Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Re-enter provisioning on cert expiry #1309

Open
ripienaar opened this issue Jul 23, 2021 · 0 comments
Open

Re-enter provisioning on cert expiry #1309

ripienaar opened this issue Jul 23, 2021 · 0 comments
Labels

Comments

@ripienaar
Copy link
Member

When a server knows it can go into provisioning mode - either build settings or via jwt - it should note the expiry age of its certificate and near expiry re-enter provisioning.

Lets say the cert is valid for 7 days at start and the cert was obtained through provisioning, on the last day of cert validity it should at a random duration before expiry re-enter provisioning mode.

This means if 10k machines were provisioning at the same time - a week later they will gradually, spread over several hours, reprovision themselves to get new certs.

@ripienaar ripienaar added the wd label Jul 23, 2021
@ripienaar ripienaar changed the title Renter provisioning on cert expiry Re-enter provisioning on cert expiry Jul 23, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant