Page MenuHomePhabricator

Remove OCSP monitoring and related bits
Closed, ResolvedPublic

Description

Both Lets Encrypt (LE) and Google Trust Service (GTS) have deprecated support for OCSP and we have removed it in our infrastructure in T370821 for LE and T399079 for GTS. As such, we should remove all monitoring around OCSP from our infrastructure and the Puppet bits that support it.

Event Timeline

ssingh changed the task status from Open to In Progress.Jul 9 2025, 6:22 PM
ssingh triaged this task as Medium priority.

Change #1167686 had a related patch set uploaded (by Ssingh; author: Ssingh):

[operations/puppet@production] P:cache::haproxy: remove obsolete do_ocsp

https://gerrit.wikimedia.org/r/1167686

Mentioned in SAL (#wikimedia-operations) [2025-07-09T18:42:31Z] <sukhe> re-adding ocsp from deployment-prep: commit 3307286c7d18827b87231b61652efbaf0e3ba4c8: T399114: will remove after Puppet removal

Change #1167695 had a related patch set uploaded (by Ssingh; author: Ssingh):

[operations/puppet@production] P:cache::haproxy, C:haproxy, hiera: remove OCSP flag and monitoring

https://gerrit.wikimedia.org/r/1167695

Change #1167698 had a related patch set uploaded (by Ssingh; author: Ssingh):

[operations/puppet@production] nagios_common: remove check_ssl_cdn_ocsp*

https://gerrit.wikimedia.org/r/1167698

Change #1167695 merged by Ssingh:

[operations/puppet@production] P:cache::haproxy, C:haproxy, hiera: remove OCSP flag and monitoring

https://gerrit.wikimedia.org/r/1167695

Mentioned in SAL (#wikimedia-operations) [2025-07-14T14:55:00Z] <sukhe> sudo cumin 'O:alerting_host' 'run-puppet-agent' :T399114

Change #1167698 merged by Ssingh:

[operations/puppet@production] nagios_common: remove check_ssl_cdn_ocsp*

https://gerrit.wikimedia.org/r/1167698

ssingh claimed this task.

Change #1167686 merged by Ssingh:

[operations/puppet@production] P:cache::haproxy: remove obsolete do_ocsp

https://gerrit.wikimedia.org/r/1167686

Mentioned in SAL (#wikimedia-operations) [2025-07-21T16:10:10Z] <vgutierrez> cumin 'A:cp' 'systemctl reset-failed update-ocsp-all.timer' - T399114