openshift / service-serving-cert-signer

Archiving in favor of https://github.com/openshift/service-ca-operator
Apache License 2.0
13 stars 18 forks source link

Warn when signing CA is halfway expired #44

Closed mrogers950 closed 5 years ago

mrogers950 commented 5 years ago

This PR adds the check function for half of the CA lifetime (half of its lifetime is for a rollover grace period), and calls it in manageSigningSecret_v311_00_to_latest() to check the existing signing CA. For now, log a warning. @openshift/sig-auth

mrogers950 commented 5 years ago

/retest

openshift-merge-robot commented 5 years ago

/retest