mirror of
https://github.com/certbot/certbot.git
synced 2026-07-28 00:35:50 +02:00
9599364837459b6dea19589b3e65be65f63a1950
Fixes https://github.com/certbot/certbot/issues/10180. So first of all, the core issue here is that [pyca deliberately chose](https://github.com/pyca/cryptography/blob/ec80c1c2894320d30fd674ea2c6103d91b4e777e/src/cryptography/utils.py#L15-L18) to override the default python functionality and make deprecation warnings appear by default. This isn't common. If they'd actually used a `DeprecationWarning`, it wouldn't have shown up to users, at least. That being said, we should still try to catch it, as we do in fact want to know about deprecation warnings for our own updates. To do that, this PR searches upwards for a `pytest.ini` file from the file's location. If found, it reads the warnings from the file, and passes them using the `PYTHONWARNINGS` env variable. It also explicitly sets warnings to `error` always in case we can't find the `pytest.ini`, and ignores the subsequent unverified-https-on-localhost warning. It also fixes a warning in our test nginx config that seemed reasonable to address. I tested this by adding a temporary warning, which I then removed, but since it turned out there were two other warnings, that wasn't actually necessary. Options I considered and rejected: - Switch from `atexit` to calling `main` directly. To do this, we'd have to switch our `main` function to something like a try-finally. That's complicated by the fact that we call `atexit` from other places in the code. Also, `exc_info` isn't availabe in `finally` while it is in `at_exit`, so it's not as versatile. But mostly if we wanted to do this, we'd have to implement a custom atexit handler, basically, and that seems worse than this option. - Looking into pytest-forked. It's apparently buggy and not being maintained. Not even sure this is what it's for anyway. - Multiple [-W](https://docs.python.org/3/using/cmdline.html#cmdoption-W) options can be given instead of an env variable. The env version seemed cleaner. - More closely mimicking [how pytest finds ini files](https://docs.pytest.org/en/stable/reference/customize.html#finding-the-rootdir). It seemed unnecessary to me. Potential drawbacks: - If we move or rename the `pytest.ini` file and for some reason don't do a reasonable grep for `pytest.ini`, we will no longer catch any additional `ignore`s in there. But imo we're likely to do that grep, and also a missing ignore will then show up when we run the tests.
Add --use-pep517 flag to pip to silence warning in tools/venv.py, and switch codebase to src-layout (#10249)
This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
.. This file contains a series of comments that are used to include sections of this README in other files. Do not modify these comments unless you know what you are doing. tag:intro-begin |build-status| .. |build-status| image:: https://img.shields.io/azure-devops/build/certbot/ba534f81-a483-4b9b-9b4e-a60bec8fee72/5/main :target: https://dev.azure.com/certbot/certbot/_build?definitionId=5 :alt: Azure Pipelines CI status .. image:: https://raw.githubusercontent.com/EFForg/design/master/logos/certbot/eff-certbot-lockup.png :width: 200 :alt: EFF Certbot Logo Certbot is part of EFF’s effort to encrypt the entire Internet. Secure communication over the Web relies on HTTPS, which requires the use of a digital certificate that lets browsers verify the identity of web servers (e.g., is that really google.com?). Web servers obtain their certificates from trusted third parties called certificate authorities (CAs). Certbot is an easy-to-use client that fetches a certificate from Let’s Encrypt—an open certificate authority launched by the EFF, Mozilla, and others—and deploys it to a web server. Anyone who has gone through the trouble of setting up a secure website knows what a hassle getting and maintaining a certificate is. Certbot and Let’s Encrypt can automate away the pain and let you turn on and manage HTTPS with simple commands. Using Certbot and Let's Encrypt is free. .. _installation: Getting Started --------------- The best way to get started is to use our `interactive guide <https://certbot.eff.org>`_. It generates instructions based on your configuration settings. In most cases, you’ll need `root or administrator access <https://certbot.eff.org/faq/#does-certbot-require-root-administrator-privileges>`_ to your web server to run Certbot. Certbot is meant to be run directly on your web server on the command line, not on your personal computer. If you’re using a hosted service and don’t have direct access to your web server, you might not be able to use Certbot. Check with your hosting provider for documentation about uploading certificates or using certificates issued by Let’s Encrypt. Contributing ------------ If you'd like to contribute to this project please read `Developer Guide <https://certbot.eff.org/docs/contributing.html>`_. This project is governed by `EFF's Public Projects Code of Conduct <https://www.eff.org/pages/eppcode>`_. Links ===== .. Do not modify this comment unless you know what you're doing. tag:links-begin Documentation: https://certbot.eff.org/docs Software project: https://github.com/certbot/certbot Changelog: https://github.com/certbot/certbot/blob/main/certbot/CHANGELOG.md For Contributors: https://certbot.eff.org/docs/contributing.html For Users: https://certbot.eff.org/docs/using.html Main Website: https://certbot.eff.org Let's Encrypt Website: https://letsencrypt.org Community: https://community.letsencrypt.org ACME spec: `RFC 8555 <https://tools.ietf.org/html/rfc8555>`_ ACME working area in github (archived): https://github.com/ietf-wg-acme/acme .. Do not modify this comment unless you know what you're doing. tag:links-end .. Do not modify this comment unless you know what you're doing. tag:intro-end .. Do not modify this comment unless you know what you're doing. tag:features-begin Current Features ===================== * Supports multiple web servers: - Apache 2.4+ - nginx/0.8.48+ - webroot (adds files to webroot directories in order to prove control of domains and obtain certificates) - standalone (runs its own simple webserver to prove you control a domain) - other server software via `third party plugins <https://certbot.eff.org/docs/using.html#third-party-plugins>`_ * The private key is generated locally on your system. * Can talk to the Let's Encrypt CA or optionally to other ACME compliant services. * Can get domain-validated (DV) certificates. * Can revoke certificates. * Supports ECDSA (default) and RSA certificate private keys. * Can optionally install a http -> https redirect, so your site effectively runs https only. * Fully automated. * Configuration changes are logged and can be reverted. .. Do not modify this comment unless you know what you're doing. tag:features-end Thanks ------ We appreciate the donation of credits to help us test and develop Certbot from: .. image:: https://opensource.nyc3.cdn.digitaloceanspaces.com/attribution/assets/SVG/DO_Logo_horizontal_blue.svg :width: 201 :alt: DigitalOcean Logo :target: https://www.digitalocean.com/
Description
Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol.
146 MiB
Languages
Python
94.5%
Shell
3.7%
Batchfile
0.8%
Makefile
0.7%
Augeas
0.2%