Bug 5654

Summary: certificate expired
Product: Infrastructure Reporter: gmgunter
Component: MirrorsAssignee: Adrian Reber <adrian>
Status: RESOLVED FIXED    
Severity: major CC: casper, ferdnyc, jadijadi, kwizart, nigel.jewell, sincorchetes
Priority: P1    
Version: NA   
Hardware: All   
OS: GNU/Linux   
namespace:

Description gmgunter 2020-05-23 10:36:00 CEST
https://mirrors.rpmfusion.org/metalink?repo=nonfree-fedora-updates-testing-31&arch=x86_64

The certificate for mirrors.rpmfusion.org expired on 5/23/2020, 12:44:47 AM (Pacific Daylight Time).

Workaround: was able to dnf update system through use of flux capacitor set to yesterday.
Comment 1 Nicolas Chauvet 2020-05-23 10:57:08 CEST
*** Bug 5655 has been marked as a duplicate of this bug. ***
Comment 2 Nicolas Chauvet 2020-05-23 11:15:26 CEST
*** Bug 5656 has been marked as a duplicate of this bug. ***
Comment 3 FeRD (Frank Dana) 2020-05-23 12:07:48 CEST
Disclaimer:
I don't know anything about RPM Fusion's web server infrastructure, and won't pretend to. I have no idea what processes or complications might be involved in maintaining and renewing certificates. No doubt they're far more complex than my own needs, which don't extend beyond encrypting traffic in and out of my home network servers, maintained solely for personal access from the outside world.

So, I'm offering this purely as a query, or a suggestion that I fully expect will be rejected as invalid / impractical, for good reasons.

When I finally got off my ass about setting up HTTPS on my servers, thanks primarily to the efforts of the letsencrypt.org project, one of the pleasant surprises for me was the EFF's certbot (https://certbot.eff.org/) auto-renewal tool, which is packaged in Fedora with a systemd timer unit certbot-renew.timer. When activated it'll check twice a day, and renew certificates when they're about 30 days from the end of their 90-day lifetime.

Is auto-renewal a possibility for the RPM Fusion certs?
Comment 4 Nicolas Chauvet 2020-05-23 12:40:14 CEST
The mirrors certs are using round robin dns, unfortunately the server where the certificate have been created and most mirror manager instance are only accessible by the assignee out of the "regular rpmfusion infra"...
Comment 5 Nicolas Chauvet 2020-05-23 14:06:39 CEST
Fixed by now - I will track improvements in the process in rhbz#5657 (private).

Thanks for all reports.