Hi,

> On 26 Jan 2023, at 13:12, MM MM via FreeIPA-users 
> <[email protected]> wrote:
> 
> Hello Antonio,
> 
> ipa getcert-list doesn't show the outdated certificate.
ipa getcert-list displays only a subset of certificates, the ones handled by 
IPA CA helper. What is the full output of “getcert list” on the master? Are all 
the certs up to date?

> The replica is failing with the following certificates:
> - CA Subsystem
> - OCSP Subsystem
> - CA Audit
> 
The replica installer downloads those certs from the master (they are identical 
on all servers/replicas), and this is why I suspect that some of them were not 
properly renewed on the master.
flo
> Thanks in advance!
> 
> Best regards
> _______________________________________________
> FreeIPA-users mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> Fedora Code of Conduct: 
> https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives: 
> https://lists.fedorahosted.org/archives/list/[email protected]
> Do not reply to spam, report it: 
> https://pagure.io/fedora-infrastructure/new_issue
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to