-
-
Notifications
You must be signed in to change notification settings - Fork 610
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Remove all static minica keys #7489
Conversation
@aarongable, this PR appears to contain configuration and/or SQL schema changes. Please ensure that a corresponding deployment ticket has been filed with the new values. |
f0f6ae7
to
d31ebfe
Compare
There's an integration test failure during the first test.
|
Yep, I'm aware. This is because I moved the challtestsrv's DoH key out of the internal PKI and into the misc PKI... which means that it is signed by a different root, and the VA doesn't trust that root when reaching out to it! Go ahead and review the rest of the change while I figure out the right tweak to make this happy. |
The rest looks good from a review earlier today, just waiting for tests to pass. |
d31ebfe
to
33124bb
Compare
I've fixed the issue with the challtestsrv cert, and I've expanded this PR to include the redis-tls certs too. PTAL! |
Test-only, and other reviewers are out, merging on one review. |
Remove the redis-tls, wfe-tls, and mail-test-srv keys which were generated by minica and then checked in to the repo. All three are replaced by the dynamically-generated ipki directory. Part of letsencrypt#7476
Remove the redis-tls, wfe-tls, and mail-test-srv keys which were generated by minica and then checked in to the repo. All three are replaced by the dynamically-generated ipki directory. Part of letsencrypt#7476
Remove the redis-tls, wfe-tls, and mail-test-srv keys which were generated by minica and then checked in to the repo. All three are replaced by the dynamically-generated ipki directory. Part of letsencrypt#7476
Remove the redis-tls, wfe-tls, and mail-test-srv keys which were generated by minica and then checked in to the repo. All three are replaced by the dynamically-generated ipki directory.
Part of #7476