Decide the certificate policy for direct administration endpoints #5

Open
opened 2026-08-23 17:07:47 +00:00 by stanta · 0 comments
Owner

Outcome

Decide whether FreeIPA and other direct administration endpoints need public CA certificates outside Traefik.

Current state

Traefik already obtains public certificates through restricted Knot RFC 2136 updates. Direct endpoints retain their current certificate ownership.

Work

  • Inventory direct TLS endpoints and their clients.
  • Record whether each endpoint needs a public CA certificate.
  • If required, define issuance, key ownership, renewal, reload, monitoring, and rollback.
  • Test renewal before replacing a working certificate.

Validation

  • Every direct endpoint has a recorded certificate policy.
  • Any implemented renewal passes a controlled test.

References

  • iac/guides/roadmap-phase-2.md
  • iac/ansible/roles/freeipa/
## Outcome Decide whether FreeIPA and other direct administration endpoints need public CA certificates outside Traefik. ## Current state Traefik already obtains public certificates through restricted Knot RFC 2136 updates. Direct endpoints retain their current certificate ownership. ## Work - [ ] Inventory direct TLS endpoints and their clients. - [ ] Record whether each endpoint needs a public CA certificate. - [ ] If required, define issuance, key ownership, renewal, reload, monitoring, and rollback. - [ ] Test renewal before replacing a working certificate. ## Validation - [ ] Every direct endpoint has a recorded certificate policy. - [ ] Any implemented renewal passes a controlled test. ## References - `iac/guides/roadmap-phase-2.md` - `iac/ansible/roles/freeipa/`
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
stanta/homelab#5
No description provided.