Skip to content

Commit

Permalink
Merge pull request #44 from hic-infra/ca-fix
Browse files Browse the repository at this point in the history
CA Certificate Fix
  • Loading branch information
AaronJackson authored Aug 23, 2024
2 parents 4e82972 + 2854eae commit 0c44934
Show file tree
Hide file tree
Showing 2 changed files with 95 additions and 63 deletions.
71 changes: 39 additions & 32 deletions modules/hic-tre-cert.ps1
Original file line number Diff line number Diff line change
@@ -1,38 +1,45 @@
# Install the HIC CA certificate
@"
-----BEGIN CERTIFICATE-----
MIIFhzCCA2+gAwIBAgIUGkv4GNM1HgQ9SYiUkSFuQ8GOg+UwDQYJKoZIhvcNAQEF
BQAwbDELMAkGA1UEBhMCR0IxPjA8BgNVBAoMNUhlYWx0aCBJbmZvcm1hdGljcyBD
ZW50cmUgKEhJQyksIFVuaXZlcnNpdHkgb2YgRHVuZGVlMR0wGwYDVQQDDBRoaWMt
dHJlLmR1bmRlZS5hYy51azAeFw0yNDA4MDYxMjI0MzFaFw0zNDA4MDQxMjI0MzFa
MGwxCzAJBgNVBAYTAkdCMT4wPAYDVQQKDDVIZWFsdGggSW5mb3JtYXRpY3MgQ2Vu
dHJlIChISUMpLCBVbml2ZXJzaXR5IG9mIER1bmRlZTEdMBsGA1UEAwwUaGljLXRy
ZS5kdW5kZWUuYWMudWswggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCz
64v2cNSAC8IvzMzzGT7n2CcsdO9u2iZkJYIVWoR/sYo+ScPn5DUWILMPUc8gTOQh
fOoOk8SBS2zoUSoIr1Z6hNqkkar6YvkZgqA9hs7AmKC7SxQPCQMHDndAKKy/PmR5
FbSKmZV+6KStEmcNCJ6hWqiP3rRV9wjGfS+wsUe52lHIbIlQSb3KPZ+7wXr/Rwby
D2eb+RAVszNX06nFTHPx44CTftxTW4BTB9hgpfcn8GYIkNPTj1A3lifYJ1Y1MC2j
R7ZUCSx6kum9TBj/zXztQejvxw7JrYbf0BX1iXQ88W74r4OnLB+xP9h1OEhMZ5hQ
+4dq4xngcI11B7VRf0QDcoAPt9u0b/CNKj4nXWR+7MNSoOR5dYt0GneMqwqA7MLY
vw+Al7N2IOmG0BgIOz25ZIEiL4VTDHZuwEsLuvr0kVbPygZGeLDrSj5k7GrLzILO
ei/dGt7lrK92NzGEJDv3x72cLvwthHMLefVE+nFJLJnQuVhuoi7L2c4oxsSuE9nJ
M3TpZ3pJIIiksghlrKDey5Bfkr/yOpNIWz53oKGXBT4JgihagBxfvILIjPVhE/5q
zt3Wic8UiIgSmHnh1BSMwhd/yPAfIUVsYUEURFyebmcN33VSzUP8qO5tycOuAYDX
qg4MHgjLchvlbE71mN1+SHA/w7aok40ujvRxIEVbDQIDAQABoyEwHzAdBgNVHQ4E
FgQUQVp7Aq/wQN19Ax32zbaH4VrJlJQwDQYJKoZIhvcNAQEFBQADggIBAFw/TQOy
LM2dXTpBJ0hPwpjwaDNHlGkI4KWuIIZANlnAcxRTNiRhm3Km8HUo2tat6dq/Y+6p
Td329tYzHsMYkECfuvjWDsVlfqFHalxlPEPgmo2cuKIgNi3sGMK9Eh3NwHFxH/5W
h8q6gis+5wSzJ23jEMaEl3p/wkvaZnazDePq66Wi5LNeXiD1vsTXedfsg+FynhDr
SqLOftAem/d5eNP1QWHUAcLHYdmzeZ9xSuTlNcv0/EqqG4NAf5qc4C9O1uvIm8kR
koJQIUs7sBOFaY1OzYnnaF96OYBbvfeoqYkMYbSKqYpmaKRgRffwajkjaGxZwcNs
FzlvfAKi3SDN4ryhIMb4uCRfUwzOXQ0Kx3TNitTrLGI7dI10al6ZcjNIURJTRhrl
eFrVvY2Vhrt5yxHaKf6Po/Sts+/D0P6C/UxdKyyxOVH/auju2xX4ETvR7Qm5g0Er
9N/EmmP5xDCv6QdS+YQk8K39aUvtK30LafCofBNcN91bpEiWKEGBZJfsrsJYwoan
TaVEtXbOrFKFgzFeVOFfycfSahb85bdWy3Fpnj4UWc5rPrIM0bl2bAH6ZgtmqYaq
3vMj23QxEFtXi10HnVuPU4fXoIdurGiktpsi+bkAvED7pm8T64Fiky8HPF5okuof
Y0yM9+mo8F2AD8Y/LGuxWBsxTK317zfQiRLc
MIIG0jCCBLqgAwIBAgIUSG5U78ew7zWqsiFJSPbTeJwhdHcwDQYJKoZIhvcNAQEF
BQAwgZMxCzAJBgNVBAYTAkdCMT4wPAYDVQQKDDVIZWFsdGggSW5mb3JtYXRpY3Mg
Q2VudHJlIChISUMpLCBVbml2ZXJzaXR5IG9mIER1bmRlZTEdMBsGA1UEAwwUaGlj
LXRyZS5kdW5kZWUuYWMudWsxJTAjBgkqhkiG9w0BCQEWFmhpYy1pbmZyYUBkdW5k
ZWUuYWMudWswHhcNMjQwODA3MDk1MDE3WhcNMzQwODA1MDk1MDE3WjCBkzELMAkG
A1UEBhMCR0IxPjA8BgNVBAoMNUhlYWx0aCBJbmZvcm1hdGljcyBDZW50cmUgKEhJ
QyksIFVuaXZlcnNpdHkgb2YgRHVuZGVlMR0wGwYDVQQDDBRoaWMtdHJlLmR1bmRl
ZS5hYy51azElMCMGCSqGSIb3DQEJARYWaGljLWluZnJhQGR1bmRlZS5hYy51azCC
AiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAKxxRuVIzKkAMy9VlW4nBm5d
aqiMIn4+cF7fVxFN0vM4UGSB6WQ+xJ8MaIMtLzDkcC4sagB67WUjVhrLzY4Wv1Tj
vNMIPhg8PUfOFiV9Ff+vB4KN2J1dIHSSib1NuO/Wvr13prc0G02uVDPGEhJKcd8d
C2HUC9xyRFUC45KtpRqjYzBBSBmpLnGHO8qhQKLnN/Y6lbYuGqqEPVCrt1nL9TYy
CwNk67XXd9KtZgFmsNbmVpYOVpiMzowEyZGatil75v3IvcinLqH0mgpVUreINGUY
aDbGLLv0lLXEktihYau27D5PhKjqjIiMtYSf/PsLdmuUdzQ0D0VRctBCupWqqiUX
JgDHCVQ4aupcz03k15pciV3nkBSVcN7MyhbWWbX3fwPIHP8udRAlTB+tvqJi82r5
PhfyBdZ+/0JmsHUA/SJOXvTWqlaPVitUnTpxK5rUccZVKxaLPd8ZmTGYS3KSx/1m
InbGPLJtfnlhaT3LoVFng7jNwgQlMeOFruhKVvnb96uw5M5lva4uPNmjD7cFN185
H+t2wE2EWdYWcx9X1i63DuXE+t9b0bz8mXEeB8R3KX7fRXjMj2KqUCgEjZNJxBh3
ABeZDif/cg3v54ycpgH+/147N7/oBPykuhPgfHsfpbq+riMvtm8ire8oBXyk/aWI
huIlXWSZF2LQ7i/GsRX5AgMBAAGjggEaMIIBFjAPBgNVHRMBAf8EBTADAQH/MB0G
A1UdDgQWBBRrrQ5I7/TGnNetJktvWUTV7nDMDDCB0wYDVR0jBIHLMIHIgBRrrQ5I
7/TGnNetJktvWUTV7nDMDKGBmaSBljCBkzELMAkGA1UEBhMCR0IxPjA8BgNVBAoM
NUhlYWx0aCBJbmZvcm1hdGljcyBDZW50cmUgKEhJQyksIFVuaXZlcnNpdHkgb2Yg
RHVuZGVlMR0wGwYDVQQDDBRoaWMtdHJlLmR1bmRlZS5hYy51azElMCMGCSqGSIb3
DQEJARYWaGljLWluZnJhQGR1bmRlZS5hYy51a4IUSG5U78ew7zWqsiFJSPbTeJwh
dHcwDgYDVR0PAQH/BAQDAgGGMA0GCSqGSIb3DQEBBQUAA4ICAQAsRo15QQbLyaIv
w3B7x5HHDdTkMYJ3SbGWasOaYn6GmoH1borKFeITa/LkhIviLmxodcswWSBxVy0G
HtJuDipPwG0thi2FxuydgNGIsRL5nq2ctMJQ++klrpOCANGVQLHfqz68xvqR+19e
MEApWppAvg68FoXREIKO+SRma7FrTif1rGrWXxHJcDUlgjKoNFzCbFAK4nb5ueFn
D5MHfYg4QWo5Tq//kBuWNLV/4Dtdwyp3OWOeFBXqkjYS4JKLrgUgyqCmlI8Tn7gv
CjTlAj8uWrOpc170MaU+FuV2/PyrXOF0izFc1UIZ0A5mP1HKNqU9P40Kmk9Ova2C
BOoiKXVJQgUffvTPZSiWhDDXwGPYrGcbz2WuEeZIZxQ0xQajMkPrtxRtKh66w6Nk
yIR9SdOE4swSortTixwqBCp7MXNvMuJ/lsudan1ITt+guVe4BfZqLxEfpQy3VxX9
oQSmSa3K8S0+/7jNK2gRl1o11PtcsBIi7nHUVUE1IrWkH3x0XE+e+VkSQ8IyNgg/
zvyXRCnDutC2I48pjubDIKtp2crIOMdsmtBVCQq6gX1Sl/4z4E6BXEWkfVcSBk+O
05i6skiAX2QQcqX+EC/9HQ8UEjKIGeXyR2SxAiACx+1ckj9MHG8nytRAJQ2glmLs
ws7bgq7KAqJqvvPyVIeOW0hx4AX+5Q==
-----END CERTIFICATE-----
"@ | Out-File -FilePath C:\workdir\hic-tre.dundee.ac.uk.crt
"@ | Out-File -FilePath C:\Tools\hic-tre.dundee.ac.uk.crt

Get-Item C:\workdir\hic-tre.dundee.ac.uk.crt | `
Get-Item C:\Tools\hic-tre.dundee.ac.uk.crt | `
Import-Certificate -CertStoreLocation Cert:\LocalMachine\Root
87 changes: 56 additions & 31 deletions modules/hic-tre-cert.sh
Original file line number Diff line number Diff line change
@@ -1,37 +1,62 @@
#!/bin/bash

# Install HIC CA certificate
sudo tee /usr/local/share/ca-certificates/hic-tre.crt <<EOF
sudo mkdir -p /usr/local/share/ca-certificates/hic
sudo chmod 755 /usr/local/share/ca-certificates/hic
sudo tee /usr/local/share/ca-certificates/hic/hic-tre.crt <<EOF
-----BEGIN CERTIFICATE-----
MIIFhzCCA2+gAwIBAgIUGkv4GNM1HgQ9SYiUkSFuQ8GOg+UwDQYJKoZIhvcNAQEF
BQAwbDELMAkGA1UEBhMCR0IxPjA8BgNVBAoMNUhlYWx0aCBJbmZvcm1hdGljcyBD
ZW50cmUgKEhJQyksIFVuaXZlcnNpdHkgb2YgRHVuZGVlMR0wGwYDVQQDDBRoaWMt
dHJlLmR1bmRlZS5hYy51azAeFw0yNDA4MDYxMjI0MzFaFw0zNDA4MDQxMjI0MzFa
MGwxCzAJBgNVBAYTAkdCMT4wPAYDVQQKDDVIZWFsdGggSW5mb3JtYXRpY3MgQ2Vu
dHJlIChISUMpLCBVbml2ZXJzaXR5IG9mIER1bmRlZTEdMBsGA1UEAwwUaGljLXRy
ZS5kdW5kZWUuYWMudWswggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCz
64v2cNSAC8IvzMzzGT7n2CcsdO9u2iZkJYIVWoR/sYo+ScPn5DUWILMPUc8gTOQh
fOoOk8SBS2zoUSoIr1Z6hNqkkar6YvkZgqA9hs7AmKC7SxQPCQMHDndAKKy/PmR5
FbSKmZV+6KStEmcNCJ6hWqiP3rRV9wjGfS+wsUe52lHIbIlQSb3KPZ+7wXr/Rwby
D2eb+RAVszNX06nFTHPx44CTftxTW4BTB9hgpfcn8GYIkNPTj1A3lifYJ1Y1MC2j
R7ZUCSx6kum9TBj/zXztQejvxw7JrYbf0BX1iXQ88W74r4OnLB+xP9h1OEhMZ5hQ
+4dq4xngcI11B7VRf0QDcoAPt9u0b/CNKj4nXWR+7MNSoOR5dYt0GneMqwqA7MLY
vw+Al7N2IOmG0BgIOz25ZIEiL4VTDHZuwEsLuvr0kVbPygZGeLDrSj5k7GrLzILO
ei/dGt7lrK92NzGEJDv3x72cLvwthHMLefVE+nFJLJnQuVhuoi7L2c4oxsSuE9nJ
M3TpZ3pJIIiksghlrKDey5Bfkr/yOpNIWz53oKGXBT4JgihagBxfvILIjPVhE/5q
zt3Wic8UiIgSmHnh1BSMwhd/yPAfIUVsYUEURFyebmcN33VSzUP8qO5tycOuAYDX
qg4MHgjLchvlbE71mN1+SHA/w7aok40ujvRxIEVbDQIDAQABoyEwHzAdBgNVHQ4E
FgQUQVp7Aq/wQN19Ax32zbaH4VrJlJQwDQYJKoZIhvcNAQEFBQADggIBAFw/TQOy
LM2dXTpBJ0hPwpjwaDNHlGkI4KWuIIZANlnAcxRTNiRhm3Km8HUo2tat6dq/Y+6p
Td329tYzHsMYkECfuvjWDsVlfqFHalxlPEPgmo2cuKIgNi3sGMK9Eh3NwHFxH/5W
h8q6gis+5wSzJ23jEMaEl3p/wkvaZnazDePq66Wi5LNeXiD1vsTXedfsg+FynhDr
SqLOftAem/d5eNP1QWHUAcLHYdmzeZ9xSuTlNcv0/EqqG4NAf5qc4C9O1uvIm8kR
koJQIUs7sBOFaY1OzYnnaF96OYBbvfeoqYkMYbSKqYpmaKRgRffwajkjaGxZwcNs
FzlvfAKi3SDN4ryhIMb4uCRfUwzOXQ0Kx3TNitTrLGI7dI10al6ZcjNIURJTRhrl
eFrVvY2Vhrt5yxHaKf6Po/Sts+/D0P6C/UxdKyyxOVH/auju2xX4ETvR7Qm5g0Er
9N/EmmP5xDCv6QdS+YQk8K39aUvtK30LafCofBNcN91bpEiWKEGBZJfsrsJYwoan
TaVEtXbOrFKFgzFeVOFfycfSahb85bdWy3Fpnj4UWc5rPrIM0bl2bAH6ZgtmqYaq
3vMj23QxEFtXi10HnVuPU4fXoIdurGiktpsi+bkAvED7pm8T64Fiky8HPF5okuof
Y0yM9+mo8F2AD8Y/LGuxWBsxTK317zfQiRLc
MIIG0jCCBLqgAwIBAgIUSG5U78ew7zWqsiFJSPbTeJwhdHcwDQYJKoZIhvcNAQEF
BQAwgZMxCzAJBgNVBAYTAkdCMT4wPAYDVQQKDDVIZWFsdGggSW5mb3JtYXRpY3Mg
Q2VudHJlIChISUMpLCBVbml2ZXJzaXR5IG9mIER1bmRlZTEdMBsGA1UEAwwUaGlj
LXRyZS5kdW5kZWUuYWMudWsxJTAjBgkqhkiG9w0BCQEWFmhpYy1pbmZyYUBkdW5k
ZWUuYWMudWswHhcNMjQwODA3MDk1MDE3WhcNMzQwODA1MDk1MDE3WjCBkzELMAkG
A1UEBhMCR0IxPjA8BgNVBAoMNUhlYWx0aCBJbmZvcm1hdGljcyBDZW50cmUgKEhJ
QyksIFVuaXZlcnNpdHkgb2YgRHVuZGVlMR0wGwYDVQQDDBRoaWMtdHJlLmR1bmRl
ZS5hYy51azElMCMGCSqGSIb3DQEJARYWaGljLWluZnJhQGR1bmRlZS5hYy51azCC
AiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAKxxRuVIzKkAMy9VlW4nBm5d
aqiMIn4+cF7fVxFN0vM4UGSB6WQ+xJ8MaIMtLzDkcC4sagB67WUjVhrLzY4Wv1Tj
vNMIPhg8PUfOFiV9Ff+vB4KN2J1dIHSSib1NuO/Wvr13prc0G02uVDPGEhJKcd8d
C2HUC9xyRFUC45KtpRqjYzBBSBmpLnGHO8qhQKLnN/Y6lbYuGqqEPVCrt1nL9TYy
