Travis West via FreeIPA-users wrote:
Spoke too soon. If I try to get a new certificate on an enrolled
host I get this
status: CA_UNREACHABLE
ca-error: Server at
https://ipa1-sea2.ipa.****.net/ipa/xml failed request, will retry:
907 (RPC failed at server. cannot connect to
'https://ipa1-sea2.ipa.****.net:443/ca/rest/account/login': [SSL:
SSL_HANDSHAKE_FAILURE] ssl handshake failure (_ssl.c:1822)).
This reflected in the UI if I go to Authentication > Certificates > Certificate
Authorities where I see the same error.
The IPA server listed there is the one where all services started via ipactl start in my
previous update.
I think you need to take a look at fresh logs to see what failed. It may
point to why.
I assume you went back in time to 2019 and then leaped forward 2 years
at a pop, renewing as you went, and now it's present day?
rob