ipa-healthcheck is showing ERROR message as "Expected certmonger tracking is missing for {key}. Automated renewal will not happen for this certificate"
Issue
# ipa-healthcheck
[
{
"source": "ipahealthcheck.ipa.certs",
"check": "IPACertTracking",
"result": "ERROR",
"uuid": "f63e7fb3-9455-48a2-a67e-4c17749451cf",
"when": "20230327110041Z",
"duration": "0.497511",
"kw": {
"key": "cert-database=/etc/pki/pki-tomcat/alias, cert-nickname=caSigningCert cert-pki-ca, ca-name=dogtag-ipa-ca-renew-agent, cert-presave-command=/usr/libexec/ipa/certmonger/stop_pkicad, cert-postsave-command=/usr/libexec/ipa/certmonger/renew_ca_cert \"caSigningCert cert-pki-ca\", template-profile=caCACert",
"msg": "Expected certmonger tracking is missing for {key}. Automated renewal will not happen for this certificate"
}
},
{
"source": "ipahealthcheck.ipa.certs",
"check": "IPACertTracking",
"result": "WARNING",
"uuid": "3e5b2680-4344-4464-a9b2-8f1dd3e833d2",
"when": "20230327110041Z",
"duration": "0.606071",
"kw": {
"key": "20210504141259",
"msg": "certmonger tracking request {key} found and is not expected on an IPA master."
}
},
{
"source": "ipahealthcheck.ipa.certs",
"check": "IPACertDNSSAN",
"result": "ERROR",
"uuid": "f6148ad9-0170-4617-b94f-d8b32abf6395",
"when": "20230327110041Z",
"duration": "0.485285",
"kw": {
"key": null,
"msg": "Found request id {key} but it is not trackedby certmonger!?"
}
}
]
Environment
- Red Hat Enterprise Linux 8
- IPA Server/Replica
ipa-healthcheck
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.