Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unifi OS removed keytool in v3.1+ and other updates to unifi deploy hook #5095

Open
wants to merge 4 commits into
base: dev
Choose a base branch
from

Conversation

3VAbdAVE
Copy link

Ubiquiti removed keytool from UnifiOS ~v3.1, but still uses a JKS keystore with a self-signed for the console application.
This script probably shouldn't be auto-installing packages on appliances, but this now explains what's up to the user and lets them decide when it fails on a missing keytool.

The Unifi console is not configured to use strong cipher suites required by default letsencrypt RSA certificates, so update the configuration prior to service restart.

In my initial attempts to use this deploy hook, it broke and I had to hunt down original certificates, so backup the existing certificates, which we just assume are working.

Neilpang and others added 3 commits April 1, 2024 11:46
…certificates in case something goes wrong.

Partial fixes in acmesh-official#3359

Comment #1817258702 and others - Unifi removed keytool from OS, which breaks the ability to deploy certificates used by the console. Deciding how to fix is up to the sysadmin, inserted some advice when it fails.

Comment #2061486940 - Automatically set the cipher suites in system configuration.
@Neilpang
Copy link
Member

fix the format errors.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants