Thank you Rob for your help.

I see no expired certificates:

getcert list | grep expires
        expires: 2022-04-17 16:46:12 CEST
        expires: unknown
        expires: unknown
        expires: unknown
        expires: unknown
        expires: 2022-04-06 16:44:19 CEST
        expires: 2022-04-06 16:44:45 CEST
        expires: 2022-04-17 16:45:23 CEST
        expires: 2022-04-17 16:45:47 CEST

I did also not see anything curious in the ca log folder.
All services seem to be running, as far as I can see.


On a restart of certmonger I get these errors, but after that its up
Jan 12 07:31:05 test.intra certmonger[53276]: 2021-01-12 07:31:05 [53378] Error 
authenticating to token "NSS Certificate DB".
Jan 12 07:31:05 test.intra certmonger[53276]: 2021-01-12 07:31:05 [53378] Error 
shutting down NSS.
Jan 12 07:31:07 test.intra certmonger[53276]: 2021-01-12 07:31:07 [53417] Error 
authenticating to token "NSS Certificate DB".
Jan 12 07:31:07 test.intra certmonger[53276]: 2021-01-12 07:31:07 [53417] Error 
shutting down NSS.
Jan 12 07:31:12 test.intra certmonger[53276]: 2021-01-12 07:31:12 [53447] Error 
authenticating to token "NSS Certificate DB".
Jan 12 07:31:12 test.intra certmonger[53276]: 2021-01-12 07:31:12 [53447] Error 
shutting down NSS.
Jan 12 07:31:17 test.intra certmonger[53276]: 2021-01-12 07:31:17 [53492] Error 
authenticating to token "NSS Certificate DB".
Jan 12 07:31:17 test.intra certmonger[53276]: 2021-01-12 07:31:17 [53492] Error 
shutting down NSS.

tomcat also answers to a curl on http://test.intra:8080/ca/admin/ca/getStatus 
with running

Any further ideas? I need to get it back runnig somehow :(!

Thanks a lot

Nico
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to