Bug 2062856 - ldap, httpd and kdc certs failing to renew post year 2038
Summary: ldap, httpd and kdc certs failing to renew post year 2038
Keywords:
Status: NEW
Alias: None
Product: Red Hat Enterprise Linux 9
Classification: Red Hat
Component: ipa
Version: 9.0
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: Florence Blanc-Renaud
QA Contact: ipa-qe
URL:
Whiteboard:
Depends On:
Blocks: 2027125
TreeView+ depends on / blocked
 
Reported: 2022-03-10 17:20 UTC by Mohammad Rizwan
Modified: 2023-08-11 07:28 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Type: Bug
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker FREEIPA-7952 0 None None None 2022-03-10 17:29:14 UTC
Red Hat Issue Tracker RHELPLAN-115244 0 None None None 2022-03-10 17:29:19 UTC

Description Mohammad Rizwan 2022-03-10 17:20:42 UTC
Description of problem:
ca-cert-renewal test is failing to renew the httpd,kdc,certs with rhel-9.0 image from idm-ci. Where as when used rhel-9.0-nightly image, httpd cert is failing.

Version-Release number of selected component (if applicable):
ipa-server-4.9.8-6.el9.x86_64
ipa-server-dns-4.9.8-6.el9.noarch

sssd-ipa-2.6.2-2.el9.x86_64
sssd-client-2.6.2-2.el9.x86_64

httpd-2.4.51-5.el9.x86_64
krb5-server-1.19.1-13.el9.x86_64
krb5-pkinit-1.19.1-13.el9.x86_64

389-ds-base-2.0.14-1.el9.x86_64
pki-base-11.0.3-1.el9.noarch
pki-server-11.0.3-1.el9.noarch

How reproducible:
always

Steps to Reproduce:
1. run https://ci-jenkins-csb-idmops.apps.ocp-c1.prod.psi.redhat.com/job/ipa-RHEL9.0/job/Nightly/job/tier-3-RHEL9.0-Nightly-pytest-ca-cert-renewal/

Actual results:
httpd, kdc, ldap cert is failing to renew and status is showing as CA_UNREACHABLE with rhel-9.0 idm-ci image (failing for year 2039)

httpd cert is failing to renew and status CA_UNREACHABLE with idm-ci rhel-9.0 nightly image. (failing for year 2030)

Expected results:
certs renew successfully 

Additional info:


Note You need to log in before you can comment on or make changes to this bug.