Project

General

Profile

Actions

Support #342

open

Support #314: OAM - Alerts and delivery thereof

OAM: PKI/SSL: tsys-ca VM + HSM CA + ACME

Support #342: OAM: PKI/SSL: tsys-ca VM + HSM CA + ACME

Added by Charles N 2 days ago. Updated 1 day ago.

Status:
New
Priority:
Normal
Assignee:
Start date:
08/06/2026
Due date:
08/31/2026 (Due in 23 days)
% Done:

0%

Estimated time:

Description

Parent/umbrella: #314 (OAM - Alerts and delivery thereof).

Scope

  • Deploy tsys-ca VM.
  • Set up HSM-backed root / intermediate CA.
  • Set up ACME endpoint for automated certificate issuance.

Why it matters

Underpins TLS everywhere; blocks mail relay deliverability (F) and secure alert transports (C).

Updated by Charles N 1 day ago Actions #1

  • Subject changed from PKI/SSL: tsys-ca VM + HSM CA + ACME to OAM: PKI/SSL: tsys-ca VM + HSM CA + ACME

Updated by Charles N 1 day ago Actions #2

  • Due date set to 08/31/2026

Updated by Charles N 1 day ago Actions #3

  • Target version set to Potential to Kinetic Ready

Updated by Charles N 1 day ago Actions #4

Related PKI work in PFVCluster: AWX currently HTTP-only (self-signed cert, temporary). Vault deployed but UNCONFIGURED - API key migration is HIGH priority. tsys-ca VM exists (referenced in KNELIAC inventory). ACME / internal CA rollout needed for: AWX TLS, Cloudron, k8s ingress.

Actions

Also available in: PDF Atom