<div dir="ltr">Thanks for the reply Rob,<div><br></div><div>So should fixing replication be more than running a re-initialize?   I've tried this with no luck.  Still the same errors in renewing the IPA certs.</div><div><div><br></div><div>status: CA_UNREACHABLE</div><div>ca-error: Server at <a href="https://spider01a.iglass.net/ipa/xml">https://spider01a.iglass.net/ipa/xml</a> failed request, will retry: 4301 (RPC failed at server.  Certificate operation cannot be completed: EXCEPTION (Certificate serial number 0x3ffe000f not found))</div></div><div><br></div><div>Is there a procedure for getting these serial numbers back in to the system? or manually recreating somehow?</div><div><br></div><div>I was able to clear 4301 error.  One ipaCert needed to be updated.</div><div><br></div><div>thanks</div><div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Jun 16, 2016 at 10:22 AM, Rob Crittenden <span dir="ltr"><<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><span class="">Marc Wiatrowski wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">
Thanks Rob,<br>
<br>
Any suggestions on how make the CA aware of the current serial number?<br>
</blockquote>
<br></span>
Serial numbers are dolled out like uid numbers, by the 389-ds DNA Plugin. So each CA that has ever issued a certificate has its own range, hence the quite different serial number values.<br>
<br>
Given that some issued certificates are unknown it stands to reason that replication is broken between one or more masters. Fixing that should resolve (most of) the other issues.<span class=""><br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">
Also started seeing the following error from two of the servers,<br>
spider01b and spider01o, but not spider01a when to navigate in the web<br>
gui.  Though it doesn't appear to stop me from doing anything.<br>
<br>
IPA Error 4301<br>
Certificate operation cannot be completed: EXCEPTION (Invalid Crential.)<br>
</blockquote>
<br></span>
Dogtag does some of its access control by comparing the incoming client certificate with an expected value in its LDAP database, in this case uid=ipara,ou=People,o=ipaca. There you'll find a copy of the client certificate and a description field that contains the expected serial #, subject and issuer.<br>
<br>
These are out-of-whack if you're getting Invalid Credentials. It could be a number of things so I'd proceed cautiously. Given you have a working master I'd use that as a starting point.<br>
<br>
Look at the the RA cert is in /etc/httpd/alias:<br>
<br>
# certutil -L -d /etc/httpd/alias -n ipaCert | grep Serial<br>
<br>
See if it is the same on all masters, it should be.<br>
<br>
If it is, look at the uid=ipara entry on all the masters. Again, should be the same.<br>
<br>
Note that fixing this won't address any replication issues.<br>
<br>
rob<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><span class="">
<br>
Marc<br>
<br>
On Tue, Jun 14, 2016 at 2:07 PM, Marc Wiatrowski <<a href="mailto:wia@iglass.net" target="_blank">wia@iglass.net</a><br></span><span class="">
<mailto:<a href="mailto:wia@iglass.net" target="_blank">wia@iglass.net</a>>> wrote:<br>
<br>
<br>
<br>
    On Tue, Jun 14, 2016 at 11:22 AM, Rob Crittenden<br></span><span class="">
    <<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a> <mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>>> wrote:<br>
<br>
        Marc Wiatrowski wrote:<br>
<br>
            Hello, I'm having issues with the 3 ipa certificates of type<br>
            CA: IPA<br>
            renewing on 2 of 3 replicas.  Particularly on the 2 that are<br>
            not the CA<br>
            master.  The other 5 certificates from getcert list do renew<br>
            and all<br>
            certificates on the CA master do look to renew.<br>
<br>
            Both servers running<br>
            ipa-server-3.0.0-50.el6.centos.1.x86_64  I've done<br>
            full updates and rebooted.<br>
<br>
<br>
        Can you check on the replication status for each CA?<br>
<br>
        $ ipa-csreplica-manage list -v <a href="http://ipa.example.com" rel="noreferrer" target="_blank">ipa.example.com</a><br></span>
        <<a href="http://ipa.example.com" rel="noreferrer" target="_blank">http://ipa.example.com</a>><span class=""><br>
<br>
        The hostname is important because including that will show the<br>
        agreements that host has. Do this for each master with a CA.<br>
<br>
        The CA being asked to do the renewal is unaware of the current<br>
        serial number so it is refusing to proceed.<br>
<br>
        rob<br>
<br>
<br>
<br>
    [root@spider01o]$ ipa-csreplica-manage list -v <a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a><br></span>
    <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
    Directory Manager password:<br>
<br>
    <a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">spider01b.iglass.net</a> <<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><span class=""><br>
       last init status: None<br>
       last init ended: None<br>
       last update status: 0 Replica acquired successfully: Incremental<br>
    update succeeded<br>
       last update ended: 2016-06-14 17:49:16+00:00<br></span>
    <a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><span class=""><br>
       last init status: None<br>
       last init ended: None<br>
       last update status: 0 Replica acquired successfully: Incremental<br>
    update started<br>
       last update ended: 2016-06-14 17:55:20+00:00<br>
<br>
    [root@spider01o]$ ipa-csreplica-manage list -v <a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a><br></span>
    <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
    Directory Manager password:<br>
<br>
    <a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><span class=""><br>
       last init status: None<br>
       last init ended: None<br>
       last update status: 0 Replica acquired successfully: Incremental<br>
    update started<br>
       last update ended: 2016-06-14 17:57:44+00:00<br></span>
    <a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">spider01b.iglass.net</a> <<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><span class=""><br>
       last init status: None<br>
       last init ended: None<br>
       last update status: 0 Replica acquired successfully: Incremental<br>
    update started<br>
       last update ended: 2016-06-14 17:57:41+00:00<br>
<br>
    [root@spider01o]$ ipa-csreplica-manage list -v <a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">spider01b.iglass.net</a><br></span>
    <<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><br>
    Directory Manager password:<br>
<br>
    <a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><span class=""><br>
       last init status: 0 Total update succeeded<br>
       last init ended: 2016-06-03 19:43:12+00:00<br>
       last update status: 0 Replica acquired successfully: Incremental<br>
    update succeeded<br>
       last update ended: 2016-06-14 17:44:17+00:00<br></span>
    <a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><span class=""><br>
       last init status: 0 Total update succeeded<br>
       last init ended: 2016-06-03 19:44:38+00:00<br>
       last update status: 0 Replica acquired successfully: Incremental<br>
    update started<br>
       last update ended: 2016-06-14 17:57:53+00:00<br></span>
    <a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><span class=""><br>
       last init status: None<br>
       last init ended: None<br>
       last update status: 0 Replica acquired successfully: Incremental<br>
    update succeeded<br>
       last update ended: 2016-06-14 17:44:13+00:00<br></span>
    <a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><span class=""><br>
       last init status: None<br>
       last init ended: None<br>
       last update status: 0 Replica acquired successfully: Incremental<br>
    update started<br>
       last update ended: 2016-06-14 17:57:54+00:00<br>
<br>
<br>
    Not sure what this is telling... This an issue with the last being<br>
    doubled?  Thanks<br>
<br>
<br>
<br>
    The failed renews look like:<br>
<br>
    [root@spider01a]$ getcert list -i 20141202144354<br>
    Number of certificates and requests being tracked: 8.<br>
    Request ID '20141202144354':<br>
    status: CA_UNREACHABLE<br>
    ca-error: Server at <a href="https://spider01a.iglass.net/ipa/xml" rel="noreferrer" target="_blank">https://spider01a.iglass.net/ipa/xml</a> failed request,<br>
    will retry: 4301 (RPC failed at server.  Certificate operation cannot be<br>
    completed: EXCEPTION (Certificate serial number 0x3ffe0010 not found)).<br>
    stuck: no<br>
    key pair storage:<br>
    type=NSSDB,location='/etc/dirsrv/slapd-PKI-IPA',nickname='Server-Cert',token='NSS<br>
    Certificate DB',pinfile='/etc/dirsrv/slapd-PKI-IPA/pwdfile.txt'<br>
    certificate:<br>
    type=NSSDB,location='/etc/dirsrv/slapd-PKI-IPA',nickname='Server-Cert',token='NSS<br>
    Certificate DB'<br>
    CA: IPA<br>
    issuer: CN=Certificate Authority,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></span>
    <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
    subject: CN=<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>><br>
