If externally signed CA cert is expired (or really close to expiry), the ipa-cert-fix will proceed with issuing new service and shared certificates using it, that produces certificates with very short validity periods. If that's the case, the situation gets worse than before ipa-cert-fix - we can't return in time to operate normally in this case.
VERSION: 4.12.2, API_VERSION: 2.254
always, if you have expired externally signed CA
system is broken and requires manual search for previous certs in LDAP repository in order to get operational again
check is run if CA is externally signed and if it is expired, and if that's the case - ipa-cert-fix doesn't perform any action (renewal not possible until new CA cert is signed and installed)
copy of https://issues.redhat.com/browse/RHEL-4941
PR opened: https://github.com/freeipa/freeipa/pull/7723
master:
Metadata Update from @frenaud: - Custom field rhbz adjusted to https://issues.redhat.com/browse/RHEL-4941
ipa-4-12:
Metadata Update from @frenaud: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)
ipa-4-9: