From zanchey at ucc.gu.uwa.edu.au Wed Oct 7 09:30:27 2015 From: zanchey at ucc.gu.uwa.edu.au (David Adam) Date: Wed, 7 Oct 2015 09:30:27 +0800 (AWST) Subject: [tech] Apache and suexec Message-ID: CGI scripts stopped working a while back - probably on 21/9/2015. They're fixed now. Some background is probably helpful. The web server has the ability to run programs for our users, but for security reasons it runs them in the security context of the person who owns the program. This is done through a mechanism called "suexec". Unfortunately, the restrictions that suexec imposes are too tight for UCC's use. In particular, it prevents any programs running for wheel members (who have a group ID of 0) and requires all programs to be in a predetermined, compiled-in directory of "public_html" (we use public-html). In order to work around that, we have a custom-compiled version of the suexec helper (/usr/lib/apache2/suexec). It doesn't get upgraded with each version of Apache, because it has to be done by hand. The offical suexec binary gets put in /usr/lib/apache2/suexec.debian, thanks to the magic of dpkg-divert. The existing helper was for some reason compiled against BDB 4.2, which got removed from the system as it had nothing marked as depending on it on 21/9. Then the suexec helper refused to load, failing with "/usr/lib/apache2/suexec: error while loading shared libraries: libdb-4.2.so: cannot open shared object file: No such file or directory" I downloaded the Apache source (apt-get source apache2) and patched the suexec program: In support/suexec.h: - dropped MIN_GID to 0 - defined AP_DOC_ROOT to "/" (and removed the #ifdef guarding it) - defined AP_USERDIR_SUFFIX to "public-html" (and removed the #ifdef guarding it) - defined AP_HTTPD_USER to "www-data" In support/suexec.c: - removed the check for GID == 0 - removed part of the Debian patch debian/patches/058_suexec-CVE-2007-1742: not the bit that fixes the race condition, but the part that always appends a "/" to the DOC_ROOT. Then I compiled it (debian/rules binary), verified the build flags were correct (debian/apache2-suexec/usr/lib/apache2/suexec -V), and copied it into place (cp debian/apache2-suexec/usr/lib/apache2/suexec /usr/lib/apache2/suexec). Easy right? It only took about seven attempts. This dance will have to be done again when we upgrade to Apache 2.4. I really can't think of any way around it; [TRS] suggested a per-user CGID but I don't know that these are actually plausible. David Adam UCC Wheel Member zanchey at ucc.gu.uwa.edu.au From matt at ucc.asn.au Wed Oct 28 22:47:51 2015 From: matt at ucc.asn.au (Matt Johnston) Date: Wed, 28 Oct 2015 22:47:51 +0800 Subject: [tech] UCC wildcard certificate Message-ID: <20151028144751.GD7184@ucc.gu.uwa.edu.au> The ssl certificate for *.ucc.asn.au expires on 11 November. I've emailed globalsign but they aren't doing wildcards for open source projects any more. letsencrypt.org goes live on November 16 [1], we should be able to use that for all UCC domains in future (bodge up zonemake.py a bit more). Perhaps for the 5 day gap we could take advantage of a 15-day refund on a wildcard certificate certificates. Anyone got other ideas? Matt [1] https://letsencrypt.org/2015/08/07/updated-lets-encrypt-launch-schedule.html ----- Forwarded message from no_reply at globalsign.com ----- Date: Wed, 28 Oct 2015 10:08:46 +0900 (JST) From: no_reply at globalsign.com To: wheel at ucc.asn.au Subject: Reminder: Do not let your GlobalSign SSL Certificate expire X-Spam-Status: No, hits=0.1 required=5.0 tests=BAYES_50, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU,RCVD_IN_DNSWL_MED autolearn=no version=3.3.2 -------------------------------------------------- Please note that this e-mail is automatically sent from a noreply mailbox. To contact GlobalSign please use the Contact Details at the footer of this email. -------------------------------------------------- Dear Matt Johnston, Your DomainSSL Certificate for *.ucc.asn.au expires on 11/11/2015. If you do not renew your Certificate before this date you will not be able to continue the security of your web site. There is no need to risk your Certificate expiring by waiting too long. You can renew your Certificate and not lose any remaining time at any point up to 11/11/2015. So be safe and ensure the continued use of SSL security. CERTIFICATE DETAILS Organization: University Computer Club Organization ID: PAR95805 - quote when contacting Tech Support Product Type: DomainSSL Common Name: *.ucc.asn.au Order Number: CEDV1409092416 HOW TO RENEW -------------------------------------------------- You can log into your GlobalSign Certificate Center account and renew your Certificate at any time. Please follow these Renewal Instructions: 1. Log into your GCC Account at https://www.globalsign.com/login 2. On the left side click: Order History & Certificate Renewals 3. Run Upcoming Renewals Report 4. Click the "Renew" button next to your expiring SSL Certificate Order 5. Complete the online form (amend details accordingly). Provide a new CSR or use our AutoCSR function and we'll create the CSR for you. 6. A 15% renewal discount will automatically be applied. 7. Complete the application process as directed. For additional information please visit the SSL Renewal Center at: https://www.globalsign.com/ssl/renew YOUR ACCOUNT & GCC LOGIN DETAILS -------------------------------------------------- Organization: University Computer Club Organization ID: PAR95805 - quote when contacting Tech Support Login to your GlobalSign Certificate Center (GCC) Account to manage the lifecycle of your certificate. Your Account gives you easy access to renew Certificates, buy additional Certificates and to revoke or cancel existing Certificates if necessary. GCC Login URL: https://www.globalsign.com/ssl-login.htm Not sure of your User ID / Password? This would have been sent when you purchased your first GlobalSign product or created a User from within your GCC account. An email confirmation would have been sent. Please check your email or Contact Support if you have forgotten your Password. RENEWAL OFFERS -------------------------------------------------- * 15% Discount on Renewal: - Renew now and receive a 15% Discount * 30 days Bonus: - Any remaining time will be transferred to your new Certificate - Plus we will give you an extra 30 days Free! * Multi-year Savings: - Renew with multi-year (up to 5 years) to avoid the renewal process again this time next year. Get over 20% discount per additional year. Thank you for choosing GlobalSign, if you have any questions or issues please do not hesitate to contact us. CONTACT US -------------------- Please note this email was sent from a nonreply mailbox. Support Contact Information Create Support Ticket: https://support.globalsign.com/customer/portal/emails/new Phone Support: 1-877-467-7543 Online Support: https://support.globalsign.com/ Vetting Contact Information Vetting Fax: 617-830-0779 Vetting Email: vetting at globalsign.com -------------------------------------------------- GlobalSign - Identity for Everything? -------------------------------------------------- www.globalsign.com . 1-877-775-4562 . sales at globalsign.com YOUR CERTIFICATE TO RENEW: -------------------------------------------------- Here is a copy of the Certificate you now need to renew: -----BEGIN CERTIFICATE----- MIIE8jCCA9qgAwIBAgISESEncmGAMwb7qKVar+tjjtWiMA0GCSqGSIb3DQEBCwUA MGAxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMTYwNAYD VQQDEy1HbG9iYWxTaWduIERvbWFpbiBWYWxpZGF0aW9uIENBIC0gU0hBMjU2IC0g RzIwHhcNMTQwOTA5MTMyMjAxWhcNMTUxMTExMDAxMDUwWjA6MSEwHwYDVQQLExhE b21haW4gQ29udHJvbCBWYWxpZGF0ZWQxFTATBgNVBAMMDCoudWNjLmFzbi5hdTCC ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANB3lB2Q9IwIPw4wA3FzOCoR 55iXkrmwWcQgGEDvwioQ9dFIIz9llqPQ88ZliUWK6S3SJ34llTuxsOF1bMFJ0wy0 0yMEUohXrUqIqF/4l8SaLMzH27zmBtIoHw+cJeaCy3sCrbw3TF0ymZZTKr0mXj1d 0jO/FSjOTwVKjQUH34teUBWOurmXCb0Vl0glfCOWpKkZR6Ve8dBIEP+in7LQkpPn /o6pgX5oiMf08FpIwb+RcLveE7RcGC5MJPTBaewfJQRV0U4TcMCMYlHTdDj5LTQJ xhLWwbcg0TCM8EuzSBdx+XW7LewmDn5INjRr3lOn2mE+q2mvBWQulqWtUHDF28EC AwEAAaOCAcowggHGMA4GA1UdDwEB/wQEAwIFoDBJBgNVHSAEQjBAMD4GBmeBDAEC ATA0MDIGCCsGAQUFBwIBFiZodHRwczovL3d3dy5nbG9iYWxzaWduLmNvbS9yZXBv c2l0b3J5LzAjBgNVHREEHDAaggwqLnVjYy5hc24uYXWCCnVjYy5hc24uYXUwCQYD VR0TBAIwADAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwQwYDVR0fBDww OjA4oDagNIYyaHR0cDovL2NybC5nbG9iYWxzaWduLmNvbS9ncy9nc2RvbWFpbnZh bHNoYTJnMi5jcmwwgZQGCCsGAQUFBwEBBIGHMIGEMEcGCCsGAQUFBzAChjtodHRw Oi8vc2VjdXJlLmdsb2JhbHNpZ24uY29tL2NhY2VydC9nc2RvbWFpbnZhbHNoYTJn MnIxLmNydDA5BggrBgEFBQcwAYYtaHR0cDovL29jc3AyLmdsb2JhbHNpZ24uY29t L2dzZG9tYWludmFsc2hhMmcyMB0GA1UdDgQWBBRlhck6a3u3snso3Y6JIqh27oK+ BzAfBgNVHSMEGDAWgBTqTnzUgC3lFYGGJoyCbcCYpM+XDzANBgkqhkiG9w0BAQsF AAOCAQEAXIufu5A5RPZdokglCXPI2yJrE4vHDhsuRvDGirsj5ToYuI1yRyqSgvwr 0vNBr6TXpfY6tDV0uVLD28DNigHjiYQ3ITjlEHSiu3eWIZ2T/1cUUHs6PslXXGNK gkGg0BUmI3kpoqhPSlxHTnqeQXxdoTbQDZNRwXVKBQUD7SGDTTyc6hoRYoTMLGSX 9IkBl5e6iT7lUykEid9aUk8ueGPlKN5DUMBb574MolTupaOb0kj1RTXHxoO6A1Ig ldVHNt6J8i0pEn66PJptOrYbgPwA8hjbSqkjSPeWfg08LcWRroiys8Vp4Xm8GBJq mWlXEWy+2M8My0lMvo1HcTTdm8BMSg== -----END CERTIFICATE----- ----- End forwarded message ----- From mtearle at ucc.asn.au Thu Oct 29 10:53:54 2015 From: mtearle at ucc.asn.au (Mark Tearle) Date: Thu, 29 Oct 2015 10:53:54 +0800 Subject: [tech] UCC wildcard certificate In-Reply-To: <20151028144751.GD7184@ucc.gu.uwa.edu.au> References: <20151028144751.GD7184@ucc.gu.uwa.edu.au> Message-ID: <1446087234.1880573.423225201.08385E44@webmail.messagingengine.com> Hi Matt Let's Encrypt is running a beta program. https://community.letsencrypt.org/t/beta-program-announcements/1631 Perhaps it might be worth exploring if we could participate in it. I'm sure we know enough folk in the right place to make it happen. We've got an interesting enough use case. Mark -- Mark Tearle On Wed, Oct 28, 2015, at 10:47 PM, Matt Johnston wrote: > The ssl certificate for *.ucc.asn.au expires on 11 November. > I've emailed globalsign but they aren't doing wildcards for > open source projects any more. > > letsencrypt.org goes live on November 16 [1], we should be > able to use that for all UCC domains in future (bodge up > zonemake.py a bit more). Perhaps for the 5 day gap we could > take advantage of a 15-day refund on a wildcard certificate > certificates. Anyone got other ideas? > > Matt > > > [1] > https://letsencrypt.org/2015/08/07/updated-lets-encrypt-launch-schedule.html > ----- Forwarded message from no_reply at globalsign.com ----- > > Date: Wed, 28 Oct 2015 10:08:46 +0900 (JST) > From: no_reply at globalsign.com > To: wheel at ucc.asn.au > Subject: Reminder: Do not let your GlobalSign SSL Certificate expire > X-Spam-Status: No, hits=0.1 required=5.0 tests=BAYES_50, DKIM_SIGNED, > DKIM_VALID, > DKIM_VALID_AU,RCVD_IN_DNSWL_MED autolearn=no version=3.3.2 > > -------------------------------------------------- > Please note that this e-mail is automatically sent from a noreply > mailbox. > To contact GlobalSign please use the Contact Details at the footer of > this email. > -------------------------------------------------- > > Dear Matt Johnston, > > Your DomainSSL Certificate for > *.ucc.asn.au expires on 11/11/2015. > If you do not renew your Certificate before this date you > will not be able to continue the security of your web site. > > There is no need to risk your Certificate expiring by waiting too > long. > > You can renew your Certificate and not lose any remaining > time at any point up to 11/11/2015. > So be safe and ensure the continued use of SSL security. > > CERTIFICATE DETAILS > > Organization: University Computer Club > Organization ID: PAR95805 - quote when contacting Tech Support > Product Type: DomainSSL > Common Name: *.ucc.asn.au > Order Number: CEDV1409092416 > > HOW TO RENEW > -------------------------------------------------- > You can log into your GlobalSign Certificate Center account and renew > your > Certificate at any time. Please follow these Renewal Instructions: > > 1. Log into your GCC Account at https://www.globalsign.com/login > > 2. On the left side click: Order History & Certificate Renewals > > 3. Run Upcoming Renewals Report > > 4. Click the "Renew" button next to your expiring SSL Certificate Order > > 5. Complete the online form (amend details accordingly). Provide a new > CSR or use our AutoCSR function and we'll create the CSR for you. > > 6. A 15% renewal discount will automatically be applied. > > 7. Complete the application process as directed. > > For additional information please visit the SSL Renewal Center at: > https://www.globalsign.com/ssl/renew > > > YOUR ACCOUNT & GCC LOGIN DETAILS > -------------------------------------------------- > Organization: University Computer Club > Organization ID: PAR95805 - quote when contacting Tech Support > > Login to your GlobalSign Certificate Center (GCC) Account to manage > the lifecycle of your certificate. Your Account gives you easy access > to renew Certificates, buy additional Certificates and to revoke or > cancel existing Certificates if necessary. > > GCC Login URL: https://www.globalsign.com/ssl-login.htm > > Not sure of your User ID / Password? This would have been sent when you > purchased your first GlobalSign product or created a User from within > your > GCC account. An email confirmation would have been sent. Please check > your email or Contact Support if you have forgotten your Password. > > > RENEWAL OFFERS > -------------------------------------------------- > * 15% Discount on Renewal: > - Renew now and receive a 15% Discount > > * 30 days Bonus: > - Any remaining time will be transferred to your new Certificate > - Plus we will give you an extra 30 days Free! > > * Multi-year Savings: > - Renew with multi-year (up to 5 years) to avoid the renewal process > again this time next year. Get over 20% discount per additional > year. > > > Thank you for choosing GlobalSign, if you have any questions or > issues please do not hesitate to contact us. > > CONTACT US > -------------------- > Please note this email was sent from a nonreply mailbox. > > Support Contact Information > Create Support Ticket: > https://support.globalsign.com/customer/portal/emails/new > Phone Support: 1-877-467-7543 > Online Support: https://support.globalsign.com/ > > Vetting Contact Information > Vetting Fax: 617-830-0779 > Vetting Email: vetting at globalsign.com > > -------------------------------------------------- > GlobalSign - Identity for Everything? > -------------------------------------------------- > > www.globalsign.com . 1-877-775-4562 . > sales at globalsign.com > > > > YOUR CERTIFICATE TO RENEW: > -------------------------------------------------- > Here is a copy of the Certificate you now need to renew: > > -----BEGIN CERTIFICATE----- > MIIE8jCCA9qgAwIBAgISESEncmGAMwb7qKVar+tjjtWiMA0GCSqGSIb3DQEBCwUA > MGAxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMTYwNAYD > VQQDEy1HbG9iYWxTaWduIERvbWFpbiBWYWxpZGF0aW9uIENBIC0gU0hBMjU2IC0g > RzIwHhcNMTQwOTA5MTMyMjAxWhcNMTUxMTExMDAxMDUwWjA6MSEwHwYDVQQLExhE > b21haW4gQ29udHJvbCBWYWxpZGF0ZWQxFTATBgNVBAMMDCoudWNjLmFzbi5hdTCC > ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANB3lB2Q9IwIPw4wA3FzOCoR > 55iXkrmwWcQgGEDvwioQ9dFIIz9llqPQ88ZliUWK6S3SJ34llTuxsOF1bMFJ0wy0 > 0yMEUohXrUqIqF/4l8SaLMzH27zmBtIoHw+cJeaCy3sCrbw3TF0ymZZTKr0mXj1d > 0jO/FSjOTwVKjQUH34teUBWOurmXCb0Vl0glfCOWpKkZR6Ve8dBIEP+in7LQkpPn > /o6pgX5oiMf08FpIwb+RcLveE7RcGC5MJPTBaewfJQRV0U4TcMCMYlHTdDj5LTQJ > xhLWwbcg0TCM8EuzSBdx+XW7LewmDn5INjRr3lOn2mE+q2mvBWQulqWtUHDF28EC > AwEAAaOCAcowggHGMA4GA1UdDwEB/wQEAwIFoDBJBgNVHSAEQjBAMD4GBmeBDAEC > ATA0MDIGCCsGAQUFBwIBFiZodHRwczovL3d3dy5nbG9iYWxzaWduLmNvbS9yZXBv > c2l0b3J5LzAjBgNVHREEHDAaggwqLnVjYy5hc24uYXWCCnVjYy5hc24uYXUwCQYD > VR0TBAIwADAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwQwYDVR0fBDww > OjA4oDagNIYyaHR0cDovL2NybC5nbG9iYWxzaWduLmNvbS9ncy9nc2RvbWFpbnZh > bHNoYTJnMi5jcmwwgZQGCCsGAQUFBwEBBIGHMIGEMEcGCCsGAQUFBzAChjtodHRw > Oi8vc2VjdXJlLmdsb2JhbHNpZ24uY29tL2NhY2VydC9nc2RvbWFpbnZhbHNoYTJn > MnIxLmNydDA5BggrBgEFBQcwAYYtaHR0cDovL29jc3AyLmdsb2JhbHNpZ24uY29t > L2dzZG9tYWludmFsc2hhMmcyMB0GA1UdDgQWBBRlhck6a3u3snso3Y6JIqh27oK+ > BzAfBgNVHSMEGDAWgBTqTnzUgC3lFYGGJoyCbcCYpM+XDzANBgkqhkiG9w0BAQsF > AAOCAQEAXIufu5A5RPZdokglCXPI2yJrE4vHDhsuRvDGirsj5ToYuI1yRyqSgvwr > 0vNBr6TXpfY6tDV0uVLD28DNigHjiYQ3ITjlEHSiu3eWIZ2T/1cUUHs6PslXXGNK > gkGg0BUmI3kpoqhPSlxHTnqeQXxdoTbQDZNRwXVKBQUD7SGDTTyc6hoRYoTMLGSX > 9IkBl5e6iT7lUykEid9aUk8ueGPlKN5DUMBb574MolTupaOb0kj1RTXHxoO6A1Ig > ldVHNt6J8i0pEn66PJptOrYbgPwA8hjbSqkjSPeWfg08LcWRroiys8Vp4Xm8GBJq > mWlXEWy+2M8My0lMvo1HcTTdm8BMSg== > -----END CERTIFICATE----- > > > > ----- End forwarded message ----- > _______________________________________________ > List Archives: http://lists.ucc.gu.uwa.edu.au/pipermail/tech > > Unsubscribe here: > http://lists.ucc.gu.uwa.edu.au/mailman/options/tech/mtearle%40ucc.gu.uwa.edu.au From zanchey at ucc.gu.uwa.edu.au Thu Oct 29 14:44:31 2015 From: zanchey at ucc.gu.uwa.edu.au (David Adam) Date: Thu, 29 Oct 2015 14:44:31 +0800 (AWST) Subject: [tech] UCC wildcard certificate In-Reply-To: <1446087234.1880573.423225201.08385E44@webmail.messagingengine.com> References: <20151028144751.GD7184@ucc.gu.uwa.edu.au> <1446087234.1880573.423225201.08385E44@webmail.messagingengine.com> Message-ID: I signed UCC up for the beta a while back, but I haven't heard anything yet. [DAA] On Thu, 29 Oct 2015, Mark Tearle wrote: > Hi Matt > > Let's Encrypt is running a beta program. > https://community.letsencrypt.org/t/beta-program-announcements/1631 > > Perhaps it might be worth exploring if we could participate in it. > I'm sure we know enough folk in the right place to make it happen. > We've got an interesting enough use case. > > Mark > > -- > Mark Tearle > > On Wed, Oct 28, 2015, at 10:47 PM, Matt Johnston wrote: > > The ssl certificate for *.ucc.asn.au expires on 11 November. > > I've emailed globalsign but they aren't doing wildcards for > > open source projects any more. > > > > letsencrypt.org goes live on November 16 [1], we should be > > able to use that for all UCC domains in future (bodge up > > zonemake.py a bit more). Perhaps for the 5 day gap we could > > take advantage of a 15-day refund on a wildcard certificate > > certificates. Anyone got other ideas? > > > > Matt > > > > > > [1] > > https://letsencrypt.org/2015/08/07/updated-lets-encrypt-launch-schedule.html > > ----- Forwarded message from no_reply at globalsign.com ----- > > > > Date: Wed, 28 Oct 2015 10:08:46 +0900 (JST) > > From: no_reply at globalsign.com > > To: wheel at ucc.asn.au > > Subject: Reminder: Do not let your GlobalSign SSL Certificate expire > > X-Spam-Status: No, hits=0.1 required=5.0 tests=BAYES_50, DKIM_SIGNED, > > DKIM_VALID, > > DKIM_VALID_AU,RCVD_IN_DNSWL_MED autolearn=no version=3.3.2 > > > > -------------------------------------------------- > > Please note that this e-mail is automatically sent from a noreply > > mailbox. > > To contact GlobalSign please use the Contact Details at the footer of > > this email. > > -------------------------------------------------- > > > > Dear