Skip to content

Conversation

@Technoguyfication
Copy link
Contributor

@Technoguyfication Technoguyfication commented Jun 8, 2021

Proposed Changes

The current CA certificate used to trust InfluxCloud servers is DST Root CA X3, this expires September 30th 2021. This change replaces it with the certificate's successor, ISRG Root X1. You can read more about the certificate update here.

Checklist

  • CHANGELOG.md updated
  • Rebased/mergeable
  • Commit messages are in semantic format

@vlastahajek
Copy link
Collaborator

@Technoguyfication, thank you for the update of the certificate and readme!

InfluxData has 3 provides for InfluxDBCloud: AWS, Azure, GCP.
This new CA certificate works OK for AWS and Azure, but doesn't work for GCP:

BSSL:_connectSSL: start connection
BSSL:_wait_for_handshake: failed
BSSL:Couldn't connect. Error = 'Chain could not be linked to a trust anchor.'

I checked AWS and GPC , but I don't understand how the AWS certificate is linked to the ISRG Root X1 CA and why the GCP fails.

@vlastahajek
Copy link
Collaborator

After giving some time to people maintaining InfluxDB Clouds to update certificates, the new CA certificate is now working for all providers 👍.

@vlastahajek vlastahajek merged commit 8025084 into tobiasschuerg:master Sep 3, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants