Renew expired TLS test certificates - #972
Merged
Merged
Conversation
The server and client leaf certs in nats-core and nats expired on 2026-06-03, breaking every TLS and WebSocket test. Re-sign both with the existing CA and keys, preserving subjects, SANs, and key usage, and extend validity to 2035 (within the CA window) so this stops recurring annually.
|
Claude finished @caspervonb's task in 2m 1s —— View job PR Review: Renew expired TLS test certificates
This PR is a clean, minimal certificate renewal. Here's what I verified from the diff and the unchanged CA cert:
The new leaf certs expire 2035-03-09, ~84 days before the CA expires (2035-06-01) — well within the CA's validity window. No issues found. |
caspervonb
marked this pull request as ready for review
June 4, 2026 12:01
wallyqs
approved these changes
Jun 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The server and client leaf certificates in
nats-core/tests/certsandnats/tests/certsexpired on 2026-06-03, so every TLS and WebSocket test fails withcertificate verify failed: certificate has expired.Re-signed both leaf certs with the existing CA and private keys, preserving the subjects, SANs (
DNS:localhost,IP:127.0.0.1), and key usage. Validity now runs to 2035 (within the CA's window) instead of one year, so this stops recurring annually.Supersedes #971, which was accidentally merged into the #970 branch instead of
main.