Missing socat only matters for standalone mode; the text even says the
warning can be ignored. Printing it to stderr made every --upgrade in a
cron noisy for DNS-only users who redirect stdout.
https://github.com/acmesh-official/acme.sh/issues/6525
The dns/deploy hooks export _H1.._H5 in the main process, and the
notify hooks run in a subshell that inherits them. A hook that does
not overwrite every slot (ntfy without NTFY_TOKEN, slack, telegram,
etc.) sent the stale headers with its request, leaking another
service's Authorization credentials to the notify endpoint.
https://github.com/acmesh-official/acme.sh/issues/6801
A trailing dot in --domain-alias/--challenge-alias was passed through
to the dnsapi hook verbatim. Providers with exact-match record-name
lookups (e.g. Cloudflare's name= filter) then never find the record,
so rm never deletes it and relic TXT records accumulate on every issue.
Stripping in issue() also fixes certs with a dotted alias already
saved in domain.conf.
fix https://github.com/acmesh-official/acme.sh/issues/4636
Mirrors _clearaccountconf_mutable: clears the SAVED_ prefixed key and
the legacy unprefixed key. Replaces the local copy in synology_dsm.sh
and the direct _cleardomainconf call in multideploy.sh.
Closes#4722. Thanks to @sg1888.
* add wiki
* feat: add support for account key rollover
* Place --update-account-key next to --update-account
* fix shfmt
* fix shfmt
* fix shfmt
* Fix from review
* fix shfmt
* fix from review
* fix review
---------
Co-authored-by: neil <gitpc@neilpang.com>
ACCOUNT_EMAIL / --email now accepts a comma- or space-separated list
and registers all of them as ACME contact entries. The ZeroSSL EAB
endpoint takes a single address, so the first one is used there.
An undecodable key (e.g. broken LibreSSL base64 -d -A) used to produce
the cryptic "Usage: _hmac hashalg secret [outputhex]" and an empty EAB
signature that the CA rejects with 403.
https://github.com/acmesh-official/acme.sh/issues/4082
Runs le_test_nginx from acmetest against Pebble: nginx listens on
Pebble's HTTP-01 validation port with an aaPanel/BT style
"location ^~ /" reverse proxy block, the regression case of #6125.
"openssl req -noout -in" aborts when the default config file is missing;
reading a CSR needs no config, so pass -config /dev/null explicitly.
Stock NetBSD does not install /etc/openssl/openssl.cnf, so --signcsr
never worked there.
With a misconfigured $HOME / CERT_HOME the glob over "$CERT_HOME"/*.*
matches nothing, so renewAll silently does nothing and returns success --
--renew-all / --cron appears to work while renewing no certificates.
Check that CERT_HOME is a directory up front and return 1 with a clear
error instead.
Closes#4508
The unquoted splitting let a "*" segment expand against files in the
current directory, so "*.*.*.*" could pass as a valid IPv4 address
(issue 4971). The old code also accepted "", "1.2.3", "1.2.3.4.5",
"1..2.3" and bare numbers. Split with IFS under set -f, require 4
octets, and validate each as a 1-3 digit number <= 255.
Based on https://github.com/acmesh-official/acme.sh/pull/4974
fix https://github.com/acmesh-official/acme.sh/issues/4971
RFC 8555 sec 7.3.6 requires 401 (Unauthorized) when a request is
signed by a deactivated account, which ZeroSSL follows, while
Boulder (Let's Encrypt) historically returns 403. Check both codes
in _regAccount and deactivateaccount.
fix https://github.com/acmesh-official/acme.sh/issues/5138
_contains matches with grep regex, so the '*' in "DNS:*.example.com," never
matched and the subject was appended to the identifiers a second time.
Escape the wildcard before the check, the same way the sed removal already does.
fix https://github.com/acmesh-official/acme.sh/issues/5251
* ARI - Add support for Mass Revocation
* feat: update ARI each time NextRenewTime is not within the suggestedWindow
* Remove _ari_should_renew and add condition on Le_NextRenewTime
* Add support for ARI explanationURL
* Fix debug variable _d_ari
* New Banner
Updated README to include responsive images for dark and light modes.
* multiple fix
* fix
* fix shfmt
* Reset README
---------
Co-authored-by: ZeroSSL-Andreas <andreas.schuster@hidglobal.com>
* ARI - Run cron job more frequently
With ACME Renewal Info (RFC9773 §4.3), fetching renewal window should be more frequent, e.g. in case of revocation incident.
"For instance, a server that needs to revoke certificates within 24 hours of notification of a problem might choose to reserve twelve hours for investigation, six hours for clients to fetch updated RenewalInfo objects, and six hours for clients to perform a renewal."
More flexible option is to run the cron job every hour and only refresh ARI when the last one + Retry-After header is in the past.
* Fix cron job schedule for certificate renewal
* Fix random_hour syntax in cron job installation
* Update Windows task scheduler to run more frequently
Add support for randomized hour and update frequency
Ref:
* [/mo](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/schtasks-create#to-schedule-a-task-to-run-every-n-hours)
* [/SC HOURLY](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/schtasks-create#parameters)
* Add padding for StartTime (/ST) in SCHTASKS.exe
* New Banner
Updated README to include responsive images for dark and light modes.
* rebase
* Reset README
---------
Co-authored-by: ZeroSSL-Andreas <andreas.schuster@hidglobal.com>