Page MenuHomePhabricator

Allow specifying a custom period of time before deploying a newly issued certificate
Closed, ResolvedPublic

Description

Let's Encrypt issues the certificates one hour in the past to attempt to minimize clock skew issues. While this is enough for the non big-public sites (icinga, phabricator...) the global unified wildcard certificate needs to be issued days before being deployed.

This needs to be configurable per certificate on certcentral.

Event Timeline

Vgutierrez triaged this task as Medium priority.Jan 14 2019, 5:13 PM
Vgutierrez created this task.

Change 485594 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/certcentral@master] certcentral: Implement staging time

https://gerrit.wikimedia.org/r/485594

Change 485594 merged by jenkins-bot:
[operations/software/certcentral@master] certcentral: Implement staging time

https://gerrit.wikimedia.org/r/485594

Change 489988 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/certcentral@debian] certcentral: Implement staging time

https://gerrit.wikimedia.org/r/489988

Change 490006 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/certcentral@master] Release 0.9 This release includes the following changes: * Implement staging time * Rename certcentral to acme-chief

https://gerrit.wikimedia.org/r/490006

Change 490006 merged by jenkins-bot:
[operations/software/certcentral@master] Release 0.9 This release includes the following changes: * Implement staging time * Rename certcentral to acme-chief

https://gerrit.wikimedia.org/r/490006

Change 490011 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/certcentral@debian] Release 0.9 This release includes the following changes: * Implement staging time * Rename certcentral to acme-chief

https://gerrit.wikimedia.org/r/490011

Change 489988 merged by jenkins-bot:
[operations/software/certcentral@debian] certcentral: Implement staging time

https://gerrit.wikimedia.org/r/489988

Change 490011 merged by jenkins-bot:
[operations/software/certcentral@debian] Release 0.9 This release includes the following changes: * Implement staging time * Rename certcentral to acme-chief

https://gerrit.wikimedia.org/r/490011

Stashbot added a subscriber: Stashbot.

Mentioned in SAL (#wikimedia-operations) [2019-02-12T13:39:41Z] <vgutierrez> uploaded acme-chief 0.9 to apt.wikimedia.org (stretch) - T207389 T213737

yes, this has been included as part of the latest release