Cloudflare DNS Authenticator

Implement an Authenticator which can fulfill a dns-01 challenge using the
Cloudflare API. Applicable only for domains using Cloudflare for DNS.

Testing Done:
 * `tox -e py27`
 * `tox -e lint`
 * Manual testing:
    * Used `certbot certonly --dns-cloudflare -d`, specifying a
      credentials file as a command line argument. Verified that a
      certificate was successfully obtained without user interaction.
    * Used `certbot certonly --dns-cloudflare -d`, without specifying a
      credentials file as a command line argument. Verified that the user
      was prompted and that a certificate was successfully obtained.
    * Used `certbot certonly -d`. Verified that the user was prompted for
      a credentials file after selecting cloudflare interactively and
      that a certificate was successfully obtained.
    * Used `certbot renew --force-renewal`. Verified that certificates
      were renewed without user interaction.
 * Negative testing:
    * Path to non-existent credentials file.
    * Credentials file with unsafe permissions (644).
    * Credentials file missing e-mail address.
    * Credentials file with blank API key.
    * Credentials file with incorrect e-mail address.
    * Credentials file with malformed API key.
    * Credentials file with invalid API key.
    * Domain name not registered to Cloudflare account.
This commit is contained in:
Zach Shepherd
2017-05-10 15:26:51 -07:00
parent 6670f828ef
commit db6defe614
26 changed files with 1562 additions and 8 deletions
+2
View File
@@ -1221,6 +1221,8 @@ def _plugins_parsing(helpful, plugins):
help='Provide laborious manual instructions for obtaining a cert')
helpful.add(["plugins", "certonly"], "--webroot", action="store_true",
help='Obtain certs by placing files in a webroot directory.')
helpful.add(["plugins", "certonly"], "--dns-cloudflare", action="store_true",
help='Obtain certs using a DNS TXT record (if you are using Cloudflare for DNS).')
# things should not be reorder past/pre this comment:
# plugins_group should be displayed in --help before plugin