<div dir="ltr"><div>Hi all,<br><br>I have inherited a IPA system that has an expired cert and the old admins have left; I followed (<a href="http://www.freeipa.org/page/IPA_2x_Certificate_Renewal">http://www.freeipa.org/page/IPA_2x_Certificate_Renewal</a>) but running into errors when I try to renew the CA certs even after time is reset.  Also tried the troubleshooting under (<a href="http://www.freeipa.org/page/Troubleshooting#Authentication_Errors">http://www.freeipa.org/page/Troubleshooting#Authentication_Errors</a>); specifically using "certutil -L -d /etc/httpd/alias -n ipaCert -a > /tmp/ra.crt" to add the cert in the database.<br><br>From the output of getcert list, I see both CA_UNREACHABLE and NEED_CSR_GEN_PIN.  I followed redhat article here (<a href="https://access.redhat.com/solutions/1142913">https://access.redhat.com/solutions/1142913</a>) which verified key file password is correct and I have reset time.  However the NEED_CSR_GEN_PIN status remains.  My company actually has redhat support but when they built this IPA whoever built it was using Centos 6 so I am out of luck here.<br><br>Would really appreciate any help since I am stuck at this point?  What else I can do at this point?  e.g. Is generate a new CA cert necessary, etc.?<br><br>Version:<br>ipa-pki-ca-theme.noarch                    9.0.3-7.el6                        @base<br>ipa-pki-common-theme.noarch          9.0.3-7.el6                        @base<br>ipa-pmincho-fonts.noarch             003.02-3.1.el6                     @base<br>ipa-python.x86_64                    3.0.0-47.el6.centos.2              @updates<br>ipa-server.x86_64                    3.0.0-47.el6.centos.2              @updates<br>ipa-server-selinux.x86_64            3.0.0-47.el6.centos.2              @updates<br><br>Part of error logs from /var/log/pki-ca/debug after I reset clock; I see these errors which I think is relevlant?:<br>[27/Dec/2015:14:12:01][main]: SigningUnit init: debug org.mozilla.jss.crypto.ObjectNotFoundException<br>Certificate object not found<br>[27/Dec/2015:14:12:01][main]: CMS:Caught EBaseException<br>Certificate object not found<br>[27/Dec/2015:14:12:01][main]: CMSEngine.shutdown()<br><br></div><div>Result seems to show key file password is correct:<br>certutil -K -d /etc/dirsrv/slapd-REALM-NET/ -f /etc/dirsrv/slapd-REALM-NET/pwdfile.txt<br>certutil: Checking token "NSS Certificate DB" in slot "NSS User Private Key and Certificate Services"<br>< 0> rsa      ############################   NSS Certificate DB:Server-Cert<br></div><div><br><br>certutil -L -d /var/lib/pki-ca/alias<br><br>Certificate Nickname                                         Trust Attributes<br>                                                             SSL,S/MIME,JAR/XPI<br><br>ocspSigningCert cert-pki-ca                                  u,u,u<br>subsystemCert cert-pki-ca                                    u,u,u<br>Server-Cert cert-pki-ca                                         u,u,u<br>auditSigningCert cert-pki-ca                                 u,u,Pu<br>caSigningCert cert-pki-ca                                    CTu,Cu,Cu<br><br><br>certutil -L -d /etc/httpd/alias<br><br>Certificate Nickname                                         Trust Attributes<br>                                                             SSL,S/MIME,JAR/XPI<br><br>Server-Cert                                                      u,u,u<br>ipaCert                                                             u,u,u<br><a href="http://REALM.COM">REALM.COM</a> IPA CA                                      CT,C,<br><br><br>certutil -L -d /etc/dirsrv/slapd-REALM-COM<br><br>Certificate Nickname                                         Trust Attributes<br>                                                             SSL,S/MIME,JAR/XPI<br><br>Server-Cert                                                          u,u,u<br><a href="http://REALM.COM">REALM.COM</a> IPA CA                                          CT,C,C<br><br><br>Output of getcert list:<br><br>Number of certificates and requests being tracked: 7.