From d3e12694b9a945664c963b3336270273d309e991 Mon Sep 17 00:00:00 2001 From: neil Date: Sat, 4 Jul 2026 19:56:37 +0800 Subject: [PATCH] fix "identifiers are duplicated" when signing a CSR with a wildcard CN also present in SAN _contains matches with grep regex, so the '*' in "DNS:*.example.com," never matched and the subject was appended to the identifiers a second time. Escape the wildcard before the check, the same way the sed removal already does. fix https://github.com/acmesh-official/acme.sh/issues/5251 --- acme.sh | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/acme.sh b/acme.sh index 148945b9..8256d5f0 100755 --- a/acme.sh +++ b/acme.sh @@ -1423,12 +1423,13 @@ _readSubjectAltNamesFromCSR() { _dnsAltnames="$(${ACME_OPENSSL_BIN:-openssl} req -noout -text -in "$_csrfile" | grep "^ *DNS:.*" | tr -d ' \n')" _debug _dnsAltnames "$_dnsAltnames" - if _contains "$_dnsAltnames," "DNS:$_csrsubj,"; then + # escape the wildcard '*' so it is not taken as a regex operator by grep/sed below + _excapedAlgnames="$(echo "$_dnsAltnames" | tr '*' '#')" + _debug _excapedAlgnames "$_excapedAlgnames" + _escapedSubject="$(echo "$_csrsubj" | tr '*' '#')" + _debug _escapedSubject "$_escapedSubject" + if _contains "$_excapedAlgnames," "DNS:$_escapedSubject,"; then _debug "AltNames contains subject" - _excapedAlgnames="$(echo "$_dnsAltnames" | tr '*' '#')" - _debug _excapedAlgnames "$_excapedAlgnames" - _escapedSubject="$(echo "$_csrsubj" | tr '*' '#')" - _debug _escapedSubject "$_escapedSubject" _dnsAltnames="$(echo "$_excapedAlgnames," | sed "s/DNS:$_escapedSubject,//g" | tr '#' '*' | sed "s/,\$//g")" _debug _dnsAltnames "$_dnsAltnames" else