Add certificate signing request for stackiq (renamed from softwarecatalog) - #1207
Conversation
mgallien
left a comment
There was a problem hiding this comment.
I would need you to also remove the certificate signing request from the old name in each PR
I would also need a confirmation by the original github account that requested the certificate that this is legitimate (I also understand that this is coming from ConductionNL)
can you also please fix the failing DCO check ?
For more information, have a look at the failing DCO CI check from the PR
see also our documentation here https://nextcloudappstore.readthedocs.io/en/latest/developer.html#obtaining-a-certificate
setting the PR as needing changes for easier overview
…alog) The app id was renamed from softwarecatalog to stackiq. This adds the CSR for the new id and removes the now-obsolete CSR for softwarecatalog. Signed-off-by: Ruben van der Linde <rubenvdlinde@gmail.com>
67a5bdf to
ffa7c6d
Compare
|
@rjzondervan could you please confirm this one? This PR is part of the ConductionNL fleet rename: the app id @mgallien I have addressed the other two points of your review:
|
|
Confirmed, I requested the original softwarecatalog certificate; the rename to stackiq and the removal of the old CSR are legitimate. |
|
Ownership of these apps should sit with our corporate app store account One additional point while this batch is being processed, relevant to all 13 PRs. These are corporate applications built and maintained by Conduction, not personal side projects. Today the app store entries are owned by individual accounts (
So our request is: when the certificates for the new ids are generated, please have the app store entries owned by
The corresponding old ids to be retired are If anything is needed from our side to make that transfer possible, such as a confirmation from each of the current owner accounts or a different procedure entirely, please let us know and we will arrange it. |
|
@MWest2020 could you please confirm this one as well? This is part of the same ConductionNL fleet rename batch: the app id For completeness on the other half of the request: this PR already removes |
|
@rjzondervan could you please confirm this one? This PR is part of the ConductionNL fleet rename: the app id A short comment here confirming that the rename to For context on where this batch stands: the old-name CSR removal @mgallien asked for is done on every PR that has a predecessor, and CI is green on all thirteen. @MWest2020 has confirmed all five of the apps they originally requested (#1204, #1205, #1206, #1208, #1209). These five are the remaining ones, and they are all yours:
Confirming all five in one pass would unblock the whole batch. |
|
@mgallien this is absolutely legit. Ruben is the owner of the Conduction company. I did the certification signing requests for the first two years. |
Signed-off-by: Matthieu Gallien <matthieu.gallien@nextcloud.com>
|
@rubenvdlinde you can find the new certificate here ef46653 |
Hello, and thank you for looking after this repository. We know certificate requests are steady background work, and we are grateful for your time.
We are Conduction B.V. We build open source Nextcloud apps for Dutch public sector organisations, all EUPL-1.2.
Why we are asking
We renamed thirteen of our apps and we are taking them to production. We would like them signed and installable in time for the Nextcloud Conference in Berlin.
softwarecatalogis nowstackiq.Nextcloud checks that a certificate's CN matches the app id. Our
softwarecatalogcertificate cannot signstackiq. So this is a new CSR rather than a reuse.We would rather ask for a new certificate than keep signing with the old one. Signing does not check the CN, so a mismatched certificate produces a release that looks fine and fails
occ integrity:check-appon the administrator's side. We would like to stop shipping that.The old App Store entry
softwarecatalogis still published on the App Store. It is superseded now, and we would like it taken down so there are not two entries for one app. We are happy to do that ourselves if there is a self-service route. If you would rather handle it, please tell us what you need from us.The rest of the set
Thirteen apps are moving together. We opened one PR each, following the convention here:
openconnectorbecomesintegriqdocudeskbecomesfilinqprocestbecomesdossiqsoftwarecatalogbecomesstackiq← this onelarpingappbecomeslarpinqnldesignbecomesthematiqscholiqbecomeslearniqdecideskbecomesdecidiqopenbuildbecomesbuildiqdoriathbecomeskeepiqhrmqbecomeshumaniqapp_versionsbecomesversioniqplanixbecomesplanninqWe are glad to combine them into one PR if that is less work for you.
What we need
If the CSR is in order, merging it is everything we need from you. If anything should be split, renamed or resubmitted, tell us. We will send it the way you prefer.