cds-snc / notification-planning-core

Project planning for GC Notify Core Team
0 stars 0 forks source link

Look into VPN Self Signed Certificates with AKID #453

Open ben851 opened 2 weeks ago

ben851 commented 2 weeks ago

Description

As a developer of notify, I don't want to spend $400 per environment per month for private certificate authorities.

WHY are we building?

AWS deprecated self signed certificates for VPN forcing us to use private certificate authorities. We may have misunderstood however and it may have just been deprecating self signed certs that don't have AKID.

WHAT are we building?

Look into recreating VPN with AKID self signed cert and see if it still works

VALUE created by our solution

We don't have to spend $$$ on PCA

Acceptance Criteria

QA Steps

ben851 commented 2 weeks ago

Dev deployed with self signed certs. Waiting a few days to see if we get any alerts from AWS

P0NDER0SA commented 2 weeks ago

We will check this one on Tuesday until after Souvenir day

ben851 commented 1 week ago

PR to review. https://github.com/cds-snc/notification-terraform/pull/1643/

Sat in dev working all last week with no issues

ben851 commented 1 week ago

Deployed this to staging yesterday, and it works!

ben851 commented 1 week ago

Released to prod, seems to be working

ben851 commented 1 week ago

@Pond to QA

P0NDER0SA commented 1 week ago

Pond needs QA steps :(

pond commented 1 week ago

I don't know who you intended to reference but it isn't me. I have nothing to do with this project or task. Perhaps you meant @P0NDER0SA ?

P0NDER0SA commented 6 days ago

QA'ed! moving to done.