Make sure the embedded SSL cert doesn't expire #242
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
I have this script that runs against my puppet environment and tells me if any certs are going to expire in the next month. It found this cert. As far as I can tell this cert is just self-signed, so I signed a new one with an expiration far in the future.
Diff of their metadata:
That diff is effectively reversed, so the - parts are what's being added :) The only change is in expiration and the actual signature (which has to change, of course). I checked to make sure this file still matches the key with:
(not just visually verified, I did a diff and they're the same)