 Damien TournoudandBrad Warren
|
44a6ec29c5
|
Fix direct usages of the root logger (#4236)
Some code uses `logging.debug` and `logging.info` instead of
the file-specific logger in `logger.debug` and `logger.info`.
|
2017-02-27 18:13:06 -08:00 |
|
Peter Eckersley
|
e05d537ff5
|
Avoid code repetition
|
2017-01-05 12:16:03 -08:00 |
|
Peter Eckersley
|
707b27418f
|
Explicitly handle "unknown" responses from openssl
|
2017-01-05 12:06:51 -08:00 |
|
Peter Eckersley
|
abd062cb94
|
Handle warnings in "revoked" responses too
|
2017-01-05 11:55:19 -08:00 |
|
Peter Eckersley
|
b1be49c14f
|
Openssl black magic
* With _some_ versions of openssl, when checking OCSP for staging certs
only, we need this -trust_other flag
|
2017-01-05 11:04:01 -08:00 |
|
Peter Eckersley
|
4d312d8ffe
|
Better logging
|
2017-01-05 11:03:53 -08:00 |
|
Peter Eckersley
|
c29878ace9
|
lint
|
2016-12-23 01:03:38 -08:00 |
|
Peter Eckersley
|
c5bda903f2
|
Another instance of overlogging
|
2016-12-23 00:42:17 -08:00 |
|
Peter Eckersley
|
2fdbb8430a
|
Don't log errors twice
- They're already being logged down in util.run_script
|
2016-12-23 00:40:10 -08:00 |
|
Peter Eckersley
|
97081452e9
|
fixup
|
2016-12-22 18:52:20 -08:00 |
|
Peter Eckersley
|
0011a3b7d8
|
Start handling some weirder OCSP states
|
2016-12-22 18:51:17 -08:00 |
|
Peter Eckersley
|
9aa93c05c1
|
Simplify the ocsp_revoked() return type
- we weren't reacting to None, so call it False instead
|
2016-12-22 15:35:29 -08:00 |
|
Peter Eckersley
|
0ed3213989
|
Remove --check-ocsp flag
- Might have been occasionally useful, but simplicity
- Add some missing tests, remove some obsolete ones
|
2016-12-21 14:38:26 -08:00 |
|
Peter Eckersley
|
76b8c53566
|
Tests for ocsp.py, and associated fixes
|
2016-12-21 14:38:26 -08:00 |
|
Peter Eckersley
|
509f4029bb
|
more py3 fixes
|
2016-12-21 14:38:26 -08:00 |
|
Peter Eckersley
|
7d02b8dbd5
|
py3fix
|
2016-12-21 14:38:26 -08:00 |
|
Peter Eckersley
|
fcf7387c3d
|
Don't crash if openssl is missing
|
2016-12-21 14:38:26 -08:00 |
|
Peter Eckersley
|
011f6055d4
|
Better message
|
2016-12-21 14:38:26 -08:00 |
|
Peter Eckersley
|
bf6084db61
|
With mixed staging/prod lineages, it might not be correct to stop OCSPing
- One lineage might fail, and a later one succeed
|
2016-12-21 14:38:26 -08:00 |
|
Peter Eckersley
|
e5e5db24d7
|
CLI flag for controlling ocsp checking now works
|
2016-12-21 14:38:26 -08:00 |
|
Peter Eckersley
|
840c584cbd
|
Make the OCSP checker a class
(Since it contains a reasonable amount of system state)
|
2016-12-21 14:38:26 -08:00 |
|
Peter Eckersley
|
7a18a124ce
|
Better error handling
|
2016-12-21 14:38:26 -08:00 |
|
Peter Eckersley
|
fe36e336a8
|
Run with both old and new versions of openssl
|
2016-12-21 14:38:26 -08:00 |
|
Peter Eckersley
|
245b84ab78
|
Format CLI to keep modern openssls happy
- This is somewhat ominous
|
2016-12-21 14:38:26 -08:00 |
|
Peter Eckersley
|
ac02cd9cb8
|
ocsp checking needs -verify_other
https://community.letsencrypt.org/t/unable-to-verify-ocsp-response/7264
|
2016-12-21 14:38:26 -08:00 |
|
Peter Eckersley
|
40e29bb95f
|
begin implementing OCSP checking for "certificates"
|
2016-12-21 14:38:20 -08:00 |
|
 James KastenandPeter Eckersley
|
15d2a0ffde
|
Import OCSP code from the historical cert_manager branch
(This is pde committing jdkasten's code)
|
2016-12-21 14:36:51 -08:00 |
|