[Freeipa-users] Ipa cert automatic renew Failing.

Lucas Diedrich lucas.diedrich at gmail.com
Wed Dec 21 18:52:48 UTC 2016


Hello guys,

I'm having some trouble with, whats is happening with my server is that i'm
hiting an old BUG (https://bugzilla.redhat.com/show_bug.cgi?id=1033273).
Talking to mbasti over irc he oriented me to send this to the email list.

The problem is, i got on CA Master, so because of this problem the CA
Master certificates couldn't be renewd, so now i promoted another master to
be the CA. And the problem still persist.

This is the certs from my new CA (
https://paste.fedoraproject.org/510617/14823448/),
this is the certs from my old CA (
https://paste.fedoraproject.org/510618/44871148/)
This is the log then i restart pki-tomcat(  "CA port 636 Error
netscape.ldap.LDAPException: Authentication failed (49)")
This is the log from dirsrv when i restart pki-tomcat (
https://paste.fedoraproject.org/510614/23446801/)

Basically my CA is not working anymore...

Anyway, i tried lots of thing but couldn't fix this, anyone has some idea?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20161221/a4499ece/attachment.htm>


More information about the Freeipa-users mailing list