<div dir="ltr">Thank you Rob! I now have two years till everything expires...<div class="gmail_extra"><br><div class="gmail_quote">On Tue, Jun 21, 2016 at 1:33 PM, Rob Crittenden <span dir="ltr"><<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><span class="">Marc Wiatrowski wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">
Thanks for the reply Rob,<br>
<br>
So should fixing replication be more than running a re-initialize?<br>
I've tried this with no luck. Still the same errors in renewing the IPA<br>
certs.<br>
</blockquote>
<br></span>
re-init drops one database and replaces it with another. If you really did that then you have potentially lost a ton of records if indeed replication was stalled. Knowing what commands you ran would help to know for sure.</blockquote><div><br></div><div><br></div><div>I'm thinking at some point in the past I may have done this backwards. So maybe not my original problem but making things worse. </div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><span class=""><br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">
status: CA_UNREACHABLE<br>
ca-error: Server at <a href="https://spider01a.iglass.net/ipa/xml" rel="noreferrer" target="_blank">https://spider01a.iglass.net/ipa/xml</a> failed request,<br>
will retry: 4301 (RPC failed at server. Certificate operation cannot be<br>
completed: EXCEPTION (Certificate serial number 0x3ffe000f not found))<br>
<br>
Is there a procedure for getting these serial numbers back in to the<br>
system? or manually recreating somehow?<br>
</blockquote>
<br></span>
When IPA gets a certificate request and the host/service it is requesting it for already has a certificate, a revocation is done on the existing certificate (which in this case is failing because the cert is unknown). If you wipe out the usercertificate field from the entry ldap/<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> then that should do it.</blockquote><div><br></div><div><br></div><div>This did the trick! I also had to delete userCertificate for dogtagldap/<a href="http://spider01a.iglass.net">spider01a.iglass.net</a> and HTTP/<a href="http://spider01a.iglass.net">spider01a.iglass.net</a> for the other two certificates not renewing.</div><div><br></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><span class=""><br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">
<br>
I was able to clear 4301 error. One ipaCert needed to be updated.<br>
</blockquote>
<br></span>
Great!<br>
<br>
rob<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><span class="">
<br>
thanks<br>
<br>
On Thu, Jun 16, 2016 at 10:22 AM, Rob Crittenden <<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a><br></span><span class="">
<mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>>> wrote:<br>
<br>
Marc Wiatrowski wrote:<br>
<br></span><div><div class="h5">
Thanks Rob,<br>
<br>
Any suggestions on how make the CA aware of the current serial<br>
number?<br>
<br>
<br>
Serial numbers are dolled out like uid numbers, by the 389-ds DNA<br>
Plugin. So each CA that has ever issued a certificate has its own<br>
range, hence the quite different serial number values.<br>
<br>
Given that some issued certificates are unknown it stands to reason<br>
that replication is broken between one or more masters. Fixing that<br>
should resolve (most of) the other issues.<br>
<br>
Also started seeing the following error from two of the servers,<br>
spider01b and spider01o, but not spider01a when to navigate in<br>
the web<br>
gui. Though it doesn't appear to stop me from doing anything.<br>
<br>
IPA Error 4301<br>
Certificate operation cannot be completed: EXCEPTION (Invalid<br>
Crential.)<br>
<br>
<br>
Dogtag does some of its access control by comparing the incoming<br>
client certificate with an expected value in its LDAP database, in<br>
this case uid=ipara,ou=People,o=ipaca. There you'll find a copy of<br>
the client certificate and a description field that contains the<br>
expected serial #, subject and issuer.<br>
<br>
These are out-of-whack if you're getting Invalid Credentials. It<br>
could be a number of things so I'd proceed cautiously. Given you<br>
have a working master I'd use that as a starting point.<br>
<br>
Look at the the RA cert is in /etc/httpd/alias:<br>
<br>
# certutil -L -d /etc/httpd/alias -n ipaCert | grep Serial<br>
<br>
See if it is the same on all masters, it should be.<br>
<br>
If it is, look at the uid=ipara entry on all the masters. Again,<br>
should be the same.<br>
<br>
Note that fixing this won't address any replication issues.<br>
<br>
rob<br>
<br>
<br>
Marc<br>
<br>
On Tue, Jun 14, 2016 at 2:07 PM, Marc Wiatrowski <<a href="mailto:wia@iglass.net" target="_blank">wia@iglass.net</a><br>
<mailto:<a href="mailto:wia@iglass.net" target="_blank">wia@iglass.net</a>><br></div></div><span class="">
<mailto:<a href="mailto:wia@iglass.net" target="_blank">wia@iglass.net</a> <mailto:<a href="mailto:wia@iglass.net" target="_blank">wia@iglass.net</a>>>> wrote:<br>
<br>
<br>
<br>
On Tue, Jun 14, 2016 at 11:22 AM, Rob Crittenden<br>
<<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a> <mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>><br></span><div><div class="h5">
<mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a> <mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>>>> wrote:<br>
<br>
Marc Wiatrowski wrote:<br>
<br>
Hello, I'm having issues with the 3 ipa<br>
certificates of type<br>
CA: IPA<br>
renewing on 2 of 3 replicas. Particularly on the 2<br>
that are<br>
not the CA<br>
master. The other 5 certificates from getcert list<br>
do renew<br>
and all<br>
certificates on the CA master do look to renew.<br>
<br>
Both servers running<br>
ipa-server-3.0.0-50.el6.centos.1.x86_64 I've done<br>
full updates and rebooted.<br>
<br>
<br>
Can you check on the replication status for each CA?<br>
<br>
$ ipa-csreplica-manage list -v <a href="http://ipa.example.com" rel="noreferrer" target="_blank">ipa.example.com</a><br>
<<a href="http://ipa.example.com" rel="noreferrer" target="_blank">http://ipa.example.com</a>><br>
<<a href="http://ipa.example.com" rel="noreferrer" target="_blank">http://ipa.example.com</a>><br>
<br>
The hostname is important because including that will<br>
show the<br>
agreements that host has. Do this for each master with<br>
a CA.<br>
<br>
The CA being asked to do the renewal is unaware of the<br>
current<br>
serial number so it is refusing to proceed.<br>
<br>
rob<br>
<br>
<br>
<br>
[root@spider01o]$ ipa-csreplica-manage list -v<br>
<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
<<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
Directory Manager password:<br>
<br>
<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">spider01b.iglass.net</a> <<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><br>
<<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><br>
last init status: None<br>
last init ended: None<br>
last update status: 0 Replica acquired successfully:<br>
Incremental<br>
update succeeded<br>
last update ended: 2016-06-14 17:49:16+00:00<br>
<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
<<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
last init status: None<br>
last init ended: None<br>
last update status: 0 Replica acquired successfully:<br>
Incremental<br>
update started<br>
last update ended: 2016-06-14 17:55:20+00:00<br>
<br>
[root@spider01o]$ ipa-csreplica-manage list -v<br>
<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
<<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
Directory Manager password:<br>
<br>
<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
<<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
last init status: None<br>
last init ended: None<br>
last update status: 0 Replica acquired successfully:<br>
Incremental<br>
update started<br>
last update ended: 2016-06-14 17:57:44+00:00<br>
<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">spider01b.iglass.net</a> <<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><br>
<<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><br>
last init status: None<br>
last init ended: None<br>
last update status: 0 Replica acquired successfully:<br>
Incremental<br>
update started<br>
last update ended: 2016-06-14 17:57:41+00:00<br>
<br>
[root@spider01o]$ ipa-csreplica-manage list -v<br>
<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">spider01b.iglass.net</a> <<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><br>
<<a href="http://spider01b.iglass.net" rel="noreferrer" target="_blank">http://spider01b.iglass.net</a>><br>
Directory Manager password:<br>
<br>
<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
<<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
last init status: 0 Total update succeeded<br>
last init ended: 2016-06-03 19:43:12+00:00<br>
last update status: 0 Replica acquired successfully:<br>
Incremental<br>
update succeeded<br>
last update ended: 2016-06-14 17:44:17+00:00<br>
<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
<<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
last init status: 0 Total update succeeded<br>
last init ended: 2016-06-03 19:44:38+00:00<br>
last update status: 0 Replica acquired successfully:<br>
Incremental<br>
update started<br>
last update ended: 2016-06-14 17:57:53+00:00<br>
<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a> <<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
<<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>><br>
last init status: None<br>
last init ended: None<br>
last update status: 0 Replica acquired successfully:<br>
Incremental<br>
update succeeded<br>
last update ended: 2016-06-14 17:44:13+00:00<br>
<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
<<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
last init status: None<br>
last init ended: None<br>
last update status: 0 Replica acquired successfully:<br>
Incremental<br>
update started<br>
last update ended: 2016-06-14 17:57:54+00:00<br>
<br>
<br>
Not sure what this is telling... This an issue with the<br>
last being<br>
doubled? Thanks<br>
<br>
<br>
<br>
The failed renews look like:<br>
<br>
[root@spider01a]$ getcert list -i 20141202144354<br>
Number of certificates and requests being tracked: 8.<br>
Request ID '20141202144354':<br>
status: CA_UNREACHABLE<br>
ca-error: Server at <a href="https://spider01a.iglass.net/ipa/xml" rel="noreferrer" target="_blank">https://spider01a.iglass.net/ipa/xml</a><br>
failed request,<br>
will retry: 4301 (RPC failed at server. Certificate<br>
operation cannot be<br>
completed: EXCEPTION (Certificate serial number 0x3ffe0010<br>
not found)).<br>
stuck: no<br>
key pair storage:<br>
<br>
type=NSSDB,location='/etc/dirsrv/slapd-PKI-IPA',nickname='Server-Cert',token='NSS<br>
Certificate DB',pinfile='/etc/dirsrv/slapd-PKI-IPA/pwdfile.txt'<br>
certificate:<br>
<br>
type=NSSDB,location='/etc/dirsrv/slapd-PKI-IPA',nickname='Server-Cert',token='NSS<br>
Certificate DB'<br>
CA: IPA<br>
issuer: CN=Certificate Authority,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></div></div>
<<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>><span class=""><br>
<<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
subject: CN=<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a><br></span>
<<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>> <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>><span class=""><br>
<<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a><br>
<<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>>>,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></span>
<<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>><div><div class="h5"><br>
<<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
expires: 2016-12-02 14:38:45 UTC<br>
key usage:<br>
<br>
digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>
eku: id-kp-serverAuth,id-kp-clientAuth<br>
pre-save command:<br>
post-save command: /usr/lib64/ipa/certmonger/restart_dirsrv<br>
PKI-IPA<br>
track: yes<br>
auto-renew: yes<br>
<br>
[root@spider01a]$ getcert list -i 20141202144616<br>
Number of certificates and requests being tracked: 8.<br>
Request ID '20141202144616':<br>
status: CA_UNREACHABLE<br>
ca-error: Server at <a href="https://spider01a.iglass.net/ipa/xml" rel="noreferrer" target="_blank">https://spider01a.iglass.net/ipa/xml</a><br>
failed request,<br>
will retry: 4301 (RPC failed at server. Certificate<br>
operation cannot be<br>
completed: EXCEPTION (Certificate serial number 0x3ffe000f<br>
not found)).<br>
stuck: no<br>
key pair storage:<br>
<br>
type=NSSDB,location='/etc/dirsrv/slapd-IGLASS-NET',nickname='Server-Cert',token='NSS<br>
Certificate<br>
DB',pinfile='/etc/dirsrv/slapd-IGLASS-NET/pwdfile.txt'<br>
certificate:<br>
<br>
type=NSSDB,location='/etc/dirsrv/slapd-IGLASS-NET',nickname='Server-Cert',token='NSS<br>
Certificate DB'<br>
CA: IPA<br>
issuer: CN=Certificate Authority,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></div></div>
<<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>><span class=""><br>
<<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
subject: CN=<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a><br></span>
<<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>> <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>><span class=""><br>
<<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a><br>
<<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>>>,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></span>
<<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>><div><div class="h5"><br>
<<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
expires: 2016-12-02 14:38:43 UTC<br>
key usage:<br>
<br>
digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>
eku: id-kp-serverAuth,id-kp-clientAuth<br>
pre-save command:<br>
post-save command: /usr/lib64/ipa/certmonger/restart_dirsrv<br>
IGLASS-NET<br>
track: yes<br>
auto-renew: yes<br>
<br>
[root@spider01a]$ getcert list -i 20141202144733<br>
Number of certificates and requests being tracked: 8.<br>
Request ID '20141202144733':<br>
status: CA_UNREACHABLE<br>
ca-error: Server at <a href="https://spider01a.iglass.net/ipa/xml" rel="noreferrer" target="_blank">https://spider01a.iglass.net/ipa/xml</a><br>
failed request,<br>
will retry: 4301 (RPC failed at server. Certificate<br>
operation cannot be<br>
completed: EXCEPTION (Certificate serial number 0x3ffe0011<br>
not found)).<br>
stuck: no<br>
key pair storage:<br>
<br>
type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS<br>
Certificate DB',pinfile='/etc/httpd/alias/pwdfile.txt'<br>
certificate:<br>
<br>
type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS<br>
Certificate DB'<br>
CA: IPA<br>
issuer: CN=Certificate Authority,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></div></div>
<<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>><span class=""><br>
<<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
subject: CN=<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">spider01a.iglass.net</a><br></span>
<<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a>> <<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>><span class=""><br>
<<a href="http://spider01a.iglass.net" rel="noreferrer" target="_blank">http://spider01a.iglass.net</a><br>
<<a href="http://spider01a.iglass.net/" rel="noreferrer" target="_blank">http://spider01a.iglass.net/</a>>>,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a><br></span>
<<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>><div><div class="h5"><br>
<<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>><br>
expires: 2016-12-02 14:38:46 UTC<br>
key usage:<br>
<br>
digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br>
eku: id-kp-serverAuth,id-kp-clientAuth<br>
pre-save command:<br>
post-save command: /usr/lib64/ipa/certmonger/restart_httpd<br>
track: yes<br>
auto-renew: yes<br>
<br>
<br>
From<br>
[root@spider01a]$ getcert resubmit -i 20141202144354<br>
<br>
On the replica issuing the resubmit<br>
<br>
==> /var/log/httpd/access_log <==<br>
192.168.176.2 - - [13/Jun/2016:15:49:32 -0400] "POST<br>
/ipa/xml HTTP/1.1"<br>
401 1370<br>
<br>
==> /var/log/httpd/error_log <==<br>
[Mon Jun 13 15:49:33 2016] [error] ipa: ERROR:<br>
ipaserver.plugins.dogtag.ra.get_certificate(): EXCEPTION<br>
(Certificate<br>
serial number 0x3ffe0010 not found)<br>
[Mon Jun 13 15:49:33 2016] [error] ipa: INFO:<br>
host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>>:<br>
<br>
cert_request(u'MIIDsTCCApkCAQAwNDETMBEGA1UEChMKSUdMQVNTLk5FVDEdMBsGA1UEAxMUc3BpZGVyMDFhLml...UVrN8lbKn17V5COjnj6k0mdbz3KptL0UI/l0BPlFBWGN5MFYaDx2F+y6LWv/aXeu2V4E6LA==',<br>
