Nico Maas via FreeIPA-users wrote:
> Dear all,
> I am using FreeIPA, Version: 4.8.4 on CentOS 8
> 
> ipa-client.x86_64           4.8.4-7.module_el8.2.0+374+0d2d74a1               
>      @AppStream
> ipa-client-common.noarch    4.8.4-7.module_el8.2.0+374+0d2d74a1               
>      @AppStream
> ipa-common.noarch           4.8.4-7.module_el8.2.0+374+0d2d74a1               
>      @AppStream
> ipa-healthcheck-core.noarch 0.4-4.module_el8.2.0+374+0d2d74a1                 
>      @AppStream
> ipa-server.x86_64           4.8.4-7.module_el8.2.0+374+0d2d74a1               
>      @AppStream
> ipa-server-common.noarch    4.8.4-7.module_el8.2.0+374+0d2d74a1               
>      @AppStream
> ipa-server-dns.noarch       4.8.4-7.module_el8.2.0+374+0d2d74a1               
>      @AppStream
> 
> Whenever I open the "Authentication" tab in the freeIPA webserver, I get the 
> error
> "IPA-Error 903: InternalError. An internal error has happend".
> Retry does not help, within Authentication I can use all tabs, except from 
> the Authentication -> Certificate -> Certificate one. This one gives the 
> error. I can also not search for a certificate. The other areas of  
> Authentication -> Certificate (Certificate Profiles, CA ACLS, Certificate 
> Authorities) work without problems.
> 
> As a test I cloned the machine and updated it to the latest CentOS 8 version 
> with a newer freeIPA version on it, but that did not solve the problem and I 
> scrapped this vm and idea again.
> 
> Any idea on how to resolve the issue / what could be broken? 
> Which logs and things would be useful to look into?
> 
> Thanks a lot for your help and have a nice day

Your CA is not working. I'd look at the log files in
/var/log/pki/pki-tomcat/ca

Also be sure the certs are still valid: getcert list | grep expires

rob
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to