Travis West via FreeIPA-users wrote:
> Spoke too soon.  If I try to get a new certificate on an enrolled host I get 
> this
> 
>  status: CA_UNREACHABLE
> ca-error: Server at https://ipa1-sea2.ipa.****.net/ipa/xml failed request, 
> will retry: 907 (RPC failed at server.  cannot connect to 
> 'https://ipa1-sea2.ipa.****.net:443/ca/rest/account/login': [SSL: 
> SSL_HANDSHAKE_FAILURE] ssl handshake failure (_ssl.c:1822)).
> 
> This reflected in the UI if I go to Authentication > Certificates > 
> Certificate Authorities where I see the same error.
> 
> The IPA server listed there is the one where all services started via ipactl 
> start in my previous update.

I think you need to take a look at fresh logs to see what failed. It may
point to why.

I assume you went back in time to 2019 and then leaped forward 2 years
at a pop, renewing as you went, and now it's present day?

rob
--
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to