From 4256e3532b37b5ff27ad5a534e50aef01003c82a Mon Sep 17 00:00:00 2001 From: neil Date: Sun, 5 Jul 2026 16:32:57 +0800 Subject: [PATCH] _regAccount: error out clearly when the eab-hmac-key cannot be base64-decoded An undecodable key (e.g. broken LibreSSL base64 -d -A) used to produce the cryptic "Usage: _hmac hashalg secret [outputhex]" and an empty EAB signature that the CA rejects with 403. https://github.com/acmesh-official/acme.sh/issues/4082 --- acme.sh | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/acme.sh b/acme.sh index 1b9c0b89..42d94f79 100755 --- a/acme.sh +++ b/acme.sh @@ -4014,6 +4014,10 @@ _regAccount() { key_hex="$(_durl_replace_base64 "$_eab_hmac_key" | _dbase64 | _hex_dump | tr -d ' ')" _debug3 key_hex "$key_hex" + if [ -z "$key_hex" ]; then + _err "Cannot base64-decode the eab-hmac-key. Please check the value, and your openssl version." + return 1 + fi eab_signature=$(printf "%s" "$eab_sign_t" | _hmac sha256 $key_hex | _base64 | _url_replace) _debug3 eab_signature "$eab_signature"