-
Notifications
You must be signed in to change notification settings - Fork 465
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Renew NDES SCEP certificates #24468
Comments
Hey @georgekarrv just a reminder that this one is ready to spec! Please work with @marko-lisica to help get it ready for estimation. |
@marko-lisica A few questions.
|
Good question @getvictor! @rachaelshaw Are we going to mark certs managed by Fleet? |
@getvictor I assume there's no reason for someone to use 0, so I think we should have option to disable renewal. We should document this in guide. |
0 would mean disabled, and 180 would be default. For QA, we would do like 1 or 2. |
@getvictor When I think better we should probably skip that in this iteration. I went fast over the message, so didn't realize this would mean that we add environment variable. Let's have just default renewal period of 180 days for now. I think users can always remove |
This implies that renewal is always enabled. |
@getvictor Good point. I think that's ok to have it always enabled. Do you see any use case where customer might want to disable renewal? |
Some admins might want to disable it so they don't have to worry about it. Maybe it simplifies the security and tracking of certificates. For example, if device lifetime is 3 years in the org, they can issue a cert for 5/10 years, so they know they will never need to renew it. |
@getvictor I think to make this simpler for now, let's skip this. I think we won't close doors for later. We can always add this? |
ok |
@georgekarrv Moving this back to "Ready to spec" as there are TODOs, and we still need to spec and estimate the remaining integration work on this. |
@georgekarrv reminder that this one is ready to spec. Can you please complete the "TODOs" in "Engineering" section so we can estimate this one? |
@noahtalerman Heads up that George is out the remainder of this week, so this won't get estimated until next week. Let me know if that's a problem. |
Goal
Key result
Deliver customer promises
Original requests
Related stories
Context
Changes
Product
$FLEET_VAR_NDES_SCEP_RENEWAL_ID
) that will be replaced withprofile_uuid
value.$FLEET_VAR_NDES_SCEP_RENEWAL_ID
in the common name (CN)CN
field in NDES SCEP profile includes$FLEET_VAR_NDES_SCEP_RENEWAL_ID
InstallProfile
command 180 days before expiration to renew the SCEP certificate.customer-numa
's use case (renewal period is specified in NDES SCEP certificate template) works.Engineering
Note: Review existing SCEP enrollment certificate renewal flow before starting implementation work on this
QA
Risk assessment
Manual testing steps
Make sure that clicking “Resend” on the Host details > OS settings page resend profile and host gets new certificate.
Step 2
Step 3
Testing notes
Confirmation
The text was updated successfully, but these errors were encountered: