Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

One SSL-Certificate for all our hosts #69

Closed
dr0i opened this issue Jul 28, 2020 · 5 comments
Closed

One SSL-Certificate for all our hosts #69

dr0i opened this issue Jul 28, 2020 · 5 comments
Assignees

Comments

@dr0i
Copy link
Member

dr0i commented Jul 28, 2020

It's possible to only have one SSL-certificate for multiple hostnames SubjectAlternativeName, SAN. Since we use a proxy, allmost all hostnames we control point to it (empyhtos). It's far more simple to have just one certificate for certificates must be renewed regularly.
For a CSR we need a list of all these hostnames.
The hostnames in need of a valid SSL certificate are listed here. The list should be updated if needed:

FQDN: lobid.org
FQDN: www.lobid.org
FQDN: beta.lobid.org
FQDN: blog.lobid.org
FQDN: labs.lobid.org
FQDN: slides.lobid.org
FQDN: test.lobid.org

FQDN: metafacture.org
FQDN: www.metafacture.org

FQDN: nwbib.de
FQDN: www.nwbib.de
FQDN: test.nwbib.de

FQDN: skohub.io
FQDN: www.skohub.io
FQDN: test.skohub.io

Note: everytime this list is updated a new CSR must be done asking our IT to provide a new certificate. Also, of course, this must be done when the certificate is going to expire.

@dr0i
Copy link
Member Author

dr0i commented Jul 28, 2020

Hi @acka47 if you find a hostname missing in the list please add it and ping.

@acka47
Copy link
Contributor

acka47 commented Jul 29, 2020

I think we do not use vocabs.lobid.org anymore and it thus can be removed. Do we still use stage.lobid.org? Otherwise it looks complete.

@acka47 acka47 assigned dr0i and unassigned acka47 Jul 29, 2020
@acka47
Copy link
Contributor

acka47 commented Jul 30, 2020

I added metafacture.org and restructured the list to take into account Mariusz' advice to have on certificate per domain.

@dr0i
Copy link
Member Author

dr0i commented Aug 4, 2020

Deployed, please test. Note that skohub and nwbib will be renewed at the end of the next year. Note also that www.metafacture.org is not enabled, I think it's an DNS issue , will contact IT. [edit: IT made it good by correcting DNS]

@acka47
Copy link
Contributor

acka47 commented Aug 5, 2020

+1 Closing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants