mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2025-02-25 18:55:28 -06:00
ipa-cert-fix man page: add note about certmonger renewal
ipa-cert-fix man page needs to explain that certmonger may trigger a renewal right after ipa-cert-fix completes because certmonger does not notice the updated certificates. Also add a similar note at the end of ipa-cert-fix. Fixes: https://pagure.io/freeipa/issue/8702 Signed-off-by: Florence Blanc-Renaud <flo@redhat.com> Reviewed-By: Mohammad Rizwan <myusuf@redhat.com> Reviewed-By: Rob Crittenden <rcritten@redhat.com>
This commit is contained in:
@@ -39,6 +39,13 @@ for shared certificates via \fIgetcert-resubmit(1)\fR (on the other
|
||||
CA server). This is to avoid unnecessary renewal of shared
|
||||
certificates.
|
||||
|
||||
Important note: the \fIcertmonger\fR daemon does not immediately notice
|
||||
the updated certificates and may trigger a renewal after \fIipa-cert-fix\fR
|
||||
completes. As a consequence, \fIgetcert list\fR output may display
|
||||
that a renewal is in progress even if \fIipa-cert-fix\fR just
|
||||
finished. It is recommended to monitor the certmonger-initiated
|
||||
renewal and wait for its completion before any other administrative task.
|
||||
|
||||
.SH "OPTIONS"
|
||||
.TP
|
||||
\fB\-\-version\fR
|
||||
|
||||
Reference in New Issue
Block a user