acme.sh: validate cert response before writing .cer (#7006)
This commit is contained in:
@@ -5544,6 +5544,13 @@ $_authorizations_map"
|
|||||||
return 1
|
return 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
if ! _contains "$response" "$BEGIN_CERT"; then
|
||||||
|
response="$(echo "$response" | _dbase64 "multiline" | tr -d '\0' | _normalizeJson)"
|
||||||
|
_err "Signing failed: $(echo "$response" | _egrep_o '"detail":"[^"]*"')"
|
||||||
|
_on_issue_err "$_post_hook"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
echo "$response" >"$CERT_PATH"
|
echo "$response" >"$CERT_PATH"
|
||||||
_split_cert_chain "$CERT_PATH" "$CERT_FULLCHAIN_PATH" "$CA_CERT_PATH"
|
_split_cert_chain "$CERT_PATH" "$CERT_FULLCHAIN_PATH" "$CA_CERT_PATH"
|
||||||
if [ -z "$_preferred_chain" ]; then
|
if [ -z "$_preferred_chain" ]; then
|
||||||
@@ -5563,6 +5570,11 @@ $_authorizations_map"
|
|||||||
_err "$response"
|
_err "$response"
|
||||||
continue
|
continue
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
if ! _contains "$response" "$BEGIN_CERT"; then
|
||||||
|
_debug2 "Skipping alternate cert link due to unexpected response format."
|
||||||
|
continue
|
||||||
|
fi
|
||||||
_relcert="$CERT_PATH.alt"
|
_relcert="$CERT_PATH.alt"
|
||||||
_relfullchain="$CERT_FULLCHAIN_PATH.alt"
|
_relfullchain="$CERT_FULLCHAIN_PATH.alt"
|
||||||
_relca="$CA_CERT_PATH.alt"
|
_relca="$CA_CERT_PATH.alt"
|
||||||
|
|||||||
Reference in New Issue
Block a user