Skip to content

feat: probe an app certificate by its fingerprint - #549

Merged
josegonzalez merged 2 commits into
mainfrom
529-probe-certificates-by-fingerprint-instead-of-full-pem
Sep 18, 2026
Merged

josegonzalez merged 2 commits into
mainfrom
529-probe-certificates-by-fingerprint-instead-of-full-pem

Conversation

@josegonzalez

Copy link
Copy Markdown
Member

dokku_certs decided whether the pinned certificate was already installed by reading the whole certificate back with certs:show on every plan, which moved certificate material off the server purely to answer a yes-or-no question, on a command whose other argument hands back the private key. dokku 0.38.28 carries the SHA-256 digest of the installed certificate on certs:report via dokku/dokku#8996, so an app is now settled against a digest taken locally from the pinned PEM and the certificate itself stays where it is. The task's documented dokku floor moves to 0.38.28 with it.

dokku takes that digest with openssl x509 -in server.crt, which reads the leaf and ignores the rest, so a recipe pinning a certificate chain keeps the exact comparison rather than quietly narrowing to its first certificate; a rotated intermediate under an unchanged leaf is still drift. The global certificate keeps it too, since dokku-global-cert computes a fingerprint internally but exposes none on its report. A value that is not a digest, or a dokku that reports none at all, falls back to the same comparison, so nothing converges less well than it did before.

Closes #529

dokku 0.38.28 adds `--ssl-fingerprint` and `--ssl-serial` to `certs:report` via dokku/dokku#8996, which the `dokku_certs` probe reads to compare an installed certificate without transferring it.
`dokku_certs` read the whole certificate back with `certs:show` on every plan to decide whether the pinned one was already installed, moving certificate material off the server purely to answer a yes-or-no question. dokku 0.38.28 carries the SHA-256 digest of the installed certificate on `certs:report`, so an app is now settled against a digest taken locally and the certificate stays where it is. A recipe pinning a certificate chain keeps the exact comparison, since dokku digests only the leaf, and so does the global certificate, whose plugin reports no fingerprint.
@josegonzalez
josegonzalez merged commit 9a27980 into main Sep 18, 2026
19 checks passed
@josegonzalez
josegonzalez deleted the 529-probe-certificates-by-fingerprint-instead-of-full-pem branch September 18, 2026 02:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Probe certificates by fingerprint instead of full PEM

1 participant