After long server downtime: cannot connect to CA #2528
Replies: 2 comments
-
|
Hmm. The server TLS certificate for |
Beta Was this translation helpful? Give feedback.
-
|
The server was shut down ungracefully by powerloss. I rebooted the CA's host which solved the issue for me. Forgot to mention that I use the CA in conjunction with a Yubikey. Highlight: |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,
my server suffered a long downtime. Certificates cannot be renewed, because they are already expired.
I use a scheduled SystemD service with command
step ca renew --force [filename].crt [filename].keydefault.json for the client is:
I know they can't be renewed because of the CA's policy, but trying to just overwrite using
step ca certificate [name] ***.crt ***.keyalso fails, because the CA itself presents an expired certificate to the client, when it tries to connect.
(I used
sudo openssl s_client -showcerts -connect [IP]:443to confirm this)
Exerpt from the CA's log:
Regarding the log entry:
Jan 07 08:37:05 ...: the "client" trying to renew was the CA itself, so that already failed.I suppose I need to make the CA renew the certificate it presents on TLS-connections. How do I do this?
Thanks in advance and kind regards.
Beta Was this translation helpful? Give feedback.
All reactions