Page MenuHomePhabricator

Provide the three cert types (chain-only, cert only and chained) as soon as we get the certificate issued
Closed, ResolvedPublic

Description

Right now on issuing time acme-chief only saves the chained cert type and generates the other two when the certificate is moved from new to live. This behaviour triggers OCSP stapling issuing when staging_time is set to >3600 seconds

Event Timeline

herron triaged this task as Normal priority.Fri, Jul 26, 4:26 PM
ema moved this task from Triage to TLS on the Traffic board.Tue, Jul 30, 10:38 AM

Change 526840 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/acme-chief@master] acme_chief: Save the certificate using the 3 save modes on issuance time

https://gerrit.wikimedia.org/r/526840

Change 526840 merged by Vgutierrez:
[operations/software/acme-chief@master] acme_chief: Save the certificate using the 3 save modes on issuance time

https://gerrit.wikimedia.org/r/526840

Change 527364 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/acme-chief@master] Release 0.20

https://gerrit.wikimedia.org/r/527364

Change 527364 merged by Vgutierrez:
[operations/software/acme-chief@master] Release 0.20

https://gerrit.wikimedia.org/r/527364

Change 527373 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/acme-chief@debian] acme_chief: Save the certificate using the 3 save modes on issuance time

https://gerrit.wikimedia.org/r/527373

Change 527374 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/acme-chief@debian] Release 0.20

https://gerrit.wikimedia.org/r/527374

Change 527375 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/acme-chief@debian] debian: Add release 0.20 to changelog

https://gerrit.wikimedia.org/r/527375

Change 527373 merged by jenkins-bot:
[operations/software/acme-chief@debian] acme_chief: Save the certificate using the 3 save modes on issuance time

https://gerrit.wikimedia.org/r/527373

Change 527374 merged by jenkins-bot:
[operations/software/acme-chief@debian] Release 0.20

https://gerrit.wikimedia.org/r/527374

Change 527375 merged by jenkins-bot:
[operations/software/acme-chief@debian] debian: Add release 0.20 to changelog

https://gerrit.wikimedia.org/r/527375

Mentioned in SAL (#wikimedia-operations) [2019-08-02T05:21:07Z] <vgutierrez> uploaded acme-chief 0.20 to apt.wikimedia.org (buster) - T229096

Mentioned in SAL (#wikimedia-operations) [2019-08-02T06:46:52Z] <vgutierrez> upgrading acme-chief to version 0.20 in acme-chief test instances - T229096

Can we close this now?

Vgutierrez closed this task as Resolved.Mon, Aug 19, 6:04 AM
Vgutierrez claimed this task.

Yeah, thanks for the reminder! :)

Mentioned in SAL (#wikimedia-operations) [2019-08-19T06:37:17Z] <vgutierrez> upgrading acme-chief to version 0.20 on production servers - T229096