<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #820: *.transitionnetwork.org 2015 security certificate</title>
    <link>http://localhost:8080/trac/ticket/820</link>
    <description>&lt;p&gt;
The current wild-card &lt;tt&gt;*.transitionnetwork.org&lt;/tt&gt; cert will run out on 24th Jan, this is a ticket to track the time spent renewing it.
&lt;/p&gt;
&lt;p&gt;
See also &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/795" title="maintenance: SHA1 Deprecation: Regenerate all certs using SHA256 (closed: fixed)"&gt;ticket:795&lt;/a&gt;, SHA1 Deprecation: Regenerate all certs using SHA256.
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/820</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Tue, 20 Jan 2015 10:16:00 GMT</pubDate>
      <title>cc changed</title>
      <link>http://localhost:8080/trac/ticket/820#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/820#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;cc&lt;/strong&gt;
              &lt;em&gt;ade&lt;/em&gt; added; &lt;em&gt;ed&lt;/em&gt; removed
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
replacing Ed with ADE as cc
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Tue, 20 Jan 2015 10:28:29 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/820#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/820#comment:2</guid>
      <description>
        &lt;p&gt;
This being done at around the same time as ticket &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/826" title="task: Switching MX records from United to Google (closed: fixed)"&gt;#826&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 22 Jan 2015 12:36:50 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/820#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/820#comment:3</guid>
      <description>
        &lt;p&gt;
For info see:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/SecurityInfo"&gt;wiki:SecurityInfo&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Following last years steps on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer"&gt;PenguinServer&lt;/a&gt;, &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/685#comment:2" title="task: SSL certificate about to expire? (closed: fixed)"&gt;ticket:685#comment:2&lt;/a&gt; with SHA256 updates, see &lt;a class="ext-link" href="https://wiki.gandi.net/en/ssl/csr"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.gandi.net/en/ssl/csr&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;sudo -i
cd /etc/ssl/transitionnetwork.org
mkdir 2015
chmod 700 2014
cd 2015
openssl req -nodes -newkey rsa:2048 -sha256 -keyout transitionnetwork.org.key -out transitionnetwork.org.csr
...
Country Name (2 letter code) [AU]:UK
State or Province Name (full name) [Some-State]:
Locality Name (eg, city) []:
Organization Name (eg, company) [Internet Widgits Pty Ltd]:Transition Network
Organizational Unit Name (eg, section) []:
Common Name (e.g. server FQDN or YOUR name) []:*.transitionnetwork.org
Email Address []:webproject@transitionnetwork.org
...
chmod 600 *.*
&lt;/pre&gt;&lt;p&gt;
The next step is one for Ed / Ade:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Please log into your handle EM7826-GANDI and visit the following URL
in order to view its status and complete the verification steps to
prove you have control of the domain:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.gandi.net/admin/ssl/steps/25785564"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.gandi.net/admin/ssl/steps/25785564&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Thu, 22 Jan 2015 14:28:28 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/820#comment:4</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/820#comment:4</guid>
      <description>
        &lt;p&gt;
Followed Chris' steps - got an error message "ERROR: you cannot cancel this operation".
&lt;/p&gt;
&lt;p&gt;
Checked the SSL status in the account and it all looks fine.
&lt;a class="ext-link" href="https://www.gandi.net/admin/ssl/121008/details"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.gandi.net/admin/ssl/121008/details&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Chris please confirm this is all good for you
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 22 Jan 2015 14:38:50 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/820#comment:5</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/820#comment:5</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Yes all is good, not sure why they said that step was needed, seems it wasn't -- the cert has come through, I'll follow up the deployment on &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/795" title="maintenance: SHA1 Deprecation: Regenerate all certs using SHA256 (closed: fixed)"&gt;ticket:795&lt;/a&gt;, note no time has been added to ticket as the time to generate the CSR and get the cert has been invoiced with the cert cost by Webarchitects (£10).
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>