[Freeipa-users] sidgen_task fails with SID conflict

2024-07-18 Thread Basile Pinsard via FreeIPA-users
Hi, I had an existing instance of freeipa that went broken so badly (pki-tomcat unrecoverable) that the only option was spinning up a new one and `ipa migrate-ds` from the broken one. The new instance was set to reuse the same id-range as the previous one, so all is good for the users in that

[Freeipa-users] Re: Authentication failures on a RHEL 9.2 IPA server

2024-07-18 Thread Basile Pinsard via FreeIPA-users
Hi, I have a similar issue after reimporting user with migrate-ds including users in a legacy range. I created the id-range to contain these users ids, but some users show an error similar to the one described above. Did you manage to fix it? When running the sidgen task after setting the range

[Freeipa-users] Re: pki-tomcat won't start + expired certificates

2024-04-19 Thread Basile Pinsard via FreeIPA-users
Hi! Here is the output of ipa-cert-fix on the original instance: ``` The following certificates will be renewed: Dogtag sslserver certificate: Subject: CN=ipa.DOMAIN.COM,O=DOMAIN.COM Serial: 3 Expires: 2024-03-19 20:36:25 Dogtag subsystem certificate: Subject: CN=CA Subsystem,O=DOMAI

[Freeipa-users] Re: pki-tomcat won't start + expired certificates

2024-04-15 Thread Basile Pinsard via FreeIPA-users
Bonjour Florence, Thanks for your help. I am using the docker image `freeipa/freeipa-server:fedora-34-4.9.6`, I guess the dependencies are correct as this is all bundled in the container, (though there might exists config mismatched if ipa upgrades failed containers updates). Se-linux is disable

[Freeipa-users] pki-tomcat won't start + expired certificates

2024-04-12 Thread Basile Pinsard via FreeIPA-users
Hi freeipa experts. I have been using freeipa for the past 5 years running in a docker container, no replicas. currently on VERSION: 4.9.6, API_VERSION: 2.245 I have the following issue, not sure what caused this: pki-tomcat service is not starting, and it is no longer possible to login throug