Matt Johnston, > > > > Your DomainSSL Certificate for > > *.ucc.asn.au expires on 11/11/2015. > > If you do not renew your Certificate before this date you > > will not be able to continue the security of your web site. > > > > There is no need to risk your Certificate expiring by waiting too > > long. > > > > You can renew your Certificate and not lose any remaining > > time at any point up to 11/11/2015. > > So be safe and ensure the continued use of SSL security. > > > > CERTIFICATE DETAILS > > > > Organization: University Computer Club > > Organization ID: PAR95805 - quote when contacting Tech Support > > Product Type: DomainSSL > > Common Name: *.ucc.asn.au > > Order Number: CEDV1409092416 > > > > HOW TO RENEW > > -------------------------------------------------- > > You can log into your GlobalSign Certificate Center account and renew > > your > > Certificate at any time. Please follow these Renewal Instructions: > > > > 1. Log into your GCC Account at https://www.globalsign.com/login > > > > 2. On the left side click: Order History & Certificate Renewals > > > > 3. Run Upcoming Renewals Report > > > > 4. Click the "Renew" button next to your expiring SSL Certificate Order > > > > 5. Complete the online form (amend details accordingly). Provide a new > > CSR or use our AutoCSR function and we'll create the CSR for you. > > > > 6. A 15% renewal discount will automatically be applied. > > > > 7. Complete the application process as directed. > > > > For additional information please visit the SSL Renewal Center at: > > https://www.globalsign.com/ssl/renew > > > > > > YOUR ACCOUNT & GCC LOGIN DETAILS > > -------------------------------------------------- > > Organization: University Computer Club > > Organization ID: PAR95805 - quote when contacting Tech Support > > > > Login to your GlobalSign Certificate Center (GCC) Account to manage > > the lifecycle of your certificate. Your Account gives you easy access > > to renew Certificates, buy additional Certificates and to revoke or > > cancel existing Certificates if necessary. > > > > GCC Login URL: https://www.globalsign.com/ssl-login.htm > > > > Not sure of your User ID / Password? This would have been sent when you > > purchased your first GlobalSign product or created a User from within > > your > > GCC account. An email confirmation would have been sent. Please check > > your email or Contact Support if you have forgotten your Password. > > > > > > RENEWAL OFFERS > > -------------------------------------------------- > > * 15% Discount on Renewal: > > - Renew now and receive a 15% Discount > > > > * 30 days Bonus: > > - Any remaining time will be transferred to your new Certificate > > - Plus we will give you an extra 30 days Free! > > > > * Multi-year Savings: > > - Renew with multi-year (up to 5 years) to avoid the renewal process > > again this time next year. Get over 20% discount per additional > > year. > > > > > > Thank you for choosing GlobalSign, if you have any questions or > > issues please do not hesitate to contact us. > > > > CONTACT US > > -------------------- > > Please note this email was sent from a nonreply mailbox. > > > > Support Contact Information > > Create Support Ticket: > > https://support.globalsign.com/customer/portal/emails/new > > Phone Support: 1-877-467-7543 > > Online Support: https://support.globalsign.com/ > > > > Vetting Contact Information > > Vetting Fax: 617-830-0779 > > Vetting Email: vetting at globalsign.com > > > > -------------------------------------------------- > > GlobalSign - Identity for Everything? > > -------------------------------------------------- > > > > www.globalsign.com . 1-877-775-4562 . > > sales at globalsign.com > > > > > > > > YOUR CERTIFICATE TO RENEW: > > -------------------------------------------------- > > Here is a copy of the Certificate you now need to renew: > > > > -----BEGIN CERTIFICATE----- > > MIIE8jCCA9qgAwIBAgISESEncmGAMwb7qKVar+tjjtWiMA0GCSqGSIb3DQEBCwUA > > MGAxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMTYwNAYD > > VQQDEy1HbG9iYWxTaWduIERvbWFpbiBWYWxpZGF0aW9uIENBIC0gU0hBMjU2IC0g > > RzIwHhcNMTQwOTA5MTMyMjAxWhcNMTUxMTExMDAxMDUwWjA6MSEwHwYDVQQLExhE > > b21haW4gQ29udHJvbCBWYWxpZGF0ZWQxFTATBgNVBAMMDCoudWNjLmFzbi5hdTCC > > ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANB3lB2Q9IwIPw4wA3FzOCoR > > 55iXkrmwWcQgGEDvwioQ9dFIIz9llqPQ88ZliUWK6S3SJ34llTuxsOF1bMFJ0wy0 > > 0yMEUohXrUqIqF/4l8SaLMzH27zmBtIoHw+cJeaCy3sCrbw3TF0ymZZTKr0mXj1d > > 0jO/FSjOTwVKjQUH34teUBWOurmXCb0Vl0glfCOWpKkZR6Ve8dBIEP+in7LQkpPn > > /o6pgX5oiMf08FpIwb+RcLveE7RcGC5MJPTBaewfJQRV0U4TcMCMYlHTdDj5LTQJ > > xhLWwbcg0TCM8EuzSBdx+XW7LewmDn5INjRr3lOn2mE+q2mvBWQulqWtUHDF28EC > > AwEAAaOCAcowggHGMA4GA1UdDwEB/wQEAwIFoDBJBgNVHSAEQjBAMD4GBmeBDAEC > > ATA0MDIGCCsGAQUFBwIBFiZodHRwczovL3d3dy5nbG9iYWxzaWduLmNvbS9yZXBv > > c2l0b3J5LzAjBgNVHREEHDAaggwqLnVjYy5hc24uYXWCCnVjYy5hc24uYXUwCQYD > > VR0TBAIwADAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwQwYDVR0fBDww > > OjA4oDagNIYyaHR0cDovL2NybC5nbG9iYWxzaWduLmNvbS9ncy9nc2RvbWFpbnZh > > bHNoYTJnMi5jcmwwgZQGCCsGAQUFBwEBBIGHMIGEMEcGCCsGAQUFBzAChjtodHRw > > Oi8vc2VjdXJlLmdsb2JhbHNpZ24uY29tL2NhY2VydC9nc2RvbWFpbnZhbHNoYTJn > > MnIxLmNydDA5BggrBgEFBQcwAYYtaHR0cDovL29jc3AyLmdsb2JhbHNpZ24uY29t > > L2dzZG9tYWludmFsc2hhMmcyMB0GA1UdDgQWBBRlhck6a3u3snso3Y6JIqh27oK+ > > BzAfBgNVHSMEGDAWgBTqTnzUgC3lFYGGJoyCbcCYpM+XDzANBgkqhkiG9w0BAQsF > > AAOCAQEAXIufu5A5RPZdokglCXPI2yJrE4vHDhsuRvDGirsj5ToYuI1yRyqSgvwr > > 0vNBr6TXpfY6tDV0uVLD28DNigHjiYQ3ITjlEHSiu3eWIZ2T/1cUUHs6PslXXGNK > > gkGg0BUmI3kpoqhPSlxHTnqeQXxdoTbQDZNRwXVKBQUD7SGDTTyc6hoRYoTMLGSX > > 9IkBl5e6iT7lUykEid9aUk8ueGPlKN5DUMBb574MolTupaOb0kj1RTXHxoO6A1Ig > > ldVHNt6J8i0pEn66PJptOrYbgPwA8hjbSqkjSPeWfg08LcWRroiys8Vp4Xm8GBJq > > mWlXEWy+2M8My0lMvo1HcTTdm8BMSg== > > -----END CERTIFICATE----- > > > > > > > > ----- End forwarded message ----- > > _______________________________________________ > > List Archives: http://lists.ucc.gu.uwa.edu.au/pipermail/tech > > > > Unsubscribe here: > > http://lists.ucc.gu.uwa.edu.au/mailman/options/tech/mtearle%40ucc.gu.uwa.edu.au > _______________________________________________ > List Archives: http://lists.ucc.gu.uwa.edu.au/pipermail/tech > > Unsubscribe here: http://lists.ucc.gu.uwa.edu.au/mailman/options/tech/zanchey%40ucc.gu.uwa.edu.au > Cheers, David Adam zanchey at ucc.gu.uwa.edu.au Ask Me About Our SLA!