Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Raymond T. Racing
Jun 11, 2019

Perplx posted:

i hope entrust doesn't get distrusted

because my company uses them and I'd have to update a couple ansible playbooks

but currently you entrust entrust to not be distrusted and you shouldn't entrust them with that

it's a practice run anyway when you update the ansible playbooks

Adbot
ADBOT LOVES YOU

Midjack
Dec 24, 2007



Perplx posted:

i hope entrust doesn't get distrusted

because my company uses them and I'd have to update a couple ansible playbooks

you're a customer so your convenience is priority #1.

Ocean of Milk
Jun 25, 2018

oh yeah
entrust issues
(or rather, mis-issues!)

Wiggly Wayne DDS
Sep 11, 2010



Perplx posted:

i hope entrust doesn't get distrusted

because my company uses them and I'd have to update a couple ansible playbooks
i'd at least be preparing for much faster cert lifecycles and short-term replacements for when they stop complying

The Fool
Oct 16, 2003


it'd be hilarious if entrust is forced to do 90-day or shorter cert lifecycles

my org is super change averse during the season and that's about 5 months long

Shame Boy
Mar 2, 2010

Perplx posted:

i hope entrust doesn't get distrusted

because my company uses them and I'd have to update a couple ansible playbooks

well i hope you're excited about their [soon to be involuntary] fire drill initiative

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

ca0: entrust on fire

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

The Fool posted:

it'd be hilarious if entrust is forced to do 90-day or shorter cert lifecycles

my org is super change averse during the season and that's about 5 months long

once you get set up it’s not really a change that way any more than log rotation is, or adding scale-up nodes to the load balancer: it’s just an automated process that runs in the background. you monitor it and push the dependabot updates when you remember

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

to cross the streams, Bruce Moron is staring up at the dword of damocles

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

holy poo poo lol that typo i aint fixing it

The Fool
Oct 16, 2003


Subjunctive posted:

once you get set up it’s not really a change that way any more than log rotation is, or adding scale-up nodes to the load balancer: it’s just an automated process that runs in the background. you monitor it and push the dependabot updates when you remember

oh the automation is in place, management is just insanely risk-averse during that time of the year.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

The Fool posted:

oh the automation is in place, management is just insanely risk-averse during that time of the year.

they won’t even know it’s happening! just certbot being a good little bot and ACMEing you up some hot, fresh certs from Let’s Encrypt

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Captain Foo posted:

holy poo poo lol that typo i aint fixing it

Good

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
Always automate dumb stuff. Don't ever repeat having to do the same job twice if it can safely be managed by some lines of code

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

but if you automate it, make sure you monitor it!

Cybernetic Vermin
Apr 18, 2005

the real art of automation is making failures obvious. the automation being good or bad in any other regards is way less important

The Fool
Oct 16, 2003


We use venafi + terraform to do self-service automation for our application teams.

Any potential problems with Entrust being distrusted or having a 90-day lifecycle are purely organizational.

The Fool
Oct 16, 2003


We migrated from Digicert to Entrust a couple years ago and the automation changes took less than 30 minutes.

Took 6 months for all of the different teams to get the actual certificates replaced.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Subjunctive posted:

but if you automate it, make sure you monitor it!

yeah. that is where my 'safely' qualifier comes in. automating stuff makes me anxious but if you can monitor it then the anxiety is a tad lessened

that said, if you can avoid having to manage the automation infrastructure but still use it, it's a boon to getting work done

The Fool
Oct 16, 2003


Lain Iwakura posted:

manage the automation infrastructure

my job :negative:

Shame Boy
Mar 2, 2010

Subjunctive posted:

but if you automate it, make sure you monitor it!

but if i don't monitor it then i don't have to fix it when it breaks

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Shame Boy posted:

but if i don't monitor it then i don't have to fix it when it breaks

yes you do, it just takes you longer to figure out that it’s the thing that needs fixing, because instead of an alert for “certificate update failure: https://www.shameboy.ai NXDOMAIN” you get “payments failing from mobile app”

spankmeister
Jun 15, 2008






at work i forgot to automate an 802.1X certificate thing on a goofball server that wasn't in IT's herd, and it bit me in the rear end every loving year for three consecutive years before I fixed it.


then it turned out i made a mistake and had to manually fix it a fourth time

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Subjunctive posted:

yes you do, it just takes you longer to figure out that it’s the thing that needs fixing, because instead of an alert for “certificate update failure: https://www.shameboy.ai NXDOMAIN” you get “payments failing from mobile app”

you also get to spend a lot longer fixing it because invariably some dependencies are broken and sometimes the mechanism to trivially repair it no longer works. also, it's now an emergency

spankmeister
Jun 15, 2008






I lust for CA death

FlapYoJacks
Feb 12, 2009

spankmeister posted:

I lust for CA death

Look, we all wish California would die, OK?

Shame Boy
Mar 2, 2010

Subjunctive posted:

yes you do, it just takes you longer to figure out that it’s the thing that needs fixing, because instead of an alert for “certificate update failure: https://www.shameboy.ai NXDOMAIN” you get “payments failing from mobile app”

more often than not in my experience it simply stops working forever and it turns out nobody was actually using it so nobody cares

i'll admit my experience is probably not representative

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

FlapYoJacks posted:

Look, we all wish California would die, OK?

California? I thought we were lusting after the frozen lands of Canuckistan up north

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Volmarias posted:

California? I thought we were lusting after the frozen lands of Canuckistan up north

please leave us alone

Raymond T. Racing
Jun 11, 2019

wait is the happening happening subjunctive

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
brb, changing iso code to en-c,eh?

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Raymond T. Racing posted:

wait is the happening happening subjunctive

things are certainly happenable now

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Raymond T. Racing posted:

wait is the happening happening subjunctive

Source ur excitement

Raymond T. Racing
Jun 11, 2019

Volmarias posted:

Source ur excitement

Subjunctive posted:

Expecting one from the head of Mozilla’s root program in the next day or two, maybe today.

Amir’s above is pretty good though incomplete.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Raymond T. Racing posted:

wait is the happening happening subjunctive

mayhaps!

Raymond T. Racing
Jun 11, 2019


I am unreasonably excited about this

are you able to spill any secrets yet or are you entrusted to secrecy

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I don’t know anything non-public other than that, which I know because of Wayne

he and Amir are the heroes here; I just shitposted in some bugs

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

oh look what we have here

https://wiki.mozilla.org/CA/Entrust_Issues

namlosh
Feb 11, 2014

I name this haircut "The Sad Rhino".
^^^^^^^^^ ooooo, can’t wait to see highlights… too busy to read for myself

Perplx posted:

i hope entrust doesn't get distrusted

because my company uses them and I'd have to update a couple ansible playbooks

nothing personal but if you look at my earlier posts, I already don’t trust your company (on one of my machines where I disabled entrust trust)

Adbot
ADBOT LOVES YOU

The Fool
Oct 16, 2003


namlosh posted:

^^^^^^^^^ ooooo, can’t wait to see highlights… too busy to read for myself

it's just a summary of the issues to date afaict

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply