Hi,
On 26 Jan 2023, at 13:12, MM MM via FreeIPA-users
<freeipa-users(a)lists.fedorahosted.org> wrote:
Hello Antonio,
ipa getcert-list doesn't show the outdated certificate.
ipa getcert-list
displays only a subset of certificates, the ones handled by IPA CA helper. What is the
full output of “getcert list” on the master? Are all the certs up to date?
The replica is failing with the following certificates:
- CA Subsystem
- OCSP Subsystem
- CA Audit
The replica installer downloads those certs from the master (they are identical on
all servers/replicas), and this is why I suspect that some of them were not properly
renewed on the master.
flo
Thanks in advance!
Best regards
_______________________________________________
FreeIPA-users mailing list -- freeipa-users(a)lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-leave(a)lists.fedorahosted.org
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines:
https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedoraho...
Do not reply to spam, report it:
https://pagure.io/fedora-infrastructure/new_issue