<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lifecycle of CA.pem files in multi-developers context in Extensions</title>
    <link>https://community.dynatrace.com/t5/Extensions/Lifecycle-of-CA-pem-files-in-multi-developers-context/m-p/251563#M4858</link>
    <description>&lt;P&gt;Hello Mike,&lt;/P&gt;&lt;P&gt;As a partner, we work for multiple clients.&lt;/P&gt;&lt;P&gt;Some use enterprise certificates and have their own certification authority, but most are not able to do so.&lt;/P&gt;&lt;P&gt;Using the ca.pem generated from the Dynatrace VSCode integration is, in most cases, the chosen solution because it is the simplest.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this context, how do you recommend we manage the ca.pem on the AG ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your feedback.&lt;BR /&gt;Regards&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jul 2024 06:36:06 GMT</pubDate>
    <dc:creator>AurelienGravier</dc:creator>
    <dc:date>2024-07-25T06:36:06Z</dc:date>
    <item>
      <title>Lifecycle of CA.pem files in multi-developers context</title>
      <link>https://community.dynatrace.com/t5/Extensions/Lifecycle-of-CA-pem-files-in-multi-developers-context/m-p/251506#M4848</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In a context where multiple developers are authorized to create and distribute custom Dynatrace V2 extensions in production, I have some questions about&amp;nbsp;how the lifecycle of ca.pem files be managed on ActiveGates.&lt;BR /&gt;&lt;BR /&gt;Ca.pem verification is done at each extension execution or only at the first execution ?&lt;/P&gt;&lt;P&gt;Can each developer overwrite the existing ca.pem with each new extension distribution without impacting other custom extensions ?&lt;/P&gt;&lt;P&gt;Or should each developer manage a rotation of the CA certificate at each new extension distribution, for example, ca_dev1.pem, ca_dev2.pem, ... ?&lt;BR /&gt;&lt;BR /&gt;Thank you for the clarification.&lt;BR /&gt;Regards Aurélien.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 12:13:29 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/Lifecycle-of-CA-pem-files-in-multi-developers-context/m-p/251506#M4848</guid>
      <dc:creator>AurelienGravier</dc:creator>
      <dc:date>2024-07-24T12:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Lifecycle of CA.pem files in multi-developers context</title>
      <link>https://community.dynatrace.com/t5/Extensions/Lifecycle-of-CA-pem-files-in-multi-developers-context/m-p/251518#M4852</link>
      <description>&lt;P&gt;I'd recommend that you provide leaf certificates for your developers and place the root certificate on the AG/OAs. That way you don't have to worry about different files per developer, or overwriting files.&lt;/P&gt;
&lt;P&gt;If you quickly need to kill the extensions signed by one certificate you can add it to a certificate revocation list and the extensions signed with that certificate will be killed immediately.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 12:50:04 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/Lifecycle-of-CA-pem-files-in-multi-developers-context/m-p/251518#M4852</guid>
      <dc:creator>Mike_L</dc:creator>
      <dc:date>2024-07-24T12:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: Lifecycle of CA.pem files in multi-developers context</title>
      <link>https://community.dynatrace.com/t5/Extensions/Lifecycle-of-CA-pem-files-in-multi-developers-context/m-p/251563#M4858</link>
      <description>&lt;P&gt;Hello Mike,&lt;/P&gt;&lt;P&gt;As a partner, we work for multiple clients.&lt;/P&gt;&lt;P&gt;Some use enterprise certificates and have their own certification authority, but most are not able to do so.&lt;/P&gt;&lt;P&gt;Using the ca.pem generated from the Dynatrace VSCode integration is, in most cases, the chosen solution because it is the simplest.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this context, how do you recommend we manage the ca.pem on the AG ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your feedback.&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 06:36:06 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/Lifecycle-of-CA-pem-files-in-multi-developers-context/m-p/251563#M4858</guid>
      <dc:creator>AurelienGravier</dc:creator>
      <dc:date>2024-07-25T06:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Lifecycle of CA.pem files in multi-developers context</title>
      <link>https://community.dynatrace.com/t5/Extensions/Lifecycle-of-CA-pem-files-in-multi-developers-context/m-p/251570#M4864</link>
      <description>&lt;P&gt;In that case, rename it with the developer alias or so in there.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 07:27:27 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/Lifecycle-of-CA-pem-files-in-multi-developers-context/m-p/251570#M4864</guid>
      <dc:creator>Mike_L</dc:creator>
      <dc:date>2024-07-25T07:27:27Z</dc:date>
    </item>
  </channel>
</rss>

