[Freeipa-users] Re: certmonger Error 77 Problem with the SSL CA cert

2018-10-26 Thread Florence Blanc-Renaud via FreeIPA-users
On 10/26/18 6:09 PM, Kees Bakker via FreeIPA-users wrote: On 26-10-18 18:00, Timo Aaltonen wrote: On 26.10.2018 18.59, Kees Bakker wrote: On 26-10-18 14:55, Timo Aaltonen wrote: On 26.10.2018 09:59, Kees Bakker via FreeIPA-users wrote: On 25-10-18 20:46, Timo Aaltonen wrote: On 25.10.2018

[Freeipa-users] Re: certmonger Error 77 Problem with the SSL CA cert

2018-10-26 Thread Timo Aaltonen via FreeIPA-users
On 26.10.2018 19.09, Kees Bakker wrote: > > > On 26-10-18 18:00, Timo Aaltonen wrote: >> On 26.10.2018 18.59, Kees Bakker wrote: >>> On 26-10-18 14:55, Timo Aaltonen wrote: On 26.10.2018 09:59, Kees Bakker via FreeIPA-users wrote: > On 25-10-18 20:46, Timo Aaltonen wrote: >> On

[Freeipa-users] Re: certmonger Error 77 Problem with the SSL CA cert

2018-10-26 Thread Kees Bakker via FreeIPA-users
On 26-10-18 18:00, Timo Aaltonen wrote: > On 26.10.2018 18.59, Kees Bakker wrote: >> On 26-10-18 14:55, Timo Aaltonen wrote: >>> On 26.10.2018 09:59, Kees Bakker via FreeIPA-users wrote: On 25-10-18 20:46, Timo Aaltonen wrote: > On 25.10.2018 21.44, Rob Crittenden wrote: >> Kees

[Freeipa-users] Re: certmonger Error 77 Problem with the SSL CA cert

2018-10-26 Thread Kees Bakker via FreeIPA-users
On 26-10-18 14:55, Timo Aaltonen wrote: > On 26.10.2018 09:59, Kees Bakker via FreeIPA-users wrote: >> On 25-10-18 20:46, Timo Aaltonen wrote: >>> On 25.10.2018 21.44, Rob Crittenden wrote: Kees Bakker wrote: > On 25-10-18 16:11, Rob Crittenden wrote: >> Kees Bakker via FreeIPA-users

[Freeipa-users] Re: ipa-replica-manage --force replica.server fails

2018-10-26 Thread Rob Crittenden via FreeIPA-users
Ralph Crongeyer wrote: > Well I got it fixed by using ApacheDirectoryStudio and searching for the > old stuck replica and deleted all of it's entries, which fixed the issues, > I wish I would have gotten this email sooner, I would have tried what > you suggested. > > Thanks for your help with

[Freeipa-users] Re: ipa-replica-manage --force replica.server fails

2018-10-26 Thread Ralph Crongeyer via FreeIPA-users
Well I got it fixed by using ApacheDirectoryStudio and searching for the old stuck replica and deleted all of it's entries, which fixed the issues, I wish I would have gotten this email sooner, I would have tried what you suggested. Thanks for your help with this. Ralph On Wed, Oct 24, 2018 at

[Freeipa-users] Re: certmonger Error 77 Problem with the SSL CA cert

2018-10-26 Thread Kees Bakker via FreeIPA-users
On 26-10-18 17:33, Timo Aaltonen wrote: > On 26.10.2018 18.30, Kees Bakker wrote: >> On 26-10-18 14:55, Timo Aaltonen wrote: >>> On 26.10.2018 09:59, Kees Bakker via FreeIPA-users wrote: On 25-10-18 20:46, Timo Aaltonen wrote: > On 25.10.2018 21.44, Rob Crittenden wrote: >> Kees

[Freeipa-users] Re: certmonger Error 77 Problem with the SSL CA cert

2018-10-26 Thread Timo Aaltonen via FreeIPA-users
On 26.10.2018 18.30, Kees Bakker wrote: > On 26-10-18 14:55, Timo Aaltonen wrote: >> On 26.10.2018 09:59, Kees Bakker via FreeIPA-users wrote: >>> On 25-10-18 20:46, Timo Aaltonen wrote: On 25.10.2018 21.44, Rob Crittenden wrote: > Kees Bakker wrote: >> On 25-10-18 16:11, Rob

[Freeipa-users] Re: Testing requested - certificate checking tool

2018-10-26 Thread Rob Crittenden via FreeIPA-users
Louis Lagendijk via FreeIPA-users wrote: > On Mon, 2018-10-22 at 12:07 -0400, Rob Crittenden via FreeIPA-users > wrote: >> Gah, regarding >> >> Missing tracking for {'cert-nickname': 'Server-Cert', 'ca-name': >> 'IPA', >> 'cert-database': '/etc/httpd/alias', 'cert-postsave-command': >>

[Freeipa-users] Re: certmonger Error 77 Problem with the SSL CA cert

2018-10-26 Thread Timo Aaltonen via FreeIPA-users
On 26.10.2018 09:59, Kees Bakker via FreeIPA-users wrote: > On 25-10-18 20:46, Timo Aaltonen wrote: >> On 25.10.2018 21.44, Rob Crittenden wrote: >>> Kees Bakker wrote: On 25-10-18 16:11, Rob Crittenden wrote: > Kees Bakker via FreeIPA-users wrote: >> On 25-10-18 14:18, Rob Crittenden

[Freeipa-users] Re: IPA sub-CAs; cleaning up spurious Dogtag LWCA entries

2018-10-26 Thread Louis Lagendijk via FreeIPA-users
On Tue, 2018-10-23 at 11:23 +1000, Fraser Tweedale via FreeIPA-users wrote: > Hi Rob, > > (Cc freeipa-users@ for visibility) > > On Mon, Oct 22, 2018 at 04:12:05PM -0400, Rob Crittenden wrote: > > I've gotten some upstream feedback on my cert checking tool and one > > user > > came back with a

[Freeipa-users] Re: Testing requested - certificate checking tool

2018-10-26 Thread Louis Lagendijk via FreeIPA-users
Hi Rob, Here are the answer to your questions. On Mon, 2018-10-22 at 12:01 -0400, Rob Crittenden via FreeIPA-users wrote: > Let's tackle these one at a time. > > Missing tracking for {'cert-nickname': 'Server-Cert', 'ca-name': > 'IPA', > 'cert-database': '/etc/httpd/alias',

[Freeipa-users] Re: Testing requested - certificate checking tool

2018-10-26 Thread Louis Lagendijk via FreeIPA-users
On Mon, 2018-10-22 at 12:07 -0400, Rob Crittenden via FreeIPA-users wrote: > Gah, regarding > > Missing tracking for {'cert-nickname': 'Server-Cert', 'ca-name': > 'IPA', > 'cert-database': '/etc/httpd/alias', 'cert-postsave-command': > '/usr/libexec/ipa/certmonger/restart_httpd'} > > never mind.

[Freeipa-users] Re: ipa.service "fails" to start

2018-10-26 Thread Florence Blanc-Renaud via FreeIPA-users
On 10/26/18 7:36 AM, Z D via FreeIPA-users wrote: Hi Rob, I follow one of your suggestions in another post, it's : "certmonger _should_ have renewed them. Try killing ntpd, going back a few days, restart krb5kdc, dirsrv, httpd and the CA then certmonger and see what happens" I did it, no

[Freeipa-users] Re: Is IPA-AD two-way trust really two-way?

2018-10-26 Thread Winfried de Heiden via FreeIPA-users
Hi all, Thanks! This explains a lot, I'm happy :) Winfried Alexander Bokovoy via FreeIPA-users schreef op 26-10-2018 11:16: On pe, 26 loka 2018, Winfried de Heiden wrote: Hi all, Refering to this bit of older post, What now the difference between a One-way or Two-Way Trust anyway? The

[Freeipa-users] Re: Is IPA-AD two-way trust really two-way?

2018-10-26 Thread Alexander Bokovoy via FreeIPA-users
On pe, 26 loka 2018, Winfried de Heiden wrote: Hi all, Refering to this bit of older post, What now the difference between a One-way or Two-Way Trust anyway? The docs are not too clear abut it: " Two-way trust enables AD users and groups to access resources in IdM. However, the two-way

[Freeipa-users] Re: Is IPA-AD two-way trust really two-way?

2018-10-26 Thread Winfried de Heiden via FreeIPA-users
Hi all, Refering to this bit of older post, What now the difference between a One-way or Two-Way Trust anyway? The docs are not too clear abut it: " Two-way trust enables AD users and groups to access resources in IdM. However, the two-way trust in IdM does not give the users any

[Freeipa-users] Re: certmonger Error 77 Problem with the SSL CA cert

2018-10-26 Thread Kees Bakker via FreeIPA-users
On 25-10-18 20:46, Timo Aaltonen wrote: > On 25.10.2018 21.44, Rob Crittenden wrote: >> Kees Bakker wrote: >>> On 25-10-18 16:11, Rob Crittenden wrote: Kees Bakker via FreeIPA-users wrote: > On 25-10-18 14:18, Rob Crittenden wrote: >> Kees Bakker via FreeIPA-users wrote: >>> Could