#9693 certmonger renews dirsrv service certificate after ipa-healthcheck warns it's about to expire
Closed: duplicate by rcritten. Opened by yrro.

Issue

I'm getting an alert because ipa-healthcheck warning me that my directory server certificate expires within 30 days.

# ipa-healthcheck --source=ipahealthcheck.ds.nss_ssl --check=NssCheck --output-type=human 
ERROR: ipahealthcheck.ds.nss_ssl.NssCheck.DSCERTLE0001: The certificate (Server-Cert) will expire in less than 30 days

The warning

[description of the issue]

Steps to Reproduce

1.
2.
3.

Actual behavior

(what happens)

Expected behavior

(what do you expect to happen)

Version/Release/Distribution

$ rpm -q freeipa-server freeipa-client ipa-server ipa-client 389-ds-base pki-ca krb5-server

Additional info:

Any additional information, configuration, data or log snippets that is needed for reproduction or investigation of the issue.

Log file locations: https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/config-files-logs.html
Troubleshooting guide: https://www.freeipa.org/page/Troubleshooting


Is the title poorly worded? What's the issue with certmonger renewing a certificate that healthcheck noted will expire soon?

Closing as duplicate of https://pagure.io/freeipa/issue/9694

Metadata Update from @rcritten:
- Issue close_status updated to: duplicate
- Issue status updated to: Closed (was: Open)

Sorry about that!

Metadata