Master Article - How to fix IPA+CA and IPA+KRA related ipa-healthcheck errors ?
Issue
-
ra.get_certificate(): Unable to communicate with CMS (500)
-
ERROR: ipahealthcheck.ipa.certs.IPACertRevocation.xxxxxxxx: Request for certificate failed, Certificate operation cannot be completed: Unable to communicate with CMS (500)
-
ERROR: ipahealthcheck.dogtag.ca.DogtagCertsConfigCheck.transportCert cert-pki-kra: Certificate 'transportCert cert-pki-kra' does not match the value of ca.connector.KRA.transportCert in /var/lib/pki/pki-tomcat/conf/ca/CS.cfg
-
Missing tracking for ca-name=dogtag-ipa-ca-renew-agent, cert-database=/etc/pki/pki-tomcat/alias
Environment
- IPA server
- IPA+CA
- IPA+KRA
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.