fleetdm / fleet

Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)
https://fleetdm.com
Other
2.74k stars 392 forks source link

Renew SCEP certificates 180 days before expiration #19684

Open noahtalerman opened 1 month ago

noahtalerman commented 1 month ago

Goal

User story
As an IT admin,
I want Fleet to automatically renew the SCEP certificates installed on my hosts 180 days from expiration
so that my SCEP certificates don't expire when an end user goes on parental leave and thus, I don't have to turn on MDM again these macOS hosts.

Context

It looks like this is what Jamf does (from this doc): Screenshot 2024-06-12 at 10 03 42 AM

Today, Fleet renews certificates 30 days from expiration:

Changes

Product

Engineering

ℹ️  Please read this issue carefully and understand it. Pay special attention to UI wireframes, especially "dev notes".

QA

Risk assessment

Manual testing steps

  1. Step 1
  2. Step 2
  3. Step 3

Testing notes

Confirmation

  1. [ ] Engineer (@____): Added comment to user story confirming successful completion of QA.
  2. [ ] QA (@____): Added comment to user story confirming successful completion of QA.
georgekarrv commented 2 weeks ago

Hey team! Please add your planning poker estimate with Zenhub @dantecatalfamo @ghernandez345 @gillespi314 @jahzielv @mna @roperzh

georgekarrv commented 2 weeks ago

Just a call out that this will retry the next cron instead of next day