DigitalOcean DNS Authenticator

Implement an Authenticator which can fulfill a dns-01 challenge using the
DigitalOcean API. Applicable only for domains using DigitalOcean for DNS.

Testing Done:
 * `tox -e py27`
 * `tox -e lint`
 * Manual testing:
    * Used `certbot certonly --dns-digitalocean -d`, specifying a
      credentials file as a command line argument. Verified that a
      certificate was successfully obtained without user interaction.
    * Used `certbot certonly --dns-digitalocean -d`, without specifying a
      credentials file as a command line argument. Verified that the user
      was prompted and that a certificate was successfully obtained.
    * Used `certbot certonly -d`. Verified that the user was prompted for
      a credentials file after selecting digitalocean interactively and
      that a certificate was successfully obtained.
    * Used `certbot renew --force-renewal`. Verified that certificates
      were renewed without user interaction.
 * Negative testing:
    * Path to non-existent credentials file.
    * Credentials file with unsafe permissions (644).
    * Credentials file missing token.
    * Credentials file with blank token.
    * Credentials file with incorrect token.
    * Domain name not registered to DigitalOcean account.
This commit is contained in:
Zach Shepherd
2017-05-11 17:26:02 -07:00
parent 71451dd54b
commit 9e206f8024
22 changed files with 897 additions and 4 deletions
+2
View File
@@ -1223,6 +1223,8 @@ def _plugins_parsing(helpful, plugins):
help='Obtain certs by placing files in a webroot directory.')
helpful.add(["plugins", "certonly"], "--dns-cloudflare", action="store_true",
help='Obtain certs using a DNS TXT record (if you are using Cloudflare for DNS).')
helpful.add(["plugins", "certonly"], "--dns-digitalocean", action="store_true",
help='Obtain certs using a DNS TXT record (if you are using DigitalOcean for DNS).')
# things should not be reorder past/pre this comment:
# plugins_group should be displayed in --help before plugin
+1
View File
@@ -29,6 +29,7 @@ class PluginEntryPoint(object):
"certbot",
"certbot-apache",
"certbot-dns-cloudflare",
"certbot-dns-digitalocean",
"certbot-nginx",
]
"""Distributions for which prefix will be omitted."""
+3 -1
View File
@@ -133,7 +133,7 @@ def choose_plugin(prepared, question):
else:
return None
noninstaller_plugins = ["webroot", "manual", "standalone", "dns-cloudflare"]
noninstaller_plugins = ["webroot", "manual", "standalone", "dns-cloudflare", "dns-digitalocean"]
def record_chosen_plugins(config, plugins, auth, inst):
"Update the config entries to reflect the plugins we actually selected."
@@ -239,6 +239,8 @@ def cli_plugin_requests(config):
req_auth = set_configurator(req_auth, "manual")
if config.dns_cloudflare:
req_auth = set_configurator(req_auth, "dns-cloudflare")
if config.dns_digitalocean:
req_auth = set_configurator(req_auth, "dns-digitalocean")
logger.debug("Requested authenticator %s and installer %s", req_auth, req_inst)
return req_auth, req_inst