dash's echo has no -e flag and sends a literal "-e " prefix to the
socket, so haproxy rejects the command and the hot update always fails
on Debian/Ubuntu (/bin/sh = dash). Also accept "Transaction updated",
which haproxy replies when an uncommitted transaction already exists.
fix https://github.com/acmesh-official/acme.sh/issues/6165
* Add WEDOS WAPI DNS API (dns_wedos)
* dns_wedos: fix response parsing on systems without egrep -o
* dns_wedos: report WAPI auth errors, UTC fallback for hosts ignoring TZ
"openssl req -noout -in" aborts when the default config file is missing;
reading a CSR needs no config, so pass -config /dev/null explicitly.
Stock NetBSD does not install /etc/openssl/openssl.cnf, so --signcsr
never worked there.
With a misconfigured $HOME / CERT_HOME the glob over "$CERT_HOME"/*.*
matches nothing, so renewAll silently does nothing and returns success --
--renew-all / --cron appears to work while renewing no certificates.
Check that CERT_HOME is a directory up front and return 1 with a clear
error instead.
Closes#4508
Core-Networks' API rejects Unicode domain names with "invalid domain";
it requires punycode. dns_cn_add / dns_cn_rm passed the raw challenge
domain straight through, so IDN certs failed at the TXT add step
(issue #4804). Run fulldomain through _idn() in both functions. For
ASCII/punycode input _idn() is a pass-through, so non-IDN domains are
unaffected.
Fixes#4804
The unquoted splitting let a "*" segment expand against files in the
current directory, so "*.*.*.*" could pass as a valid IPv4 address
(issue 4971). The old code also accepted "", "1.2.3", "1.2.3.4.5",
"1..2.3" and bare numbers. Split with IFS under set -f, require 4
octets, and validate each as a 1-3 digit number <= 255.
Based on https://github.com/acmesh-official/acme.sh/pull/4974
fix https://github.com/acmesh-official/acme.sh/issues/4971
_get_root matched the candidate zone with _contains (grep), which treats
the domain as a regex. For "-d g.<zone>" the candidate "g.<zone>" matched
"<string>...<zone>" because '.' matches the '>' after "string" and the 'g'
comes from the "<string>" tag, so "g.<zone>" was wrongly taken as the root
zone (sub=_acme-challenge instead of _acme-challenge.g). Anchor the match
to <string>$h</string> and escape dots so the zone is compared literally.
Fixes#5129
RFC 8555 sec 7.3.6 requires 401 (Unauthorized) when a request is
signed by a deactivated account, which ZeroSSL follows, while
Boulder (Let's Encrypt) historically returns 403. Check both codes
in _regAccount and deactivateaccount.
fix https://github.com/acmesh-official/acme.sh/issues/5138
_contains matches with grep regex, so the '*' in "DNS:*.example.com," never
matched and the subject was appended to the identifiers a second time.
Escape the wildcard before the check, the same way the sed removal already does.
fix https://github.com/acmesh-official/acme.sh/issues/5251
* ARI - Add support for Mass Revocation
* feat: update ARI each time NextRenewTime is not within the suggestedWindow
* Remove _ari_should_renew and add condition on Le_NextRenewTime
* Add support for ARI explanationURL
* Fix debug variable _d_ari
* New Banner
Updated README to include responsive images for dark and light modes.
* multiple fix
* fix
* fix shfmt
* Reset README
---------
Co-authored-by: ZeroSSL-Andreas <andreas.schuster@hidglobal.com>
_normalizeJson reads its JSON from stdin (sed | sed | tr) and ignores
any positional argument. dns_czechia_add() called it as
`_normalizeJson "$_res"`, so the response was discarded and the inner
sed blocked reading from stdin.
When issuing for a single domain, or for a record that already exists,
the "already exists" branch returns early and never reaches this call,
which is why the bug stayed hidden. With multiple domains, the first
record often short-circuits on "already exists" while the next,
freshly-added record reaches the broken call and hangs on interactive
runs (or consumes unrelated stdin non-interactively).
Pipe the response into _normalizeJson via stdin, matching
dns_czechia_rm() and every other dnsapi plugin.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: add volcengine dns api
* fix(volcengine): address review findings and fix record matching
Code review fixes:
- fix format string usage in signature computation (use printf %b / %s)
- clear _H1.._H5 header state at start of request to avoid leaking
conditionally-set headers into subsequent requests
- check ListZones return status in _get_root
- document Volcengine_SESSION_TOKEN option and fix duplicate "and" typo
- fix Docs and Issues sections
- remove and update some code comments
Functional fixes:
- stop matching ListRecords results by FQDN string: Volcengine lowercases
the Host/FQDN in responses, so a case-sensitive compare against
$fulldomain failed for mixed-case names, making rm silently skip
deletion and add lose idempotency. ListRecords is already filtered by
ZID+Host+Value+SearchMode:exact, so just extract RecordID from the
result instead.
- reset _record_id at the start of add/rm to avoid stale state leaking
across calls within the same process
- tag created records with Remark "acme.sh" for easier identification
- adjust debug levels: hide Authorization header behind _debug2, surface
response at _debug
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: wenxuan70 <t736660416@gmail.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* ARI - Run cron job more frequently
With ACME Renewal Info (RFC9773 §4.3), fetching renewal window should be more frequent, e.g. in case of revocation incident.
"For instance, a server that needs to revoke certificates within 24 hours of notification of a problem might choose to reserve twelve hours for investigation, six hours for clients to fetch updated RenewalInfo objects, and six hours for clients to perform a renewal."
More flexible option is to run the cron job every hour and only refresh ARI when the last one + Retry-After header is in the past.
* Fix cron job schedule for certificate renewal
* Fix random_hour syntax in cron job installation
* Update Windows task scheduler to run more frequently
Add support for randomized hour and update frequency
Ref:
* [/mo](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/schtasks-create#to-schedule-a-task-to-run-every-n-hours)
* [/SC HOURLY](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/schtasks-create#parameters)
* Add padding for StartTime (/ST) in SCHTASKS.exe
* New Banner
Updated README to include responsive images for dark and light modes.
* rebase
* Reset README
---------
Co-authored-by: ZeroSSL-Andreas <andreas.schuster@hidglobal.com>