South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.




Simply astounding that a major bank can mess this up. Is their dev/testing department asleep?
Sure, you want to automate as much as you can.Certs are one of those issues that sneak up on you from nowhere if you don't specifically make a point of monitoring it and even then if your communication between departments isn't perfect they sometimes still sneak through. We wrote a lambda that crawls our cloud services looking for domains with SSL and verifies their certs and alerts if it finds any that are about to expire. Having humans do that was not as reliable for us.
Sure, you want to automate as much as you can.
I'm quite happy I don't need to deal with shitty certs that often - only one manually this year.
Letsencrypt has removed a lot of pain points for that in my life.
USB GPS + GPSD for the win?We are also a Letsencrypt fan but even they fail. For instance we recently had a client block NTP ports on an on premise edge node and the time drifted enough for Letsencrypt to refuse renewal. We have redundant failover so there wouldn't have been downtime but detecting an issue early saved us money and scrambling to rectify the issue.