mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2025-02-25 18:55:28 -06:00
When the CSR for an expired cert is not found in /etc/pki/pki-tomcat/{ca|kra}/CS.cfg, ipa-cert-fix fails to renew the certificate and repair the installation. The CSR can be found using certmonger as it is stored in /var/lib/certmonger/requests/<ID> in the "csr" attribute. Prior to calling pki-server cert-fix, make sure that the CSR is present in CS.cfg, or update CS.cfg with the content found using certmonger. Fixes: https://pagure.io/freeipa/issue/8618 Signed-off-by: Florence Blanc-Renaud <flo@redhat.com> Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com> Reviewed-By: Rob Crittenden <rcritten@redhat.com> |
||
---|---|---|
.. | ||
advise | ||
dnssec | ||
install | ||
plugins | ||
secrets | ||
__init__.py | ||
dcerpc_common.py | ||
dcerpc.py | ||
dns_data_management.py | ||
Makefile.am | ||
masters.py | ||
p11helper.py | ||
rpcserver.py | ||
servroles.py | ||
setup.cfg | ||
setup.py | ||
topology.py |