Skip to content

[release/9.0] Move DAC signing identity to PME - #114031

Merged
hoyosjs merged 1 commit into
dotnet:release/9.0-stagingfrom
hoyosjs:juhoyosa/dac-pme-9
Apr 1, 2025
Merged

[release/9.0] Move DAC signing identity to PME#114031
hoyosjs merged 1 commit into
dotnet:release/9.0-stagingfrom
hoyosjs:juhoyosa/dac-pme-9

Conversation

@hoyosjs

@hoyosjshoyosjs commented Mar 29, 2025

Copy link
Copy Markdown
Member

Required for SFI requirement of ESRP isolation to production tenants.

@hoyosjs
hoyosjs requested review from a team and CopilotMarch 29, 2025 03:44
@ghostghost added the needs-area-label An area label is needed to ensure this gets routed to the appropriate area owners label Mar 29, 2025

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the signing identity for diagnostic binaries to use the new PME configuration.

  • Updated connected service and authentication IDs to the PME values.
  • Revised certificate and tenant information accordingly.
Comments suppressed due to low confidence (2)

eng/pipelines/coreclr/templates/sign-diagnostic-files.yml:18

  • Verify that the new connected service name 'diagnostics-esrp-kvcertuser-pme' is correctly set up in your environment to ensure proper connectivity.
ConnectedServiceName: 'diagnostics-esrp-kvcertuser-pme'

eng/pipelines/coreclr/templates/sign-diagnostic-files.yml:23

  • Confirm that the updated AuthSignCertName 'dac-dnceng-esrpclient-cert' matches the PME certificate configuration and that the corresponding certificate is available.
AuthSignCertName: 'dac-dnceng-esrpclient-cert'

@hoyosjs

Copy link
Copy Markdown
MemberAuthor

/backport to release/8.0-staging

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/8.0-staging: https://github.com/dotnet/runtime/actions/runs/14141875850

@jeffschwMSFTjeffschwMSFT left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approved. please get a code review. we can treat this as tell mode

cc @carlossanlop

@teo-tsirpanisteo-tsirpanis added this to the 9.0.x milestone Mar 29, 2025
@teo-tsirpanisteo-tsirpanis added area-Infrastructure-coreclr Only use for closed issues and removed needs-area-label An area label is needed to ensure this gets routed to the appropriate area owners labels Mar 29, 2025
@hoyosjshoyosjs added the Servicing-approved Approved for servicing release label Apr 1, 2025
@hoyosjs
hoyosjs merged commit dcd6c39 into dotnet:release/9.0-stagingApr 1, 2025
@hoyosjs
hoyosjs deleted the juhoyosa/dac-pme-9 branch April 1, 2025 20:28
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 2, 2025
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-Infrastructure-coreclrOnly use for closed issuesServicing-approvedApproved for servicing release

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

6 participants

@hoyosjs@jkoritzinsky@jeffschwMSFT@tommcdon@teo-tsirpanis