mirror of
https://github.com/certbot/certbot.git
synced 2026-08-03 20:02:16 +02:00
Merge remote-tracking branch 'upstream/master' into multios_apache
This commit is contained in:
@@ -22,3 +22,7 @@ letsencrypt.log
|
|||||||
|
|
||||||
# auth --cert-path --chain-path
|
# auth --cert-path --chain-path
|
||||||
/*.pem
|
/*.pem
|
||||||
|
|
||||||
|
# letstest
|
||||||
|
tests/letstest/letest-*/
|
||||||
|
tests/letstest/*.pem
|
||||||
|
|||||||
@@ -1306,6 +1306,7 @@ class ApacheConfigurator(augeas_configurator.AugeasConfigurator):
|
|||||||
|
|
||||||
"""
|
"""
|
||||||
self.config_test()
|
self.config_test()
|
||||||
|
logger.debug(self.reverter.view_config_changes())
|
||||||
self._reload()
|
self._reload()
|
||||||
|
|
||||||
def _reload(self):
|
def _reload(self):
|
||||||
|
|||||||
@@ -75,7 +75,7 @@ REWRITE_HTTPS_ARGS_WITH_END = [
|
|||||||
https vhost"""
|
https vhost"""
|
||||||
|
|
||||||
HSTS_ARGS = ["always", "set", "Strict-Transport-Security",
|
HSTS_ARGS = ["always", "set", "Strict-Transport-Security",
|
||||||
"\"max-age=31536000; includeSubDomains\""]
|
"\"max-age=31536000\""]
|
||||||
"""Apache header arguments for HSTS"""
|
"""Apache header arguments for HSTS"""
|
||||||
|
|
||||||
UIR_ARGS = ["always", "set", "Content-Security-Policy",
|
UIR_ARGS = ["always", "set", "Content-Security-Policy",
|
||||||
|
|||||||
@@ -1,12 +1,14 @@
|
|||||||
"""A class that performs TLS-SNI-01 challenges for Apache"""
|
"""A class that performs TLS-SNI-01 challenges for Apache"""
|
||||||
|
|
||||||
import os
|
import os
|
||||||
|
import logging
|
||||||
|
|
||||||
from letsencrypt.plugins import common
|
from letsencrypt.plugins import common
|
||||||
|
|
||||||
from letsencrypt_apache import obj
|
from letsencrypt_apache import obj
|
||||||
from letsencrypt_apache import parser
|
from letsencrypt_apache import parser
|
||||||
|
|
||||||
|
logger = logging.getLogger(__name__)
|
||||||
|
|
||||||
class ApacheTlsSni01(common.TLSSNI01):
|
class ApacheTlsSni01(common.TLSSNI01):
|
||||||
"""Class that performs TLS-SNI-01 challenges within the Apache configurator
|
"""Class that performs TLS-SNI-01 challenges within the Apache configurator
|
||||||
@@ -104,6 +106,7 @@ class ApacheTlsSni01(common.TLSSNI01):
|
|||||||
self.configurator.reverter.register_file_creation(
|
self.configurator.reverter.register_file_creation(
|
||||||
True, self.challenge_conf)
|
True, self.challenge_conf)
|
||||||
|
|
||||||
|
logger.debug("writing a config file with text: %s", config_text)
|
||||||
with open(self.challenge_conf, "w") as new_conf:
|
with open(self.challenge_conf, "w") as new_conf:
|
||||||
new_conf.write(config_text)
|
new_conf.write(config_text)
|
||||||
|
|
||||||
|
|||||||
@@ -15,11 +15,12 @@ from acme import crypto_util
|
|||||||
from acme import messages
|
from acme import messages
|
||||||
from letsencrypt import achallenges
|
from letsencrypt import achallenges
|
||||||
from letsencrypt import errors as le_errors
|
from letsencrypt import errors as le_errors
|
||||||
from letsencrypt import validator
|
|
||||||
from letsencrypt.tests import acme_util
|
from letsencrypt.tests import acme_util
|
||||||
|
|
||||||
from letsencrypt_compatibility_test import errors
|
from letsencrypt_compatibility_test import errors
|
||||||
from letsencrypt_compatibility_test import util
|
from letsencrypt_compatibility_test import util
|
||||||
|
from letsencrypt_compatibility_test import validator
|
||||||
|
|
||||||
from letsencrypt_compatibility_test.configurators.apache import apache24
|
from letsencrypt_compatibility_test.configurators.apache import apache24
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
+19
-16
@@ -1,4 +1,4 @@
|
|||||||
"""Tests for letsencrypt.validator."""
|
"""Tests for letsencrypt_compatibility_test.validator."""
|
||||||
import requests
|
import requests
|
||||||
import unittest
|
import unittest
|
||||||
|
|
||||||
@@ -6,28 +6,31 @@ import mock
|
|||||||
import OpenSSL
|
import OpenSSL
|
||||||
|
|
||||||
from acme import errors as acme_errors
|
from acme import errors as acme_errors
|
||||||
from letsencrypt import validator
|
from letsencrypt_compatibility_test import validator
|
||||||
|
|
||||||
|
|
||||||
class ValidatorTest(unittest.TestCase):
|
class ValidatorTest(unittest.TestCase):
|
||||||
def setUp(self):
|
def setUp(self):
|
||||||
self.validator = validator.Validator()
|
self.validator = validator.Validator()
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.crypto_util.probe_sni")
|
@mock.patch(
|
||||||
|
"letsencrypt_compatibility_test.validator.crypto_util.probe_sni")
|
||||||
def test_certificate_success(self, mock_probe_sni):
|
def test_certificate_success(self, mock_probe_sni):
|
||||||
cert = OpenSSL.crypto.X509()
|
cert = OpenSSL.crypto.X509()
|
||||||
mock_probe_sni.return_value = cert
|
mock_probe_sni.return_value = cert
|
||||||
self.assertTrue(self.validator.certificate(
|
self.assertTrue(self.validator.certificate(
|
||||||
cert, "test.com", "127.0.0.1"))
|
cert, "test.com", "127.0.0.1"))
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.crypto_util.probe_sni")
|
@mock.patch(
|
||||||
|
"letsencrypt_compatibility_test.validator.crypto_util.probe_sni")
|
||||||
def test_certificate_error(self, mock_probe_sni):
|
def test_certificate_error(self, mock_probe_sni):
|
||||||
cert = OpenSSL.crypto.X509()
|
cert = OpenSSL.crypto.X509()
|
||||||
mock_probe_sni.side_effect = [acme_errors.Error]
|
mock_probe_sni.side_effect = [acme_errors.Error]
|
||||||
self.assertFalse(self.validator.certificate(
|
self.assertFalse(self.validator.certificate(
|
||||||
cert, "test.com", "127.0.0.1"))
|
cert, "test.com", "127.0.0.1"))
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.crypto_util.probe_sni")
|
@mock.patch(
|
||||||
|
"letsencrypt_compatibility_test.validator.crypto_util.probe_sni")
|
||||||
def test_certificate_failure(self, mock_probe_sni):
|
def test_certificate_failure(self, mock_probe_sni):
|
||||||
cert = OpenSSL.crypto.X509()
|
cert = OpenSSL.crypto.X509()
|
||||||
cert.set_serial_number(1337)
|
cert.set_serial_number(1337)
|
||||||
@@ -35,67 +38,67 @@ class ValidatorTest(unittest.TestCase):
|
|||||||
self.assertFalse(self.validator.certificate(
|
self.assertFalse(self.validator.certificate(
|
||||||
cert, "test.com", "127.0.0.1"))
|
cert, "test.com", "127.0.0.1"))
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.requests.get")
|
@mock.patch("letsencrypt_compatibility_test.validator.requests.get")
|
||||||
def test_succesful_redirect(self, mock_get_request):
|
def test_succesful_redirect(self, mock_get_request):
|
||||||
mock_get_request.return_value = create_response(
|
mock_get_request.return_value = create_response(
|
||||||
301, {"location": "https://test.com"})
|
301, {"location": "https://test.com"})
|
||||||
self.assertTrue(self.validator.redirect("test.com"))
|
self.assertTrue(self.validator.redirect("test.com"))
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.requests.get")
|
@mock.patch("letsencrypt_compatibility_test.validator.requests.get")
|
||||||
def test_redirect_with_headers(self, mock_get_request):
|
def test_redirect_with_headers(self, mock_get_request):
|
||||||
mock_get_request.return_value = create_response(
|
mock_get_request.return_value = create_response(
|
||||||
301, {"location": "https://test.com"})
|
301, {"location": "https://test.com"})
|
||||||
self.assertTrue(self.validator.redirect(
|
self.assertTrue(self.validator.redirect(
|
||||||
"test.com", headers={"Host": "test.com"}))
|
"test.com", headers={"Host": "test.com"}))
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.requests.get")
|
@mock.patch("letsencrypt_compatibility_test.validator.requests.get")
|
||||||
