<div dir="ltr">I've had issues with expired certificates. In the course of troubleshooting I've somehow set the cas to external. Is there a way I can switch back?<br><br>[root@id-management-1 conf]# getcert list-cas<br>CA 'SelfSign':<br>        is-default: no<br>        ca-type: INTERNAL:SELF<br>        next-serial-number: 01<br>CA 'IPA':<br>        is-default: no<br>        ca-type: EXTERNAL<br>        helper-location: /usr/libexec/certmonger/ipa-server-guard /usr/libexec/certmonger/ipa-submit<br>CA 'certmaster':<br>        is-default: no<br>        ca-type: EXTERNAL<br>        helper-location: /usr/libexec/certmonger/certmaster-submit<br>CA 'dogtag-ipa-renew-agent':<br>        is-default: no<br>        ca-type: EXTERNAL<br>        helper-location: /usr/libexec/certmonger/ipa-server-guard /usr/libexec/certmonger/dogtag-ipa-renew-agent-submit<br>CA 'local':<br>        is-default: no<br>        ca-type: EXTERNAL<br>        helper-location: /usr/libexec/certmonger/local-submit<br>CA 'dogtag-ipa-ca-renew-agent':<br>        is-default: no<br>        ca-type: EXTERNAL<br>        helper-location: /usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit -vv<br><br clear="all"><div>Thanks,<br><br></div><div>Jeff<br></div><div><br></div></div>