Spoke too soon. If I try to get a new certificate on an enrolled host I get this
status: CA_UNREACHABLE ca-error: Server at https://ipa1-sea2.ipa.****.net/ipa/xml failed request, will retry: 907 (RPC failed at server. cannot connect to 'https://ipa1-sea2.ipa.****.net:443/ca/rest/account/login': [SSL: SSL_HANDSHAKE_FAILURE] ssl handshake failure (_ssl.c:1822)). This reflected in the UI if I go to Authentication > Certificates > Certificate Authorities where I see the same error. The IPA server listed there is the one where all services started via ipactl start in my previous update. -- _______________________________________________ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue