Thanks Rob :-) # getcert list | grep command: pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "auditSigningCert cert-pki-ca" pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "ocspSigningCert cert-pki-ca" pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "subsystemCert cert-pki-ca" pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "caSigningCert cert-pki-ca" pre-save command: post-save command: /usr/lib64/ipa/certmonger/renew_ra_cert pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "Server-Cert cert-pki-ca" pre-save command: post-save command: /usr/lib64/ipa/certmonger/restart_dirsrv TESTRELM-TEST pre-save command: post-save command: /usr/lib64/ipa/certmonger/restart_httpd # grep _command /var/lib/certmonger/requests/* /var/lib/certmonger/requests/20150127131100:pre_certsave_command=/usr/lib64/ipa/certmonger/stop_pkicad /var/lib/certmonger/requests/20150127131100:post_certsave_command=/usr/lib64/ipa/certmonger/renew_ca_cert "auditSigningCert cert-pki-ca" /var/lib/certmonger/requests/20150127131101:pre_certsave_command=/usr/lib64/ipa/certmonger/stop_pkicad /var/lib/certmonger/requests/20150127131101:post_certsave_command=/usr/lib64/ipa/certmonger/renew_ca_cert "ocspSigningCert cert-pki-ca" /var/lib/certmonger/requests/20150127131102:pre_certsave_command=/usr/lib64/ipa/certmonger/stop_pkicad /var/lib/certmonger/requests/20150127131102:post_certsave_command=/usr/lib64/ipa/certmonger/renew_ca_cert "subsystemCert cert-pki-ca" /var/lib/certmonger/requests/20150127131103:pre_certsave_command=/usr/lib64/ipa/certmonger/stop_pkicad /var/lib/certmonger/requests/20150127131103:post_certsave_command=/usr/lib64/ipa/certmonger/renew_ca_cert "caSigningCert cert-pki-ca" /var/lib/certmonger/requests/20150127131104:post_certsave_command=/usr/lib64/ipa/certmonger/renew_ra_cert /var/lib/certmonger/requests/20150127131105:pre_certsave_command=/usr/lib64/ipa/certmonger/stop_pkicad /var/lib/certmonger/requests/20150127131105:post_certsave_command=/usr/lib64/ipa/certmonger/renew_ca_cert "Server-Cert cert-pki-ca" /var/lib/certmonger/requests/20150127131106:post_certsave_command=/usr/lib64/ipa/certmonger/restart_dirsrv TESTRELM-TEST /var/lib/certmonger/requests/20150127131242:post_certsave_command=/usr/lib64/ipa/certmonger/restart_httpd This looks good. I am going to mark verified.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2015-0437.html