/VtPChWJe<wbr>N6K671FLRCzJkI1KrC+LHfGbvyTtOi<wbr>pB5O9t8RkN4Qh01r/rphPvt9Gh+/<wbr>mTlHnmGP9+sseqHHsgv2fPvRQowpJD<wbr>EytTX5w/8pLrUCATqJUYfxK5RDuwD1<wbr>304p3WXDFLoU6p2xaR63h34muj1a5N<wbr>V1CvQFqJapHB5B/w6uUbLzjg3AgMBA<wbr>AGgggFhMHcGCSqGSIb3DQEJFDFqHmg<wbr>ASQBQAEEAIABNAGEAYwBoAGkAbgBlA<wbr>CAAQwBlAHIAdABpAGYAaQBjAGEAdAB<wbr>lACAALQAgAHQAaAByAG8AdwBhAHcAY<wbr>QB5AC4AdQBuAGkAeAAuAGkAcgBpAHM<wbr>AegBvAHIAZwAuAG4AbDCB5QYJKoZIh<wbr>vcNAQkOMYHXMIHUMIGhBgNVHREBAQA<wbr>EgZYwgZOgQAYKKwYBBAGCNxQCA6AyD<wbr>DBob3N0L3Rocm93YXdheS51bml4Lml<wbr>yaXN6b3JnLm5sQFVOSVguSVJJU1pPU<wbr>kcuTkygTwYGKwYBBQICoEUwQ6ASGxB<wbr>VTklYLklSSVNaT1JHLk5MoS0wK6ADA<wbr>gEBoSQwIhsEaG9zdBsadGhyb3dhd2F<wbr>5LnVuaXguaXJpc3pvcmcubmwwDAYDV<wbr>R0TAQH/BAIwADAgBgNVHQ4BAQAEFgQ<wbr>UgXWL3vdW/I31tQxv5YjyMZy4x8kw!<br>
</blockquote>
DQYJKoZIhv<br>
cNAQELBQADggEBAD674/oGYlQTQDSv<wbr>wf0muYoxBsj1dc6gnArw0JJpGVCNMv<wbr>/J3FdgOLcOhxzZcOfZiQr4NdYoV+/6<wbr>mISOhknMa4ErJhqSAWbUA+w3+lL3CH<wbr>fdDtNueUjZRbPZezcC0rhAlnXBT7ia<wbr>kjuhE56WkZz7AihEU8RAvnZfSRi1mh<wbr>ehf3wFRYKWuzK9AW1DTY/uGMmHXiFt<wbr>vINpfAJ3yL66xPwTj4087nz9w4YUqN<wbr>yCX+hYL+7idCJeoMjDyCqYQpjFkdfZ<wbr>hRuNd+rrKWTgYvKN3w/5+ItefDCYy8<wbr>py91V2kXS7BrsYjd+2YHtQ2AbjgIW2<wbr>xpTr/+PetToZyL50oWCpduT5t+M=',<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
principal=u'host/<a href="mailto:throwaway.unix.iriszorg.nl@UNIX.IRISZORG.NL" target="_blank">throwaway.uni<wbr>x.iriszorg.nl@UNIX.IRISZORG.NL</a><br>
<mailto:<a href="mailto:throwaway.unix.iriszorg.nl@UNIX.IRISZORG.NL" target="_blank">throwaway.unix.iriszor<wbr>g.nl@UNIX.IRISZORG.NL</a>>', add=True,<span class="gmail-"><br>
version=u'2.51'): SUCCESS<br>
<br>
and now I have 3 valid certificates:<br>
<br>
$ ipa cert-find --subject=<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.irisz<wbr>org.nl</a><br></span>
<<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>><span class="gmail-"><br>
----------------------<br>
3 certificates matched<br>
----------------------<br>
   Serial number (hex): 0xFF9000D<br>
   Serial number: 267976717<br>
   Status: VALID<br></span><span class="gmail-">
   Subject: CN=<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.iriszorg.nl</a><br>
<<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>>,O=<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">UNIX.IRISZORG.NL</a><br>
<<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">http://UNIX.IRISZORG.NL</a>><br>
<br>
   Serial number (hex): 0x3FFE0002<br>
   Serial number: 1073610754<br>
   Status: VALID<br>
   Subject: CN=<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.iriszorg.nl</a><br>
<<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>>,O=<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">UNIX.IRISZORG.NL</a><br>
<<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">http://UNIX.IRISZORG.NL</a>><br>
<br>
   Serial number (hex): 0x3FFE0003<br>
   Serial number: 1073610755<br>
   Status: VALID<br>
   Subject: CN=<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.iriszorg.nl</a><br>
<<a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">http://throwaway.unix.iriszor<wbr>g.nl</a>>,O=<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">UNIX.IRISZORG.NL</a><br>
<<a href="http://UNIX.IRISZORG.NL" rel="noreferrer" target="_blank">http://UNIX.IRISZORG.NL</a>><br>
----------------------------<br></span>
Number of entries returned 3<br>
----------------------------<br>
</blockquote>
<br>
Ok, let me start by saying that this is not a bug in either certmonger or dogtag. IPA is supposed to do the revocation in the cert_request command.<br>
<br>
The steps IPA _should_ be taking are:<br>
<br>
1. Figure out if we are doing a certificate for a host or a service.<br>
2. See if the requester is allowed to manage this entry<br>
3. Look at the entry to see if it has a usercertificate attribute. If so revoke that serial number, then clear the usercertificate value in the host or service entry (via service_mod or host_mod)<br>
4. Request a new certificate<br>
5. Update IPA with the new value<br>
<br>
Does a certificate appear in ipa host-show <a href="http://throwaway.unix.iriszorg.nl" rel="noreferrer" target="_blank">throwaway.unix.iriszorg.nl</a>, and which certificate serial number?<span class="gmail-HOEnZb"><font color="#888888"><br>
</font></span></blockquote></div><br>$ ipa host-show throwaway<br>  Host name: <a href="http://throwaway.unix.iriszorg.nl">throwaway.unix.iriszorg.nl</a><br>  Certificate: MIIE0DCCA7igAwIBAgIED/kADTANBgkqhkiG9w0BAQsFADA7MRkwFwYDVQQKExBVTklYLklSSVNaT1JHLk5MMR4wHAYDVQQDExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcNMTYwOTI5MjA0MTI4WhcNMTgwOTMwMjA0MTI4WjBAMRkwFwYDVQQKDBBVTklYLklSSVNaT1JHLk5MMSMwIQYDVQQDDBp0aHJvd2F3YXkudW5peC5pcmlzem9yZy5ubDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALiMGTtXYPmlfXaRiuv76XCxarVRYfLo8z074H8a/FojQmgBEGuFHowojUS/4NXavm6Q01YePn7+Qpu1b1cjZcxn2kgFLAbdIbib2zeBBXd0ZCOVEJxT4yBeIPFG1HLZV3N3V9n3F0HW3Efdmdl9x5Oiw3Dgmndub9W08KFYl43orrvUUtELMmQjUqsL4sd8Zu/JO06KkHk723xGQ3hCHTWv+umE++30aH7+ZOUeeYY/36yx6oceyC/Z8+9FCjCkkMTK1NfnD/ykutQIBOolRh/ErlEO7APXfTindZcMUuhTqnbFpHreHfia6PVrk1XUK9AWolqkcHkH/Dq5RsvOODcCAwEAAaOCAdUwggHRMB8GA1UdIwQYMBaAFKOX5IouuM8+6jPyvJPWI96phDZoMEIGCCsGAQUFBwEBBDYwNDAyBggrBgEFBQcwAYYmaHR0cDovL2lwYS1jYS51bml4LmlyaXN6b3JnLm5sL2NhL29jc3AwDgYDVR0PAQH/BAQDAgTwMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjB7BgNVHR8EdDByMHCgOKA2hjRodHRwOi8vaXBhLWNhLnVuaXguaXJpc3pvcmcubmwvaXBhL2NybC9NYXN0ZXJDUkwuYmluojSkMjAwMQ4wDAYDVQQKDAVpcGFjYTEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB0GA1UdDgQWBBSBdYve91b8jfW1DG/liPIxnLjHyTCBngYDVR0RBIGWMIGToEAGCisGAQQBgjcUAgOgMgwwaG9zdC90aHJvd2F3YXkudW5peC5pcmlzem9yZy5ubEBVTklYLklSSVNaT1JHLk5MoE8GBisGAQUCAqBFMEOgEhsQVU5JWC5JUklTWk9SRy5OTKEtMCugAwIBAaEkMCIbBGhvc3QbGnRocm93YXdheS51bml4LmlyaXN6b3JnLm5sMA0GCSqGSIb3DQEBCwUAA4IBAQB6KplOoHG5d2+3c5J/TSE/qxWkfObqPdpzYSMg5ma+PKL7ofuEgtozfoZfH/GXKIKtUpPZCJL2NQQKauagdIwto7PX184FcohCjJxHD30RRbc6q2rm3PE7Q1vDzSxW1ZCFELmpvK0XN4YX1tz6iaPgo2B7wuyhbZpT4Vd2itT1rOQ6cAnAB7BFhVNj5XDPDoMaHabtWRJVLlIOMeGyrZDUMxmoPys5g1c1SZM1ld+8+zdgqIVEsdTo9qThqPraTUi8GTjP4QvuQkLbnlFO6KQe5RqfbVXA0gKVWDtepY7h+cBQxMa/eHROFtnhW/w1+FdKHDPvOdj8aTF1tSIU2RYP,<br>               MIIE0DCCA7igAwIBAgIEP/4AAjANBgkqhkiG9w0BAQsFADA7MRkwFwYDVQQKExBVTklYLklSSVNaT1JHLk5MMR4wHAYDVQQDExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcNMTYwOTI5MTAwOTUwWhcNMTgwOTMwMTAwOTUwWjBAMRkwFwYDVQQKDBBVTklYLklSSVNaT1JHLk5MMSMwIQYDVQQDDBp0aHJvd2F3YXkudW5peC5pcmlzem9yZy5ubDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALiMGTtXYPmlfXaRiuv76XCxarVRYfLo8z074H8a/FojQmgBEGuFHowojUS/4NXavm6Q01YePn7+Qpu1b1cjZcxn2kgFLAbdIbib2zeBBXd0ZCOVEJxT4yBeIPFG1HLZV3N3V9n3F0HW3Efdmdl9x5Oiw3Dgmndub9W08KFYl43orrvUUtELMmQjUqsL4sd8Zu/JO06KkHk723xGQ3hCHTWv+umE++30aH7+ZOUeeYY/36yx6oceyC/Z8+9FCjCkkMTK1NfnD/ykutQIBOolRh/ErlEO7APXfTindZcMUuhTqnbFpHreHfia6PVrk1XUK9AWolqkcHkH/Dq5RsvOODcCAwEAAaOCAdUwggHRMB8GA1UdIwQYMBaAFKOX5IouuM8+6jPyvJPWI96phDZoMEIGCCsGAQUFBwEBBDYwNDAyBggrBgEFBQcwAYYmaHR0cDovL2lwYS1jYS51bml4LmlyaXN6b3JnLm5sL2NhL29jc3AwDgYDVR0PAQH/BAQDAgTwMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjB7BgNVHR8EdDByMHCgOKA2hjRodHRwOi8vaXBhLWNhLnVuaXguaXJpc3pvcmcubmwvaXBhL2NybC9NYXN0ZXJDUkwuYmluojSkMjAwMQ4wDAYDVQQKDAVpcGFjYTEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB0GA1UdDgQWBBSBdYve91b8jfW1DG/liPIxnLjHyTCBngYDVR0RBIGWMIGToEAGCisGAQQBgjcUAgOgMgwwaG9zdC90aHJvd2F3YXkudW5peC5pcmlzem9yZy5ubEBVTklYLklSSVNaT1JHLk5MoE8GBisGAQUCAqBFMEOgEhsQVU5JWC5JUklTWk9SRy5OTKEtMCugAwIBAaEkMCIbBGhvc3QbGnRocm93YXdheS51bml4LmlyaXN6b3JnLm5sMA0GCSqGSIb3DQEBCwUAA4IBAQCvTRaJrl3J7Ky4VkFVfkwIGoaxocXrllYSjXZzhzHV0zJtlVeQGmHwulyrEbEzaRuMqbXe7c8WseOgU/K+UwByGiZoyxUmHgBmu2mv8Cln48UbESEAm0py4hRMmE7UzIhsHzTAKjUfyQXujB21S+FYwd97QymGRgn7kJ2TtH99zslQO0kMC//LmctUxIfTOOcrBgOojIEpcbzTeWNcyuN5+MHr6H2DNUYQZpvnDBv7XVphrk7ACrh4ETeYW5E1fFl84CdSxWehhWILF6t2WdA4RSjvtg3zvMPL+uVU8w1aru33dMuCKqvMG3iaRrDjVZ4k9/36lpf4/r1PwKYxusvg,<br>               