We had multiple cases in which either the Dogtag NSS DB on the master or replica had incorrect certs, private key assignment, or trust flags. In order to detect such issues early, FreeIPA should validate the NSS DB:
See https://pagure.io/freeipa/issue/7590 and https://pagure.io/freeipa/issue/7589
PR https://github.com/freeipa/freeipa/pull/2050 is a start. PR depends on new build of JSS (4.4.5?).
master:
Metadata Update from @cheimes: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)