Re: Let's Encrypt certificate expiration notice for domain "*.spamassassin.org" (and 1 more)

2020-12-23 Thread Henrik K
On Wed, Dec 23, 2020 at 11:50:16AM -0800, John Hardin wrote:
> On Wed, 23 Dec 2020, Kevin A. McGrail wrote:
> 
> > Henrik wrote on 10/21 that it could be ignored:
> > 
> > > FYI this can be ignored, just some leftover..
> 
> That's what I was referring to. I remembered that comment so I wasn't paying
> attention to the details of the subsequent expiry notices, on 12/3 and
> 12/13.
> 
> > > sa-vm/ruleqa uses *.spamassassin.org cert.
> 
> ...which is the one that the recent notices were about, and which just
> expired. :(

Needed to change /etc/letsencrypt/acme-dns-auth.py to use python3, cert
updated..



Re: Let's Encrypt certificate expiration notice for domain "*.spamassassin.org" (and 1 more)

2020-12-23 Thread John Hardin

On Wed, 23 Dec 2020, Kevin A. McGrail wrote:


Henrik wrote on 10/21 that it could be ignored:


FYI this can be ignored, just some leftover..


That's what I was referring to. I remembered that comment so I wasn't 
paying attention to the details of the subsequent expiry notices, on 12/3 
and 12/13.



sa-vm/ruleqa uses *.spamassassin.org cert.


...which is the one that the recent notices were about, and which just 
expired. :(



Henrik, any guidance appreciated :-)

Regards,
KAM

On 12/23/2020 1:56 PM, John Hardin wrote:

On Sun, 13 Dec 2020, Let's Encrypt Expiry Bot wrote:

Your certificate (or certificates) for the names listed below will expire 
in 10 days (on 23 Dec 20 05:39 +). Please make sure to renew your 
certificate before then, or visitors to your website will encounter 
errors.


*.spamassassin.org
spamassassin.org


ruleqa.spamassassin.org is now throwing expired cert errors:

  ruleqa.spamassassin.org uses an invalid security certificate.
  The certificate expired on 12/22/2020 09:39 PM. The current time
  is 12/23/2020 10:45 AM.

It appears that while we may have been able to ignore the 
ruleqa.spamassassin.org cert warning as Henrik noted, this one is not one 
we can ignore.


Did we fail to set up auto-renewal of this certificate somewhere?



--
 John Hardin KA7OHZhttp://www.impsec.org/~jhardin/
 jhar...@impsec.org pgpk -a jhar...@impsec.org
 key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
---
  "Bother," said Pooh as he struggled with /etc/sendmail.cf, "it never
  does quite what I want. I wish Christopher Robin was here."
   -- Peter da Silva in a.s.r
---
 2 days until Christmas

Re: Let's Encrypt certificate expiration notice for domain "*.spamassassin.org" (and 1 more)

2020-12-23 Thread Kevin A. McGrail

Henrik wrote on 10/21 that it could be ignored:

FYI this can be ignored, just some leftover..  sa-vm/ruleqa uses 
*.spamassassin.org cert.


Henrik, any guidance appreciated :-)

Regards,
KAM

On 12/23/2020 1:56 PM, John Hardin wrote:

On Sun, 13 Dec 2020, Let's Encrypt Expiry Bot wrote:

Your certificate (or certificates) for the names listed below will 
expire in 10 days (on 23 Dec 20 05:39 +). Please make sure to 
renew your certificate before then, or visitors to your website will 
encounter errors.


*.spamassassin.org
spamassassin.org


ruleqa.spamassassin.org is now throwing expired cert errors:

  ruleqa.spamassassin.org uses an invalid security certificate.
  The certificate expired on 12/22/2020 09:39 PM. The current time
  is 12/23/2020 10:45 AM.

It appears that while we may have been able to ignore the 
ruleqa.spamassassin.org cert warning as Henrik noted, this one is not 
one we can ignore.


Did we fail to set up auto-renewal of this certificate somewhere?



--
Kevin A. McGrail
kmcgr...@apache.org

Member, Apache Software Foundation
Chair Emeritus Apache SpamAssassin Project
https://www.linkedin.com/in/kmcgrail - 703.798.0171



Re: Let's Encrypt certificate expiration notice for domain "*.spamassassin.org" (and 1 more)

2020-12-23 Thread John Hardin

On Sun, 13 Dec 2020, Let's Encrypt Expiry Bot wrote:

Your certificate (or certificates) for the names listed below will 
expire in 10 days (on 23 Dec 20 05:39 +). Please make sure to renew 
your certificate before then, or visitors to your website will encounter 
errors.


*.spamassassin.org
spamassassin.org


ruleqa.spamassassin.org is now throwing expired cert errors:

  ruleqa.spamassassin.org uses an invalid security certificate.
  The certificate expired on 12/22/2020 09:39 PM. The current time
  is 12/23/2020 10:45 AM.

It appears that while we may have been able to ignore the 
ruleqa.spamassassin.org cert warning as Henrik noted, this one is not one 
we can ignore.


Did we fail to set up auto-renewal of this certificate somewhere?


--
 John Hardin KA7OHZhttp://www.impsec.org/~jhardin/
 jhar...@impsec.org pgpk -a jhar...@impsec.org
 key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
---
  "Bother," said Pooh as he struggled with /etc/sendmail.cf, "it never
  does quite what I want. I wish Christopher Robin was here."
   -- Peter da Silva in a.s.r
---
 2 days until Christmas