mirror of
https://github.com/certbot/certbot.git
synced 2026-08-02 19:31:51 +02:00
Warn when using deprecated acme.challenges.TLSSNI01 (#6469)
* Warn when using deprecated acme.challenges.TLSSNI01 * Update changelog * remove specific date from warning * add a raw assert for mypy optional type checking
This commit is contained in:
@@ -14,6 +14,7 @@ Certbot adheres to [Semantic Versioning](http://semver.org/).
|
|||||||
* Removed documentation mentions of `#letsencrypt` IRC on Freenode.
|
* Removed documentation mentions of `#letsencrypt` IRC on Freenode.
|
||||||
* Write README to the base of (config-dir)/live directory
|
* Write README to the base of (config-dir)/live directory
|
||||||
* `--manual` will explicitly warn users that earlier challenges should remain in place when setting up subsequent challenges.
|
* `--manual` will explicitly warn users that earlier challenges should remain in place when setting up subsequent challenges.
|
||||||
|
* Warn when using deprecated acme.challenges.TLSSNI01
|
||||||
* Stop preferring TLS-SNI in the Apache, Nginx, and standalone plugins
|
* Stop preferring TLS-SNI in the Apache, Nginx, and standalone plugins
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ import functools
|
|||||||
import hashlib
|
import hashlib
|
||||||
import logging
|
import logging
|
||||||
import socket
|
import socket
|
||||||
|
import warnings
|
||||||
|
|
||||||
from cryptography.hazmat.primitives import hashes # type: ignore
|
from cryptography.hazmat.primitives import hashes # type: ignore
|
||||||
import josepy as jose
|
import josepy as jose
|
||||||
@@ -493,6 +494,11 @@ class TLSSNI01(KeyAuthorizationChallenge):
|
|||||||
# boulder#962, ietf-wg-acme#22
|
# boulder#962, ietf-wg-acme#22
|
||||||
#n = jose.Field("n", encoder=int, decoder=int)
|
#n = jose.Field("n", encoder=int, decoder=int)
|
||||||
|
|
||||||
|
def __init__(self, *args, **kwargs):
|
||||||
|
warnings.warn("TLS-SNI-01 is deprecated, and will stop working soon.",
|
||||||
|
DeprecationWarning, stacklevel=2)
|
||||||
|
super(TLSSNI01, self).__init__(*args, **kwargs)
|
||||||
|
|
||||||
def validation(self, account_key, **kwargs):
|
def validation(self, account_key, **kwargs):
|
||||||
"""Generate validation.
|
"""Generate validation.
|
||||||
|
|
||||||
|
|||||||
@@ -1,5 +1,6 @@
|
|||||||
"""Tests for acme.challenges."""
|
"""Tests for acme.challenges."""
|
||||||
import unittest
|
import unittest
|
||||||
|
import warnings
|
||||||
|
|
||||||
import josepy as jose
|
import josepy as jose
|
||||||
import mock
|
import mock
|
||||||
@@ -360,20 +361,29 @@ class TLSSNI01ResponseTest(unittest.TestCase):
|
|||||||
class TLSSNI01Test(unittest.TestCase):
|
class TLSSNI01Test(unittest.TestCase):
|
||||||
|
|
||||||
def setUp(self):
|
def setUp(self):
|
||||||
from acme.challenges import TLSSNI01
|
|
||||||
self.msg = TLSSNI01(
|
|
||||||
token=jose.b64decode('a82d5ff8ef740d12881f6d3c2277ab2e'))
|
|
||||||
self.jmsg = {
|
self.jmsg = {
|
||||||
'type': 'tls-sni-01',
|
'type': 'tls-sni-01',
|
||||||
'token': 'a82d5ff8ef740d12881f6d3c2277ab2e',
|
'token': 'a82d5ff8ef740d12881f6d3c2277ab2e',
|
||||||
}
|
}
|
||||||
|
|
||||||
|
def _msg(self):
|
||||||
|
from acme.challenges import TLSSNI01
|
||||||
|
with warnings.catch_warnings(record=True) as warn:
|
||||||
|
warnings.simplefilter("always")
|
||||||
|
msg = TLSSNI01(
|
||||||
|
token=jose.b64decode('a82d5ff8ef740d12881f6d3c2277ab2e'))
|
||||||
|
assert warn is not None # using a raw assert for mypy
|
||||||
|
self.assertTrue(len(warn) == 1)
|
||||||
|
self.assertTrue(issubclass(warn[-1].category, DeprecationWarning))
|
||||||
|
self.assertTrue('deprecated' in str(warn[-1].message))
|
||||||
|
return msg
|
||||||
|
|
||||||
def test_to_partial_json(self):
|
def test_to_partial_json(self):
|
||||||
self.assertEqual(self.jmsg, self.msg.to_partial_json())
|
self.assertEqual(self.jmsg, self._msg().to_partial_json())
|
||||||
|
|
||||||
def test_from_json(self):
|
def test_from_json(self):
|
||||||
from acme.challenges import TLSSNI01
|
from acme.challenges import TLSSNI01
|
||||||
self.assertEqual(self.msg, TLSSNI01.from_json(self.jmsg))
|
self.assertEqual(self._msg(), TLSSNI01.from_json(self.jmsg))
|
||||||
|
|
||||||
def test_from_json_hashable(self):
|
def test_from_json_hashable(self):
|
||||||
from acme.challenges import TLSSNI01
|
from acme.challenges import TLSSNI01
|
||||||
@@ -388,7 +398,7 @@ class TLSSNI01Test(unittest.TestCase):
|
|||||||
@mock.patch('acme.challenges.TLSSNI01Response.gen_cert')
|
@mock.patch('acme.challenges.TLSSNI01Response.gen_cert')
|
||||||
def test_validation(self, mock_gen_cert):
|
def test_validation(self, mock_gen_cert):
|
||||||
mock_gen_cert.return_value = ('cert', 'key')
|
mock_gen_cert.return_value = ('cert', 'key')
|
||||||
self.assertEqual(('cert', 'key'), self.msg.validation(
|
self.assertEqual(('cert', 'key'), self._msg().validation(
|
||||||
KEY, cert_key=mock.sentinel.cert_key))
|
KEY, cert_key=mock.sentinel.cert_key))
|
||||||
mock_gen_cert.assert_called_once_with(key=mock.sentinel.cert_key)
|
mock_gen_cert.assert_called_once_with(key=mock.sentinel.cert_key)
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user