MIIE0DCCA7igAwIBAgIEP/4AAzANBgkqhkiG9w0BAQsFADA7MRkwFwYDVQQKExBVTklYLklSSVNaT1JHLk5MMR4wHAYDVQQDExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcNMTYwOTI5MTAxMzE3WhcNMTgwOTMwMTAxMzE3WjBAMRkwFwYDVQQKDBBVTklYLklSSVNaT1JHLk5MMSMwIQYDVQQDDBp0aHJvd2F3YXkudW5peC5pcmlzem9yZy5ubDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALiMGTtXYPmlfXaRiuv76XCxarVRYfLo8z074H8a/FojQmgBEGuFHowojUS/4NXavm6Q01YePn7+Qpu1b1cjZcxn2kgFLAbdIbib2zeBBXd0ZCOVEJxT4yBeIPFG1HLZV3N3V9n3F0HW3Efdmdl9x5Oiw3Dgmndub9W08KFYl43orrvUUtELMmQjUqsL4sd8Zu/JO06KkHk723xGQ3hCHTWv+umE++30aH7+ZOUeeYY/36yx6oceyC/Z8+9FCjCkkMTK1NfnD/ykutQIBOolRh/ErlEO7APXfTindZcMUuhTqnbFpHreHfia6PVrk1XUK9AWolqkcHkH/Dq5RsvOODcCAwEAAaOCAdUwggHRMB8GA1UdIwQYMBaAFKOX5IouuM8+6jPyvJPWI96phDZoMEIGCCsGAQUFBwEBBDYwNDAyBggrBgEFBQcwAYYmaHR0cDovL2lwYS1jYS51bml4LmlyaXN6b3JnLm5sL2NhL29jc3AwDgYDVR0PAQH/BAQDAgTwMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjB7BgNVHR8EdDByMHCgOKA2hjRodHRwOi8vaXBhLWNhLnVuaXguaXJpc3pvcmcubmwvaXBhL2NybC9NYXN0ZXJDUkwuYmluojSkMjAwMQ4wDAYDVQQKDAVpcGFjYTEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB0GA1UdDgQWBBSBdYve91b8jfW1DG/liPIxnLjHyTCBngYDVR0RBIGWMIGToEAGCisGAQQBgjcUAgOgMgwwaG9zdC90aHJvd2F3YXkudW5peC5pcmlzem9yZy5ubEBVTklYLklSSVNaT1JHLk5MoE8GBisGAQUCAqBFMEOgEhsQVU5JWC5JUklTWk9SRy5OTKEtMCugAwIBAaEkMCIbBGhvc3QbGnRocm93YXdheS51bml4LmlyaXN6b3JnLm5sMA0GCSqGSIb3DQEBCwUAA4IBAQCh6lySZa1AyUyP8AuaLUDj6X0Lt/tGS+ZIw/O248FVMJDwvLvkFUxOjTAK1mip0AHxkib+QtKqFgN9lbidnxeKFYNN2komTfLgFV+G+8kBIInxWbU1OsuYw4J6xCu5IE+F7jfdHX1yw6HSgDixYgKHe9mw+8HTbUR1a/ntZ90pmai8I7daem9bMrPHGSSChjcbjif6YNZ8ibmilqq0vw8CEwQopXFToO/mHfbXNDw6gJY5rKu19fWPi3VRQdQxKKtwY/gXg39q4FWBymDaMwjErC7G4AnGeeTYp4iFYZkfcjYvdxGXGF0CpLgunvcMMQ0rTYx5w1MrLbbnqjq1qBZO<br>  Principal name: host/<a href="mailto:throwaway.unix.iriszorg.nl@UNIX.IRISZORG.NL">throwaway.unix.iriszorg.nl@UNIX.IRISZORG.NL</a><br>  Password: False<br>  Keytab: True<br>  Managed by: <a href="http://throwaway.unix.iriszorg.nl">throwaway.unix.iriszorg.nl</a><br>  Subject: CN=<a href="http://throwaway.unix.iriszorg.nl">throwaway.unix.iriszorg.nl</a>,O=<a href="http://UNIX.IRISZORG.NL">UNIX.IRISZORG.NL</a><br>  Serial Number: 267976717<br>  Serial Number (hex): 0xFF9000D<br>  Issuer: CN=Certificate Authority,O=<a href="http://UNIX.IRISZORG.NL">UNIX.IRISZORG.NL</a><br>  Not Before: Thu Sep 29 20:41:28 2016 UTC<br>  Not After: Sun Sep 30 20:41:28 2018 UTC<br>  Fingerprint (MD5): 52:a1:06:a1:39:27:bc:ed:dd:45:f5:36:32:11:99:c1<br>  Fingerprint (SHA1): 81:d4:01:5a:26:83:9c:c4:fb:76:fb:c3:29:cd:32:c1:8a:4c:eb:45<br>  SSH public key fingerprint: 61:66:4D:D7:E6:83:B3:31:BB:50:C3:28:11:79:FD:42 (ssh-rsa),<br>                              71:80:40:26:50:64:CD:FE:9A:FB:8D:DA:55:56:18:95 (ssh-dss)<br clear="all"><br><br></div><div class="gmail_extra">so it shows the three certificates but the serial is 267976717<br><br></div><div class="gmail_extra"><div class="gmail_signature">--<br>Groeten,<br>natxo</div>
</div></div>