zonca / cmb-s4-data-portal

LSST DESC Data Portal web app and the associated documentation and example notebooks.
https://lsstdesc-portal.nersc.gov/
BSD 3-Clause "New" or "Revised" License
0 stars 0 forks source link

Letsencrypt SSL root certificate expired #5

Closed zonca closed 3 years ago

zonca commented 3 years ago

Unfortunately Letsencrypt starting in Oct 2021 is not supported anymore in older devices,

see the compatibility list: https://letsencrypt.org/docs/certificate-compatibility/ and the announcement: https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/

the only fix I can think about is to install a different SSL certificate.

Maybe @jdanderson3 can get one from LBL? I can then install it on the instance.

jdanderson3 commented 3 years ago

Yes I can get a free certificate through InCommon. It will be good for one year will need to be manually updated.

You may want to consider whether supporting up old devices is even desirable. Depending on how old, some of these may not be well supported other tools anyway. It depends on how you expect the gateway to be used.

Jeff

On Tue, Oct 19, 2021, 9:51 PM Andrea Zonca @.***> wrote:

Unfortunately Letsencrypt starting in Oct 2021 is not supported anymore in older devices,

see the compatibility list: https://letsencrypt.org/docs/certificate-compatibility/ and the announcement: https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/

the only fix I can think about is to install a different SSL certificate.

Maybe @jdanderson3 https://github.com/jdanderson3 can get one from LBL? I can then install it on the instance.

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/zonca/cmb-s4-data-portal/issues/5, or unsubscribe https://github.com/notifications/unsubscribe-auth/AIZ2GUUM5JVK7Q5SG6WOC6LUHZDFVANCNFSM5GKV764A . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.

zonca commented 3 years ago

@jdanderson3 a few members of the collaboration already reported issues, so we definitely need to.

@jdborrill @elidart, should @jdanderson3 proceed with InCommon cert?

elidart commented 3 years ago

I would say yes - let's move ahead with InCommon. I expect we may want some of the federation capabilities that InCommon might provide.

Eli

On Wed, Oct 20, 2021 at 9:28 AM Andrea Zonca @.***> wrote:

@jdanderson3 https://github.com/jdanderson3 a few members of the collaboration already reported issues, so we definitely need to.

@jdborrill https://github.com/jdborrill @elidart https://github.com/elidart, should @jdanderson3 https://github.com/jdanderson3 proceed with InCommon cert?

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/zonca/cmb-s4-data-portal/issues/5#issuecomment-947833615, or unsubscribe https://github.com/notifications/unsubscribe-auth/AB66DMHGHBOCZH6FQ6BFFU3UH3U2PANCNFSM5GKV764A . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.

--

Eli Dart, Network Engineer NOC: (510) 486-7600 ESnet Science Engagement Group (800) 333-7638 Lawrence Berkeley National Laboratory

jdanderson3 commented 3 years ago

I'll go ahead with getting the InCommon cert. There is no cost, and no penalty for not using it. It is just marginally less convenient than the self-renewing LetsEncrypt certs.

On Wed, Oct 20, 2021 at 9:28 AM Andrea Zonca @.***> wrote:

@jdanderson3 https://github.com/jdanderson3 a few members of the collaboration already reported issues, so we definitely need to.

@jdborrill https://github.com/jdborrill @elidart https://github.com/elidart, should @jdanderson3 https://github.com/jdanderson3 proceed with InCommon cert?

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/zonca/cmb-s4-data-portal/issues/5#issuecomment-947833615, or unsubscribe https://github.com/notifications/unsubscribe-auth/AIZ2GUVKIXVNDQ5TW2OHIN3UH3U2PANCNFSM5GKV764A . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.

--

Jeffrey Anderson | @.*** Lawrence Berkeley National Laboratory | Office: 50B-3216 | Mailstop 50B3238 Phone: 510 486-4208 | Fax: 510 486-6498

jdanderson3 commented 3 years ago

I've applied for the certificate. We should have it in less than an hour. But having an InCommon certificate doesn't really grant any special privileges or access to other InCommon services.

Jeff

On Wed, Oct 20, 2021 at 10:20 AM elidart @.***> wrote:

I would say yes - let's move ahead with InCommon. I expect we may want some of the federation capabilities that InCommon might provide.

Eli

On Wed, Oct 20, 2021 at 9:28 AM Andrea Zonca @.***> wrote:

@jdanderson3 https://github.com/jdanderson3 a few members of the collaboration already reported issues, so we definitely need to.

@jdborrill https://github.com/jdborrill @elidart https://github.com/elidart, should @jdanderson3 https://github.com/jdanderson3 proceed with InCommon cert?

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub < https://github.com/zonca/cmb-s4-data-portal/issues/5#issuecomment-947833615 , or unsubscribe < https://github.com/notifications/unsubscribe-auth/AB66DMHGHBOCZH6FQ6BFFU3UH3U2PANCNFSM5GKV764A

. Triage notifications on the go with GitHub Mobile for iOS < https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675

or Android < https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub .

--

Eli Dart, Network Engineer NOC: (510) 486-7600 ESnet Science Engagement Group (800) 333-7638 Lawrence Berkeley National Laboratory

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/zonca/cmb-s4-data-portal/issues/5#issuecomment-947872980, or unsubscribe https://github.com/notifications/unsubscribe-auth/AIZ2GUQG3GBEWTPZWPRD2HLUH326DANCNFSM5GKV764A . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.

--

Jeffrey Anderson | @.*** Lawrence Berkeley National Laboratory | Office: 50B-3216 | Mailstop 50B3238 Phone: 510 486-4208 | Fax: 510 486-6498

elidart commented 3 years ago

OK - Thanks Jeff!

Eli

On Wed, Oct 20, 2021 at 10:26 AM Jeff Anderson @.***> wrote:

I've applied for the certificate. We should have it in less than an hour. But having an InCommon certificate doesn't really grant any special privileges or access to other InCommon services.

Jeff

On Wed, Oct 20, 2021 at 10:20 AM elidart @.***> wrote:

I would say yes - let's move ahead with InCommon. I expect we may want some of the federation capabilities that InCommon might provide.

Eli

On Wed, Oct 20, 2021 at 9:28 AM Andrea Zonca @.***> wrote:

@jdanderson3 https://github.com/jdanderson3 a few members of the collaboration already reported issues, so we definitely need to.

@jdborrill https://github.com/jdborrill @elidart https://github.com/elidart, should @jdanderson3 https://github.com/jdanderson3 proceed with InCommon cert?

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub <

https://github.com/zonca/cmb-s4-data-portal/issues/5#issuecomment-947833615

, or unsubscribe <

https://github.com/notifications/unsubscribe-auth/AB66DMHGHBOCZH6FQ6BFFU3UH3U2PANCNFSM5GKV764A

. Triage notifications on the go with GitHub Mobile for iOS <

https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675

or Android <

https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub

.

--

Eli Dart, Network Engineer NOC: (510) 486-7600 ESnet Science Engagement Group (800) 333-7638 Lawrence Berkeley National Laboratory

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub < https://github.com/zonca/cmb-s4-data-portal/issues/5#issuecomment-947872980 , or unsubscribe < https://github.com/notifications/unsubscribe-auth/AIZ2GUQG3GBEWTPZWPRD2HLUH326DANCNFSM5GKV764A

. Triage notifications on the go with GitHub Mobile for iOS < https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675

or Android < https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub .

--

Jeffrey Anderson | @.*** Lawrence Berkeley National Laboratory | Office: 50B-3216 | Mailstop 50B3238 Phone: 510 486-4208 | Fax: 510 486-6498

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/zonca/cmb-s4-data-portal/issues/5#issuecomment-947882280, or unsubscribe https://github.com/notifications/unsubscribe-auth/AB66DMEOXGIQC76UZANBKYDUH33UHANCNFSM5GKV764A . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.

--

Eli Dart, Network Engineer NOC: (510) 486-7600 ESnet Science Engagement Group (800) 333-7638 Lawrence Berkeley National Laboratory

zonca commented 3 years ago

Received the InCommon cert, I'll notify here once I have installed it.

zonca commented 3 years ago

yes! it's working. strange thing is that initially I also uploaded the interm cert, and it wasn't working. I had to only upload the cert.

@elidart

image

elidart commented 3 years ago

Most excellent! Thank you!!

Eli

On Wed, Oct 20, 2021 at 4:51 PM Andrea Zonca @.***> wrote:

yes! it's working. strange thing is that initially I also uploaded the interm cert, and it wasn't working. I had to only upload the cert.

@elidart https://github.com/elidart

[image: image] https://user-images.githubusercontent.com/383090/138187849-4c45e9a1-cd6e-4113-aa2e-718057e96783.png

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/zonca/cmb-s4-data-portal/issues/5#issuecomment-948118988, or unsubscribe https://github.com/notifications/unsubscribe-auth/AB66DMCHAW2MV7NU4WO6QTDUH5IZHANCNFSM5GKV764A . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.

--

Eli Dart, Network Engineer NOC: (510) 486-7600 ESnet Science Engagement Group (800) 333-7638 Lawrence Berkeley National Laboratory