Lukas Schauer
b5de2e26eb
sign_domain: Use existing CSR with matching timestamp
2018-02-06 20:41:26 +01:00
Lukas Schauer
73a116e879
Create required certificate and chaincache directories outside of sign_domain
2018-02-06 20:40:32 +01:00
Lukas Schauer
9c35fce61e
Pre-generate timestamp outside of sign_domain
2018-02-06 20:39:23 +01:00
Lukas Schauer
87194f6596
Remove additional whitespace from extract_altnames
2018-02-06 20:38:02 +01:00
Lukas Schauer
b53cb6643b
moved manpage to docs directory
2018-02-06 18:53:21 +01:00
Lukas Schauer
fb41783885
automatic discovery of remote acme api version
2018-02-05 19:20:28 +01:00
Lukas Schauer
6d02bfdb42
shrink "logo" a bit
2018-02-03 22:14:43 +01:00
Lukas Schauer
727443483d
added acmev2 information to readme
2018-02-03 22:12:32 +01:00
Lukas Schauer
7a0e71c6c2
follow location on http get-requests
2018-02-03 22:03:58 +01:00
Lukas Schauer
45f5c17260
fixed altname extraction of csr with wildcard domains, moved altname extraction from sign_csr to command_sign_csr
2018-02-02 23:47:29 +01:00
Lukas Schauer
61083cf522
disable globbing globally (only allow for cleanup routine)
2018-02-02 23:45:34 +01:00
Lukas Schauer
afba7c694c
moved deploy_challenge to earlier loop so it works with multiple challenge tokens on the same identifier (important for wildcard certificate), fixed array-name, removed hook-chain warning
2018-01-28 19:48:25 +01:00
Lukas Schauer
ec5dbcc816
updated changelog
2018-01-28 06:14:44 +01:00
Lukas Schauer
0f69481e2b
rewrote challenge validation to iterate over authorizations instead of altnames (fixes some acmev2 validation edgecases), also removed broken test-script (for now)
2018-01-28 06:13:37 +01:00
Lukas Schauer
6f3fed496d
rewrote donation section in readme
2018-01-28 06:13:01 +01:00
Lukas Schauer
5fd93ea874
be more verbose for acme v2 challenge handling
2018-01-27 22:51:39 +01:00
Lukas Schauer
656af8cadc
don't fail on nested json array in challenge info
2018-01-13 23:10:31 +01:00
Lukas Schauer
3e521e1c01
fixed domains.txt parsing (theoretically compatible with wildcard domains)
2018-01-13 20:54:55 +01:00
Lukas Schauer
35a9f31643
changelog template, year update
2018-01-13 20:10:32 +01:00
Lukas Schauer
4a811759dc
version 0.5.0
2018-01-13 20:08:12 +01:00
Lukas Schauer
2adc57791c
Add optional user and group configuration ( fixes #434 )
2017-12-18 00:35:26 +01:00
Lukas Schauer
f35aed6ae6
replace backticks with escaped dollarbracethingy ( fixes #438 )
2017-12-18 00:01:47 +01:00
Lukas Schauer
b6b56d0df7
export certificate alias to be used in hook scripts
2017-12-17 23:54:19 +01:00
Lukas Schauer
13c853d43b
also reset configvars after domains loop
2017-12-17 23:51:23 +01:00
Lukas Schauer
c62f3d91fc
implement certificate aliases as suggested by typingArtist ( fixes #396 )
2017-12-17 23:50:46 +01:00
Lukas Schauer
eb4aaefda1
also inform about still-valid ocsp stapling files ( fixes #457 )
2017-12-14 00:11:40 +01:00
Lukas Schauer
3d97799d6a
always revalidate challenges if --force is set ( fixes #370 )
2017-11-07 14:43:41 +01:00
Lukas Schauer
da3428a84a
use nullglob, disable warning on empty CONFIG_D directory
2017-09-21 18:10:01 +02:00
Lukas Schauer
b5e178ea75
allow for spaces when extracting commonName from csr ( fixes #423 )
2017-09-20 15:44:05 +02:00
Lukas Schauer
bc20ec79f3
also show freebsd version
2017-09-20 15:31:38 +02:00
Lukas Schauer
f838d93f40
stop verification loop after invalid challenge ( fixes #431 )
2017-09-20 15:17:30 +02:00
Lukas Schauer
58647cab65
added OPENSSL variable to example config ( #414 )
2017-07-18 15:46:25 +02:00
Lukas Schauer
c57ad87e7c
fixed error handling on non-2xx http status codes ( #413 )
2017-07-18 03:29:39 +02:00
Lukas Schauer
2687054d25
cut path from url for ocsp host
2017-07-13 00:53:32 +02:00
Lukas Schauer
2b76d038d3
ocsp fetching should now also work with older openssl versions
2017-07-12 16:00:25 +02:00
Lukas Schauer
e339b28159
add host header to ocsp request
2017-07-12 15:33:56 +02:00
Lukas Schauer
4f3bd3e956
fixed exit_hook
2017-07-11 10:06:42 +02:00
Lukas Schauer
f86290ea52
revocation: don't fail if certificate already has been revoked ( fixes #236 )
2017-07-11 01:30:30 +02:00
Lukas Schauer
f1bc2b14ba
cleanup old ocsp response files
2017-07-11 00:50:05 +02:00
Lukas Schauer
367ef574f1
export altnames so it can be used in hook scripts ( fixes #360 )
2017-07-11 00:47:37 +02:00
Lukas Schauer
4e7fb80bcd
support otherName SAN entries for domain verification ( fixes #356 )
2017-07-11 00:35:59 +02:00
Lukas Schauer
ee75c5dca7
Initial support for fetching OCSP status to be used for OCSP stapling (as suggested in #385 )
2017-07-11 00:28:36 +02:00
Lukas Schauer
82ca3ffcd3
added giant donation section to readme (please send me all your money)
2017-07-10 22:48:50 +02:00
Lukas Schauer
bb99742aa7
load config for version information but disable verification
2017-07-10 21:36:32 +02:00
Lukas Schauer
60583d3ef9
added hook to run before cron command ( fixes #371 )
2017-07-10 21:36:10 +02:00
Lukas Schauer
cbb661ca17
specify openssl config location when converting CSR to DER ( fixes #397 )
2017-07-10 20:32:05 +02:00
Lukas Schauer
67cf20765c
updated changelog
2017-07-10 20:28:38 +02:00
Lukas Schauer
89377a1004
git: ignore chains directory
2017-07-10 20:28:20 +02:00
Lukas Schauer
dc600e39b8
cleanup: also move .pem-revoked files ( fixes #237 )
2017-07-10 20:27:42 +02:00
Lukas Schauer
16e91b415b
added auto-cleanup feature to changelog
2017-07-10 20:23:27 +02:00
Lukas Schauer
e6d6882c78
added option to automatically run cleanup routine (implements #389 )
2017-07-10 20:21:30 +02:00
Lukas Schauer
db18820991
made openssl binary configurable ( closes #393 , closes #379 )
2017-07-10 19:13:52 +02:00
Lukas Schauer
2f775d0e2a
remove duplicate -a short option from --account ( fixes #410 )
2017-07-10 18:21:06 +02:00
Lukas Schauer
f2b589430c
added version command
2017-07-10 17:21:22 +02:00
Lukas Schauer
533aa80129
replaced source url with dehydrated.de
2017-07-10 17:15:29 +02:00
Lukas Schauer
d1f215b652
fixed typos as suggested by @jwilk ( closes #369 )
2017-07-10 16:55:18 +02:00
Lukas Schauer
d685463673
implemented issuer-chain cache
2017-07-10 15:06:50 +02:00
Lukas Schauer
98ad01a110
allow using parts of dehydrated without running the main script (intended for testing parts of the script)
2017-07-10 14:51:55 +02:00
Lukas Schauer
8709d21ef2
updated usage instructions in readme (added --account)
2017-07-10 14:08:29 +02:00
Lukas Schauer
6ebaae416c
removed build status from readme (test system seems to be broken...)
2017-07-10 14:07:28 +02:00
Lukas Schauer
7fc4040f47
updated changelog with account-update feature
2017-07-10 14:05:45 +02:00
Lukas Schauer
116386486b
release 0.4.0
2017-02-05 15:33:17 +01:00
Lukas Schauer
aed4272e97
improved register command ( closes #350 )
2017-02-05 15:32:29 +01:00
Lukas Schauer
ad21b41e27
also test under osx
2017-02-04 13:54:22 +01:00
Lukas Schauer
3d8d320c9f
trying to fix compatibility with mawk
2017-02-04 13:32:56 +01:00
Lukas Schauer
449490a981
Merge branch 'simondeziel-fix-example-hook'
2017-01-31 02:58:29 +01:00
Lukas Schauer
e5452922e9
whitelist handlers for example hook ( fixes #348 )
2017-01-30 03:53:59 +01:00
Lukas Schauer
ee65261ea8
exclude root certificate from certificate chain
2017-01-30 03:45:21 +01:00
Lukas Schauer
03f0dc18b9
use awk instead of grep for reading trailing line after match ( fixes #255 )
2017-01-30 00:12:01 +01:00
Lukas Schauer
197ca8e82c
Revert "curl: use custom user agent"
...
This reverts commit a5fde931f8 .
2017-01-29 22:56:42 +01:00
Lukas Schauer
a5fde931f8
curl: use custom user agent
2017-01-29 22:42:02 +01:00
Lukas Schauer
6a32f20e00
ask user to read and accept license, added register-command, fullchain.pem is now actually the full chain
2017-01-29 22:06:53 +01:00
Lukas Schauer
b2376ed437
updated changelog
2017-01-29 16:06:24 +01:00
Lukas Schauer
57197306d7
export some config variables for use within hook scripts
2017-01-29 16:03:59 +01:00
Lukas Schauer
298a7e9aaf
added exit_hook hook
2017-01-29 15:48:03 +01:00
Lukas Schauer
0f299623be
updated changelog
2017-01-29 14:33:41 +01:00
Lukas Schauer
cfc00c42a2
check for diff using command
2017-01-29 14:04:43 +01:00
Lukas Schauer
5d92c3b352
use awk instead of tr for changing case
2017-01-29 14:00:45 +01:00
Lukas Schauer
e2e2c362d2
check for mktemp using command (busybox compatibility)
2017-01-29 13:58:42 +01:00
Lukas Schauer
b36d638a91
missing filename in config path
2017-01-06 00:40:03 +01:00
Lukas Schauer
84274f7436
moved and rewritten config section of readme
2017-01-06 00:38:13 +01:00
Lukas Schauer
de36a63fe6
removed note about project renaming
2017-01-06 00:31:03 +01:00
Lukas Schauer
3c1d2673d1
trying to fix #320 again
2016-12-22 22:56:50 +01:00
Lukas Schauer
69eea9527f
removed some spaces
2016-12-22 10:00:05 +01:00
Lukas Schauer
7f30826a6d
removed temporary wrapper script
2016-12-19 01:21:43 +01:00
Lukas Schauer
607c89cae2
updated ngrok url in test.sh
2016-10-17 22:46:28 +02:00
Lukas Schauer
a316a094df
Revert "strip leading null-bytes from urlbase64" (see #282 )
...
This reverts commit 319852dc8c .
2016-09-21 13:20:51 +02:00
Lukas Schauer
319852dc8c
strip leading null-bytes from urlbase64 ( fixes #275 )
2016-09-17 13:15:15 +02:00
Lukas Schauer
7eca8aec5a
use temporary file for DER->PEM conversion ( fixes #279 )
2016-09-17 13:02:48 +02:00
Lukas Schauer
0c1e958d19
added temporary wrapper script for compatibility with old config locations and symlinks, will be removed in a few weeks
2016-09-17 12:46:46 +02:00
Lukas Schauer
ec49a4433b
fixed a few things after project rename
2016-09-13 20:00:43 +02:00
Lukas Schauer
64e35463cb
renamed project to dehydrated and main script to dehydrated.sh
2016-09-13 19:48:27 +02:00
Lukas Schauer
992beecbdb
release v0.3.0
2016-09-07 21:20:28 +02:00
Lukas Schauer
624ce4436a
updated readme
2016-08-04 00:11:08 +02:00
Lukas Schauer
d81eb58536
Only print full chain on signcsr command if --full-chain/-fc is set (related to #150 )
2016-08-04 00:11:02 +02:00
Lukas Schauer
afabfff06e
updated url to letsencrypt license agreement
2016-08-01 20:35:46 +02:00
Lukas Schauer
bd9cc5b0c4
Added option to run letsencrypt.sh without locks
...
This should only be used when letsencrypt.sh is under control by a
different script which makes sure that no two processes are touching the
same files.
2016-07-21 12:34:40 +02:00
Lukas Schauer
194464b04b
Default WELLKNOWN location is now /var/www/letsencrypt
...
With this change private and public files are now separated by default.
2016-07-20 17:04:25 +02:00
Lukas Schauer
f4138efab9
changed dependency check for diff to be compatible with openbsd diff ( fixes #219 )
2016-06-04 04:12:21 +02:00
Lukas Schauer
034ec30c7d
added multi-account support ( fixes #92 , #163 )
2016-06-04 04:01:24 +02:00