Advertisement
Guest User

Untitled

a guest
Mar 11th, 2022
111
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.82 KB | None | 0 0
  1. Expired Cert: ocsp_signing
  2. Expired Cert: subsystem
  3. Expired Cert: audit_signing
  4. Internal server error 503 Server Error: Service Unavailable for url: http://london.idm.domain.uk:80/ca/rest/securityDomain/domainInfo
  5. Internal server error HTTPSConnectionPool(host='london.idm.domain.uk', port=8443): Max retries exceeded with url: /ca/admin/ca/getStatus (Caused by NewConnectionError('<urllib3.connection.VerifiedHTTPSConnection object at 0x7fc4e6c58198>: Failed to establish a new connection: [Errno 111] Connection refused',))
  6. CN=Public Services CA,OU=IT Department,O=Compass Plus Ltd,L=Magnitogorsk,ST=Chelyabinsk,C=RU not found, assuming 3rd party
  7. [
  8. {
  9. "source": "ipahealthcheck.meta.services",
  10. "check": "pki_tomcatd",
  11. "result": "ERROR",
  12. "uuid": "94dee3bf-4930-49f1-9486-24e58549f9cc",
  13. "when": "20220311130832Z",
  14. "duration": "0.000695",
  15. "kw": {
  16. "status": false,
  17. "msg": "pki_tomcatd: not running"
  18. }
  19. },
  20. {
  21. "source": "pki.server.healthcheck.certs.expiration",
  22. "check": "CASystemCertExpiryCheck",
  23. "result": "ERROR",
  24. "uuid": "36c8fbed-571d-4d38-9919-53322fea4aa2",
  25. "when": "20220311130832Z",
  26. "duration": "0.188329",
  27. "kw": {
  28. "cert_id": "ocsp_signing",
  29. "expiry_date": "Mar 01 2022",
  30. "msg": "Certificate has ALREADY EXPIRED"
  31. }
  32. },
  33. {
  34. "source": "pki.server.healthcheck.certs.expiration",
  35. "check": "CASystemCertExpiryCheck",
  36. "result": "ERROR",
  37. "uuid": "195970e4-e2fd-4eca-aeac-f1e97e9c3b13",
  38. "when": "20220311130832Z",
  39. "duration": "0.360146",
  40. "kw": {
  41. "cert_id": "subsystem",
  42. "expiry_date": "Mar 01 2022",
  43. "msg": "Certificate has ALREADY EXPIRED"
  44. }
  45. },
  46. {
  47. "source": "pki.server.healthcheck.certs.expiration",
  48. "check": "CASystemCertExpiryCheck",
  49. "result": "ERROR",
  50. "uuid": "a84a9bc5-de4d-4cdc-b7fd-41b83f3a11af",
  51. "when": "20220311130833Z",
  52. "duration": "0.454225",
  53. "kw": {
  54. "cert_id": "audit_signing",
  55. "expiry_date": "Mar 01 2022",
  56. "msg": "Certificate has ALREADY EXPIRED"
  57. }
  58. },
  59. {
  60. "source": "pki.server.healthcheck.meta.connectivity",
  61. "check": "DogtagCACertsConnectivityCheck",
  62. "result": "CRITICAL",
  63. "uuid": "35a76cd5-0600-4dad-9044-96f68a5b7f39",
  64. "when": "20220311130833Z",
  65. "duration": "0.012377",
  66. "kw": {
  67. "msg": "Internal server error. Is your CA subsystem and LDAP database up?",
  68. "instance_name": "pki-tomcat",
  69. "exception": "HTTPSConnectionPool(host='london.idm.domain.uk', port=8443): Max retries exceeded with url: /ca/admin/ca/getStatus (Caused by NewConnectionError('<urllib3.connection.VerifiedHTTPSConnection object at 0x7fc4e6c58198>: Failed to establish a new connection: [Errno 111] Connection refused',))"
  70. }
  71. },
  72. {
  73. "source": "ipahealthcheck.dogtag.ca",
  74. "check": "DogtagCertsConnectivityCheck",
  75. "result": "ERROR",
  76. "uuid": "de4e6b9f-0d4c-46f4-9e66-f2d4288b8b9b",
  77. "when": "20220311130834Z",
  78. "duration": "0.163632",
  79. "kw": {
  80. "msg": "Request for certificate failed, cannot connect to 'https://london.idm.domain.uk:443/ca/rest/certs/1': [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:897)"
  81. }
  82. },
  83. {
  84. "source": "ipahealthcheck.ipa.certs",
  85. "check": "IPACertmongerExpirationCheck",
  86. "result": "ERROR",
  87. "uuid": "f5ea9a10-44db-4e55-8ada-347c5ec68fa4",
  88. "when": "20220311130835Z",
  89. "duration": "0.010969",
  90. "kw": {
  91. "key": "20200505141836",
  92. "msg": "certmonger request id {key} does not have a not-valid-after date, assuming it has not been issued yet."
  93. }
  94. },
  95. {
  96. "source": "ipahealthcheck.ipa.certs",
  97. "check": "IPACertmongerExpirationCheck",
  98. "result": "ERROR",
  99. "uuid": "65d12d21-be1a-446f-a6f8-0c94806353da",
  100. "when": "20220311130835Z",
  101. "duration": "0.014854",
  102. "kw": {
  103. "key": "20200505141838",
  104. "msg": "certmonger request id {key} does not have a not-valid-after date, assuming it has not been issued yet."
  105. }
  106. },
  107. {
  108. "source": "ipahealthcheck.ipa.certs",
  109. "check": "IPACertmongerExpirationCheck",
  110. "result": "ERROR",
  111. "uuid": "f2405649-2ead-48e9-a3c4-c6c355e03db3",
  112. "when": "20220311130835Z",
  113. "duration": "0.018772",
  114. "kw": {
  115. "key": "20200505141840",
  116. "msg": "certmonger request id {key} does not have a not-valid-after date, assuming it has not been issued yet."
  117. }
  118. },
  119. {
  120. "source": "ipahealthcheck.ipa.certs",
  121. "check": "IPACertmongerExpirationCheck",
  122. "result": "ERROR",
  123. "uuid": "c285044c-5b87-489b-9aa4-7d7b6b69e34a",
  124. "when": "20220311130835Z",
  125. "duration": "0.022615",
  126. "kw": {
  127. "key": "20200505141841",
  128. "msg": "certmonger request id {key} does not have a not-valid-after date, assuming it has not been issued yet."
  129. }
  130. },
  131. {
  132. "source": "ipahealthcheck.ipa.certs",
  133. "check": "IPACertfileExpirationCheck",
  134. "result": "ERROR",
  135. "uuid": "8c7989ef-1b44-41ff-9fa1-ddc28e70fd96",
  136. "when": "20220311130835Z",
  137. "duration": "0.062739",
  138. "kw": {
  139. "key": "20200505141836",
  140. "expiration_date": "20220301002943Z",
  141. "msg": "Request id {key} expired on {expiration_date}"
  142. }
  143. },
  144. {
  145. "source": "ipahealthcheck.ipa.certs",
  146. "check": "IPACertfileExpirationCheck",
  147. "result": "ERROR",
  148. "uuid": "af2f4d79-c0c7-4fe8-abcf-f3c562692d76",
  149. "when": "20220311130835Z",
  150. "duration": "0.112692",
  151. "kw": {
  152. "key": "20200505141838",
  153. "expiration_date": "20220301002943Z",
  154. "msg": "Request id {key} expired on {expiration_date}"
  155. }
  156. },
  157. {
  158. "source": "ipahealthcheck.ipa.certs",
  159. "check": "IPACertfileExpirationCheck",
  160. "result": "ERROR",
  161. "uuid": "c175deba-f64a-4aef-9e67-a031b4972a1f",
  162. "when": "20220311130835Z",
  163. "duration": "0.163695",
  164. "kw": {
  165. "key": "20200505141840",
  166. "expiration_date": "20220301002943Z",
  167. "msg": "Request id {key} expired on {expiration_date}"
  168. }
  169. },
  170. {
  171. "source": "ipahealthcheck.ipa.certs",
  172. "check": "IPAOpenSSLChainValidation",
  173. "result": "ERROR",
  174. "uuid": "215b3007-786d-4c67-8ef0-e596fd6b5efe",
  175. "when": "20220311130837Z",
  176. "duration": "0.011657",
  177. "kw": {
  178. "key": "/var/lib/ipa/certs/httpd.crt",
  179. "reason": "C = RU, ST = Chelyabinsk, L = Magnitogorsk, O = Compass Plus Ltd, OU = IT Department, CN = london.idm.domain.uk\nerror 10 at 0 depth lookup: certificate has expired\n",
  180. "msg": "Certificate validation for {key} failed: {reason}"
  181. }
  182. },
  183. {
  184. "source": "ipahealthcheck.ipa.certs",
  185. "check": "IPACertRevocation",
  186. "result": "ERROR",
  187. "uuid": "1def9514-7098-49ba-b230-9e683ad7db70",
  188. "when": "20220311130838Z",
  189. "duration": "0.401545",
  190. "kw": {
  191. "key": "20200505141843",
  192. "serial": 16,
  193. "error": "cannot connect to 'https://london.idm.domain.uk:443/ca/rest/certs/16': [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:897)",
  194. "msg": "Request for certificate serial number {serial} in request {key} failed: {error}"
  195. }
  196. },
  197. {
  198. "source": "ipahealthcheck.ipa.certs",
  199. "check": "IPACertRevocation",
  200. "result": "ERROR",
  201. "uuid": "7780a7ff-523a-482e-8cdc-dffdf0b65fd1",
  202. "when": "20220311130838Z",
  203. "duration": "0.484815",
  204. "kw": {
  205. "key": "20200505141836",
  206. "serial": 5,
  207. "error": "cannot connect to 'https://london.idm.domain.uk:443/ca/rest/certs/5': [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:897)",
  208. "msg": "Request for certificate serial number {serial} in request {key} failed: {error}"
  209. }
  210. },
  211. {
  212. "source": "ipahealthcheck.ipa.certs",
  213. "check": "IPACertRevocation",
  214. "result": "ERROR",
  215. "uuid": "320fdbf8-cdca-41bf-823a-7279c45546c2",
  216. "when": "20220311130838Z",
  217. "duration": "0.567894",
  218. "kw": {
  219. "key": "20200505141838",
  220. "serial": 2,
  221. "error": "cannot connect to 'https://london.idm.domain.uk:443/ca/rest/certs/2': [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:897)",
  222. "msg": "Request for certificate serial number {serial} in request {key} failed: {error}"
  223. }
  224. },
  225. {
  226. "source": "ipahealthcheck.ipa.certs",
  227. "check": "IPACertRevocation",
  228. "result": "ERROR",
  229. "uuid": "f3a78df9-7cfd-4b6c-b58c-122f024561ea",
  230. "when": "20220311130838Z",
  231. "duration": "0.651398",
  232. "kw": {
  233. "key": "20200505141840",
  234. "serial": 4,
  235. "error": "cannot connect to 'https://london.idm.domain.uk:443/ca/rest/certs/4': [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:897)",
  236. "msg": "Request for certificate serial number {serial} in request {key} failed: {error}"
  237. }
  238. },
  239. {
  240. "source": "ipahealthcheck.ipa.certs",
  241. "check": "IPACertRevocation",
  242. "result": "ERROR",
  243. "uuid": "dc959415-311b-4055-ac29-5257418509f1",
  244. "when": "20220311130838Z",
  245. "duration": "0.734597",
  246. "kw": {
  247. "key": "20200505141841",
  248. "serial": 1,
  249. "error": "cannot connect to 'https://london.idm.domain.uk:443/ca/rest/certs/1': [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:897)",
  250. "msg": "Request for certificate serial number {serial} in request {key} failed: {error}"
  251. }
  252. },
  253. {
  254. "source": "ipahealthcheck.ipa.certs",
  255. "check": "IPACertRevocation",
  256. "result": "ERROR",
  257. "uuid": "02213174-779d-428a-a24b-0f291fd712b9",
  258. "when": "20220311130838Z",
  259. "duration": "0.817826",
  260. "kw": {
  261. "key": "20200505141842",
  262. "serial": 268369921,
  263. "error": "cannot connect to 'https://london.idm.domain.uk:443/ca/rest/certs/268369921': [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:897)",
  264. "msg": "Request for certificate serial number {serial} in request {key} failed: {error}"
  265. }
  266. },
  267. {
  268. "source": "ipahealthcheck.ipa.certs",
  269. "check": "IPACertRevocation",
  270. "result": "ERROR",
  271. "uuid": "5328e333-9b2b-42db-8064-e7aa5682c5b6",
  272. "when": "20220311130838Z",
  273. "duration": "0.857216",
  274. "kw": {
  275. "key": "20200311221056",
  276. "serial": 268369922,
  277. "error": "cannot connect to 'https://london.idm.domain.uk:443/ca/rest/certs/268369922': [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:897)",
  278. "msg": "Request for certificate serial number {serial} in request {key} failed: {error}"
  279. }
  280. },
  281. {
  282. "source": "ipahealthcheck.ipa.files",
  283. "check": "IPAFileCheck",
  284. "result": "WARNING",
  285. "uuid": "7d7b8919-a7f0-4b0e-b4dd-c4b5814c46cb",
  286. "when": "20220311130839Z",
  287. "duration": "0.008287",
  288. "kw": {
  289. "key": "_var_log_kadmind.log_mode",
  290. "path": "/var/log/kadmind.log",
  291. "type": "mode",
  292. "expected": "0600",
  293. "got": "0640",
  294. "msg": "Permissions of /var/log/kadmind.log are too permissive: 0640 and should be 0600"
  295. }
  296. }
  297.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement