SSL Renewal - bcgov/common-service-showcase GitHub Wiki

SSL Certificate Renewal

Steps to create or renew a SSL on OpenShift

  1. Create a service desk ticket with CITZ Identity Management Solutions CITZ:EX - [email protected]:

https://citz-imb.atlassian.net/servicedesk/customer/portal/5/group/286/create/135

  1. Generate a Certificate Signing Request (CSR) and Key using openssl cli on your workstation.
    Using BCBox as an example, run the following command:

    openssl req -new -newkey rsa:2048 -nodes -out bcbox.nrs.gov.bc.ca.csr -keyout bcbox.nrs.gov.bc.ca.key -subj "/C=CA/ST=British Columbia/L=Victoria/O=Government of the Province of British Columbia/OU=Ministry of Water Land and Resource Stewardship/CN=bcbox.nrs.gov.bc.ca"

    This will create the .csr and .key files in the current directory.

    Note: openssl is bundled with the git cli. if you get errors when you run the command due to escaping of backslashes you can try appending the subject param like //C=CA/C=CA/ST=British Columbia...

  2. Attach the .csr file to the service desk ticket or send them it by email.

  3. **IMS will generate the certificate and attach or reply with the required files. Typically these are:

    • the original .csr file (which we don't need other than to check it matches our request)

    • 4 files:

      • 'bcbox.nrs.gov.bc.ca.pem' (the certificate)
      • 'Entrust OV TLS Issuing RSA CA 2.pem' (the CA certificate)
      • 'Sectigo Public Server Authentication Root R46.pem' (part of the CA certificate) - optional
      • 'TrustedRoot.txt' (part of the CA certificate) - optional

      CA names are current as of writing. These may change if Infrastructure & Middle Tier Services changes certificate providers.

  4. Install the new certificate:

    Go to the route configuration in our openshift namespace. eg: https://console.apps.silver.devops.gov.bc.ca/k8s/ns/e7679d-prod/routes/bcbox-nrs-vanity

    Edit the route and paste the contents of the files in the associated fields:

    • Certificate: contents of file 'bcbox.nrs.gov.bc.ca.pem'
    • Key: contents of file 'bcbox.nrs.gov.bc.ca.key' (that you generated locally in step 2)
    • CA certificate: contents of 'Entrust OV TLS Issuing RSA CA 2.pem'

    The site should work immediately after saving these OpenShift settings. A tool to verify is: https://www.ssllabs.com/ssltest/analyze.html?d=bcbox.nrs.gov.bc.ca

⚠️ **GitHub.com Fallback** ⚠️