Project

General

Profile

Task #3087

Non-productions servers need to migrate to new commercial certificates

Added by Chris Jones over 12 years ago. Updated over 12 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Support Operations
Start date:
2012-07-18
Due date:
% Done:

100%

Milestone:
None
Product Version:
*
Story Points:
Sprint:

Description

The GoDaddy test SSL certificates expired on July 17th, and so servers in each environment need to transition to use the newly purchased certificates. Dave has added these new certs to the 3 development CNs:

I have placed the certificate, key, and intermediate CA cert on cn-dev, cn-dev-2, and cn-dev-3.

The *.test.dataone.org certificate is /etc/ssl/.test.dataone.org.crt
The geotrust intermediate CA cert is /etc/ssl/geotrust_intermediate.crt
The key for *.test.dataone.org is /etc/ssl/private/
.test.dataone.org.key

The new certs are for the test.dataone.org domain, and so the server names will need to change in DNS. During this transition, the CNs in the development environment will also be renamed to be aligned with our new name conventions (outlined by Andy):

I am proposing that we take advantage of the change to bring the three development coordinating nodes
in line with the current naming convention (cn---).

As a result, if this proposal is accepted, the machine names would change from --> to:

            cn-dev.dataone.org --> cn-dev-ucsb-1.test.dataone.org
            cn-dev-2.dataone.org --> cn-dev-unm-1.test.dataone.org
            cn-dev-3.dataone.org --> cn-dev-orc-1.test.dataone.org

            cn-sandbox-ucsb-1.dataone.org --> cn-sandbox-ucsb-1.test.dataone.org
            cn-sandbox-unm-1.dataone.org --> cn-sandbox-unm-1.test.dataone.org
            cn-sandbox-orc-1.dataone.org --> cn-sandbox-orc-1.test.dataone.org

            cn-stage-ucsb-1.dataone.org --> cn-stage-ucsb-1.test.dataone.org
            cn-stage-unm-1.dataone.org --> cn-stage-unm-1.test.dataone.org
            cn-stage-orc-1.dataone.org --> cn-stage-orc-1.test.dataone.org

Configuration scripts in the dataone-cn-os-core debian package will need to be updated to reflect the DNS changes


Subtasks

Task #3088: Change non-production server names to the *.test.dataone.org domainClosedNick Outin

Task #3089: Change dataone-cn-os-core configuration scripts to reflect DNS changesClosedChris Jones

Task #3091: Put new *.test.dataone.org cert, key, and ca bundle on serversClosedBen Leinfelder

Task #3092: Generate new DataONE client certificates for the non-production serversClosedDave Vieglais

Task #3094: Change hostnames for stage and sandbox hostsClosedChris Jones

Task #3095: Change hostnames for development hostsClosedChris Jones

History

#1 Updated by Chris Jones over 12 years ago

  • Status changed from New to In Progress

#2 Updated by Chris Jones over 12 years ago

  • Status changed from In Progress to Closed

DNS changeover is complete for the 3 development environment CNs.

Also available in: Atom PDF

Add picture from clipboard (Maximum size: 14.8 MB)