SSL Renewal - bcgov/common-service-showcase GitHub Wiki
- Create a service desk ticket with CITZ Identity Management Solutions CITZ:EX - [email protected]:
https://citz-imb.atlassian.net/servicedesk/customer/portal/5/group/286/create/135
-
Generate a Certificate Signing Request (CSR) and Key using openssl cli on your workstation.
Using BCBox as an example, run the following command:openssl req -new -newkey rsa:2048 -nodes -out bcbox.nrs.gov.bc.ca.csr -keyout bcbox.nrs.gov.bc.ca.key -subj "/C=CA/ST=British Columbia/L=Victoria/O=Government of the Province of British Columbia/OU=Ministry of Water Land and Resource Stewardship/CN=bcbox.nrs.gov.bc.ca"This will create the
.csrand.keyfiles in the current directory.Note:
opensslis bundled with the git cli. if you get errors when you run the command due to escaping of backslashes you can try appending the subject param like//C=CA/C=CA/ST=British Columbia... -
Attach the
.csrfile to the service desk ticket or send them it by email. -
**IMS will generate the certificate and attach or reply with the required files. Typically these are:
-
the original .csr file (which we don't need other than to check it matches our request)
-
4 files:
- 'bcbox.nrs.gov.bc.ca.pem' (the certificate)
- 'Entrust OV TLS Issuing RSA CA 2.pem' (the CA certificate)
- 'Sectigo Public Server Authentication Root R46.pem' (part of the CA certificate) - optional
- 'TrustedRoot.txt' (part of the CA certificate) - optional
CA names are current as of writing. These may change if Infrastructure & Middle Tier Services changes certificate providers.
-
-
Install the new certificate:
Go to the route configuration in our openshift namespace. eg: https://console.apps.silver.devops.gov.bc.ca/k8s/ns/e7679d-prod/routes/bcbox-nrs-vanity
Edit the route and paste the contents of the files in the associated fields:
- Certificate: contents of file 'bcbox.nrs.gov.bc.ca.pem'
- Key: contents of file 'bcbox.nrs.gov.bc.ca.key' (that you generated locally in step 2)
- CA certificate: contents of 'Entrust OV TLS Issuing RSA CA 2.pem'
The site should work immediately after saving these OpenShift settings. A tool to verify is: https://www.ssllabs.com/ssltest/analyze.html?d=bcbox.nrs.gov.bc.ca