CwNk67XXd9KtZgFmsNbmVpYOVpiMzowEyZGatil75v3IvcinLqH0mgpVUreINGUY
aDbGLLv0lLXEktihYau27D5PhKjqjIiMtYSf/PsLdmuUdzQ0D0VRctBCupWqqiUX
JgDHCVQ4aupcz03k15pciV3nkBSVcN7MyhbWWbX3fwPIHP8udRAlTB+tvqJi82r5
PhfyBdZ+/0JmsHUA/SJOXvTWqlaPVitUnTpxK5rUccZVKxaLPd8ZmTGYS3KSx/1m
InbGPLJtfnlhaT3LoVFng7jNwgQlMeOFruhKVvnb96uw5M5lva4uPNmjD7cFN185
H+t2wE2EWdYWcx9X1i63DuXE+t9b0bz8mXEeB8R3KX7fRXjMj2KqUCgEjZNJxBh3
ABeZDif/cg3v54ycpgH+/147N7/oBPykuhPgfHsfpbq+riMvtm8ire8oBXyk/aWI
huIlXWSZF2LQ7i/GsRX5AgMBAAGjggEaMIIBFjAPBgNVHRMBAf8EBTADAQH/MB0G
A1UdDgQWBBRrrQ5I7/TGnNetJktvWUTV7nDMDDCB0wYDVR0jBIHLMIHIgBRrrQ5I
7/TGnNetJktvWUTV7nDMDKGBmaSBljCBkzELMAkGA1UEBhMCR0IxPjA8BgNVBAoM
NUhlYWx0aCBJbmZvcm1hdGljcyBDZW50cmUgKEhJQyksIFVuaXZlcnNpdHkgb2Yg
RHVuZGVlMR0wGwYDVQQDDBRoaWMtdHJlLmR1bmRlZS5hYy51azElMCMGCSqGSIb3
DQEJARYWaGljLWluZnJhQGR1bmRlZS5hYy51a4IUSG5U78ew7zWqsiFJSPbTeJwh
dHcwDgYDVR0PAQH/BAQDAgGGMA0GCSqGSIb3DQEBBQUAA4ICAQAsRo15QQbLyaIv
w3B7x5HHDdTkMYJ3SbGWasOaYn6GmoH1borKFeITa/LkhIviLmxodcswWSBxVy0G
HtJuDipPwG0thi2FxuydgNGIsRL5nq2ctMJQ++klrpOCANGVQLHfqz68xvqR+19e
MEApWppAvg68FoXREIKO+SRma7FrTif1rGrWXxHJcDUlgjKoNFzCbFAK4nb5ueFn
D5MHfYg4QWo5Tq//kBuWNLV/4Dtdwyp3OWOeFBXqkjYS4JKLrgUgyqCmlI8Tn7gv
CjTlAj8uWrOpc170MaU+FuV2/PyrXOF0izFc1UIZ0A5mP1HKNqU9P40Kmk9Ova2C
BOoiKXVJQgUffvTPZSiWhDDXwGPYrGcbz2WuEeZIZxQ0xQajMkPrtxRtKh66w6Nk
yIR9SdOE4swSortTixwqBCp7MXNvMuJ/lsudan1ITt+guVe4BfZqLxEfpQy3VxX9
oQSmSa3K8S0+/7jNK2gRl1o11PtcsBIi7nHUVUE1IrWkH3x0XE+e+VkSQ8IyNgg/
zvyXRCnDutC2I48pjubDIKtp2crIOMdsmtBVCQq6gX1Sl/4z4E6BXEWkfVcSBk+O
05i6skiAX2QQcqX+EC/9HQ8UEjKIGeXyR2SxAiACx+1ckj9MHG8nytRAJQ2glmLs
ws7bgq7KAqJqvvPyVIeOW0hx4AX+5Q==
-----END CERTIFICATE-----
EOF
sudo chmod 644 /usr/local/share/ca-certificates/hic/hic-tre.crt
sudo update-ca-certificates

# Firefox doesn't use the system certificates by default, but a policy
# can be used to force the installation of the certificate at the next
# run.
sudo mkdir /etc/firefox/policies
sudo tee /etc/firefox/policies/policies.json <<JSON
{
"policies": {
"Certificates": {
"Install": ["/usr/local/share/ca-certificates/hic/hic-tre.crt"]
}
}
}
JSON

0 comments on commit 0c44934

Please sign in to comment.