Uploaded image for project: 'JS - JS7 JobScheduler Engine'
  1. JS - JS7 JobScheduler Engine
  2. JS-2219

Accept expired X.509 signing certificates

    XMLWordPrintable

Details

    • Feature
    • Status: Released (View Workflow)
    • Blocker
    • Resolution: Fixed
    • 2.0.0
    • 2.5.13, 2.7.7, 2.8.2
    • None
    • None

    Description

      Current Situation

      • Controller and Agent check the validity period of the X.509 Signing Certificate used from JOC Cockpit when deploying Workflows and Job Resources.
      • If the validity period is expired, then the related Workflow or Job Resource cannot be accessed. Orders will stop running and will be set to the blocked state.

      Desired Behavior

      • Digital signing of Workflows and Job Resources is performed with a Private Key. If the Signing Certificate expires after creating the signature, then this does not affect security. The Signing Certificate is verified from the CA Certificate stored with the Controller and Agent. If the CA Certificate expires, then it will not be used.
      • Users want to deploy Workflows and Job Resources just once and keep them in place for a number of years. Short expiration periods of 1-2 years as frequently used by Public CAs do not match this situation as they force users to redeploy scheduling objects on an annual or bi-annual basis.
      • Controller and Agent will accept X.509 Signing Certificates after reaching their expiration date from the certificate's notAfter property.

      Maintainer Notes
      Documentation is available from JS7 - Signing Certificate Renewal

      Patch Availability

      Attachments

        Issue Links

          Activity

            People

              jz Joacim Zschimmer
              jz Joacim Zschimmer
              Ajay Kumbhkar Ajay Kumbhkar
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: