#5522 IPA certificate auto renewal fail with SSL_ERROR_EXPIRED_CERT_ALERT
Closed: insufficientinfo 5 years ago by rcritten. Opened 8 years ago by pvoborni.

Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 7): Bug 1286651

Created attachment 1100493
getcert_console.log

Description of problem:
While verifying BZ1277696 encountered following error

[root@dhcp201-135 ~]# getcert list | egrep
"status|expires|Request|subject|ca-error"

<snip>
Request ID '20151130092850':
        status: CA_UNREACHABLE
        ca-error: Server at https://dhcp201-135.testrelm.test/ipa/xml failed
request, will retry: 907 (RPC failed at server.  cannot connect to
'https://dhcp201-135.testrelm.test:443/ca/eeca/ca/profileSubmitSSLClient':
(SSL_ERROR_EXPIRED_CERT_ALERT) SSL peer rejected your certificate as expired.).
        subject: CN=dhcp201-135.testrelm.test,O=TESTRELM.TEST
        expires: 2025-09-07 11:07:45 UTC

</snip>

Version-Release number of selected component (if applicable):
ipa-server-4.2.0-15.el7_2.3.x86_64


Steps to Reproduce:
1. Install IPA server
2. Change system date closer to expire date
3. check "getcert list" output

Assigning to Jan since he already did some investigation together with Abhijeet

Metadata Update from @pvoborni:
- Issue assigned to jcholast
- Issue set to the milestone: FreeIPA 4.5 backlog

7 years ago

Issues related to certificate renewal are the most common. Moving to 4.5.1 to focus on this sooner.

Metadata Update from @pvoborni:
- Assignee reset
- Issue close_status updated to: None
- Issue set to the milestone: FreeIPA 4.5.1 (was: FreeIPA 4.5 backlog)

7 years ago

Metadata Update from @mbasti:
- Issue set to the milestone: FreeIPA 4.5.2 (was: FreeIPA 4.5.1)

6 years ago

FreeIPA 4.5.1 has been released, moving to FreeIPA 4.5.2 milestone

Metadata Update from @tkrizek:
- Issue set to the milestone: FreeIPA 4.5.3 (was: FreeIPA 4.5.2)

6 years ago

Metadata Update from @tkrizek:
- Issue set to the milestone: FreeIPA 4.5.4 (was: FreeIPA 4.5.3)

6 years ago

Metadata Update from @tkrizek:
- Issue set to the milestone: FreeIPA 4.5.5 (was: FreeIPA 4.5.4)

6 years ago

Closing. The associated BZ was closed with insufficient info.

Metadata Update from @rcritten:
- Issue close_status updated to: insufficientinfo
- Issue status updated to: Closed (was: Open)

5 years ago

Login to comment on this ticket.

Metadata