[Freeipa-users] Recovering from messed-up certs
rcritten at redhat.com
Thu Oct 23 20:05:35 UTC 2014
Eric McCoy wrote:
> Some nicknames changed to protect the innocent. The
> puppetmaster/hostname cert is nominally unrelated, though its creation
> was contemporaneous with the disappearance of server-cert so I can't
> entirely rule it out.
> Certificate Nickname Trust
> puppetmaster/hostname u,u,u
> REALMNAME IPA CA CT,C,C
> ipaCert u,u,u
> Signing-Cert u,u,u
Ok, this is good. If we have ipaCert we can get a cert directly from the
CA like we do during installation.
The attached python script should fix things up for you.
Save it, modify it and replace subjectbase with what matches your
environment. You can get the base from an existing cert with:
# certutil -L -d /etc/dirsrv/slapd-REALM -n Server-Cert |grep Subject
Unless you changed it during installation it should be O=<REALM>
Then just run the script:
# python newcert.py
Setting up NSS databases
Untracking existing Apache Server-Cert
Issuing new cert
# service httpd start
The only thing this script doesn't do is put this updated certificate in
the service record's LDAP entry.
> On Thu, Oct 23, 2014 at 12:53 PM, Rob Crittenden <rcritten at redhat.com
> <mailto:rcritten at redhat.com>> wrote:
> Eric McCoy wrote:
> > Hi all,
> > I somehow destroyed my primary IPA server's Server-Cert in
> > /etc/httpd/alias. I don't understand how or why it happened, all
> I know
> > is that I went to restart Apache and it was gone. Apache won't start,
> > of course, because the cert is missing. I can't issue a new cert
> on the
> > primary because Apache is down. I tried using the secondary, but it
> > fails saying that it can't connect to the web server on the primary
> > (it's the same error message I get when I try to issue a cert from the
> > primary). I can't figure out how to tell ipa-getcert et al. to
> talk to
> > the secondary and not the primary. I'm not using DNS for service
> > discovery, so I'm not sure how the various tools figure out where
> > are.
> > This is all on CentOS 6.5 with IPA 3.0.0-37.
> What certs do you have in the database?
> # certutil -L -d /etc/httpd/alias
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 769 bytes
Desc: not available
More information about the Freeipa-users