    <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a><br>
    <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>>>,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br>
    <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><span class=""><br>
    expires: 2016-12-02 14:38:45 UTC<br>
    key usage:<br>
    digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>
    eku: id-kp-serverAuth,id-kp-clientAuth<br>
    pre-save command:<br>
    post-save command: /usr/lib64/ipa/certmonger/restart_dirsrv PKI-IPA<br>
    track: yes<br>
    auto-renew: yes<br>
<br>
    [root@spider01a]$ getcert list -i 20141202144616<br>
    Number of certificates and requests being tracked: 8.<br>
    Request ID '20141202144616':<br>
    status: CA_UNREACHABLE<br>
    ca-error: Server at <a href="https://spider01a.iglass.net/ipa/xml" rel="noreferrer" target="_blank">https://spider01a.iglass.net/ipa/xml</a> failed request,<br>
    will retry: 4301 (RPC failed at server.  Certificate operation cannot be<br>
    completed: EXCEPTION (Certificate serial number 0x3ffe000f not found)).<br>
    stuck: no<br>
    key pair storage:<br>
    type=NSSDB,location='/etc/dirsrv/slapd-IGLASS-NET',nickname='Server-Cert',token='NSS<br>
    Certificate DB',pinfile='/etc/dirsrv/slapd-IGLASS-NET/pwdfile.txt'<br>
    certificate:<br>
    type=NSSDB,location='/etc/dirsrv/slapd-IGLASS-NET',nickname='Server-Cert',token='NSS<br>
    Certificate DB'<br>
    CA: IPA<br>
    issuer: CN=Certificate Authority,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></span>
    <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
    subject: CN=<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>><br>
    <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a><br>
    <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>>>,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br>
    <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><span class=""><br>
    expires: 2016-12-02 14:38:43 UTC<br>
    key usage:<br>
    digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>
    eku: id-kp-serverAuth,id-kp-clientAuth<br>
    pre-save command:<br>
    post-save command: /usr/lib64/ipa/certmonger/restart_dirsrv IGLASS-NET<br>
    track: yes<br>
    auto-renew: yes<br>
<br>
    [root@spider01a]$ getcert list -i 20141202144733<br>
    Number of certificates and requests being tracked: 8.<br>
    Request ID '20141202144733':<br>
    status: CA_UNREACHABLE<br>
    ca-error: Server at <a href="https://spider01a.iglass.net/ipa/xml" rel="noreferrer" target="_blank">https://spider01a.iglass.net/ipa/xml</a> failed request,<br>
    will retry: 4301 (RPC failed at server.  Certificate operation cannot be<br>
    completed: EXCEPTION (Certificate serial number 0x3ffe0011 not found)).<br>
    stuck: no<br>
    key pair storage:<br>
    type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS<br>
    Certificate DB',pinfile='/etc/httpd/alias/pwdfile.txt'<br>
    certificate:<br>
    type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS<br>
    Certificate DB'<br>
    CA: IPA<br>
    issuer: CN=Certificate Authority,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></span>
    <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
    subject: CN=<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>><br>
    <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a><br>
    <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>>>,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br>
    <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><span class=""><br>
    expires: 2016-12-02 14:38:46 UTC<br>
    key usage:<br>
    digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>
    eku: id-kp-serverAuth,id-kp-clientAuth<br>
    pre-save command:<br>
    post-save command: /usr/lib64/ipa/certmonger/restart_httpd<br>
    track: yes<br>
    auto-renew: yes<br>
<br>
<br>
    From<br>
    [root@spider01a]$ getcert resubmit -i 20141202144354<br>
<br>
    On the replica issuing the resubmit<br>
<br>
    ==> /var/log/httpd/access_log <==<br>
    192.168.176.2 - - [13/Jun/2016:15:49:32 -0400] "POST /ipa/xml HTTP/1.1"<br>
    401 1370<br>
<br>
    ==> /var/log/httpd/error_log <==<br>
    [Mon Jun 13 15:49:33 2016] [error] ipa: ERROR:<br>
    ipaserver.plugins.dogtag.ra.get_certificate(): EXCEPTION (Certificate<br>
    serial number 0x3ffe0010 not found)<br>
    [Mon Jun 13 15:49:33 2016] [error] ipa: INFO:<br>
    host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br></span>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><span class=""><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>:<br>
    cert_request(u'MIIDsTCCApkCAQAwNDETMBEGA1UEChMKSUdMQVNTLk5FVDEdMBsGA1UEAxMUc3BpZGVyMDFhLml...UVrN8lbKn17V5COjnj6k0mdbz3KptL0UI/l0BPlFBWGN5MFYaDx2F+y6LWv/aXeu2V4E6LA==',<br>
    principal=u'dogtagldap/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br></span>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><span class=""><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>', add=True):<br>
    CertificateOperationError<br>
<br>
    ==> /var/log/httpd/access_log <==<br>
    192.168.176.2 - - [13/Jun/2016:15:49:33 -0400] "POST<br>
    /ca/agent/ca/displayBySerial HTTP/1.1" 200 262<br>
    192.168.176.2 - host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br></span>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><span class=""><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>> [13/Jun/2016:15:49:32 -0400]<br>
    "POST /ipa/xml HTTP/1.1" 200 376<br>
<br>
    ==> /var/log/pki-ca/system <==<br>
    2508.TP-Processor6 - [13/Jun/2016:15:49:33 EDT] [3] [3] Servlet<br>
    caDisplayBySerial: Error encountered in DisplayBySerial. Error Record<br>
    not found.<br>
<br>
<br>
    On the CA master spider01o:<br>
<br>
    ==> /var/log/httpd/access_log <==<br>
    192.168.176.2 - - [13/Jun/2016:15:49:33 -0400] "POST /ipa/xml HTTP/1.1"<br>
    401 1370<br>
<br>
    ==> krb5kdc.log <==<br>
    Jun 13 15:49:34 <a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a><br></span>
    <<a href="http://spider01o.iglass.net/" rel="noreferrer" target="_blank">http://spider01o.iglass.net/</a>> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a><br>
    <<a href="http://spider01o.iglass.net/" rel="noreferrer" target="_blank">http://spider01o.iglass.net/</a>>><span class=""><br>
    krb5kdc[1963](info): TGS_REQ (4 etypes {18 17 16 23}) 192.168.177.2<br></span>
    <<a href="http://192.168.177.2" rel="noreferrer" target="_blank">http://192.168.177.2</a> <<a href="http://192.168.177.2/" rel="noreferrer" target="_blank">http://192.168.177.2/</a>>>: ISSUE: authtime<span class=""><br>
    1465847372, etypes {rep=18<br>
    tkt=18 ses=18}, host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br></span>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><span class=""><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>> for<br>
    ldap/<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a><br>
    <mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a>><br></span>
    <mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a><span class=""><br>
    <mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a>>><br>
<br>
    ==> /var/log/httpd/error_log <==<br>
    [Mon Jun 13 15:49:34 2016] [error] ipa: ERROR:<br>
    ipaserver.plugins.dogtag.ra.get_certificate(): EXCEPTION (Invalid<br>
    Credential.)<br>
    [Mon Jun 13 15:49:34 2016] [error] ipa: INFO:<br>
    host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br></span>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><span class=""><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>:<br>
    cert_request(u'MIIDsTCCApkCAQAwNDETMBEGA1UEChMKSUdMQVNTLk5FVDEdMBsGA1UEAxMUc3BpZGVyMDFhLml...UVrN8lbKn17V5COjnj6k0mdbz3KptL0UI/l0BPlFBWGN5MFYaDx2F+y6LWv/aXeu2V4E6LA==',<br>
    principal=u'dogtagldap/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br></span>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><span class=""><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>', add=True):<br>
    CertificateOperationError<br>
<br>
    ==> /var/log/httpd/access_log <==<br>
    192.168.177.2 - - [13/Jun/2016:15:49:34 -0400] "POST<br>
    /ca/agent/ca/displayBySerial HTTP/1.1" 200 235<br>
    192.168.176.2 - host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br></span>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><span class=""><br>
    <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>> [13/Jun/2016:15:49:33 -0400]<br>
    "POST /ipa/xml HTTP/1.1" 200 349<br>
<br>
    ==> /var/log/pki-ca/system <==<br>
    2231.TP-Processor3 - [13/Jun/2016:15:49:34 EDT] [6] [3] Cannot<br>
    authenticate agent with certificate Serial 0x5ffc0008 Subject DN CN=IPA<br></span>
    RA,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a><br>
    <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>>. Error: User not found<span class=""><br>
<br>
<br>
    I realize they expire at the end of the year, but I've had my<br>
    certificates expire before and would rather not go through that again.<br>
    Any idea on what's wrong or suggestions on where to look would be<br>
    appreciated.<br>
<br>
    Thanks,<br>
    Marc<br>
<br>
<br>
<br>
<br>
</span></blockquote>
<br>
</blockquote></div><br></div></div></div>