I've tried that actually, but then I'm also getting an error

cannot connect to 'https://XXXX/ipa/json': [SSL: CERTIFICATE_VERIFY_FAILED] 
certificate verify failed: certificate has expired (_ssl.c:1131)
The ipa-certupdate command failed.

My certificate is still valid, so this must also be related to the expired root 
CA. Is there a manual way to update the NSS database? Our FreeIPA version is 
4.8.10 by the way. I remember fixing the NSS db on an older installation at 
some time, but I haven't found the db location on this new installation yet.

I guess I could reconfigure Apache to use a different certificate or even a 
self-signed one to get `ipa-certupdate` working again.
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure

Reply via email to