I'm getting an alert because ipa-healthcheck warning me that my directory server certificate expires within 30 days.
# ipa-healthcheck --source=ipahealthcheck.ds.nss_ssl --check=NssCheck --output-type=human ERROR: ipahealthcheck.ds.nss_ssl.NssCheck.DSCERTLE0001: The certificate (Server-Cert) will expire in less than 30 days
The warning
[description of the issue]
1. 2. 3.
(what happens)
(what do you expect to happen)
$ rpm -q freeipa-server freeipa-client ipa-server ipa-client 389-ds-base pki-ca krb5-server
Any additional information, configuration, data or log snippets that is needed for reproduction or investigation of the issue.
Log file locations: https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/config-files-logs.html Troubleshooting guide: https://www.freeipa.org/page/Troubleshooting
Is the title poorly worded? What's the issue with certmonger renewing a certificate that healthcheck noted will expire soon?
Closing as duplicate of https://pagure.io/freeipa/issue/9694
Metadata Update from @rcritten: - Issue close_status updated to: duplicate - Issue status updated to: Closed (was: Open)
Sorry about that!