<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EF2 extensions: More than one root CA in root.pem? in Extensions</title>
    <link>https://community.dynatrace.com/t5/Extensions/EF2-extensions-More-than-one-root-CA-in-root-pem/m-p/259887#M5391</link>
    <description>&lt;P&gt;Use a single CA and generate certificates for individual developers. You upload the root CA cert only to Environment/AG/OA. But you will have you generate the certs manually (do not autogenerate it in vscode).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 20 Oct 2024 20:13:34 GMT</pubDate>
    <dc:creator>Julius_Loman</dc:creator>
    <dc:date>2024-10-20T20:13:34Z</dc:date>
    <item>
      <title>EF2 extensions: More than one root CA in root.pem?</title>
      <link>https://community.dynatrace.com/t5/Extensions/EF2-extensions-More-than-one-root-CA-in-root-pem/m-p/259886#M5390</link>
      <description>&lt;P&gt;When developing custom extensions, we have to upload the root cert CA to the root.pem file, in your AG, according to:&lt;BR /&gt;&lt;A href="https://docs.dynatrace.com/docs/extend-dynatrace/extensions20/sign-extension" target="_blank"&gt;https://docs.dynatrace.com/docs/extend-dynatrace/extensions20/sign-extension&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Has anyone experienced or had the need to have more than one root CA, for two set of developers. Do these files and Dynatrace support multiple root CAs in the file?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Oct 2024 20:08:56 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/EF2-extensions-More-than-one-root-CA-in-root-pem/m-p/259886#M5390</guid>
      <dc:creator>AntonioSousa</dc:creator>
      <dc:date>2024-10-20T20:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: EF2 extensions: More than one root CA in root.pem?</title>
      <link>https://community.dynatrace.com/t5/Extensions/EF2-extensions-More-than-one-root-CA-in-root-pem/m-p/259887#M5391</link>
      <description>&lt;P&gt;Use a single CA and generate certificates for individual developers. You upload the root CA cert only to Environment/AG/OA. But you will have you generate the certs manually (do not autogenerate it in vscode).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Oct 2024 20:13:34 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/EF2-extensions-More-than-one-root-CA-in-root-pem/m-p/259887#M5391</guid>
      <dc:creator>Julius_Loman</dc:creator>
      <dc:date>2024-10-20T20:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: EF2 extensions: More than one root CA in root.pem?</title>
      <link>https://community.dynatrace.com/t5/Extensions/EF2-extensions-More-than-one-root-CA-in-root-pem/m-p/259888#M5392</link>
      <description>&lt;P&gt;As long as you name the files differently, you can have several certificates in the folder. That being said, I recommend to do what Julius said though for simplicity’s sake when you onboard new developers.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Oct 2024 20:20:21 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/EF2-extensions-More-than-one-root-CA-in-root-pem/m-p/259888#M5392</guid>
      <dc:creator>Mike_L</dc:creator>
      <dc:date>2024-10-20T20:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: EF2 extensions: More than one root CA in root.pem?</title>
      <link>https://community.dynatrace.com/t5/Extensions/EF2-extensions-More-than-one-root-CA-in-root-pem/m-p/259889#M5393</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/11520"&gt;@Mike_L&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Does that mean that I can have a root.pem, root1.pem, etc in the same directory?&lt;/P&gt;&lt;P&gt;BTW, the use case is a client where two Organizations are developing, both us &amp;amp; the client. And I also can see eventually other custom extensions in the future &lt;img class="lia-deferred-image lia-image-emoji" src="https://community.dynatrace.com/html/@6EDF483EF947B43E16DF999BED8ABCC0/images/emoticons/dynaspin.gif" alt=":dynaspin:" title=":dynaspin:" /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Oct 2024 20:50:55 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/EF2-extensions-More-than-one-root-CA-in-root-pem/m-p/259889#M5393</guid>
      <dc:creator>AntonioSousa</dc:creator>
      <dc:date>2024-10-20T20:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: EF2 extensions: More than one root CA in root.pem?</title>
      <link>https://community.dynatrace.com/t5/Extensions/EF2-extensions-More-than-one-root-CA-in-root-pem/m-p/259890#M5394</link>
      <description>&lt;P&gt;We load in any certificate in that folder, no matter the name.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Oct 2024 21:15:48 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/EF2-extensions-More-than-one-root-CA-in-root-pem/m-p/259890#M5394</guid>
      <dc:creator>Mike_L</dc:creator>
      <dc:date>2024-10-20T21:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: EF2 extensions: More than one root CA in root.pem?</title>
      <link>https://community.dynatrace.com/t5/Extensions/EF2-extensions-More-than-one-root-CA-in-root-pem/m-p/259942#M5395</link>
      <description>&lt;P&gt;Hi Antonio,&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can have several root certificates uploaded in the certificate folder, however that may defeat the benefits of signing extensions in the first place.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to ensure that only your trusted developers are able to upload extensions, please consider the following:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Code signing certificate issued by your domain admins to each of your developers.&lt;/LI&gt;&lt;LI&gt;Use a single CA so the certificates issued to the developers are valid.&lt;/LI&gt;&lt;LI&gt;Optional to use Intermediate certificates and upload the chain to OA. The benefits here are to create structures for what systems the developers can deploy extensions to.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Detailed sketch on how Extensions 2.0 are validated and ran.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Workflow" style="width: 999px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/23859iA301CFFBC69C453E/image-size/large?v=v2&amp;amp;px=999" role="button" title="workflow.png" alt="Workflow" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Workflow&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Example on how additional security is being added to different systems using several intermediate CA's in a domain. Please ignore "script 2" in the sketch, as an extension cannot be signed by multiple signers (yet)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Additional security" style="width: 583px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/23860i4CE9AAA2724CE4C1/image-size/large?v=v2&amp;amp;px=999" role="button" title="structure.png" alt="Additional security" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Additional security&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Let me know if the figures attached will help you determine what the best course of action will be for your environment.&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 09:23:19 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/EF2-extensions-More-than-one-root-CA-in-root-pem/m-p/259942#M5395</guid>
      <dc:creator>jonhaugen</dc:creator>
      <dc:date>2024-10-21T09:23:19Z</dc:date>
    </item>
  </channel>
</rss>

