Chapter 25. Verifying system certificates using IdM Healthcheck
Learn more about identifying issues with system certificates in Identity Management (IdM) by using the Healthcheck tool.
Prerequisites
- The Healthcheck tool is only available on RHEL 8.1 or newer.
25.1. System certificates Healthcheck tests
The Healthcheck tool includes several tests for verifying system, or Dogtag, certificates.
				You can find all certificate-related tests under the ipahealthcheck.dogtag.ca source in the output of the ipa-healthcheck --list-sources command.
			
- DogtagCertsConfigCheck
- This test compares the CA (Certificate Authority) certificates in its NSS database to the same values stored in - CS.cfg. If they do not match, the CA fails to start.- Specifically, it checks: - 
									auditSigningCert cert-pki-caagainstca.audit_signing.cert
- 
									ocspSigningCert cert-pki-caagainstca.ocsp_signing.cert
- 
									caSigningCert cert-pki-caagainstca.signing.cert
- 
									subsystemCert cert-pki-caagainstca.subsystem.cert
- 
									Server-Cert cert-pki-caagainstca.sslserver.cert
 - If Key Recovery Authority (KRA) is installed, it also checks: - 
									transportCert cert-pki-kraagainstca.connector.KRA.transportCert
 
- 
									
- DogtagCertsConnectivityCheck
- This test verifies connectivity. This test is equivalent to the - ipa cert-show 1command which checks the following:- The PKI proxy configuration in Apache
- IdM being able to find a CA
- The RA agent client certificate
- The correctness of CA replies to requests
 - The test verifies that the - ipa cert-showcommand can be executed and that an expected response is returned from the IdM CA - either the certificate itself or a- not foundresponse.
25.2. Screening system certificates using Healthcheck
Follow this procedure to run a standalone manual test of Identity Management (IdM) certificates using the Healthcheck tool.
Procedure
- Enter: - ipa-healthcheck --source=ipahealthcheck.dogtag.ca - # ipa-healthcheck --source=ipahealthcheck.dogtag.ca- Copy to Clipboard Copied! - Toggle word wrap Toggle overflow - 
								The --source=ipahealthcheck.dogtag.caoption ensures that Healthcheck only performs the certificate tests.
 
- 
								The 
An example of a successful test:
An example of a failed test:
Run the certificate tests on all IdM servers when trying to find an issue.