mozilla-services / mozilla-services/autograph

make it easier to force content signature renewal

Open
#618 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
Go
Stars
176
Forks
34
Avg merge
1d 17h
Merged PRs (30d)
3

Description

Currently, it csigpki renewal runs on autograph app start when all key handles and EE certs in the DB are expired.

Doing this manually requires:

  1. connecting to the DB and expiring ee entries
  2. restarting all running autograph app instances

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing the csigpki renewal path that runs when the autograph app starts and checking how expired key handles and EE certificates are identified in the database. Reproduce the current manual process of expiring EE entries and restarting app instances. Done should provide a documented, testable way to force renewal without repeating those steps.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
backend, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.