Permanent Update Policy Exception for certbot #3124

Closed
opened 2023-12-21 17:20:24 +00:00 by jonathanspw · 13 comments

This ticket asks FESCo to consider whether the certbot package should be granted a permanent exception under the Updates Policy.

The certbot package is a Python package published by EFF to manage free SSL certs mostly from Let's Encrypt but others are supported as well. It has integrations for various DNS providers as well as Apache and Nginx web servers.

No package depends on the certbot package.

This request is mostly so EPEL can inherit the exception as the short lifecycle of Fedora makes it less relevant to Fedora specifically. Given EPEL's long life cycle, many things can change cert-wise over a 10-year period along with APIs of the DNS providers with which certbot integrates. This leads to folks being unable to get the most ideal (secure) certs and/or completely broken integrations which can break or otherwise leave websites vulnerable if server admins don't take action.

certbot does have breaking changes in the traditional sense of changed functionality, it generally does not require user intervention and the value of updating far outweighs the very minute chance of an obscure breakage from said update.

This ticket asks FESCo to consider whether the certbot package should be granted a permanent exception under the Updates Policy. The certbot package is a Python package published by EFF to manage free SSL certs mostly from Let's Encrypt but others are supported as well. It has integrations for various DNS providers as well as Apache and Nginx web servers. No package depends on the certbot package. This request is mostly so EPEL can inherit the exception as the short lifecycle of Fedora makes it less relevant to Fedora specifically. Given EPEL's long life cycle, many things can change cert-wise over a 10-year period along with APIs of the DNS providers with which certbot integrates. This leads to folks being unable to get the most ideal (secure) certs and/or completely broken integrations which can break or otherwise leave websites vulnerable if server admins don't take action. certbot does have breaking changes in the traditional sense of changed functionality, it generally does not require user intervention and the value of updating far outweighs the very minute chance of an obscure breakage from said update.
Owner

I think this is reasonable as a Fedora-wide exception.

+1

I think this is reasonable as a Fedora-wide exception. ***+1***
Owner

Metadata Update from @ngompa:

  • Issue tagged with: updates policy exception
**Metadata Update from @ngompa**: - Issue tagged with: updates policy exception
Owner

+1 from me

Keeping certbot up to date is "critical infrastructure" in 2024.

+1 from me Keeping certbot up to date is "critical infrastructure" in 2024.
Owner

We've passed the seven day mark (adjusted for the end-of-year absences) but we don't yet have +3, so voting will extend for another week,

We've passed the seven day mark (adjusted for the end-of-year absences) but we don't yet have +3, so voting will extend for another week,

@jonathanspw Good idea. +1 👏

@jonathanspw Good idea. +1 👏
Owner

+1

+1
Owner

+1

+1

+1

+1

+1

+1
Owner

This is APPROVED (+7, 0, 0)

This is APPROVED (+7, 0, 0)
Owner

Metadata Update from @ngompa:

  • Issue tagged with: pending announcement
**Metadata Update from @ngompa**: - Issue tagged with: pending announcement

Metadata Update from @tstellar:

  • Issue untagged with: pending announcement
  • Issue close_status updated to: Accepted
  • Issue status updated to: Closed (was: Open)
**Metadata Update from @tstellar**: - Issue **un**tagged with: pending announcement - Issue close_status updated to: Accepted - Issue status updated to: Closed (was: Open)
Announced: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/message/UBVG6IOTUHHY5SHXFHOISZNHK3QLXTMX/
Sign in to join this conversation.
No milestone
No project
No assignees
9 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
fesco/tickets#3124
No description provided.