]>
git.street.me.uk Git - andy/dehydrated.git/log
Lukas Schauer [Mon, 14 Dec 2015 13:44:38 +0000 (14:44 +0100)]
fixed travis config? maybe. again.
Lukas Schauer [Mon, 14 Dec 2015 13:39:31 +0000 (14:39 +0100)]
fixed travis config? maybe.
Lukas Schauer [Mon, 14 Dec 2015 13:38:06 +0000 (14:38 +0100)]
removed root certificates
Lukas Schauer [Mon, 14 Dec 2015 13:37:28 +0000 (14:37 +0100)]
travis: use fullchain to verify ssl certificate
Lukas Schauer [Mon, 14 Dec 2015 13:30:37 +0000 (14:30 +0100)]
grab root certificate url from certificate, fixes #43
Lukas Schauer [Mon, 14 Dec 2015 13:10:54 +0000 (14:10 +0100)]
fixed usage of openssl sha in newer openssl versions by using direct binary output
Lukas Schauer [Mon, 14 Dec 2015 13:04:11 +0000 (14:04 +0100)]
use sha in openssl instead of shasum, fixes #42
Lukas Schauer [Mon, 14 Dec 2015 00:37:03 +0000 (01:37 +0100)]
use config vars from letsencrypt.sh in import-script
Lukas Schauer [Mon, 14 Dec 2015 00:35:43 +0000 (01:35 +0100)]
also output config location on --env
Lukas Schauer [Mon, 14 Dec 2015 00:30:22 +0000 (01:30 +0100)]
making shellcheck happy again
Lukas Schauer [Mon, 14 Dec 2015 00:20:21 +0000 (01:20 +0100)]
allow export of config variables for use in other scripts
Lukas Schauer [Mon, 14 Dec 2015 00:03:32 +0000 (01:03 +0100)]
changed order of config locations to be a bit more sane
Lukas Schauer [Sun, 13 Dec 2015 23:57:43 +0000 (00:57 +0100)]
Merge pull request #40 from digint/no_scriptdir
Don't use SCRIPTDIR
Axel Burri [Sat, 12 Dec 2015 14:41:34 +0000 (15:41 +0100)]
make default PRIVATE_KEY and WELLKNOWN relative to BASEDIR, even if BASEDIR is overridden in config.sh; basic checks on BASEDIR
Axel Burri [Sat, 12 Dec 2015 14:10:10 +0000 (15:10 +0100)]
never fallback to SCRIPTDIR, this is error-prone and confusing
Lukas Schauer [Sat, 12 Dec 2015 03:45:01 +0000 (04:45 +0100)]
Merge pull request #37 from germeier/privatekey
fix logic if private key is specified via command line option
Markus Germeier [Sat, 12 Dec 2015 02:48:11 +0000 (03:48 +0100)]
actually move BASEDIR up as intended
Markus Germeier [Sat, 12 Dec 2015 02:39:45 +0000 (03:39 +0100)]
- make private key a config option
- fix logic if private key is specified via command line option
- start using PARAM_* for parameters provided at the command line
Lukas Schauer [Sat, 12 Dec 2015 01:09:08 +0000 (02:09 +0100)]
don't assume we are in the same directory as the script
Lukas Schauer [Sat, 12 Dec 2015 01:01:56 +0000 (02:01 +0100)]
fancy autogenerated help text
Lukas Schauer [Sat, 12 Dec 2015 00:18:27 +0000 (01:18 +0100)]
added commandline options (thanks to germeier, fixes #35)
Lukas Schauer [Tue, 8 Dec 2015 17:41:17 +0000 (18:41 +0100)]
fixed travis config
Lukas Schauer [Tue, 8 Dec 2015 17:37:27 +0000 (18:37 +0100)]
added staging-ca certificate and added verification test to travis config
Lukas Schauer [Tue, 8 Dec 2015 17:14:15 +0000 (18:14 +0100)]
Merge pull request #33 from M-M-M-M/clean_challenge
Move cleaning challenge in order to clean when challenge is valid and when challenge is invalid.
Lukas Schauer [Tue, 8 Dec 2015 17:11:25 +0000 (18:11 +0100)]
added travis-ci badge to readme
ET [Tue, 8 Dec 2015 17:09:46 +0000 (18:09 +0100)]
Move cleaning challenge in order to clean when challenge is valid and when challenge is invalid.
Lukas Schauer [Tue, 8 Dec 2015 16:55:22 +0000 (17:55 +0100)]
added travis config
Simon Ruderich [Tue, 8 Dec 2015 16:50:46 +0000 (17:50 +0100)]
use lock file to prevent concurrent access
Closes #31.
Simon Ruderich [Tue, 8 Dec 2015 16:36:29 +0000 (17:36 +0100)]
fix missing variable
Simon Ruderich [Tue, 8 Dec 2015 15:39:34 +0000 (16:39 +0100)]
check certificate to detect corruption
Lukas Schauer [Tue, 8 Dec 2015 15:54:34 +0000 (16:54 +0100)]
fixed output of config location
Lukas Schauer [Tue, 8 Dec 2015 15:38:25 +0000 (16:38 +0100)]
grab action urls from ca-directory
Lukas Schauer [Tue, 8 Dec 2015 15:13:40 +0000 (16:13 +0100)]
removed line-break in example config
Simon Ruderich [Tue, 8 Dec 2015 15:00:43 +0000 (16:00 +0100)]
_request: fix unset variable
_request() is also called when $challenge_token/$keyauth is not set.
Simon Ruderich [Tue, 8 Dec 2015 14:19:02 +0000 (15:19 +0100)]
fix typo in error message
Simon Ruderich [Tue, 8 Dec 2015 14:16:05 +0000 (15:16 +0100)]
pass altname/domain as second argument to HOOK
Simon Ruderich [Tue, 8 Dec 2015 14:15:08 +0000 (15:15 +0100)]
display errors from openssl
Simon Ruderich [Tue, 8 Dec 2015 09:23:44 +0000 (10:23 +0100)]
import-certs.sh: simplify expiry check
Simon Ruderich [Tue, 8 Dec 2015 09:20:36 +0000 (10:20 +0100)]
ugly fix to syntax highlighting in Vim
Simon Ruderich [Tue, 8 Dec 2015 09:10:59 +0000 (10:10 +0100)]
README.md: letsencrypt.sh is written in bash
Simon Ruderich [Tue, 8 Dec 2015 09:09:04 +0000 (10:09 +0100)]
chmod +x import-account.pl
Simon Ruderich [Tue, 8 Dec 2015 09:08:24 +0000 (10:08 +0100)]
replace echo with printf
Simon Ruderich [Tue, 8 Dec 2015 09:06:52 +0000 (10:06 +0100)]
fix typo in comment
Simon Ruderich [Tue, 8 Dec 2015 09:06:17 +0000 (10:06 +0100)]
simplify expiry check
Simon Ruderich [Tue, 8 Dec 2015 09:04:44 +0000 (10:04 +0100)]
replace rm -f; ln -s with ln -sf
Lukas Schauer [Tue, 8 Dec 2015 14:51:12 +0000 (15:51 +0100)]
Check for config file in various locations
Lukas Schauer [Tue, 8 Dec 2015 14:42:57 +0000 (15:42 +0100)]
also add default CA definition in description of variable
Lukas Schauer [Tue, 8 Dec 2015 14:38:33 +0000 (15:38 +0100)]
fixed default path to WELLKNOWN and moved SCRIPTDIR definition out of default-config block
Lukas Schauer [Tue, 8 Dec 2015 14:35:45 +0000 (15:35 +0100)]
cleaned up example config
et@corde.org [Tue, 8 Dec 2015 13:03:59 +0000 (14:03 +0100)]
A single HOOK to handle challenge, cleaning of challenge files and uploading of certs.
Lukas Schauer [Tue, 8 Dec 2015 13:46:50 +0000 (14:46 +0100)]
certificate comes first in fullchain.pem, fixes #26
Lukas Schauer [Tue, 8 Dec 2015 13:43:15 +0000 (14:43 +0100)]
added shebang to example config
Lukas Schauer [Tue, 8 Dec 2015 13:42:26 +0000 (14:42 +0100)]
making shellcheck happy
et@corde.org [Tue, 8 Dec 2015 13:30:31 +0000 (14:30 +0100)]
add CONTACT_EMAIL option on registration
Lukas Schauer [Mon, 7 Dec 2015 20:15:32 +0000 (21:15 +0100)]
added certificate revocation to feature-list
Markus Germeier [Mon, 7 Dec 2015 18:51:54 +0000 (19:51 +0100)]
implement revoke
Lukas Schauer [Mon, 7 Dec 2015 13:56:04 +0000 (14:56 +0100)]
renamed import scripts, updated readme
Lukas Schauer [Mon, 7 Dec 2015 13:28:53 +0000 (14:28 +0100)]
update symlinks after signing the certificate
Lukas Schauer [Mon, 7 Dec 2015 13:00:51 +0000 (14:00 +0100)]
making shellcheck happy
Lukas Schauer [Mon, 7 Dec 2015 12:22:25 +0000 (13:22 +0100)]
umask in import script
Lukas Schauer [Mon, 7 Dec 2015 12:21:12 +0000 (13:21 +0100)]
added import script (allows import of existing certificates from the original letsencrypt client)
Lukas Schauer [Mon, 7 Dec 2015 11:50:31 +0000 (12:50 +0100)]
create fullchain.pem
Lukas Schauer [Mon, 7 Dec 2015 11:41:03 +0000 (12:41 +0100)]
also store csr with timestamp and symlink to default location
Lukas Schauer [Mon, 7 Dec 2015 11:36:56 +0000 (12:36 +0100)]
look for domains.txt under BASEDIR
Lukas Schauer [Mon, 7 Dec 2015 11:19:15 +0000 (12:19 +0100)]
updated readme
Lukas Schauer [Mon, 7 Dec 2015 11:18:06 +0000 (12:18 +0100)]
updated readme
Lukas Schauer [Mon, 7 Dec 2015 11:10:51 +0000 (12:10 +0100)]
delete challenge response after verification
Lukas Schauer [Mon, 7 Dec 2015 11:08:30 +0000 (12:08 +0100)]
parse challenges json differently to be compatible with bsd sed
Lukas Schauer [Mon, 7 Dec 2015 10:45:09 +0000 (11:45 +0100)]
added config option to set path for openssl config file (currently only used for generating a signing request)
Lukas Schauer [Mon, 7 Dec 2015 10:36:58 +0000 (11:36 +0100)]
use bash functionality instead of sed to filter SAN variable
Lukas Schauer [Mon, 7 Dec 2015 10:36:27 +0000 (11:36 +0100)]
don't use '-r' on sed
Lukas Schauer [Mon, 7 Dec 2015 10:26:14 +0000 (11:26 +0100)]
making shellcheck happy
Lukas Schauer [Mon, 7 Dec 2015 10:21:26 +0000 (11:21 +0100)]
use absolute path of script directory as default BASEDIR, remove trailing slash from BASEDIR
Lukas Schauer [Mon, 7 Dec 2015 10:15:10 +0000 (11:15 +0100)]
added default BASEDIR to example config
Andrey Jr. Melnikov [Sun, 6 Dec 2015 17:58:53 +0000 (20:58 +0300)]
Store keys and certs in $BASEDIR
Martin Geiseler [Sun, 6 Dec 2015 17:22:17 +0000 (18:22 +0100)]
Cleaner outputs
Lukas Schauer [Sun, 6 Dec 2015 17:42:04 +0000 (18:42 +0100)]
Merge pull request #13 from germeier/master
show expire date when we don't need to renew a certifcate
Markus Germeier [Sun, 6 Dec 2015 17:25:54 +0000 (18:25 +0100)]
change openssl to use enddate for expiry date check
Markus Germeier [Sun, 6 Dec 2015 16:03:59 +0000 (17:03 +0100)]
show expire date when we don't need to renew a certifcate
Lukas Schauer [Sun, 6 Dec 2015 15:47:58 +0000 (16:47 +0100)]
Merge pull request #12 from germeier/newkeys
generate a new private key for each csr if the user wishes so
Lukas Schauer [Sun, 6 Dec 2015 15:35:28 +0000 (16:35 +0100)]
trying to capture http status codes from curl instead of using "--fail" to be able to capture acme error messages
Markus Germeier [Sun, 6 Dec 2015 15:27:15 +0000 (16:27 +0100)]
generate a new private key for each csr if the user wishes so
Lukas Schauer [Sun, 6 Dec 2015 15:09:49 +0000 (16:09 +0100)]
Merge pull request #11 from germeier/fixpending
fixed logic to check status from our challenge
Markus Germeier [Sun, 6 Dec 2015 14:51:38 +0000 (15:51 +0100)]
fixed logic to check status from our challenge
the old code had a problem and would interpret a challenge that
returned "pending" and then "invalid" as valid.
This code actually has another problem. The RFC defines:
"status (optional, string): The status of this authorization.
Possible values are: "pending", "valid", and "invalid". If this
field is missing, then the default value is "pending"."
So actually the correct way to implement this would be:
while [[ -z "${status}" ]] || [[ "${status}" = "pending" ]]; do
But without further checks this might lead to an endless loop. So this
is "good enough(tm)". ;)
Lukas Schauer [Sun, 6 Dec 2015 14:41:49 +0000 (15:41 +0100)]
removed acme-challenges directory from git, create if needed
Lukas Schauer [Sun, 6 Dec 2015 14:38:52 +0000 (15:38 +0100)]
make config.sh optional
Lukas Schauer [Sun, 6 Dec 2015 14:37:41 +0000 (15:37 +0100)]
default location for acme-challenges
Martin Geiseler [Sun, 6 Dec 2015 13:42:46 +0000 (14:42 +0100)]
Renew timeframe as config option
Martin Geiseler [Sun, 6 Dec 2015 12:51:40 +0000 (13:51 +0100)]
Check expire date of existing certs
Markus Germeier [Sun, 6 Dec 2015 13:33:00 +0000 (14:33 +0100)]
don't overwrite certificate files
In a worst case scenario the new certificate is broken and we are left
without a working certificate (or need to restore one from our backup).
This way we only need to change the symlink to the known working cert
Markus Germeier [Sun, 6 Dec 2015 11:14:51 +0000 (12:14 +0100)]
make openssl keysize configurable
Lukas Schauer [Sun, 6 Dec 2015 14:01:34 +0000 (15:01 +0100)]
use "-s" to detect content in temporary curl error logfile
Benjamin Dos Santos [Sun, 6 Dec 2015 00:33:40 +0000 (01:33 +0100)]
style: double quote to prevent globbing and word splitting
https://github.com/koalaman/shellcheck/wiki/Sc2086
Benjamin Dos Santos [Sun, 6 Dec 2015 00:26:08 +0000 (01:26 +0100)]
style: [[ ... ]] is preferred over [, test and /usr/bin/[.
https://google.github.io/styleguide/shell.xml#Test,_%5B_and_%5B%5B
Lukas Schauer [Sun, 6 Dec 2015 01:49:05 +0000 (02:49 +0100)]
Merge pull request #7 from rudis/master
add challenge hook and minor fixes/improvements
Simon Ruderich [Sun, 6 Dec 2015 00:06:17 +0000 (01:06 +0100)]
add HOOK_CHALLENGE option to run a command before the reponse
Simon Ruderich [Sat, 5 Dec 2015 17:36:34 +0000 (18:36 +0100)]
use mkdir -p to create certs/$domain/
Prevents an error if running for the first time in a different
directory.
Simon Ruderich [Sat, 5 Dec 2015 17:25:02 +0000 (18:25 +0100)]
make license agreement configurable as LICENSE
Simon Ruderich [Sat, 5 Dec 2015 17:23:22 +0000 (18:23 +0100)]
set CA setting per default
letsencrypt.sh is mainly used with letsencrypt.org.
Simon Ruderich [Sat, 5 Dec 2015 17:17:33 +0000 (18:17 +0100)]
fix typo in error string