<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<br>
<br>
<div class="moz-cite-prefix">On 29.04.2016 13:02, <a class="moz-txt-link-abbreviated" href="mailto:barrykfl@gmail.com">barrykfl@gmail.com</a>
wrote:<br>
</div>
<blockquote
cite="mid:CAELz9dsVM1-TYv2+rx5JEDgG1SQUJj1RR2su7tbbpFj0C=1W+A@mail.gmail.com"
type="cite">
<div dir="ltr">
<div>Hi All:</div>
<div><br>
</div>
<div>Any method can fall back the default ipa cert if I didn't
backup orginal?</div>
<div><br>
</div>
<div>Now the slapd and ipa cert storage quite a mess so they
cant replicate even disabled nsslapd:security to off</div>
<div><br>
</div>
<div><br>
</div>
<div>thx</div>
<div>Barry</div>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
</blockquote>
Hello Barry,<br>
<br>
Can you provide more info?<br>
<br>
What is your IPA version, OS?<br>
What are the symptoms you are experiencing?<br>
What do you mean by default ipa cert ?<br>
Can you provide logs from replicas?<br>
Can you provide `getcert list` command output?<br>
Can you provide `ipactl status` from both server?<br>
<br>
Replication uses GSSAPI, at least on new IPA versions, I'm not sure
if certificates are involved in this.<br>
<br>
Martin<br>
</body>
</html>