principal=u'dogtagldap/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>>', add=True):<br>
CertificateOperationError<br>
<br>
==> /var/log/httpd/access_log <==<br>
192.168.176.2 - - [13/Jun/2016:15:49:33 -0400] "POST<br>
/ca/agent/ca/displayBySerial HTTP/1.1" 200 262<br>
192.168.176.2 - host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>> [13/Jun/2016:15:49:32<br>
-0400]<br>
"POST /ipa/xml HTTP/1.1" 200 376<br>
<br>
==> /var/log/pki-ca/system <==<br>
2508.TP-Processor6 - [13/Jun/2016:15:49:33 EDT] [3] [3] Servlet<br>
caDisplayBySerial: Error encountered in DisplayBySerial.<br>
Error Record<br>
not found.<br>
<br>
<br>
On the CA master spider01o:<br>
<br>
==> /var/log/httpd/access_log <==<br>
192.168.176.2 - - [13/Jun/2016:15:49:33 -0400] "POST<br>
/ipa/xml HTTP/1.1"<br>
401 1370<br>
<br>
==> krb5kdc.log <==<br>
Jun 13 15:49:34 <a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">spider01o.iglass.net</a><br>
<<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a>><br>
<<a href="http://spider01o.iglass.net/" rel="noreferrer" target="_blank">http://spider01o.iglass.net/</a>> <<a href="http://spider01o.iglass.net" rel="noreferrer" target="_blank">http://spider01o.iglass.net</a><br>
<<a href="http://spider01o.iglass.net/" rel="noreferrer" target="_blank">http://spider01o.iglass.net/</a>>><br>
krb5kdc[1963](info): TGS_REQ (4 etypes {18 17 16 23})<br>
192.168.177.2<br>
<<a href="http://192.168.177.2" rel="noreferrer" target="_blank">http://192.168.177.2</a> <<a href="http://192.168.177.2/" rel="noreferrer" target="_blank">http://192.168.177.2/</a>>>: ISSUE: authtime<br>
1465847372, etypes {rep=18<br>
tkt=18 ses=18}, host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>> for<br>
ldap/<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a>>><br>
<mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01o.iglass.net@IGLASS.NET" target="_blank">spider01o.iglass.net@IGLASS.NET</a>>>><br>
<br>
==> /var/log/httpd/error_log <==<br>
[Mon Jun 13 15:49:34 2016] [error] ipa: ERROR:<br>
ipaserver.plugins.dogtag.ra.get_certificate(): EXCEPTION<br>
(Invalid<br>
Credential.)<br>
[Mon Jun 13 15:49:34 2016] [error] ipa: INFO:<br>
host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>>:<br>
<br>
cert_request(u'MIIDsTCCApkCAQAwNDETMBEGA1UEChMKSUdMQVNTLk5FVDEdMBsGA1UEAxMUc3BpZGVyMDFhLml...UVrN8lbKn17V5COjnj6k0mdbz3KptL0UI/l0BPlFBWGN5MFYaDx2F+y6LWv/aXeu2V4E6LA==',<br>
principal=u'dogtagldap/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br></div></div><span class="">
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>>', add=True):<br>
CertificateOperationError<br>
<br>
==> /var/log/httpd/access_log <==<br>
192.168.177.2 - - [13/Jun/2016:15:49:34 -0400] "POST<br>
/ca/agent/ca/displayBySerial HTTP/1.1" 200 235<br>
192.168.176.2 - host/<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>><br></span><span class="">
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>><br>
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a><br></span><span class="">
<mailto:<a href="mailto:spider01a.iglass.net@IGLASS.NET" target="_blank">spider01a.iglass.net@IGLASS.NET</a>>>> [13/Jun/2016:15:49:33<br>
-0400]<br>
"POST /ipa/xml HTTP/1.1" 200 349<br>
<br>
==> /var/log/pki-ca/system <==<br>
2231.TP-Processor3 - [13/Jun/2016:15:49:34 EDT] [6] [3] Cannot<br>
authenticate agent with certificate Serial 0x5ffc0008<br>
Subject DN CN=IPA<br></span>
RA,O=<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">IGLASS.NET</a> <<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a>> <<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>><span class=""><br>
<<a href="http://IGLASS.NET" rel="noreferrer" target="_blank">http://IGLASS.NET</a><br>
<<a href="http://iglass.net/" rel="noreferrer" target="_blank">http://iglass.net/</a>>>. Error: User not found<br>
<br>
<br>
I realize they expire at the end of the year, but I've had my<br>
certificates expire before and would rather not go through<br>
that again.<br>
Any idea on what's wrong or suggestions on where to look<br>
would be<br>
appreciated.<br>
<br>
Thanks,<br>
Marc<br>
<br>
<br>
<br>
<br>
<br>
<br>
</span></blockquote>
<br>
</blockquote></div><br></div></div>