Skip to content

chore(security): rotate TLS certificate pins - #83

Open
PeterXMR wants to merge 1 commit into
mainfrom
automation/tls-pin-rotation
Open

PeterXMR wants to merge 1 commit into
mainfrom
automation/tls-pin-rotation

Conversation

@PeterXMR

@PeterXMR PeterXMR commented Sep 9, 2026

Copy link
Copy Markdown
Owner

Closes #78.

Automated TLS pin rotation, opened by hand. The TLS pin auto-rotation workflow refreshed the pins on automation/tls-pin-rotation (run 34349212551) but its final gh pr create step is rejected with:

pull request create failed: GraphQL: GitHub Actions is not permitted to create or approve pull requests (createPullRequest)

That is a repository setting, not a workflow permission (the job already declares pull-requests: write). To let the daily run open this PR itself: Settings → Actions → General → Workflow permissions → enable "Allow GitHub Actions to create and approve pull requests". Until that is switched on, every scheduled run force-pushes this branch and then fails at the PR step, which is why the workflow has been red on main for three days.

Per-host summary

Independently re-verified on 2026-09-09 with the openssl one-liner from docs/PIN-ROTATION.md. All three refreshed leaf SPKI pins and notAfter dates match what the workflow committed.

Host expiration before expiration after Leaf notAfter (live) Leaf SPKI matches live
api.kraken.com 2026-09-23 2026-11-21 2026-11-26 yes
api.coingecko.com 2026-09-26 2026-11-24 2026-11-29 yes
api.coinbase.com 2026-09-29 2026-11-27 2026-12-02 yes
www.bitstamp.net 2026-11-02 unchanged 2026-11-07 not rotated

The intermediate (backup) pin for the three Google Trust Services hosts is unchanged. The driving deadline moves from api.kraken.com on 2026-09-23 to www.bitstamp.net on 2026-11-02.

Before merge

  1. Sanity-check the pin/expiration diff in network_security_config.xml.
  2. Verify on a real device against a proxy (mitmproxy). Pinning must still reject the proxy cert (docs/PIN-ROTATION.md).
  3. Merge, then cut a release before the earliest expiration date (2026-11-02).

@github-actions
github-actions Bot force-pushed the automation/tls-pin-rotation branch 7 times, most recently from f377817 to 9d1b29a Compare September 16, 2026 12:23
@github-actions
github-actions Bot force-pushed the automation/tls-pin-rotation branch 7 times, most recently from 4982621 to 2e423ea Compare September 23, 2026 12:31
@github-actions
github-actions Bot force-pushed the automation/tls-pin-rotation branch 7 times, most recently from 9b80356 to f0e8265 Compare September 30, 2026 13:18
@github-actions
github-actions Bot force-pushed the automation/tls-pin-rotation branch 3 times, most recently from c22882e to 22bbb07 Compare October 3, 2026 12:11
Auto-generated by .github/workflows/pin-rotation.yml. Re-fetched the
live chains and refreshed the leaf + intermediate SPKI pins and the
pin-set expiration dates. Review the diff and verify on-device against
a proxy before merging (docs/PIN-ROTATION.md).
@github-actions
github-actions Bot force-pushed the automation/tls-pin-rotation branch from 22bbb07 to 267bcc2 Compare October 4, 2026 13:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

TLS pins approaching expiry — refresh required

1 participant