Project

General

Profile

Actions

Enhancement #461

open

Prepare TLSA rollover tools

Added by Marc Dequènes over 9 years ago. Updated about 5 years ago.

Status:
New
Priority:
Low
Assignee:
-
Category:
Service :: DNS
Start date:
2015-07-12
Due date:
% Done:

0%

Estimated time:
Patch Available:
Confirmed:
No
Branch:
Entity:
DuckCorp
Security:
Help Needed:

Description

Currently tools are able to publish TLSA, but this does not allow rollovers.

We need to upgrade the process/script to publish the new records while keeping the previous records a certain time. Which means we need to memoize when it was published, and have some automated way of removing the old one.

In this process we need to pre-publish, which means install the new certificate later. So we need to act in advance before the previous one expire.


Related issues 1 (1 open0 closed)

Related to DuckCorp Infrastructure - Enhancement #675: Publish DANE/TLSA records for Let's Encrypt generated certsIn ProgressMarc Dequènes2019-09-20

Actions
Actions

Also available in: Atom PDF