Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove obsolete embedded RootCA bundle #241

Merged
merged 1 commit into from
Nov 19, 2021
Merged

Remove obsolete embedded RootCA bundle #241

merged 1 commit into from
Nov 19, 2021

Conversation

markdascher
Copy link
Contributor

Removes an embedded RootCA bundle that hasn't been necessary for quite a while. All Papertrail syslog endpoints provide full certificate chains that validate in any modern OS.

Even if this bundle was needed for some operating system, the current logic wouldn't be effective because it only kicks in for logs.papertrailapp.com, which only accounts for ~15% of customer port assignments these days. We haven't heard any complaints about the other six destinations, so it's safe to assume they've all been working fine without it.

Tested to confirm that I can still send to various Papertrail destinations afterwards. Also used openssl s_client -showcerts to confirm all of Papertrail's destinations present the same certificate chain.

@markdascher markdascher self-assigned this Nov 19, 2021
@markdascher markdascher merged commit 8d9e5c8 into master Nov 19, 2021
@markdascher markdascher deleted the bye-root-ca branch November 19, 2021 19:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants