I was testing ipsilon OpenID instance on staging when working on https://pagure.io/fedora-infrastructure/issue/10241 and after we get all the redirects right it was still failing with 404, when I tried to access the identity page manually I got net::ERR_CERT_COMMON_NAME_INVALID.
net::ERR_CERT_COMMON_NAME_INVALID
Looking at the cert the common name is set to Common Name (CN) *.stg.fedoraproject.org, which should work. But on production there is Common Name (CN) *.id.fedoraproject.org, so I assume the id is missing there.
Common Name (CN) *.stg.fedoraproject.org
Common Name (CN) *.id.fedoraproject.org
id
Not urgent as it's staging, but it's blocking future work on https://pagure.io/fedora-infrastructure/issue/10241
Metadata Update from @zlopez: - Issue marked as blocking: #10241 - Issue tagged with: low-gain, medium-trouble
Metadata Update from @zlopez: - Issue priority set to: Waiting on Assignee (was: Needs Review) - Issue tagged with: ops
So, we never got a cert for this. I am not sure why... but it needs a new seperate wildcard cert.
We get them from digicert.
I'd like to see about setting up you and @james and @gwmngilfen to have access to request these certs, etc. Perhaps we can setup a meeting sometime next week?
I will be on SRECon 2025 this week, but I would like to be part of this process. As there will be freeze soon I assume this can wait till I'm back.
I'm up for this - but we should also add cert monitoring for Zabbix I guess?
I'm going to try and set you all up with digicert here soon and will send an email on the process... will then get @gwmngilfen and @james up on it now and can get you setup after you get back. ;)
Oh and yes, we should monitor cert expiration in zabbix
This seems to be fixed now. Re-open if there's anything more to do.
Metadata Update from @kevin: - Issue assigned to zlopez - Issue close_status updated to: Fixed - Issue status updated to: Closed (was: Open)