#9118 Strange CA error during FreeIPA connection
Closed: invalid by frenaud. Opened by alexadevinta.

Request for enhancement

A strange error is occurring when I try to access my FreeIPA.

Issue

The problem occurs when I try to access the FreeIPA portal.

"The message occurs saying IPA Error 4301: CertificateOperationError"
"Certificate operation cannot be completed: Unable to communicate with CMS (500)"

in Certificate Authority appear:

"cannot connect to 'https://xyz.xxxxxhq.it:443/ca/rest/account/login': [SSL: SSL_HANDSHAKE_FAILURE] ssl handshake failure (_ssl.c:1826)"

and if I try to connect with KINIT ADMIN command on the console appear this error:

"kinit: Cannot contact any KDC for realm 'SUBITOHQ.IT' while getting initial credentials"

Actual behavior

Serverweb and console with kinit admin doesn't work. LDAPADMIN tool too.

Version/Release/Distribution

package freeipa-server is not installed
package freeipa-client is not installed
ipa-server-4.6.5-11.el7.centos.3.x86_64
ipa-client-4.6.5-11.el7.centos.3.x86_64
389-ds-base-1.3.9.1-12.el7_7.x86_64
pki-ca-10.5.16-5.el7_7.noarch
krb5-server-1.15.1-37.el7_7.2.x86_64

Additional info:

maybe it's a problem with CA but how is the process to solve that issue? The fact is that this behavior it's on a replica FreeIPA server with CA and DOMAIN. There is a resolution or a command to solve that?


Hi @alexadevinta
please use freeipa-users@lists.fedorahosted.org mailing list if you need help troubleshooting a problem. I will close this ticket as pagure issue tracker is used for bug reports.

The first thing to check would be to ensure that all services are running on your server with ipactl status.

Metadata Update from @frenaud:
- Issue close_status updated to: invalid
- Issue status updated to: Closed (was: Open)

Metadata