Skip to content

Commit 3d43ffb

Browse files
author
Salvatore Nitopi
committed
CMK-25340 - 18988 Automatic certificate rotation for "Authority Key Identifier" compliance
With the release of Checkmk 2.5, we have introduced an automatic update that seamlessly rotates the site certificate. The update action checks whether the existing site certificate has the "Authority Key Identifier" property (that was introduced with Werk 18990). If the property is missing, the script automatically rotates (regenerates) the certificate. This ensures that, after the update, all certificates are compliant with the new standard. No user action is required during the update process. If a certificate already has the AKI property, no changes are made. Additionally, the underlying certificate creation libraries have been updated. Any certificate manually created or rotated in the future (e.g., via the cmk-cert tool) will include the Authority Key Identifier by default. Change-Id: I84efeef694963ae0ec702b50aab7e5e738a8973d
1 parent 74abd8c commit 3d43ffb

File tree

1 file changed

+22
-0
lines changed

1 file changed

+22
-0
lines changed

.werks/18988.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
[//]: # (werk v2)
2+
# Automatic certificate rotation for "Authority Key Identifier" compliance
3+
4+
key | value
5+
---------- | ---
6+
date | 2025-12-17T15:30:42+00:00
7+
version | 2.5.0b1
8+
class | feature
9+
edition | cre
10+
component | core
11+
level | 1
12+
compatible | yes
13+
14+
With the release of Checkmk 2.5, we have introduced an automatic update that seamlessly rotates the site certificate.
15+
16+
The update action checks whether the existing site certificate has the "Authority Key Identifier" property (that was introduced with Werk 18990).
17+
If the property is missing, the script automatically rotates (regenerates) the certificate. This ensures that, after the update, all certificates are compliant with the new standard.
18+
19+
No user action is required during the update process.
20+
If a certificate already has the AKI property, no changes are made.
21+
22+
Additionally, the underlying certificate creation libraries have been updated. Any certificate manually created or rotated in the future (e.g., via the cmk-cert tool) will include the Authority Key Identifier by default.

0 commit comments

Comments
 (0)