Uploaded image for project: 'Data Management'
  1. Data Management
  2. DM-12760

lsst-demo.ncsa.illinois.edu SSL cert expires 2017-11-26

    XMLWordPrintable

    Details

    • Type: Story
    • Status: Done
    • Resolution: Done
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None
    • Story Points:
      3
    • Epic Link:
    • Sprint:
      SUIT Sprint 2018-05
    • Team:
      Science User Interface

      Description

      Trey, et. al.

      Qualys reports that the SSL certificate for https://lsst-demo.ncsa.illinois.edu expires on November 26th. Looks like this is a Let's Encrypt cert so it should auto-renew, but we believe that should have already happened by now and it has not so probably a good idea to look into why it has not renewed yet.

      This is the SSL certificate used by the proxy Docker container installed by SUI, and not something general to the server.

      Similarly, the SSL certificate for https://lsst-demo2.ncsa.illinois.edu has already expired.

        Attachments

          Activity

          Hide
          bglick Bill Glick [X] (Inactive) added a comment -

          I just got notice from our security team that this is still an issue:

          Qualys reports that SSL certificate on lsst-demo.ncsa.illinois.edu expires on March 6th. Looks like this is a Let's Encrypt cert, however it should have auto-renewed by now so either that functionality is not setup or there is some kind of problem.

          Can someone from the SUI team resolve this?

          Show
          bglick Bill Glick [X] (Inactive) added a comment - I just got notice from our security team that this is still an issue: Qualys reports that SSL certificate on lsst-demo.ncsa.illinois.edu expires on March 6th. Looks like this is a Let's Encrypt cert, however it should have auto-renewed by now so either that functionality is not setup or there is some kind of problem. Can someone from the SUI team resolve this?
          Hide
          loi Loi Ly added a comment -

          Yes, it should have auto-renewed but it's not.  I've manually renewed the SSL certificate on  https://lsst-demo.ncsa.illinois.edu.

          I will look into why it's not doing it on its own at a later time and update the container as needed.

          We are not using lsst-demo2.  It was originally setup as a test and it was not used ever since.

          I am unable to access https://lsst-demo2.ncsa.illinois.edu from here nor am I able to ssh into it.

          I think it can be taken down.

          Show
          loi Loi Ly added a comment - Yes, it should have auto-renewed but it's not.  I've manually renewed the SSL certificate on   https://lsst-demo.ncsa.illinois.edu . I will look into why it's not doing it on its own at a later time and update the container as needed. We are not using lsst-demo2.  It was originally setup as a test and it was not used ever since. I am unable to access  https://lsst-demo2.ncsa.illinois.edu  from here nor am I able to ssh into it. I think it can be taken down.
          Hide
          bglick Bill Glick [X] (Inactive) added a comment -

          Thanks.

          We never could get the lsst-demo2 server to work as desired, so we shut down that server about 1 month ago.

          Show
          bglick Bill Glick [X] (Inactive) added a comment - Thanks. We never could get the lsst-demo2  server to work as desired, so we shut down that server about 1 month ago.
          Hide
          cclausen Christopher Clausen [X] (Inactive) added a comment -

          Got another cert warning for this host:

          Certificate #0 CN=lsst-demo.ncsa.illinois.edu The certificate will expire within a month: Jun 3 16:54:24 2018 GMT

          Show
          cclausen Christopher Clausen [X] (Inactive) added a comment - Got another cert warning for this host: Certificate #0 CN=lsst-demo.ncsa.illinois.edu The certificate will expire within a month: Jun 3 16:54:24 2018 GMT
          Hide
          loi Loi Ly added a comment -

          It's fixed.

          Show
          loi Loi Ly added a comment - It's fixed.
          Hide
          bglick Bill Glick [X] (Inactive) added a comment -

          Loi Ly - While I'm seeing a newly updated cert at https://lsst-demo.ncsa.illinois.edu/, the new certificate is not showing up as trusted in my web browser. Is this still a certificate from Let's Encrypt?

          Show
          bglick Bill Glick [X] (Inactive) added a comment - Loi Ly - While I'm seeing a newly updated cert at https://lsst-demo.ncsa.illinois.edu/,  the new certificate is not showing up as trusted in my web browser. Is this still a certificate from Let's Encrypt?
          Hide
          cclausen Christopher Clausen [X] (Inactive) added a comment -

          According to https://www.ssllabs.com/ssltest/analyze.html?d=lsst%2ddemo.ncsa.illinois.edu&hideResults=on&latest the cert is signed by "Fake LE Intermediate X1" which I assume it some kind of Let's Encrypt test or dev system.

          Show
          cclausen Christopher Clausen [X] (Inactive) added a comment - According to https://www.ssllabs.com/ssltest/analyze.html?d=lsst%2ddemo.ncsa.illinois.edu&hideResults=on&latest the cert is signed by "Fake LE Intermediate X1" which I assume it some kind of Let's Encrypt test or dev system.
          Hide
          loi Loi Ly added a comment -

          I had to update the letsencrypt client I was using. While testing, I was using their staging environment. I thought I had switched over to production before testing it on my browser. Apparently not. Sorry for the trouble. It should be good now.

          Show
          loi Loi Ly added a comment - I had to update the letsencrypt client I was using. While testing, I was using their staging environment. I thought I had switched over to production before testing it on my browser. Apparently not. Sorry for the trouble. It should be good now.

            People

            Assignee:
            loi Loi Ly
            Reporter:
            bglick Bill Glick [X] (Inactive)
            Watchers:
            Bill Glick [X] (Inactive), Christopher Clausen [X] (Inactive), Gregory Dubois-Felsmann, Loi Ly, Xiuqin Wu [X] (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Dates

              Due:
              Created:
              Updated:
              Resolved:

                Jenkins

                No builds found.