New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
HOSTEDCP-1344: use library-go crypto where we can #3326
HOSTEDCP-1344: use library-go crypto where we can #3326
Conversation
Signed-off-by: Steve Kuznetsov <skuznets@redhat.com>
Signed-off-by: Steve Kuznetsov <skuznets@redhat.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@@ -188,3 +216,39 @@ func duration(certTTL time.Duration, expirationSeconds *int32) time.Duration { | |||
return requestedDuration | |||
} | |||
} | |||
|
|||
// boundaries computes NotBefore and NotAfter: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@deads2k please let me know if you want this kind of logic to live in library-go or not
@@ -468,7 +453,7 @@ func TestSign(t *testing.T) { | |||
KeyUsage: x509.KeyUsageDigitalSignature | x509.KeyUsageKeyEncipherment, | |||
ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth, x509.ExtKeyUsageClientAuth}, | |||
BasicConstraintsValid: true, | |||
NotBefore: fakeClock.Now().Add(-5 * time.Minute), |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This uncovered a bug in the test - we were always signing a short-lived certificate, so we should not be back-dating.
@stevekuznetsov: This pull request references HOSTEDCP-1344 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.16.0" version, but no target version was set. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
@stevekuznetsov: all tests passed! Full PR test history. Your PR dashboard. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
/approve |
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: sjenning, stevekuznetsov The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
[ART PR BUILD NOTIFIER] This PR has been included in build ose-hypershift-container-v4.16.0-202312150810.p0.g9a32615.assembly.stream for distgit hypershift. |
go.mod: update openshift/library-go to latest
Signed-off-by: Steve Kuznetsov skuznets@redhat.com
control-plane-pki-operator: use library-go crypto everywhere
Signed-off-by: Steve Kuznetsov skuznets@redhat.com