Bob Strachan via FreeIPA-users <[email protected]>
writes:

> At some point and I believe it was when we got to Rhel8.6 we started
> getting hc errors with this type of message:
> "msg": "Certificate 'subsystemCert cert-pki-ca' does not match the
> value of kra.subsystem.cert in
> /var/lib/pki/pki-tomcat/kra/conf/CS.cfg"

My analysis is documented here, more or less what you found:
https://pagure.io/freeipa/issue/9277

I've posted my take on an ansible script to fix my servers:
https://lists.fedorahosted.org/archives/list/[email protected]/message/CEHJ6FE7N5D2XJ7ZCGHN76OX4GMBMOIV/

HTH
Jochen

-- 
This space is intentionally left blank.
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to