Getting started with 1Password for your growing team, or refining your setup? Our Secured Success quickstart guide is for you.
Forum Discussion
Former Member
4 years agoRenewing Let's Encrypt certificate in AKS
Hello 1Password Support -
I'm taking over management of our 1Password SCIM bridge from a previous employee who left our organization. I'm kinda new to Kubernetes, but I'm fairly comfortable with D...
Former Member
4 years agoHi @graham_1P,
Thanks! That's excellent news. I'm really glad we don't need to open port 80. I checked back on the timelines:
- On January 24th, we started receiving emails that our SCIM bridge (running version 2.2.1) wasn't working. The certificate had expired, so communication was failing.
- On January 28th, my colleague updated the SCIM bridge to version 2.3.0, which generated a new certificate.
- On April 22nd, I noticed the certificate was due to expire on May 5th, which was less than 30 days away - per the documentation, the SCIM bridge attempts to renew Let's Encrypt certificates after 60 days, so I assumed the renewal process hadn't been working.
- On May 4th, I updated the SCIM bridge to 2.3.1, which generated a new certificate. This certificate doesn't expire until August 2nd.
If I'm reading the Bugzilla thread correctly, we somehow might have dodged the entire issue. Our old certificate expired before the bug was found on January 25th, and our new certificate was generated before the certificate revocation on January 30th. That said, we were running 2.3.0 until this week, so it's possible that's why the certificate didn't renew last month.
Since our current certificate doesn't expire until August, I'll keep an eye on things and reach out to support in mid-July if it doesn't auto-renew itself before then. I really appreciate the help with this!
Also, thanks for the fantastic documentation! I absolutely wouldn't have been able to update our SCIM bridge without the detailed instructions. :)
Mike
P.S. - Is there a good way to keep up with SCIM bridge updates? The 1Password admin console will show if there's a pending update on the "Integrations" page, but the bridge itself doesn't notify us. Would it be possible to add an RSS feed to the release notes page, or set up a mailing list?