<br>Request ID '21135214223243':<br>        status: CA_UNREACHABLE<br>        ca-error: Server at <a href="https://host.example.net/ipa/xml">https://host.example.net/ipa/xml</a> failed request, will retry: 4301 (RPC failed at server.  Certificate oper<br>ation cannot be completed: Unable to communicate with CMS (Not Found)).<br>        stuck: no<br>        key pair storage: type=NSSDB,location='/etc/dirsrv/slapd-example-NET',nickname='Server-Cert',token='NSS Certificate DB',pinfil<br>e='/etc/dirsrv/slapd-example-NET//pwdfile.txt'<br>        certificate: type=NSSDB,location='/etc/dirsrv/slapd-example-NET',nickname='Server-Cert',token='NSS Certificate DB'<br>        CA: IPA<br>        issuer: CN=Certificate Authority,O=example.NET<br>        subject: CN=<a href="http://host.example.net">host.example.net</a>,O=example.NET<br>        expires: 2016-03-29 14:09:46 UTC<br>        key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>        eku: id-kp-serverAuth<br>        pre-save command:<br>        post-save command:<br>        track: yes<br>        auto-renew: yes<br>Request ID '21135214223300':<br>        status: CA_UNREACHABLE<br>        ca-error: Server at <a href="https://host.example.net/ipa/xml">https://host.example.net/ipa/xml</a> failed request, will retry: 4301 (RPC failed at server.  Certificate oper<br>ation cannot be completed: Unable to communicate with CMS (Not Found)).<br>        stuck: no<br>        key pair storage: type=NSSDB,location='/etc/dirsrv/slapd-PKI-IPA',nickname='Server-Cert',token='NSS Certificate DB',pinfile='<br>/etc/dirsrv/slapd-PKI-IPA//pwdfile.txt'<br>        certificate: type=NSSDB,location='/etc/dirsrv/slapd-PKI-IPA',nickname='Server-Cert',token='NSS Certificate DB'<br>        CA: IPA<br>        issuer: CN=Certificate Authority,O=example.NET<br>        subject: CN=<a href="http://host.example.net">host.example.net</a>,O=example.NET<br>        expires: 2016-03-29 14:09:45 UTC<br>        key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>        eku: id-kp-serverAuth<br>        pre-save command:<br>        post-save command:<br>        track: yes<br>        auto-renew: yes<br>Request ID '20130519130741':<br>        status: NEED_CSR_GEN_PIN<br>        ca-error: Internal error: no response to "<a href="http://host.example.net:9180/ca/ee/ca/profileSubmit?profileId=auditSigningCert+cert-">http://host.example.net:9180/ca/ee/ca/profileSubmit?profileId=auditSigningCert+cert-</a><br>pki-ca&serial_num=61&renewal=true&xml=true".<br>        stuck: yes<br>        key pair storage: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='auditSigningCert cert-pki-ca',token='NSS Certificate<br>DB',pin set<br>        certificate: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='auditSigningCert cert-pki-ca',token='NSS Certificate DB'<br>        CA: dogtag-ipa-renew-agent<br>        issuer: CN=Certificate Authority,O=example.NET<br>        subject: CN=CA Audit,O=example.NET<br>        expires: 2017-10-13 14:10:49 UTC<br>        key usage: digitalSignature,nonRepudiation<br>        pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad<br>        post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "auditSigningCert cert-pki-ca"<br>        track: yes<br>        auto-renew: yes<br>Request ID '20130519130742':<br>        status: NEED_CSR_GEN_PIN<br>        ca-error: Internal error: no response to "<a href="http://host.example.net:9180/ca/ee/ca/profileSubmit?profileId=caServerCert&serial_nu">http://host.example.net:9180/ca/ee/ca/profileSubmit?profileId=caServerCert&serial_nu</a><br>m=60&renewal=true&xml=true".