Skip to content

Conversation

jcharaoui
Copy link
Contributor

Fix openssl 3.4.0 compatibility which fails on crl.version = 2, and regenerate the pki for additional ci tests which also use git-tracked x509 certs that fail to verify when the tests are run in environments where the clock is set a few years into the future such as Debian CI.

The restructuring leverages the puppetserver-ca-cli gem as much as possible except is for some corner cases where a specific serial or certificate extension needs to be used for the purposes of particular tests such as the update-crls-test case.

Fix openssl 3.4.0 compatibility which fails on crl.version = 2, and
regenerate the pki for additional ci tests which also use git-tracked
x509 certs that fail to verify when the tests are run in environments
where the clock is set a few years into the future such as Debian CI.

The restructuring leverages the puppetserver-ca-cli gem as much as
possible except is for some corner cases where a specific serial or
certificate extension needs to be used for the purposes of particular
tests such as the update-crls-test case.
@jcharaoui jcharaoui requested review from a team as code owners February 3, 2025 22:53
jcharaoui added a commit to jcharaoui/openvox-server that referenced this pull request Aug 9, 2025
Fix openssl 3.4.0 compatibility which fails on crl.version = 2, and regenerate
the pki for additional ci tests which also use git-tracked x509 certs that fail
to verify when the tests are run a few years into the future, leading to FTBFS
errors.

https://bugs.debian.org/1078635
puppetlabs/puppetserver#2902
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant