agrc / porter

UGRC tracks the additions, replacements, and deletions of SGID items (in the broadest sense of add, replace, or delete) through issues in this repository.
https://gis.utah.gov/documentation/policy/
MIT License
2 stars 0 forks source link

Deprecate Some Old DNSs #158

Closed stdavis closed 2 years ago

stdavis commented 2 years ago

Summary

These SSL certs are about to expire:

DNS expiration date can be deprecated
api.mapserv.utah.gov Oct 25 23:59:59 2021 GMT
developer.mapserv.utah.gov Oct 25 23:59:59 2021 GMT
secure.mapserv.utah.gov Oct 25 23:59:59 2021 GMT X
test.mapserv.utah.gov Oct 25 23:59:59 2021 GMT
test.secure.mapserv.utah.gov Oct 25 23:59:59 2021 GMT X
test2.mapserv.utah.gov Oct 25 23:59:59 2021 GMT X
wvc.mapserv.utah.gov Oct 25 23:59:59 2021 GMT X

We could just send a ticket to Conn's group (is that hosting?) and he said that they would renew them. However, I'm pretty sure that there are a few of these that could be deprecated/retired. I've marked the ones that I believe can go.

Also, I asked Conn if we are responsible to remember when they expire. Here is his response:

Yes. We track them as well, but we don't always know if they need to be renewed or not.

We probably shouldn't leave this to chance for next year. It would be a pretty disruptive thing for our certs to expire.

Action items (wait until @steveoh verifies that my proposed deprecations are OK)

Group Task Assignments

  1. Check [x] the box when you have assigned all the tasks relevant to your group.

~- [ ] Data Team (@gregbunce)~

~- [ ] Cadastre Team (@rkelson)~

steveoh commented 2 years ago

I approve. We should remove any vips and f5 rules of they are empty after the depreciations.

steveoh commented 2 years ago

conductor results for tasks - 158

check status
@steveoh has completed 0 out of 1 tasks :no_entry:
@nathankota has completed 0 out of 3 tasks :no_entry:
@stdavis has completed 1 out of 2 tasks :no_entry:
stdavis commented 2 years ago

I submitted INC1551805 - for removal of the wvc.mapserv.utah.gov VIP and INC1551816 for removing the rules on the F5.

stdavis commented 2 years ago

I removed the following web server bindings:

I couldn't find any others on the production or test web servers. I assume that the rest were handled with *s.

nathankota commented 2 years ago

Submit a ticket to retire/remove the deprecated DNS entries

INC1551858

Submit a ticket to Conn's group to renew the valid DNS entries

INC1551868

steveoh commented 2 years ago

@stdavis can you take a look at the vip diagram and make sure any of the deprecations will empty a particular VIP

stdavis commented 2 years ago

@stdavis can you take a look at the vip diagram and make sure any of the deprecations will empty a particular VIP

I did look at the diagram to figure out which VIP needed to be retired. However, I forgot to update it. I removed the VIP and two other DNSs. That was all that needed to be updated from what I could see.

nathankota commented 2 years ago

@stdavis or @steveoh please confirm the following and I will have DTS resolve INC1551858 image

stdavis commented 2 years ago

please confirm the following and I will have DTS resolve INC1551858

@nathankota: I confirmed that these are cleaned up: image

steveoh commented 2 years ago

conductor results for tasks - 158

check status
steveoh has completed 1 out of 1 tasks :+1:
nathankota has completed 3 out of 3 tasks :+1:
stdavis has completed 4 out of 4 tasks :+1:
stdavis commented 2 years ago

Go team. ✋