Hi,
I re-sync the date to today and ran ipa-cert-fix but it returns an error
[root@ipa1 ~]# ipa-cert-fix
WARNING
ipa-cert-fix is intended for recovery when expired certificates prevent the normal operation of IPA. It should ONLY be used in such scenarios, and backup of the system, especially certificates and keys, is STRONGLY RECOMMENDED.
The following certificates will be renewed:
Dogtag sslserver certificate: Subject: CN=ipa1.itec.lab,O=ITEC.LAB Serial: 17 Expires: 2020-12-08 09:35:05
Dogtag subsystem certificate: Subject: CN=CA Subsystem,O=ITEC.LAB Serial: 19 Expires: 2020-12-08 09:37:36
Dogtag ca_ocsp_signing certificate: Subject: CN=OCSP Subsystem,O=ITEC.LAB Serial: 21 Expires: 2020-12-08 09:38:07
Dogtag ca_audit_signing certificate: Subject: CN=CA Audit,O=ITEC.LAB Serial: 18 Expires: 2020-12-08 09:35:14
IPA IPA RA certificate: Subject: CN=IPA RA,O=ITEC.LAB Serial: 20 Expires: 2020-12-08 09:37:47
IPA Apache HTTPS certificate: Subject: CN=ipa1.itec.lab,O=ITEC.LAB Serial: 24 Expires: 2020-12-30 09:35:04
IPA LDAP certificate: Subject: CN=ipa1.itec.lab,O=ITEC.LAB Serial: 25 Expires: 2020-12-30 09:35:16
IPA KDC certificate: Subject: CN=ipa1.itec.lab,O=ITEC.LAB Serial: 1 Expires: 2020-12-31 20:19:55
Enter "yes" to proceed: yes Proceeding. [Errno 2] No such file or directory: '/etc/pki/pki-tomcat/certs/sslserver.crt' The ipa-cert-fix command failed.