acme.sh: validate cert response before writing .cer (#7006)

This commit is contained in:
rajcz
2026-06-05 19:38:50 +02:00
committed by GitHub
Unverified
parent a2f046306e
commit 58d9c8d7f6
+12
View File
@@ -5544,6 +5544,13 @@ $_authorizations_map"
return 1
fi
if ! _contains "$response" "$BEGIN_CERT"; then
response="$(echo "$response" | _dbase64 "multiline" | tr -d '\0' | _normalizeJson)"
_err "Signing failed: $(echo "$response" | _egrep_o '"detail":"[^"]*"')"
_on_issue_err "$_post_hook"
return 1
fi
echo "$response" >"$CERT_PATH"
_split_cert_chain "$CERT_PATH" "$CERT_FULLCHAIN_PATH" "$CA_CERT_PATH"
if [ -z "$_preferred_chain" ]; then
@@ -5563,6 +5570,11 @@ $_authorizations_map"
_err "$response"
continue
fi
if ! _contains "$response" "$BEGIN_CERT"; then
_debug2 "Skipping alternate cert link due to unexpected response format."
continue
fi
_relcert="$CERT_PATH.alt"
_relfullchain="$CERT_FULLCHAIN_PATH.alt"
_relca="$CA_CERT_PATH.alt"