We have 1 master server (CA) and 4 replica servers.
The RootRA certificates on the replica servers did not renew automatically. We moved the date back on all the servers and performed the steps to renew the certs. The certs appear to be updated properly with valid expiration dates and report a status of Monitoring. The date was moved forward to the current time and we verified the ipa services were up and running. After rebooting the replicas two of the them are failing to start the pki-tomcatd service the other 2 are functioning properly.
One thing we had to do that was different from other post is we exported the rootra (ipaCert), ocsp subsystem, ca subsystem, and ca audit cert from the master and imported then into the replicas.
We have verified the /etc/pki/pki-tomcat/ca/CS.cfg file has the correct ca signing cert.
We have verified the httpd and pki-tomcat certs are updated with the correct certs and trust attributes.
We have verified the serial number from the RootRA certificate matches the ipara description object.
We have updated the krb5 keytab files.
Version-Release number of selected component (if applicable):
Centos 7.2 SElinux=Enforcing
freeipa 4.2