Uploaded image for project: 'Infrastructure'
  1. Infrastructure
  2. INFRA-2732

We need a new yearly cert for update-center2

    XMLWordPrintable

    Details

    • Similar Issues:

      Description

      00:00:30.266 Exception in thread "main" java.security.cert.CertificateExpiredException: NotAfter: Wed Oct 21 15:09:02 UTC 2020
      00:00:30.267 	at sun.security.x509.CertificateValidity.valid(CertificateValidity.java:274)
      00:00:30.267 	at sun.security.x509.X509CertImpl.checkValidity(X509CertImpl.java:629)
      00:00:30.267 	at io.jenkins.update_center.Signer.getCertificateChain(Signer.java:180)
      00:00:30.267 	at io.jenkins.update_center.Signer.sign(Signer.java:82)
      00:00:30.267 	at io.jenkins.update_center.json.WithSignature.writeWithSignature(WithSignature.java:51)
      00:00:30.267 	at io.jenkins.update_center.json.WithSignature.encodeWithSignature(WithSignature.java:86)
      00:00:30.268 	at io.jenkins.update_center.Main.run(Main.java:247)
      00:00:30.268 	at io.jenkins.update_center.Main.run(Main.java:193)
      00:00:30.268 	at io.jenkins.update_center.Main.main(Main.java:167) 

      Like INFRA-1863, this is the yearly cert update we need.

        Attachments

          Activity

          Hide
          olblak Olivier Vernin added a comment -

          I generated a new update-center certificate valid until the 16th of April 2021 (when the root ca expire), then uploaded the zip file on trusted.ci

          Show
          olblak Olivier Vernin added a comment - I generated a new update-center certificate valid until the 16th of April 2021 (when the root ca expire), then uploaded the zip file on trusted.ci
          Hide
          olblak Olivier Vernin added a comment -

          I am reopening this as the key generated is too small

          Show
          olblak Olivier Vernin added a comment - I am reopening this as the key generated is too small
          Hide
          olblak Olivier Vernin added a comment -

          while I initially reused an old update-center key to generate the csr and the certificate, this time I generated a new key with a length of 4096 bits then updated trusted.ci 

          Show
          olblak Olivier Vernin added a comment - while I initially reused an old update-center key to generate the csr and the certificate, this time I generated a new key with a length of 4096 bits then updated trusted.ci 
          Hide
          olblak Olivier Vernin added a comment -

          Bumping this ticket, it's seems to be time to notify end users

          Show
          olblak Olivier Vernin added a comment - Bumping this ticket, it's seems to be time to notify end users
          Hide
          danielbeck Daniel Beck added a comment -

          Should be a separate task, this one was resolved.

          Show
          danielbeck Daniel Beck added a comment - Should be a separate task, this one was resolved.

            People

            Assignee:
            olblak Olivier Vernin
            Reporter:
            danielbeck Daniel Beck
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: