-
Notifications
You must be signed in to change notification settings - Fork 859
Custom SCEP proxy certificates intermittently failing to auto-renew #44111
Copy link
Copy link
Open
Labels
#g-security-complianceSecurity & Compliance product groupSecurity & Compliance product group:releaseReady to write code. Scheduled in a release. See "Making changes" in handbook.Ready to write code. Scheduled in a release. See "Making changes" in handbook.P1Critical: Broken workflow (critical bug), potential vuln, new feature for immediate Fleet needCritical: Broken workflow (critical bug), potential vuln, new feature for immediate Fleet needbugSomething isn't working as documentedSomething isn't working as documentedcustomer-shackleton
Milestone
Metadata
Metadata
Assignees
Labels
#g-security-complianceSecurity & Compliance product groupSecurity & Compliance product group:releaseReady to write code. Scheduled in a release. See "Making changes" in handbook.Ready to write code. Scheduled in a release. See "Making changes" in handbook.P1Critical: Broken workflow (critical bug), potential vuln, new feature for immediate Fleet needCritical: Broken workflow (critical bug), potential vuln, new feature for immediate Fleet needbugSomething isn't working as documentedSomething isn't working as documentedcustomer-shackleton
Type
Projects
Status
🐣 In progress
customer-shackleton: Slack thread.Fleet versions
Web browser and operating system: N/A
💥 Actual behavior
customer-shackletonis experiencing an issue where some devices are failing to automatically renew a certificate deployed via a custom SCEP proxy. The cert validity period is set to 30 days, and the devices are online during the 15 days before expiration (when Fleet should be attempting to renew the certs). No errors surface in the Fleet UI.🛠️ To fix
TODO
🧑💻 Steps to reproduce
These steps:
🕯️ More info (optional)
host_mdm_managed_certificatesfor affected devices showedNULLvalues fornot_valid_after,not_valid_before, andserial.