#1843: SSL certificale expired for svn.cactuscode.org ---------------------------+------------------------------------------------ Reporter: barry.wardell | Owner: Type: defect | Status: new Priority: unset | Milestone: Component: Cactus | Version: development version Keywords: | ---------------------------+------------------------------------------------ It appears that the SSL certificate for svn.cactuscode.org expired today. This can cause the svn checkout of Cactus thorns (in particular external libraries) to fail.
#1843: SSL certificale expired for svn.cactuscode.org ----------------------------+----------------------------------------------- Reporter: barry.wardell | Owner: Type: defect | Status: confirmed Priority: blocker | Milestone: Component: Cactus | Version: development version Resolution: | Keywords: ----------------------------+----------------------------------------------- Changes (by hinder):
* priority: unset => blocker * status: new => confirmed
Comment:
cactuscode.org is also down.
#1843: SSL certificale expired for svn.cactuscode.org ----------------------------+----------------------------------------------- Reporter: barry.wardell | Owner: knarf Type: defect | Status: accepted Priority: blocker | Milestone: Component: Cactus | Version: development version Resolution: | Keywords: ----------------------------+----------------------------------------------- Changes (by knarf):
* owner: => knarf * status: confirmed => accepted
#1843: SSL certificale expired for svn.cactuscode.org ----------------------------+----------------------------------------------- Reporter: barry.wardell | Owner: knarf Type: defect | Status: accepted Priority: blocker | Milestone: Component: Cactus | Version: development version Resolution: | Keywords: ----------------------------+-----------------------------------------------
Comment (by knarf):
ssl chain is broken on https://cactuscode.org/ (not my doing, will investigate). ssl is fine on https://svn.cactuscode.org/ - so why should svn fail?
#1843: SSL certificale expired for svn.cactuscode.org ----------------------------+----------------------------------------------- Reporter: barry.wardell | Owner: knarf Type: defect | Status: accepted Priority: blocker | Milestone: Component: Cactus | Version: development version Resolution: | Keywords: ----------------------------+-----------------------------------------------
Comment (by knarf):
ah - it _is_ expired.
#1843: SSL certificale expired for svn.cactuscode.org ----------------------------+----------------------------------------------- Reporter: barry.wardell | Owner: knarf Type: defect | Status: accepted Priority: blocker | Milestone: Component: Cactus | Version: development version Resolution: | Keywords: ----------------------------+-----------------------------------------------
Comment (by knarf):
Talked to IT, ticket is open, once the admin is "in" this should be handled.
#1843: SSL certificale expired for svn.cactuscode.org ----------------------------+----------------------------------------------- Reporter: barry.wardell | Owner: knarf Type: defect | Status: accepted Priority: blocker | Milestone: Component: Cactus | Version: development version Resolution: | Keywords: ----------------------------+-----------------------------------------------
Comment (by hinder):
For svn.cactuscode.org, SSLChecker says that it is not trusted in all web browsers (https://www.sslshopper.com/ssl- checker.html#hostname=svn.cactuscode.org), and the automated checkout that Jenkins uses says that the certificate is not issued by a trusted authority. This means we have no running tests at the moment.
For cactuscode.org, SSLChecker says that in addition to not being trusted in all web browsers, there is a hostname mismatch. Indeed, the certificate common name is einsteintoolkit.org, which is incorrect. https://www.sslshopper.com/ssl-checker.html#hostname=cactuscode.org
#1843: SSL certificate expired for svn.cactuscode.org ----------------------------+----------------------------------------------- Reporter: barry.wardell | Owner: knarf Type: defect | Status: accepted Priority: blocker | Milestone: Component: Cactus | Version: development version Resolution: | Keywords: ----------------------------+-----------------------------------------------
#1843: SSL certificate expired for svn.cactuscode.org ----------------------------+----------------------------------------------- Reporter: barry.wardell | Owner: knarf Type: defect | Status: accepted Priority: blocker | Milestone: Component: Cactus | Version: development version Resolution: | Keywords: ----------------------------+-----------------------------------------------
Comment (by knarf):
svn.cactuscode.org is fixed. The intermediate certificate chain was missing.
#1843: SSL certificate expired for svn.cactuscode.org ----------------------------+----------------------------------------------- Reporter: barry.wardell | Owner: knarf Type: defect | Status: accepted Priority: blocker | Milestone: Component: Cactus | Version: development version Resolution: | Keywords: ----------------------------+-----------------------------------------------
Comment (by barry.wardell):
I can confirm that this now works in cases (in particular svn checkouts) where it did not work before the intermediate certificate chain was added.
#1843: SSL certificate missing for cactuscode.org (website) -----------------------------+---------------------------------------------- Reporter: barry.wardell | Owner: knarf Type: defect | Status: accepted Priority: minor | Milestone: Component: Cactus website | Version: development version Resolution: | Keywords: -----------------------------+---------------------------------------------- Changes (by knarf):
* priority: blocker => minor * component: Cactus => Cactus website
Comment:
We never had a certificate for cactuscode.org. All an attempt was leading to was a test page. I tried to redirect the https site to simple http, but that doesn't work, since ssl is handled first in a connection and since there is no certificate in the first place, this already fails before any redirection could take place. I can also not simply have apache not serve that port, since the ET website comes in there too. The only way to gracefully solve this (besides using two physical servers for the two web sites) is to get a certificate. And once you have one you might as well serve it. We also redirect www.cactuscode.org to cactuscode.org. This redirection would also not work when using ssl, so either we get a certificate for both (one just for the redirection), or we live with it.
#1843: SSL certificate missing for cactuscode.org (website) -----------------------------+---------------------------------------------- Reporter: barry.wardell | Owner: knarf Type: defect | Status: accepted Priority: minor | Milestone: Component: Cactus website | Version: development version Resolution: | Keywords: -----------------------------+----------------------------------------------
Comment (by hinder):
We seem to have these certificate issues fairly regularly. I suggest that we discuss how we can improve our processes so that this doesn't happen again.
#1843: SSL certificate missing for cactuscode.org (website) -----------------------------+---------------------------------------------- Reporter: barry.wardell | Owner: knarf Type: defect | Status: accepted Priority: minor | Milestone: Component: Cactus website | Version: development version Resolution: | Keywords: -----------------------------+----------------------------------------------
Comment (by anonymous):
For all sites hosted at LSU, certificates have to be from LSU (I specifically asked about that). That means I have to go through CCT support.
What happened last week: one certificate expired, and (i) I didn't notice (my bad, I am truly sorry), and (ii) while an automatic ticket was opened beforehand for IT support, the person usually in charge was out-of-office, and the fall-back didn't get it done in time. Once he got it done, the chain wasn't correct, and I was out-of-touch for the weekend.
I will be with IT support in person today (once they are 'in'), to make sure the fall-back also knows the correct installation of certificates; the first-contact person already does.
The following is a quick script to check on things - of course you have to remember to do it from time to time. https://www.cct.lsu.edu/~knarf/cgi-bin/monitor.cgi
The issue with cactuscode.org (the website) is unrelated, and not new.
#1843: SSL certificate missing for cactuscode.org (website) -----------------------------+---------------------------------------------- Reporter: barry.wardell | Owner: knarf Type: defect | Status: closed Priority: minor | Milestone: Component: Cactus website | Version: development version Resolution: fixed | Keywords: -----------------------------+---------------------------------------------- Changes (by rhaas):
* status: accepted => closed * resolution: => fixed
trac@lists.einsteintoolkit.org