Re: [XEN PATCH 3/4] automation: Remove expired root certificates used to be used by let's encrypt

2023-02-16 Thread Stefano Stabellini
On Thu, 16 Feb 2023, Anthony PERARD wrote: > On Wed, Feb 15, 2023 at 04:14:53PM -0800, Stefano Stabellini wrote: > > On Wed, 15 Feb 2023, Andrew Cooper wrote: > > > Honestly, I think I'd prefer to drop all of these legacy versions... > > > > Good timing! It just so happens that we need to shave

Re: [XEN PATCH 3/4] automation: Remove expired root certificates used to be used by let's encrypt

2023-02-16 Thread Anthony PERARD
On Wed, Feb 15, 2023 at 04:14:53PM -0800, Stefano Stabellini wrote: > On Wed, 15 Feb 2023, Andrew Cooper wrote: > > Honestly, I think I'd prefer to drop all of these legacy versions... > > Good timing! It just so happens that we need to shave some of the old > container tests as we have too many

Re: [XEN PATCH 3/4] automation: Remove expired root certificates used to be used by let's encrypt

2023-02-15 Thread Stefano Stabellini
On Wed, 15 Feb 2023, Andrew Cooper wrote: > On 15/02/2023 12:02 pm, Anthony PERARD wrote: > > While the Let's Encrypt root certificate ISRG_Root_X1.crt is already > > present, openssl seems to still check for the root certificate > > DST_Root_CA_X3.crt which has expired. This prevent https

Re: [XEN PATCH 3/4] automation: Remove expired root certificates used to be used by let's encrypt

2023-02-15 Thread Andrew Cooper
On 15/02/2023 12:02 pm, Anthony PERARD wrote: > While the Let's Encrypt root certificate ISRG_Root_X1.crt is already > present, openssl seems to still check for the root certificate > DST_Root_CA_X3.crt which has expired. This prevent https connections. > > Removing DST_Root_CA_X3 fix the issue. >

[XEN PATCH 3/4] automation: Remove expired root certificates used to be used by let's encrypt

2023-02-15 Thread Anthony PERARD
While the Let's Encrypt root certificate ISRG_Root_X1.crt is already present, openssl seems to still check for the root certificate DST_Root_CA_X3.crt which has expired. This prevent https connections. Removing DST_Root_CA_X3 fix the issue. centos: found the filter by looking for "DST Root" in