| Commit message (Collapse) | Author | Age | Files |
| ... | |
| | | |
|
| | |
| |
| |
| | |
And doesn't retain root privileges.
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
It might croak and we want to log that error also.
|
| | | |
|
| | |
| |
| |
| | |
It's handy to be able to run `./test tests/accountd*` or similar.
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
“The JWS Protected Header is a JSON object” — RFC 7515 sec. 2.
“The JWS Protected Header MUST include the following fields:
- "alg"
- "nonce"
- "url"
- either "jwk" or "kid"”
— RFC 8555 sec. 6.2.
|
| | |
| |
| |
| | |
Again…
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| | |
for 'config'.
This matches the arguably expected behavior that ‘config = %h/foo’ is
passed as ‘--config=%h/foo’ and resolved by lacme-accountd(1) (possibly
remote and with another passwd database).
|
| | |
| |
| |
| |
| |
| | |
Changes-By: lintian-brush
Fixes: lintian: out-of-date-standards-version
See-also: https://lintian.debian.org/tags/out-of-date-standards-version.html
|
| | |
| |
| |
| | |
Changes-By: lintian-brush
|
| |\ \
| | |
| | |
| | |
| | | |
Apply hints suggested by the multi-arch hinter
See merge request debian/lacme!1
|
| |/ /
| |
| |
| |
| |
| | |
+ lacme-accountd: Add Multi-Arch: foreign.
Changes-By: apply-multiarch-hints
|
| | | |
|
| | |
| |
| |
| |
| |
| | |
Instead, set ‘recipes/debian.yml@salsa-ci-team/pipeline’ as CI/CD configuration
file in the GitLab repository setting. Per recommendation from the Salsa CI
maintainers: https://salsa.debian.org/salsa-ci-team/pipeline#debian-pipeline-for-developers .
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| | |
_lacme-www shouldn't own any file or directories, but there might be
files on disk owned by _lacme-client when 'challenge-directory' is used.
See https://wiki.debian.org/AccountHandlingInMaintainerScripts#Reasons_for_not_deleting_accounts .
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
Now part of the upstream build system.
|
| | | |
|
| | |
| |
| |
| |
| | |
lacme also works with earlier accountds, but might yield bad suprises
when the 'keyid' setting is set.
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
See b54d248515357297d84a01cf45a42a6787c21240.
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
* The internal webserver now runs as a dedicated system user _lacme-www
(and group nogroup) instead of www-data:www-data. This is configurable
in the [webserver] section of the lacme(8) configuration file.
* The internal ACME client now runs as a dedicated system user _lacme-client
(and group nogroup) instead of nobody:nogroup. This is configurable in
the [client] section of the lacme(8) configuration file.
* The _lacme-www and _lacme-client system users are created automatically by
lacme.postinst (hence a new Depends: adduser), and deleted on purge. (So
make sure not to chown any file to these internal users.)
|
| | |
| |
| |
| | |
And add "Forwarded: not-needed" annotations when relevant.
|
| |\|
| |
| |
| | |
Release version 0.8.0
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
The staging environment wasn't set properly for the Debian packages.
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| | |
This saves a round trip and provides a safeguard against malicious
clients.
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Passing the JWA to the ACME client is required if we want to support
account keys other than RSA. As of 0.7 both lacme-accountd(1) and
lacme(8) hardcode “RS256” (SHA256withRSA per RFC 7518 sec. A.1).
Passing the JWK thumbprint is handy as it gives more flexibility if RFC
8555 sec. 8.1 were to be updated with another digest algorithm (it's
currently hardcoded to SHA-256). A single lacme-account(1) instance
might be used to sign requests from many clients, and it's easier to
upgrade a single ‘lacme-accountd’ than many ‘lacme’. Moreover, in some
restricted environments lacme-accountd might hide the JWK from the
client to prevent ‘newAccount’ requests (such as contact updates);
passing its thumbprint is enough for ‘newOrder’ requests.
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|