Configure Authenticode prod key in Production Autograph
Categories
(Cloud Services :: Operations: Autograph, task)
Tracking
(Not tracked)
People
(Reporter: hwine, Assigned: u581815)
Details
New private key has been generated in the HSM, and an associated certificate issued in bug 1634577
That key now needs to be configured in production Autograph.
Added the new key (autograph hiera sops commit eca1e58863b863c05a95aaefae709712343b9b56 on train-11 branch). Pending config review from hwine in the autograph train-11 bug, I'll send the creds to aki and catlee.
r? :hwine on config changes in the autograph-hiera-sops train-11 branch (just bug 1636269 AFAIK)
(In reply to Greg Guthe [:g-k] [:gguthe] from comment #2)
r? :hwine on config changes in the autograph-hiera-sops train-11 branch (just bug 1636269 AFAIK)
r+ @eca1e58863b863c05a95aaefae709712343b9b56
Landed the config change to go out with train-11. Sent creds to :aki (ran into a gpg error encrypting for :catlee that I didn't want to dive into just now).
Updated config to reuse the releng_authenticode_rel creds with the 202005 key as the non-default signer (same signer ID authenticode_rel_202005).
hwine can you r? the sops change in commit f6217108a67e0ae209bfb5e47e381d521e8c3d35 on branch train-11-update-releng-authz ?
hwine: actually commit 83a477602167e24741618bff33a145a11aebfc67 (head on the same branch)
r+ on 83a477602167e24741618bff33a145a11aebfc67 (thanks for the assist)
Landed in sops master.
Description
•