Closed Bug 1438222 Opened 7 years ago Closed 7 years ago

PKI: verify if aus4-admin.mozilla.org can use LEA or will need Private PKI

Categories

(Infrastructure & Operations Graveyard :: WebOps: Other, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: sidler, Assigned: sidler)

Details

(Whiteboard: [kanban:https://webops.kanbanize.com/ctrl_board/2/6216])

Summary: PKI: verify if aus4-admin.mozilla.org will need a private cert → PKI: verify if aus4-admin.mozilla.org can use LEA or will need Private PKI
check with bhearsum on IRC
Whiteboard: [kanban:https://webops.kanbanize.com/ctrl_board/2/6216]
Assignee: server-ops-webops → sidler
This host(s) is currently using a cert created from our internal root-ca. We are decommisioning all uses of certs from the root-ca in 2018. Most certs can retrieved from LE automation via https://github.com/Neilpang/acme.sh/blob/master/dnsapi/dns_infoblox.sh 1) Does this host(s) require an SSL cert? 2) Does this host(s) survive scl3 exit? 3) Can this host use LE automation (acme.sh, certbot, etc)? 4) If not can this cert use a public SSL cert from DigiCert? 5) If not can this cert use a private PKI cert from DigiCert?
I can confirm that aus4-admin.mozilla.org is currently using a public SSL certificate issued by DigiCert
Thanks :jbuck would it be a candidate to use the LE automation I mention above? Basically requires a cron job that grabs that repo and runs the script with some parameters. The script will communicate with LE servers over the internet and then coordinate with out internal infoblox server for doing DNS auth. Once setup LE certs will be automatically updated every 2mos. Getting rid of root-ca generate certs is part of this work for me. The other part is identifying potential hosts that can benefit from the LE automation.
Flags: needinfo?(jbuckley)
No, I don't think it's a good candidate for LE automation
Flags: needinfo?(jbuckley)
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → FIXED
Product: Infrastructure & Operations → Infrastructure & Operations Graveyard
You need to log in before you can comment on or make changes to this bug.