Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RDS CA 2019 cert expires soon/now 22 Aug #340

Open
RichardBradley opened this issue Aug 20, 2024 · 1 comment
Open

RDS CA 2019 cert expires soon/now 22 Aug #340

RichardBradley opened this issue Aug 20, 2024 · 1 comment

Comments

@RichardBradley
Copy link
Contributor

The control-tower system includes a copy of AWS's "RDS CA" "2019" cert, which is set to expire on 22 Aug 2024.

This will need updating to the new one. I'm not sure what will break if not. Perhaps everything? Perhaps just fresh installs?
We have updated our RDS to thew new cert directly a few minutes ago and our (running) Concourse hasn't broken yet...

See
#48
and
ee3dbde
from the last time this was needed

The final cert in this file is the one that expires 22 Aug 2024:
https://github.com/EngineerBetter/control-tower/blob/master/db/rds_root_cert.go

@RichardBradley
Copy link
Contributor Author

Our install stopped working over the weekend, looks it's due to this expired RDS CA cert. The old one is hardcoded in the source.
(I don't know why it took 25 days to fail since the expiry.)

I wouldn't mind trying to fork the project, but I'm not sure how to build and release it (seems to require a Concourse, which is a bit of a circular dependency) or how to update our install to point to my fork.

I've also posted this to concourse/concourse#9002

Any advice would be greatly appreciated

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant