<div dir="ltr">Thank you Rob!  I now have two years till everything expires...<div class="gmail_extra"><br><div class="gmail_quote">On Tue, Jun 21, 2016 at 1:33 PM, Rob Crittenden <span dir="ltr"><<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><span class="">Marc Wiatrowski wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">
Thanks for the reply Rob,<br>
<br>
So should fixing replication be more than running a re-initialize?<br>
I've tried this with no luck.  Still the same errors in renewing the IPA<br>
certs.<br>
</blockquote>
<br></span>
re-init drops one database and replaces it with another. If you really did that then you have potentially lost a ton of records if indeed replication was stalled. Knowing what commands you ran would help to know for sure.</blockquote><div><br></div><div><br></div><div>I'm thinking at some point in the past I may have done this backwards. So maybe not my original problem but making things worse.  </div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><span class=""><br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">
status: CA_UNREACHABLE<br>
ca-error: Server at <a href="https://spider01a.iglass.net/ipa/xml" rel="noreferrer" target="_blank">https://spider01a.iglass.net/ipa/xml</a> failed request,<br>
will retry: 4301 (RPC failed at server.  Certificate operation cannot be<br>
completed: EXCEPTION (Certificate serial number 0x3ffe000f not found))<br>
<br>
Is there a procedure for getting these serial numbers back in to the<br>
system? or manually recreating somehow?<br>
</blockquote>
<br></span>
When IPA gets a certificate request and the host/service it is requesting it for already has a certificate, a revocation is done on the existing certificate (which in this case is failing because the cert is unknown). If you wipe out the usercertificate field from  the entry ldap/<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> then that should do it.</blockquote><div><br></div><div><br></div><div>This did the trick!  I also had to delete userCertificate for dogtagldap/<a href="http://spider01a.iglass.net">spider01a.iglass.net</a> and HTTP/<a href="http://spider01a.iglass.net">spider01a.iglass.net</a> for the other two certificates not renewing.</div><div><br></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><span class=""><br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">
<br>
I was able to clear 4301 error.  One ipaCert needed to be updated.<br>
</blockquote>
<br></span>
Great!<br>
<br>
rob<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><span class="">
<br>
thanks<br>
<br>
On Thu, Jun 16, 2016 at 10:22 AM, Rob Crittenden <<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a><br></span><span class="">
<mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>>> wrote:<br>
<br>
    Marc Wiatrowski wrote:<br>
<br></span><div><div class="h5">
        Thanks Rob,<br>
<br>
        Any suggestions on how make the CA aware of the current serial<br>
        number?<br>
<br>
<br>
    Serial numbers are dolled out like uid numbers, by the 389-ds DNA<br>
    Plugin. So each CA that has ever issued a certificate has its own<br>
    range, hence the quite different serial number values.<br>
<br>
    Given that some issued certificates are unknown it stands to reason<br>
    that replication is broken between one or more masters. Fixing that<br>
    should resolve (most of) the other issues.<br>
<br>
        Also started seeing the following error from two of the servers,<br>
        spider01b and spider01o, but not spider01a when to navigate in<br>
        the web<br>
        gui.  Though it doesn't appear to stop me from doing anything.<br>
<br>
        IPA Error 4301<br>
        Certificate operation cannot be completed: EXCEPTION (Invalid<br>
        Crential.)<br>
<br>
<br>
    Dogtag does some of its access control by comparing the incoming<br>
    client certificate with an expected value in its LDAP database, in<br>
    this case uid=ipara,ou=People,o=ipaca. There you'll find a copy of<br>
    the client certificate and a description field that contains the<br>
    expected serial #, subject and issuer.<br>
<br>
    These are out-of-whack if you're getting Invalid Credentials. It<br>
    could be a number of things so I'd proceed cautiously. Given you<br>
    have a working master I'd use that as a starting point.<br>
<br>
    Look at the the RA cert is in /etc/httpd/alias:<br>
<br>
    # certutil -L -d /etc/httpd/alias -n ipaCert | grep Serial<br>
<br>
    See if it is the same on all masters, it should be.<br>
<br>
    If it is, look at the uid=ipara entry on all the masters. Again,<br>
    should be the same.<br>
<br>
    Note that fixing this won't address any replication issues.<br>
<br>
    rob<br>
<br>
<br>
        Marc<br>
<br>
        On Tue, Jun 14, 2016 at 2:07 PM, Marc Wiatrowski <<a href="mailto:wia@iglass.net" target="_blank">wia@iglass.net</a><br>
        <mailto:<a href="mailto:wia@iglass.net" target="_blank">wia@iglass.net</a>><br></div></div><span class="">
        <mailto:<a href="mailto:wia@iglass.net" target="_blank">wia@iglass.net</a> <mailto:<a href="mailto:wia@iglass.net" target="_blank">wia@iglass.net</a>>>> wrote:<br>
<br>
<br>
<br>
             On Tue, Jun 14, 2016 at 11:22 AM, Rob Crittenden<br>
             <<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a> <mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>><br></span><div><div class="h5">
        <mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a> <mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>>>> wrote:<br>
<br>
                 Marc Wiatrowski wrote:<br>
<br>
                     Hello, I'm having issues with the 3 ipa<br>
        certificates of type<br>
                     CA: IPA<br>
                     renewing on 2 of 3 replicas.  Particularly on the 2<br>
        that are<br>
                     not the CA<br>
                     master.  The other 5 certificates from getcert list<br>
        do renew<br>
                     and all<br>
                     certificates on the CA master do look to renew.<br>
<br>
                     Both servers running<br>
                     ipa-server-3.0.0-50.el6.centos.1.x86_64  I've done<br>
                     full updates and rebooted.<br>
<br>
<br>
                 Can you check on the replication status for each CA?<br>
<br>
                 $ ipa-csreplica-manage list -v <a href="http://ipa.example.com" rel="noreferrer" target="_blank">ipa.example.com</a><br>
        <<a href="http://ipa.example.com" rel="noreferrer" target="_blank">http://ipa.example.com</a>><br>
                 <<a href="http://ipa.example.com" rel="noreferrer" target="_blank">http://ipa.example.com</a>><br>
<br>
                 The hostname is important because including that will<br>
        show the<br>
                 agreements that host has. Do this for each master with<br>
        a CA.<br>
<br>
                 The CA being asked to do the renewal is unaware of the<br>
        current<br>
                 serial number so it is refusing to proceed.<br>
<br>
                 rob<br>
<br>
<br>
<br>
             [root@spider01o]$ ipa-csreplica-manage list -v<br>
        <a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
             <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
             Directory Manager password:<br>
<br>
        <a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">spider01b.iglass.net</a> <<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><br>
        <<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><br>
                last init status: None<br>
                last init ended: None<br>
                last update status: 0 Replica acquired successfully:<br>
        Incremental<br>
             update succeeded<br>
                last update ended: 2016-06-14 17:49:16+00:00<br>
        <a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
        <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
                last init status: None<br>
                last init ended: None<br>
                last update status: 0 Replica acquired successfully:<br>
        Incremental<br>
             update started<br>
                last update ended: 2016-06-14 17:55:20+00:00<br>
<br>
             [root@spider01o]$ ipa-csreplica-manage list -v<br>
        <a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
             <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
             Directory Manager password:<br>
<br>
        <a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
        <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
                last init status: None<br>
                last init ended: None<br>
                last update status: 0 Replica acquired successfully:<br>
        Incremental<br>
             update started<br>
                last update ended: 2016-06-14 17:57:44+00:00<br>
        <a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">spider01b.iglass.net</a> <<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><br>
        <<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><br>
                last init status: None<br>
                last init ended: None<br>
                last update status: 0 Replica acquired successfully:<br>
        Incremental<br>
             update started<br>
                last update ended: 2016-06-14 17:57:41+00:00<br>
<br>
             [root@spider01o]$ ipa-csreplica-manage list -v<br>
        <a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">spider01b.iglass.net</a> <<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><br>
             <<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><br>
             Directory Manager password:<br>
<br>
        <a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
        <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
                last init status: 0 Total update succeeded<br>
                last init ended: 2016-06-03 19:43:12+00:00<br>
                last update status: 0 Replica acquired successfully:<br>
        Incremental<br>
             update succeeded<br>
                last update ended: 2016-06-14 17:44:17+00:00<br>
        <a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
        <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
                last init status: 0 Total update succeeded<br>
                last init ended: 2016-06-03 19:44:38+00:00<br>
                last update status: 0 Replica acquired successfully:<br>
        Incremental<br>
             update started<br>
                last update ended: 2016-06-14 17:57:53+00:00<br>
        <a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
        <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
                last init status: None<br>
                last init ended: None<br>
                last update status: 0 Replica acquired successfully:<br>
        Incremental<br>
             update succeeded<br>
                last update ended: 2016-06-14 17:44:13+00:00<br>
        <a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
        <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
                last init status: None<br>
                last init ended: None<br>
                last update status: 0 Replica acquired successfully:<br>
        Incremental<br>
             update started<br>
                last update ended: 2016-06-14 17:57:54+00:00<br>
<br>
<br>
             Not sure what this is telling... This an issue with the<br>
        last being<br>
             doubled?  Thanks<br>
<br>
<br>
<br>
             The failed renews look like:<br>
<br>
             [root@spider01a]$ getcert list -i 20141202144354<br>
             Number of certificates and requests being tracked: 8.<br>
             Request ID '20141202144354':<br>
             status: CA_UNREACHABLE<br>
             ca-error: Server at <a href="https://spider01a.iglass.net/ipa/xml" rel="noreferrer" target="_blank">https://spider01a.iglass.net/ipa/xml</a><br>
        failed request,<br>
             will retry: 4301 (RPC failed at server.  Certificate<br>
        operation cannot be<br>
             completed: EXCEPTION (Certificate serial number 0x3ffe0010<br>
        not found)).<br>
             stuck: no<br>
             key pair storage:<br>
<br>
        type=NSSDB,location='/etc/dirsrv/slapd-PKI-IPA',nickname='Server-Cert',token='NSS<br>
             Certificate DB',pinfile='/etc/dirsrv/slapd-PKI-IPA/pwdfile.txt'<br>
             certificate:<br>
<br>
        type=NSSDB,location='/etc/dirsrv/slapd-PKI-IPA',nickname='Server-Cert',token='NSS<br>
             Certificate DB'<br>
             CA: IPA<br>
             issuer: CN=Certificate Authority,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></div></div>
        <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>><span class=""><br>
             <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
             subject: CN=<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a><br></span>
        <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>> <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>><span class=""><br>
             <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a><br>
             <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>>>,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></span>
        <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>><div><div class="h5"><br>
             <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
             expires: 2016-12-02 14:38:45 UTC<br>
             key usage:<br>
<br>
        digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>
             eku: id-kp-serverAuth,id-kp-clientAuth<br>
             pre-save command:<br>
             post-save command: /usr/lib64/ipa/certmonger/restart_dirsrv<br>
        PKI-IPA<br>
             track: yes<br>
             auto-renew: yes<br>
<br>
             [root@spider01a]$ getcert list -i 20141202144616<br>
             Number of certificates and requests being tracked: 8.<br>
             Request ID '20141202144616':<br>
             status: CA_UNREACHABLE<br>
             ca-error: Server at <a href="https://spider01a.iglass.net/ipa/xml" rel="noreferrer" target="_blank">https://spider01a.iglass.net/ipa/xml</a><br>
        failed request,<br>
             will retry: 4301 (RPC failed at server.  Certificate<br>
        operation cannot be<br>
             completed: EXCEPTION (Certificate serial number 0x3ffe000f<br>
        not found)).<br>
             stuck: no<br>
             key pair storage:<br>
<br>
        type=NSSDB,location='/etc/dirsrv/slapd-IGLASS-NET',nickname='Server-Cert',token='NSS<br>
             Certificate<br>
        DB',pinfile='/etc/dirsrv/slapd-IGLASS-NET/pwdfile.txt'<br>
             certificate:<br>
<br>
        type=NSSDB,location='/etc/dirsrv/slapd-IGLASS-NET',nickname='Server-Cert',token='NSS<br>
             Certificate DB'<br>
             CA: IPA<br>
             issuer: CN=Certificate Authority,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></div></div>
        <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>><span class=""><br>
             <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
             subject: CN=<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a><br></span>
        <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>> <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>><span class=""><br>
             <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a><br>
             <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>>>,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></span>
        <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>><div><div class="h5"><br>
             <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
             expires: 2016-12-02 14:38:43 UTC<br>
             key usage:<br>
<br>
        digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>
             eku: id-kp-serverAuth,id-kp-clientAuth<br>
             pre-save command:<br>
             post-save command: /usr/lib64/ipa/certmonger/restart_dirsrv<br>
        IGLASS-NET<br>
             track: yes<br>
             auto-renew: yes<br>
<br>
             [root@spider01a]$ getcert list -i 20141202144733<br>
             Number of certificates and requests being tracked: 8.<br>
             Request ID '20141202144733':<br>
             status: CA_UNREACHABLE<br>
             ca-error: Server at <a href="https://spider01a.iglass.net/ipa/xml" rel="noreferrer" target="_blank">https://spider01a.iglass.net/ipa/xml</a><br>
        failed request,<br>
             will retry: 4301 (RPC failed at server.  Certificate<br>
        operation cannot be<br>
             completed: EXCEPTION (Certificate serial number 0x3ffe0011<br>
        not found)).<br>
             stuck: no<br>
             key pair storage:<br>
<br>
        type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS<br>
             Certificate DB',pinfile='/etc/httpd/alias/pwdfile.txt'<br>
             certificate:<br>
<br>
        type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS<br>
             Certificate DB'<br>
             CA: IPA<br>
             issuer: CN=Certificate Authority,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></div></div>
        <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>><span class=""><br>
             <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
             subject: CN=<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a><br></span>
        <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>> <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>><span class=""><br>
             <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a><br>
             <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>>>,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></span>
        <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>><div><div class="h5"><br>
             <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
             expires: 2016-12-02 14:38:46 UTC<br>
             key usage:<br>
<br>
        digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>
             eku: id-kp-serverAuth,id-kp-clientAuth<br>
             pre-save command:<br>
             post-save command: /usr/lib64/ipa/certmonger/restart_httpd<br>
             track: yes<br>
             auto-renew: yes<br>
<br>
<br>
             From<br>
             [root@spider01a]$ getcert resubmit -i 20141202144354<br>
<br>
             On the replica issuing the resubmit<br>
<br>
             ==> /var/log/httpd/access_log <==<br>
             192.168.176.2 - - [13/Jun/2016:15:49:32 -0400] "POST<br>
        /ipa/xml HTTP/1.1"<br>
             401 1370<br>
<br>
             ==> /var/log/httpd/error_log <==<br>
             [Mon Jun 13 15:49:33 2016] [error] ipa: ERROR:<br>
             ipaserver.plugins.dogtag.ra.get_certificate(): EXCEPTION<br>
        (Certificate<br>
             serial number 0x3ffe0010 not found)<br>
             [Mon Jun 13 15:49:33 2016] [error] ipa: INFO:<br>
             host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>>:<br>
<br>
        cert_request(u'MIIDsTCCApkCAQAwNDETMBEGA1UEChMKSUdMQVNTLk5FVDEdMBsGA1UEAxMUc3BpZGVyMDFhLml...UVrN8lbKn17V5COjnj6k0mdbz3KptL0UI/l0BPlFBWGN5MFYaDx2F+y6LWv/aXeu2V4E6LA==',<br>
             principal=u'dogtagldap/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>>', add=True):<br>
             CertificateOperationError<br>
<br>
             ==> /var/log/httpd/access_log <==<br>
             192.168.176.2 - - [13/Jun/2016:15:49:33 -0400] "POST<br>
             /ca/agent/ca/displayBySerial HTTP/1.1" 200 262<br>
             192.168.176.2 - host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>> [13/Jun/2016:15:49:32<br>
        -0400]<br>
             "POST /ipa/xml HTTP/1.1" 200 376<br>
<br>
             ==> /var/log/pki-ca/system <==<br>
             2508.TP-Processor6 - [13/Jun/2016:15:49:33 EDT] [3] [3] Servlet<br>
             caDisplayBySerial: Error encountered in DisplayBySerial.<br>
        Error Record<br>
             not found.<br>
<br>
<br>
             On the CA master spider01o:<br>
<br>
             ==> /var/log/httpd/access_log <==<br>
             192.168.176.2 - - [13/Jun/2016:15:49:33 -0400] "POST<br>
        /ipa/xml HTTP/1.1"<br>
             401 1370<br>
<br>
             ==> krb5kdc.log <==<br>
             Jun 13 15:49:34 <a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a><br>
        <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
             <<a href="http://spider01o.iglass.net/" rel="noreferrer" target="_blank">http://spider01o.iglass.net/</a>> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a><br>
             <<a href="http://spider01o.iglass.net/" rel="noreferrer" target="_blank">http://spider01o.iglass.net/</a>>><br>
             krb5kdc[1963](info): TGS_REQ (4 etypes {18 17 16 23})<br>
        192.168.177.2<br>
             <<a href="http://192.168.177.2" rel="noreferrer" target="_blank">http://192.168.177.2</a> <<a href="http://192.168.177.2/" rel="noreferrer" target="_blank">http://192.168.177.2/</a>>>: ISSUE: authtime<br>
             1465847372, etypes {rep=18<br>
             tkt=18 ses=18}, host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>> for<br>
             ldap/<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a>>><br>
             <mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a>>>><br>
<br>
             ==> /var/log/httpd/error_log <==<br>
             [Mon Jun 13 15:49:34 2016] [error] ipa: ERROR:<br>
             ipaserver.plugins.dogtag.ra.get_certificate(): EXCEPTION<br>
        (Invalid<br>
             Credential.)<br>
             [Mon Jun 13 15:49:34 2016] [error] ipa: INFO:<br>
             host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>>:<br>
<br>
        cert_request(u'MIIDsTCCApkCAQAwNDETMBEGA1UEChMKSUdMQVNTLk5FVDEdMBsGA1UEAxMUc3BpZGVyMDFhLml...UVrN8lbKn17V5COjnj6k0mdbz3KptL0UI/l0BPlFBWGN5MFYaDx2F+y6LWv/aXeu2V4E6LA==',<br>
             principal=u'dogtagldap/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br></div></div><span class="">
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>>', add=True):<br>
             CertificateOperationError<br>
<br>
             ==> /var/log/httpd/access_log <==<br>
             192.168.177.2 - - [13/Jun/2016:15:49:34 -0400] "POST<br>
             /ca/agent/ca/displayBySerial HTTP/1.1" 200 235<br>
             192.168.176.2 - host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br></span><span class="">
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
             <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br></span><span class="">
        <mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>> [13/Jun/2016:15:49:33<br>
        -0400]<br>
             "POST /ipa/xml HTTP/1.1" 200 349<br>
<br>
             ==> /var/log/pki-ca/system <==<br>
             2231.TP-Processor3 - [13/Jun/2016:15:49:34 EDT] [6] [3] Cannot<br>
             authenticate agent with certificate Serial 0x5ffc0008<br>
        Subject DN CN=IPA<br></span>
             RA,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>><span class=""><br>
        <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a><br>
             <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>>. Error: User not found<br>
<br>
<br>
             I realize they expire at the end of the year, but I've had my<br>
             certificates expire before and would rather not go through<br>
        that again.<br>
             Any idea on what's wrong or suggestions on where to look<br>
        would be<br>
             appreciated.<br>
<br>
             Thanks,<br>
             Marc<br>
<br>
<br>
<br>
<br>
<br>
<br>
</span></blockquote>
<br>
</blockquote></div><br></div></div>