mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2025-01-11 00:31:56 -06:00
5509e00a82
ipa-cert-fix man page needs to explain that certmonger may trigger a renewal right after ipa-cert-fix completes because certmonger does not notice the updated certificates. Also add a similar note at the end of ipa-cert-fix. Fixes: https://pagure.io/freeipa/issue/8702 Signed-off-by: Florence Blanc-Renaud <flo@redhat.com> Reviewed-By: Mohammad Rizwan <myusuf@redhat.com> Reviewed-By: Rob Crittenden <rcritten@redhat.com>
74 lines
2.6 KiB
Groff
74 lines
2.6 KiB
Groff
.\"
|
|
.\" Copyright (C) 2019 FreeIPA Contributors see COPYING for license
|
|
.\"
|
|
.TH "ipa-cert-fix" "1" "Mar 25 2019" "IPA" "IPA Manual Pages"
|
|
.SH "NAME"
|
|
ipa\-cert\-fix \- Renew expired certificates
|
|
.SH "SYNOPSIS"
|
|
ipa\-cert\-fix [options]
|
|
.SH "DESCRIPTION"
|
|
|
|
\fIipa-cert-fix\fR is a tool for recovery when expired certificates
|
|
prevent the normal operation of IPA. It should ONLY be used in
|
|
such scenarios, and backup of the system, especially certificates
|
|
and keys, is \fBSTRONGLY RECOMMENDED\fR.
|
|
|
|
Do not use this program unless expired certificates are inhibiting
|
|
normal operation and renewal procedures.
|
|
|
|
To renew the IPA CA certificate, use \fIipa-cacert-manage(1)\fR.
|
|
|
|
This tool cannot renew certificates signed by external CAs. To
|
|
install new, externally-signed HTTP, LDAP or KDC certificates, use
|
|
\fIipa-server-certinstall(1)\fR.
|
|
|
|
\fIipa-cert-fix\fR will examine IPA and Certificate System
|
|
certificates and renew certificates that are expired, or close to
|
|
expiry (less than two weeks). If any "shared" certificates are
|
|
renewed, \fIipa-cert-fix\fR will set the current server to be the CA
|
|
renewal master, and add the new shared certificate(s) to LDAP for
|
|
replication to other CA servers. Shared certificates include all
|
|
Dogtag system certificates except the HTTPS certificate, and the IPA
|
|
RA certificate.
|
|
|
|
To repair certificates across multiple CA servers, first ensure that
|
|
LDAP replication is working across the topology. Then run
|
|
\fIipa-cert-fix\fR on one CA server. Before running
|
|
\fIipa-cert-fix\fR on another CA server, trigger Certmonger renewals
|
|
for shared certificates via \fIgetcert-resubmit(1)\fR (on the other
|
|
CA server). This is to avoid unnecessary renewal of shared
|
|
certificates.
|
|
|
|
Important note: the \fIcertmonger\fR daemon does not immediately notice
|
|
the updated certificates and may trigger a renewal after \fIipa-cert-fix\fR
|
|
completes. As a consequence, \fIgetcert list\fR output may display
|
|
that a renewal is in progress even if \fIipa-cert-fix\fR just
|
|
finished. It is recommended to monitor the certmonger-initiated
|
|
renewal and wait for its completion before any other administrative task.
|
|
|
|
.SH "OPTIONS"
|
|
.TP
|
|
\fB\-\-version\fR
|
|
Show the program's version and exit.
|
|
.TP
|
|
\fB\-h\fR, \fB\-\-help\fR
|
|
Show the help for this program.
|
|
.TP
|
|
\fB\-v\fR, \fB\-\-verbose\fR
|
|
Print debugging information.
|
|
.TP
|
|
\fB\-q\fR, \fB\-\-quiet\fR
|
|
Output only errors (output from child processes may still be shown).
|
|
.TP
|
|
\fB\-\-log\-file\fR=\fIFILE\fR
|
|
Log to the given file.
|
|
.SH "EXIT STATUS"
|
|
0 if the command was successful
|
|
|
|
1 if an error occurred
|
|
|
|
.SH "SEE ALSO"
|
|
.BR ipa-cacert-manage(1)
|
|
.BR ipa-server-certinstall(1)
|
|
.BR getcert-resubmit(1)
|