<br>        stuck: yes<br>        key pair storage: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='ocspSigningCert cert-pki-ca',token='NSS Certificate D<br>B',pin set<br>        certificate: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='ocspSigningCert cert-pki-ca',token='NSS Certificate DB'<br>        CA: dogtag-ipa-renew-agent<br>        issuer: CN=Certificate Authority,O=example.NET<br>        subject: CN=OCSP Subsystem,O=example.NET<br>        expires: 2017-10-13 14:09:49 UTC<br>        eku: id-kp-OCSPSigning<br>        pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad<br>        post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "ocspSigningCert cert-pki-ca"<br>        track: yes<br>        auto-renew: yes<br>Request ID '20130519130743':<br>        status: NEED_CSR_GEN_PIN<br>        ca-error: Internal error: no response to "<a href="http://host.example.net:9180/ca/ee/ca/profileSubmit?profileId=caServerCert&serial_nu">http://host.example.net:9180/ca/ee/ca/profileSubmit?profileId=caServerCert&serial_nu</a><br>m=62&renewal=true&xml=true".<br>        stuck: yes<br>        key pair storage: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='subsystemCert cert-pki-ca',token='NSS Certificate DB'<br>,pin set<br>        certificate: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='subsystemCert cert-pki-ca',token='NSS Certificate DB'<br>        CA: dogtag-ipa-renew-agent<br>        issuer: CN=Certificate Authority,O=example.NET<br>        subject: CN=CA Subsystem,O=example.NET<br>        expires: 2017-10-13 14:09:49 UTC<br>        key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>        eku: id-kp-serverAuth,id-kp-clientAuth<br>        pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad<br>        post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "subsystemCert cert-pki-ca"<br>        track: yes<br>        auto-renew: yes<br>Request ID '20130519130744':<br>        status: MONITORING<br>        ca-error: Internal error: no response to "<a href="http://host.example.net:9180/ca/ee/ca/profileSubmit?profileId=caServerCert&serial_nu">http://host.example.net:9180/ca/ee/ca/profileSubmit?profileId=caServerCert&serial_nu</a><br>m=64&renewal=true&xml=true".<br>        stuck: no<br>        key pair storage: type=NSSDB,location='/etc/httpd/alias',nickname='ipaCert',token='NSS Certificate DB',pinfile='/etc/httpd/al<br>ias/pwdfile.txt'<br>        certificate: type=NSSDB,location='/etc/httpd/alias',nickname='ipaCert',token='NSS Certificate DB'<br>        CA: dogtag-ipa-renew-agent<br>        issuer: CN=Certificate Authority,O=example.NET<br>        subject: CN=RA Subsystem,O=example.NET<br>        expires: 2017-10-13 14:09:49 UTC<br>        key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>        eku: id-kp-serverAuth,id-kp-clientAuth<br>        pre-save command:<br>        post-save command: /usr/lib64/ipa/certmonger/renew_ra_cert<br>        track: yes<br>        auto-renew: yes<br>Request ID '20130519130745':<br>        status: NEED_CSR_GEN_PIN<br>        ca-error: Internal error: no response to "<a href="http://host.example.net:9180/ca/ee/ca/profileSubmit?profileId=caServerCert&serial_nu">http://host.example.net:9180/ca/ee/ca/profileSubmit?profileId=caServerCert&serial_nu</a><br>m=63&renewal=true&xml=true".<br>        stuck: yes<br>        key pair storage: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='Server-Cert cert-pki-ca',token='NSS Certificate DB',p<br>in set<br>        certificate: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='Server-Cert cert-pki-ca',token='NSS Certificate DB'<br>        CA: dogtag-ipa-renew-agent<br>        issuer: CN=Certificate Authority,O=example.NET<br>        subject: CN=<a href="http://host.example.net">host.example.net</a>,O=example.NET<br>        expires: 2017-10-13 14:09:49 UTC<br>        key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>        eku: id-kp-serverAuth,id-kp-clientAuth<br>        pre-save command:<br>        post-save command:<br>        track: yes<br>        auto-renew: yes<br><br><br></div>Regards, Adam<br></div>