def test_redirect_missing_location(self, mock_get_request):
|
def test_redirect_missing_location(self, mock_get_request):
|
||||||
mock_get_request.return_value = create_response(301)
|
mock_get_request.return_value = create_response(301)
|
||||||
self.assertFalse(self.validator.redirect("test.com"))
|
self.assertFalse(self.validator.redirect("test.com"))
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.requests.get")
|
@mock.patch("letsencrypt_compatibility_test.validator.requests.get")
|
||||||
def test_redirect_wrong_status_code(self, mock_get_request):
|
def test_redirect_wrong_status_code(self, mock_get_request):
|
||||||
mock_get_request.return_value = create_response(
|
mock_get_request.return_value = create_response(
|
||||||
201, {"location": "https://test.com"})
|
201, {"location": "https://test.com"})
|
||||||
self.assertFalse(self.validator.redirect("test.com"))
|
self.assertFalse(self.validator.redirect("test.com"))
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.requests.get")
|
@mock.patch("letsencrypt_compatibility_test.validator.requests.get")
|
||||||
def test_redirect_wrong_redirect_code(self, mock_get_request):
|
def test_redirect_wrong_redirect_code(self, mock_get_request):
|
||||||
mock_get_request.return_value = create_response(
|
mock_get_request.return_value = create_response(
|
||||||
303, {"location": "https://test.com"})
|
303, {"location": "https://test.com"})
|
||||||
self.assertFalse(self.validator.redirect("test.com"))
|
self.assertFalse(self.validator.redirect("test.com"))
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.requests.get")
|
@mock.patch("letsencrypt_compatibility_test.validator.requests.get")
|
||||||
def test_hsts_empty(self, mock_get_request):
|
def test_hsts_empty(self, mock_get_request):
|
||||||
mock_get_request.return_value = create_response(
|
mock_get_request.return_value = create_response(
|
||||||
headers={"strict-transport-security": ""})
|
headers={"strict-transport-security": ""})
|
||||||
self.assertFalse(self.validator.hsts("test.com"))
|
self.assertFalse(self.validator.hsts("test.com"))
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.requests.get")
|
@mock.patch("letsencrypt_compatibility_test.validator.requests.get")
|
||||||
def test_hsts_malformed(self, mock_get_request):
|
def test_hsts_malformed(self, mock_get_request):
|
||||||
mock_get_request.return_value = create_response(
|
mock_get_request.return_value = create_response(
|
||||||
headers={"strict-transport-security": "sdfal"})
|
headers={"strict-transport-security": "sdfal"})
|
||||||
self.assertFalse(self.validator.hsts("test.com"))
|
self.assertFalse(self.validator.hsts("test.com"))
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.requests.get")
|
@mock.patch("letsencrypt_compatibility_test.validator.requests.get")
|
||||||
def test_hsts_bad_max_age(self, mock_get_request):
|
def test_hsts_bad_max_age(self, mock_get_request):
|
||||||
mock_get_request.return_value = create_response(
|
mock_get_request.return_value = create_response(
|
||||||
headers={"strict-transport-security": "max-age=not-an-int"})
|
headers={"strict-transport-security": "max-age=not-an-int"})
|
||||||
self.assertFalse(self.validator.hsts("test.com"))
|
self.assertFalse(self.validator.hsts("test.com"))
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.requests.get")
|
@mock.patch("letsencrypt_compatibility_test.validator.requests.get")
|
||||||
def test_hsts_expire(self, mock_get_request):
|
def test_hsts_expire(self, mock_get_request):
|
||||||
mock_get_request.return_value = create_response(
|
mock_get_request.return_value = create_response(
|
||||||
headers={"strict-transport-security": "max-age=3600"})
|
headers={"strict-transport-security": "max-age=3600"})
|
||||||
self.assertFalse(self.validator.hsts("test.com"))
|
self.assertFalse(self.validator.hsts("test.com"))
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.requests.get")
|
@mock.patch("letsencrypt_compatibility_test.validator.requests.get")
|
||||||
def test_hsts(self, mock_get_request):
|
def test_hsts(self, mock_get_request):
|
||||||
mock_get_request.return_value = create_response(
|
mock_get_request.return_value = create_response(
|
||||||
headers={"strict-transport-security": "max-age=31536000"})
|
headers={"strict-transport-security": "max-age=31536000"})
|
||||||
self.assertTrue(self.validator.hsts("test.com"))
|
self.assertTrue(self.validator.hsts("test.com"))
|
||||||
|
|
||||||
@mock.patch("letsencrypt.validator.requests.get")
|
@mock.patch("letsencrypt_compatibility_test.validator.requests.get")
|
||||||
def test_hsts_include_subdomains(self, mock_get_request):
|
def test_hsts_include_subdomains(self, mock_get_request):
|
||||||
mock_get_request.return_value = create_response(
|
mock_get_request.return_value = create_response(
|
||||||
headers={"strict-transport-security":
|
headers={"strict-transport-security":
|
||||||
@@ -10,6 +10,7 @@ install_requires = [
|
|||||||
'letsencrypt=={0}'.format(version),
|
'letsencrypt=={0}'.format(version),
|
||||||
'letsencrypt-apache=={0}'.format(version),
|
'letsencrypt-apache=={0}'.format(version),
|
||||||
'docker-py',
|
'docker-py',
|
||||||
|
'requests',
|
||||||
'zope.interface',
|
'zope.interface',
|
||||||
]
|
]
|
||||||
|
|
||||||
@@ -18,6 +19,11 @@ if sys.version_info < (2, 7):
|
|||||||
else:
|
else:
|
||||||
install_requires.append('mock')
|
install_requires.append('mock')
|
||||||
|
|
||||||
|
if sys.version_info < (2, 7, 9):
|
||||||
|
# For secure SSL connexion with Python 2.7 (InsecurePlatformWarning)
|
||||||
|
install_requires.append('ndg-httpsclient')
|
||||||
|
install_requires.append('pyasn1')
|
||||||
|
|
||||||
docs_extras = [
|
docs_extras = [
|
||||||
'repoze.sphinx.autointerface',
|
'repoze.sphinx.autointerface',
|
||||||
'Sphinx>=1.0', # autodoc_member_order = 'bysource', autodoc_default_flags
|
'Sphinx>=1.0', # autodoc_member_order = 'bysource', autodoc_default_flags
|
||||||
|
|||||||
@@ -450,12 +450,15 @@ class RenewableCert(object): # pylint: disable=too-many-instance-attributes
|
|||||||
:param int version: the desired version number
|
:param int version: the desired version number
|
||||||
:returns: the subject names
|
:returns: the subject names
|
||||||
:rtype: `list` of `str`
|
:rtype: `list` of `str`
|
||||||
|
:raises .CertStorageError: if could not find cert file.
|
||||||
|
|
||||||
"""
|
"""
|
||||||
if version is None:
|
if version is None:
|
||||||
target = self.current_target("cert")
|
target = self.current_target("cert")
|
||||||
else:
|
else:
|
||||||
target = self.version("cert", version)
|
target = self.version("cert", version)
|
||||||
|
if target is None:
|
||||||
|
raise errors.CertStorageError("could not find cert file")
|
||||||
with open(target) as f:
|
with open(target) as f:
|
||||||
return crypto_util.get_sans_from_cert(f.read())
|
return crypto_util.get_sans_from_cert(f.read())
|
||||||
|
|
||||||
|
|||||||
@@ -40,7 +40,6 @@ install_requires = [
|
|||||||
'pyrfc3339',
|
'pyrfc3339',
|
||||||
'python2-pythondialog>=3.2.2rc1', # Debian squeeze support, cf. #280
|
'python2-pythondialog>=3.2.2rc1', # Debian squeeze support, cf. #280
|
||||||
'pytz',
|
'pytz',
|
||||||
'requests',
|
|
||||||
'setuptools', # pkg_resources
|
'setuptools', # pkg_resources
|
||||||
'six',
|
'six',
|
||||||
'zope.component',
|
'zope.component',
|
||||||
@@ -61,11 +60,6 @@ else:
|
|||||||
'mock',
|
'mock',
|
||||||
])
|
])
|
||||||
|
|
||||||
if sys.version_info < (2, 7, 9):
|
|
||||||
# For secure SSL connexion with Python 2.7 (InsecurePlatformWarning)
|
|
||||||
install_requires.append('ndg-httpsclient')
|
|
||||||
install_requires.append('pyasn1')
|
|
||||||
|
|
||||||
dev_extras = [
|
dev_extras = [
|
||||||
# Pin astroid==1.3.5, pylint==1.4.2 as a workaround for #289
|
# Pin astroid==1.3.5, pylint==1.4.2 as a workaround for #289
|
||||||
'astroid==1.3.5',
|
'astroid==1.3.5',
|
||||||
|
|||||||
Reference in New Issue
Block a user