waited 2-3 hours
here is the output getcert list|more Number of certificates and requests being tracked: 8. Request ID '20141125183905': status: MONITORING ca-error: Internal error: no response to "http://lax4ipa01.mia.bill1st.local:9180/ca/ee/ca/profileSubmit?profileId=caS...". stuck: no key pair storage: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='auditSigningCert cert-pki-ca',token='NSS Certificate DB',pin set certificate: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='auditSigningCert cert-pki-ca',token='NSS Certificate DB' CA: dogtag-ipa-renew-agent issuer: CN=Certificate Authority,O=MIA.BILL1ST.LOCAL subject: CN=CA Audit,O=MIA.BILL1ST.LOCAL expires: 2018-10-08 17:15:13 UTC key usage: digitalSignature,nonRepudiation pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "auditSigningCert cert-pki-ca" track: yes auto-renew: yes Request ID '20141125183906': status: MONITORING ca-error: Internal error: no response to "http://lax4ipa01.mia.bill1st.local:9180/ca/ee/ca/profileSubmit?profileId=caS...". stuck: no key pair storage: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='ocspSigningCert cert-pki-ca',token='NSS Certificate DB',pin set certificate: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='ocspSigningCert cert-pki-ca',token='NSS Certificate DB' CA: dogtag-ipa-renew-agent issuer: CN=Certificate Authority,O=MIA.BILL1ST.LOCAL subject: CN=OCSP Subsystem,O=MIA.BILL1ST.LOCAL expires: 2018-10-08 17:14:13 UTC eku: id-kp-OCSPSigning pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "ocspSigningCert cert-pki-ca" track: yes auto-renew: yes Request ID '20141125183907': status: MONITORING ca-error: Internal error: no response to "http://lax4ipa01.mia.bill1st.local:9180/ca/ee/ca/profileSubmit?profileId=caS...". stuck: no key pair storage: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='subsystemCert cert-pki-ca',token='NSS Certificate DB',pin set certificate: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='subsystemCert cert-pki-ca',token='NSS Certificate DB' CA: dogtag-ipa-renew-agent issuer: CN=Certificate Authority,O=MIA.BILL1ST.LOCAL subject: CN=CA Subsystem,O=MIA.BILL1ST.LOCAL expires: 2018-10-08 17:14:13 UTC key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment eku: id-kp-serverAuth,id-kp-clientAuth pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "subsystemCert cert-pki-ca" track: yes auto-renew: yes Request ID '20141125183908': status: MONITORING ca-error: Internal error: no response to "http://lax4ipa01.mia.bill1st.local:9180/ca/ee/ca/profileSubmit?profileId=caS...". stuck: no key pair storage: type=NSSDB,location='/etc/httpd/alias',nickname='ipaCert',token='NSS Certificate DB',pinfile='/etc/httpd/alias/pwdfile.txt' certificate: type=NSSDB,location='/etc/httpd/alias',nickname='ipaCert',token='NSS Certificate DB' CA: dogtag-ipa-renew-agent issuer: CN=Certificate Authority,O=MIA.BILL1ST.LOCAL subject: CN=IPA RA,O=MIA.BILL1ST.LOCAL expires: 2018-10-08 17:14:13 UTC key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment eku: id-kp-serverAuth,id-kp-clientAuth pre-save command: post-save command: /usr/lib64/ipa/certmonger/renew_ra_cert track: yes auto-renew: yes Request ID '20141125183909': status: MONITORING ca-error: Internal error: no response to "http://lax4ipa01.mia.bill1st.local:9180/ca/ee/ca/profileSubmit?profileId=caS...". stuck: no key pair storage: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='Server-Cert cert-pki-ca',token='NSS Certificate DB',pin set certificate: type=NSSDB,location='/var/lib/pki-ca/alias',nickname='Server-Cert cert-pki-ca',token='NSS Certificate DB' CA: dogtag-ipa-renew-agent issuer: CN=Certificate Authority,O=MIA.BILL1ST.LOCAL subject: CN=lax4ipa01.mia.bill1st.local,O=MIA.BILL1ST.LOCAL expires: 2018-10-08 17:14:13 UTC key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment eku: id-kp-serverAuth,id-kp-clientAuth pre-save command: post-save command: track: yes auto-renew: yes Request ID '20141125183922': status: CA_UNREACHABLE ca-error: Error setting up ccache for "host" service on client using default keytab: Cannot contact any KDC for realm 'MIA.BILL1ST.LOCAL'. stuck: no key pair storage: type=NSSDB,location='/etc/dirsrv/slapd-MIA-BILL1ST-LOCAL',nickname='Server-Cert',token='NSS Certificate DB',pinfile='/etc/dirsrv/slapd-MIA-BILL1ST-LOCAL/pwdfile.txt' certificate: type=NSSDB,location='/etc/dirsrv/slapd-MIA-BILL1ST-LOCAL',nickname='Server-Cert',token='NSS Certificate DB' CA: IPA issuer: CN=Certificate Authority,O=MIA.BILL1ST.LOCAL subject: CN=lax4ipa01.mia.bill1st.local,O=MIA.BILL1ST.LOCAL expires: 2018-10-30 17:14:19 UTC key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment eku: id-kp-serverAuth,id-kp-clientAuth pre-save command: post-save command: /usr/lib64/ipa/certmonger/restart_dirsrv MIA-BILL1ST-LOCAL track: yes auto-renew: yes Request ID '20141125183953': status: CA_UNREACHABLE ca-error: Error setting up ccache for "host" service on client using default keytab: Cannot contact any KDC for realm 'MIA.BILL1ST.LOCAL'. stuck: no key pair storage: type=NSSDB,location='/etc/dirsrv/slapd-PKI-IPA',nickname='Server-Cert',token='NSS Certificate DB',pinfile='/etc/dirsrv/slapd-PKI-IPA/pwdfile.txt' certificate: type=NSSDB,location='/etc/dirsrv/slapd-PKI-IPA',nickname='Server-Cert',token='NSS Certificate DB' CA: IPA issuer: CN=Certificate Authority,O=MIA.BILL1ST.LOCAL subject: CN=lax4ipa01.mia.bill1st.local,O=MIA.BILL1ST.LOCAL expires: 2018-10-30 17:14:22 UTC key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment eku: id-kp-serverAuth,id-kp-clientAuth pre-save command: post-save command: /usr/lib64/ipa/certmonger/restart_dirsrv PKI-IPA track: yes auto-renew: yes Request ID '20141125184220': status: CA_UNREACHABLE ca-error: Error setting up ccache for "host" service on client using default keytab: Cannot contact any KDC for realm 'MIA.BILL1ST.LOCAL'. stuck: no key pair storage: type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS Certificate DB',pinfile='/etc/httpd/alias/pwdfile.txt' certificate: type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS Certificate DB' CA: IPA issuer: CN=Certificate Authority,O=MIA.BILL1ST.LOCAL subject: CN=lax4ipa01.lax.bill1st.local,O=MIA.BILL1ST.LOCAL expires: 2019-05-03 14:41:19 UTC key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment eku: id-kp-serverAuth,id-kp-clientAuth pre-save command: post-save command: /usr/lib64/ipa/certmonger/restart_httpd track: yes auto-renew: yes