[Freeipa-users] Urgent Help Needed - CA subsystem certificate renewal

Martin Kosek mkosek at redhat.com
Fri Nov 14 10:20:17 UTC 2014


On 11/14/2014 08:02 AM, pki tech wrote:
> Dear All,
>
> In our Issuing CA, all the subsystem certificates are expired except the
> caSigningCert.
>
> I can generate the new certificate requests via certutil, but how can i get
> them signed?
>
> your swift response is appreciated.
>
> Regards,
> Kamal

What IPA version did you use? We have a related howto article on FreeIPA.org 
wiki with instructions what to do when PKI subsystem certificate expire:

http://www.freeipa.org/page/IPA_2x_Certificate_Renewal

Also CCing Jan who owns the PKI knowledge.

Martin




More information about the Freeipa-users mailing list