Skip to content

Conversation

@breskeby
Copy link
Contributor

@breskeby breskeby commented May 5, 2025

No description provided.

@breskeby breskeby requested a review from a team as a code owner May 5, 2025 14:48
@breskeby breskeby added :Delivery/Build Build or test infrastructure Team:Delivery Meta label for Delivery team auto-backport Automatically create backport pull requests when merged v8.19.0 v9.1.0 labels May 5, 2025
@breskeby breskeby self-assigned this May 5, 2025
@elasticsearchmachine
Copy link
Collaborator

Pinging @elastic/es-delivery (Team:Delivery)

@breskeby breskeby marked this pull request as draft May 5, 2025 15:49
-srckeystore /usr/share/elasticsearch/jdk/lib/security/cacerts \
-srcstoretype PKCS12 \
-destkeystore config/cacerts.bcfks \
-deststorepass password \
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we will need a strong password, 14 chars of Ascii. Not sure if that is explicitly required for FIPS BCFKS but aligns with our custom keystore requirements.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tweaked this

Copy link
Contributor

@tvernum tvernum left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@breskeby breskeby marked this pull request as ready for review May 6, 2025 06:22
@breskeby breskeby changed the title Ensure we use BCFKS based cacert truststore for cloud ess fips Ensure BCFKS based cacert truststore is used for cloud ess fips May 6, 2025
@breskeby breskeby merged commit aee4465 into elastic:main May 6, 2025
14 of 18 checks passed
breskeby added a commit to breskeby/elasticsearch that referenced this pull request May 6, 2025
…tic#127716)

* Ensure we use BCFKS based cacert truststore for cloud ess fips
* Make truststore default password 14 characters
@elasticsearchmachine
Copy link
Collaborator

💚 Backport successful

Status Branch Result
8.19

breskeby added a commit that referenced this pull request May 6, 2025
) (#127737)

* Ensure we use BCFKS based cacert truststore for cloud ess fips
* Make truststore default password 14 characters
ywangd pushed a commit to ywangd/elasticsearch that referenced this pull request May 9, 2025
…tic#127716)

* Ensure we use BCFKS based cacert truststore for cloud ess fips
* Make truststore default password 14 characters
jfreden pushed a commit to jfreden/elasticsearch that referenced this pull request May 12, 2025
…tic#127716)

* Ensure we use BCFKS based cacert truststore for cloud ess fips
* Make truststore default password 14 characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-backport Automatically create backport pull requests when merged :Delivery/Build Build or test infrastructure >non-issue Team:Delivery Meta label for Delivery team v8.19.0 v9.1.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants