Metadata expiry and computing a new expiration time.
Simon Fraser
srf at sanger.ac.uk
Mon Sep 14 06:24:36 EDT 2015
On 14/09/15 11:20, Ian Young wrote:
>
>> On 14 Sep 2015, at 11:02, Ian Young <ian at iay.org.uk> wrote:
>>
>>> On 14 Sep 2015, at 10:01, Simon Fraser <srf at sanger.ac.uk> wrote:
>>>
>>> I've added the verification based on the example in the config file:
>>
>> Not sure why that isn't working (and we should definitely try to get to the bottom of it)
>
> Looking deeper, I note that the example in the config file is for an inline *public key*. What you have in your configuration is an embedded *certificate*. The error you're seeing is the low-level ASN.1 parser trying to parse an encoded public key and failing.
>
> One option would be to go through the effort of extracting the UKf public key from the certificate to use in the way described in the example, but it seems like a lot of work. The UKf recommended configuration I listed in an earlier message is a better approach here.
Ah, I had missed that distinction in what it was looking for. I've used
the snippet you've suggested and it does work.
It's next due for a refresh in a few hours, according to the logs, so we
can see if this was also the cause of the expiry time not updating.
Thank you for your help
Simon.
--
The Wellcome Trust Sanger Institute is operated by Genome Research
Limited, a charity registered in England with number 1021457 and a
company registered in England with number 2742969, whose registered
office is 215 Euston Road, London, NW1 2BE.
More information about the users
mailing list