Skip to content

Nexus - KL gateway - certs 2026#100

Open
LindaLawton wants to merge 1 commit intotrifork:mainfrom
LindaLawton:main
Open

Nexus - KL gateway - certs 2026#100
LindaLawton wants to merge 1 commit intotrifork:mainfrom
LindaLawton:main

Conversation

@LindaLawton
Copy link
Copy Markdown

new certs for KL gateway old certs expire 26/04/201

we need these added ASAP please.

new certs for KL gateway old certs expire 26/04/2016
@ohetrifork
Copy link
Copy Markdown
Contributor

Hi @LindaLawton
I may find time to do it later this afternoon. Would you prefer to have new clientIds (such that both old and new certificates can be used simultaneously) or re-use the existing clientIds?

@LindaLawton
Copy link
Copy Markdown
Author

If you can leave both that would be wonderful.

It will mean i dont have to time our server restart with you adding it.

I really appreciate you having time to do it today

Linda

@ohetrifork
Copy link
Copy Markdown
Contributor

👍 I'll keep you updated on this issue

@ohetrifork
Copy link
Copy Markdown
Contributor

@LindaLawton
It seems that the TEST and PROD certificates are identical... that doesn't sound right to me?

@LindaLawton
Copy link
Copy Markdown
Author

As far as i can see the test and prod ones where identical before.

This is not a "kamp" i can take up right now
.

It may be something for another day.

@ohetrifork
Copy link
Copy Markdown
Contributor

ohetrifork commented Apr 23, 2026

@LindaLawton
The public keys I currently see registered for test do not match any of the public keys for production, so I don't see any issue there. However, we can't whitelist the same public key for test as for production, because this allows you to sent production data to the test environment.
I will continue with whitelisting your production public key, but I will have to request another public key from you for the test environment.

Decoding the test certificate, I see this:
Common Name: NEXUS KL Gateway PROD

@ohetrifork
Copy link
Copy Markdown
Contributor

ohetrifork commented Apr 23, 2026

Can you confirm that your current production clientId is "kmd-nexus-prod-2023-06"?

(that is the one I'll be updating, unless noticed otherwise)

@LindaLawton
Copy link
Copy Markdown
Author

Not sure how to verify that the current one is in Azure secret and i dont have access to see it let me see if someone in the cloud security can tall me

Leave test for now we can deal with that after we Are sure production is working

@LindaLawton
Copy link
Copy Markdown
Author

Yes thats the client id

@ohetrifork
Copy link
Copy Markdown
Contributor

I have reserved a service window at 14-15 today to replace the current public key. I will give notice here when it has been completed.

@ohetrifork
Copy link
Copy Markdown
Contributor

ohetrifork commented Apr 23, 2026

The PROD public key has been replaced now.
I will keep this PR open until the test certificate part has been clarified.

@ohetrifork
Copy link
Copy Markdown
Contributor

I see lots of reports coming in tp PROD001 since yesterday, so the certificate change looks successful 👍

@LindaLawton
Copy link
Copy Markdown
Author

Thank you for making time for this.

I havent heard anything from our side. Im going to send a few messages to be 100% sure

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants