Ticket #895 (closed defect: fixed)
HTTPS wildcard *.transitionnnetwork.org expires on 22nd January 2016
Reported by: | chris | Owned by: | chris |
---|---|---|---|
Priority: | major | Milestone: | Maintenance |
Component: | Live server | Keywords: | |
Cc: | sam, ade, paul | Estimated Number of Hours: | 0.0 |
Add Hours to Ticket: | 0 | Billable?: | yes |
Total Hours: | 1.25 |
Description
Unless I hear otherwise I'll renew the *.transitionnnetwork.org cert which is used by PuffinServer, PenguinServer and ParrotServer at a cost of £130.50 on or before the 22nd January 2016 when the current one expires.
An alternative would be to use Free HTTPS certificates from Let's Encrypt but this would take some time to set up as Let's Encrypt don't provide wild card certs.
Change History
Note: See
TracTickets for help on using
tickets.
Switching to using a SHA2 Intermediate Certificate, on PenguinServer, generating a CSR:
Getting the intermediate certs and setting up the .pem files:
The above however is causing chain errors at both https://www.ssllabs.com/ssltest/index.html and https://www.digicert.com/help/ and it took a while to work out why, but the Gandi wiki https://wiki.gandi.net/en/ssl/intermediate#sha2_intermediate_certificates hasn't been updated to say that the https://www.gandi.net/static/CAs/GandiStandardSSLCA2.pem file already contains a pem version of http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt
Test results:
Syncing the files to the other servers, after changing PermitRootLogin no to yes for sshd and then switching it back afterwards:
Restart the web servers and test:
Testing: