[Freeipa-users] Re: handling certificate expirations

2024-02-20 Thread Grant Janssen via FreeIPA-users
well, I thought I was out of the woods, but I still have some issues. the services are running, but kinit gets me a ticket to nowhere. "ipa: ERROR: No valid Negotiate header in server response" grant@ef-idm01:~[20240220-14:36][#785]$ klist Ticket cache: KCM:555 Default principal:

[Freeipa-users] Re: handling certificate expirations

2024-02-16 Thread Grant Janssen via FreeIPA-users
this was definitely the hot tip. executing a server upgrade fixed everything for me. thanx rob -- ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora

[Freeipa-users] Re: handling certificate expirations

2024-02-15 Thread Rob Crittenden via FreeIPA-users
Grant Janssen via FreeIPA-users wrote: > When I upgraded the servers to EL8 (I rebuilt from scratch using the old > hostnames), I had neglected to assign an IPA CA renewal master after the > old “boss” was retired. > This crime is of course it’s own punishment. > > I found the documentation for