How do I manually renew Identity Management (IPA) certificates on RHEL 8 after they have expired? (CA-less IPA)
Issue
Identity Management (IdM
) installed with or without an embedded Certificate Authority (CA
) can use externally signed certificates for the Apache Webserver
and 389 Directory Server
.
The process is described in the documentation - 11.3. Replacing the web server and LDAP server certificates, but if the certificates are expired on all IPA
servers, this approach will not work, because ipa-server-certinstall
needs to communicate with other IPA
via TLS
connection, which will not be verified due to installed certificate invalidity.
For installations with integrated CA
, please follow this solution.
Environment
Red Hat Enterprise Linux 8
,Red Hat Enterprise Linux 9
Red Hat Identity Management (IPA) v4
+
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.