Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Renew PROD Certificate (around June, 2024) #606

Closed
2 tasks done
MCatherine1994 opened this issue Mar 26, 2024 · 5 comments
Closed
2 tasks done

Renew PROD Certificate (around June, 2024) #606

MCatherine1994 opened this issue Mar 26, 2024 · 5 comments
Assignees

Comments

@MCatherine1994
Copy link
Contributor

MCatherine1994 commented Mar 26, 2024

Describe the task
Our PROD certificate will expire on Aug 9, 2024. Ticket for renew we done last year #421. Since the Certbot is not working anymore, we might not get notification, created this ticket to remind us. We need to send service desk a ticket to renew the certificate, and write Derek a ticket to help us install the new one.

Acceptance Criteria

  • Create a service desk ticket
  • Install the new certificate

Additional context

@MCatherine1994 MCatherine1994 changed the title Renew Certificate (around June, 2024) Renew PROD Certificate (around June, 2024) Mar 27, 2024
@ianliuwk1019
Copy link
Collaborator

@ianliuwk1019
Copy link
Collaborator

SD-117317 ticket is currently being processed:
Image

@ianliuwk1019
Copy link
Collaborator

Service Request RITM0814460 is approved (https://ociomysc.service-now.com/sp?id=form&table=sc_req_item&sys_id=61d50ed81b1fc690f436542f0a4bcb3c&view=ess) but I haven't got email for the renewed certificate yet.

@ianliuwk1019
Copy link
Collaborator

Got the certificate and chain CA certificate today sent by email from OCIO.
Backup previous certs to local drive.
Using steps from FOM Wiki to update certificate (option 1 for renewing certificate)
The are updated to FOM PROD routes (public/admin/api) after office hour. Verify all 3 domain links, seems to work after update.
However, from OpenShift, I can't find any place that could check the route's certificate expiry date.

I can only verify directly at the certificate itself by using openssl:
Expiry Date: August 09, 2025
Image

Side note: before updating to new certificate, noticed previous CA certificate contains 3 segments (BEGIN-END). However, this time the new CA certificate contains only 1 segment(BEGIN-END). It works after updating to new cert.
@basilv

@basilv
Copy link
Collaborator

basilv commented Jul 11, 2024

@ianliuwk1019 Easiest way to check the certificate expiry is in the browser. I confirmed Aug 9, 2025 expiry dates for FOM prod public, admin, and API

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants