Peter Eckersley
4d312d8ffe
Better logging
2017-01-05 11:03:53 -08:00
schoen and GitHub
2cddd2f1b6
Merge pull request #3849 from thomaszbz/dev/3844-preserve-must-staple
...
Preserve --must-staple in configuration for renewal (#3844 )
together with updated version of PR #3948 Save allow_subset_of_names in renewal conf files
2017-01-04 17:46:44 -08:00
Seth Schoen
f238781c10
Add must_staple config test to parallel allow_subset_of_names test
2017-01-04 17:30:34 -08:00
Peter Eckersley
7f686b15c7
Merge remote-tracking branch 'origin/subset-renewal' into dev/3844-preserve-must-staple
2017-01-04 17:22:09 -08:00
Brad Warren
beb5db805b
Fix docstring
2017-01-04 12:59:43 -08:00
Brad Warren
dae9eee7d4
bool(len([])) == bool([])
2017-01-04 12:58:59 -08:00
Brad Warren
458c7c8131
Use a set for pre_hook.already
2017-01-04 12:57:54 -08:00
Brad Warren
b748f1afe4
Undo changes to certbot.util
2017-01-04 12:55:55 -08:00
Brad Warren
d08cf89ad2
Remove all calls to which
2017-01-04 12:54:51 -08:00
Brad Warren
42b0188519
Merge branch 'master' into save-more-hooks
2017-01-04 12:24:53 -08:00
Peter Eckersley and GitHub
8794c4fd41
Document some particularities of the revoke subcommand ( #3923 )
...
* Document some particularities of the revoke subcommand
* Add --test-cert to "run" help topic
2017-01-03 13:49:59 -08:00
Brad Warren and Peter Eckersley
12edbb53db
Fixes #3954 and adds a test to prevent regressions ( #3957 )
...
* fixes #3954 and adds test to prevent regressions
* assure pylint I know what I'm doing
* Test FileDisplay methods take force_interactive
2016-12-23 10:49:51 -08:00
Peter Eckersley
c29878ace9
lint
2016-12-23 01:03:38 -08:00
Peter Eckersley
c5bda903f2
Another instance of overlogging
2016-12-23 00:42:17 -08:00
Peter Eckersley
2fdbb8430a
Don't log errors twice
...
- They're already being logged down in util.run_script
2016-12-23 00:40:10 -08:00
Peter Eckersley
21287b414f
Finish unit tests for OCSP warning states
2016-12-23 00:24:47 -08:00
Peter Eckersley
97081452e9
fixup
2016-12-22 18:52:20 -08:00
Peter Eckersley
0011a3b7d8
Start handling some weirder OCSP states
2016-12-22 18:51:17 -08:00
Peter Eckersley and GitHub
839ff7a265
Merge pull request #3941 from certbot/ocsp
...
OCSP checking and other cool "certbot certificates" features
2016-12-22 16:21:29 -08:00
Peter Eckersley
9aa93c05c1
Simplify the ocsp_revoked() return type
...
- we weren't reacting to None, so call it False instead
2016-12-22 15:35:29 -08:00
Peter Eckersley
19143d8303
Increase test coverage
2016-12-22 13:07:00 -08:00
Brad Warren and GitHub
39f5551305
Merge the manual and script plugins ( #3890 )
...
* Start of combined manual/script plugin
* Return str from hooks.execute, not bytes
* finish manual/script rewrite
* delete old manual and script plugins
* manually specify we want chall.token
* use consistent quotes
* specify chall for uri
* s/script/hook
* fix spacing on instructions
* remove unneeded response argument
* make achall more helpful
* simplify perform
* remove old test files
* add start of manual_tests
* fix ParseTest.test_help
* stop using manual_test_mode in cli tests
* Revert "make achall more helpful"
This reverts commit 54b01cea30 .
* use bad response/validation methods on achalls
* simplify perform and cleanup environment
* finish manual tests
* Add HTTP manual hook integration test
* add manual http scripts
* Add manual DNS script integration test
* remove references to the script plugin
* they're hooks, not scripts
* add --manual-public-ip-logging-ok to integration tests
* use --pref-chall for dns integration
* does dns work?
* validate hooks
* test hook validation
* Revert "does dns work?"
This reverts commit 1224cc2961 .
* busy wait in manual-http-auth
* remove DNS script test for now
* Fix challenge prefix and add trailing .
* Add comment about universal_newlines
* Fix typo from 0464ba2c4
* fix nits and typos
* Generalize HookCOmmandNotFound error
* Add verify_exe_exists
* Don't duplicate code in hooks.py
* Revert changes to hooks.py
* Use consistent hook error messages
2016-12-22 08:24:08 -08:00
Peter Eckersley
7014ab5fd0
lint
2016-12-21 23:20:19 -08:00
Peter Eckersley
ac17f98b0c
Refactor post_hook storage during "renew"
2016-12-21 23:02:27 -08:00
Peter Eckersley
61e822a897
Add a few more tests
2016-12-21 21:50:19 -08:00
Brad Warren
efad646960
add restore_required_config_elements test
2016-12-21 16:49:24 -08:00
Brad Warren
5119d09966
save allow_subset_of_names in renew conf
2016-12-21 16:24:28 -08:00
Brad Warren
36c9c49ab9
restore allow_subset_of_names
2016-12-21 16:12:41 -08:00
Brad Warren
2bbf28b4b9
refactor _restore_required_config_elements
2016-12-21 15:49:46 -08:00
Peter Eckersley
e2d8630f5e
py3fix
2016-12-21 14:42:35 -08:00
Peter Eckersley
0ed3213989
Remove --check-ocsp flag
...
- Might have been occasionally useful, but simplicity
- Add some missing tests, remove some obsolete ones
2016-12-21 14:38:26 -08:00
Peter Eckersley
76b8c53566
Tests for ocsp.py, and associated fixes
2016-12-21 14:38:26 -08:00
Peter Eckersley
f495863da9
Check --check-ocsp flags, and test those checks
2016-12-21 14:38:26 -08:00
Peter Eckersley
509f4029bb
more py3 fixes
2016-12-21 14:38:26 -08:00
Peter Eckersley
7d02b8dbd5
py3fix
2016-12-21 14:38:26 -08:00
Peter Eckersley
fcf7387c3d
Don't crash if openssl is missing
2016-12-21 14:38:26 -08:00
Peter Eckersley
011f6055d4
Better message
2016-12-21 14:38:26 -08:00
Peter Eckersley
bf6084db61
With mixed staging/prod lineages, it might not be correct to stop OCSPing
...
- One lineage might fail, and a later one succeed
2016-12-21 14:38:26 -08:00
Peter Eckersley
15ed372df6
Fix existing tests
2016-12-21 14:38:26 -08:00
Peter Eckersley
03f312e653
Allow filtering of "certbot certificates output" with --config-name or -d
2016-12-21 14:38:26 -08:00
Peter Eckersley
e5e5db24d7
CLI flag for controlling ocsp checking now works
2016-12-21 14:38:26 -08:00
Peter Eckersley
840c584cbd
Make the OCSP checker a class
...
(Since it contains a reasonable amount of system state)
2016-12-21 14:38:26 -08:00
Peter Eckersley
7a18a124ce
Better error handling
2016-12-21 14:38:26 -08:00
Peter Eckersley
fe36e336a8
Run with both old and new versions of openssl
2016-12-21 14:38:26 -08:00
Peter Eckersley
245b84ab78
Format CLI to keep modern openssls happy
...
- This is somewhat ominous
2016-12-21 14:38:26 -08:00
Peter Eckersley
ac02cd9cb8
ocsp checking needs -verify_other
...
https://community.letsencrypt.org/t/unable-to-verify-ocsp-response/7264
2016-12-21 14:38:26 -08:00
Peter Eckersley
40e29bb95f
begin implementing OCSP checking for "certificates"
2016-12-21 14:38:20 -08:00
James Kasten and Peter Eckersley
15d2a0ffde
Import OCSP code from the historical cert_manager branch
...
(This is pde committing jdkasten's code)
2016-12-21 14:36:51 -08:00
Erica Portnoy and GitHub
8ebca1c052
Return domains for _find_domains_or_certname ( #3937 )
...
* Return domains for _find_domains_or_certname
* Revamp find_domains_or_certname
2016-12-20 17:17:01 -08:00
Brad Warren and Peter Eckersley
f92254769b
I promise checklists are OK ( fixes #3934 ) ( #3940 )
...
* TIL checklist calls input
* full coverage on certbot/display/util.py
* improve no double warning test
2016-12-20 14:34:12 -08:00