Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

deploy-hook doesn't run #1492

Closed
soostdijck opened this issue Apr 5, 2018 · 3 comments
Closed

deploy-hook doesn't run #1492

soostdijck opened this issue Apr 5, 2018 · 3 comments

Comments

@soostdijck
Copy link

As far as I can tell (also from debug mode) the deploy-hook doesn't run at all with my setup. Is deploy-hook ignored when running --staging maybe?

Steps to reproduce

/export/acme-home/acme.sh --staging -d irc.example.net --challenge-alias irc.example.ripe.net --dns dns_nsupdate --dnssleep 10 --home /export/acme-home --renew --force --deploy-hook 'touch /test'

Debug log

0:root@cryptosaurus [/export/acme-home> /export/acme-home/acme.sh --staging -d irc.ripe.net --challenge-alias irc.tokens.ripe.net --dns dns_nsupdate --dnssleep 10 --home /export/acme-home --renew --force --deploy-hook 'touch /biteme' --debug 2
[Thu Apr  5 12:39:49 CEST 2018] Lets find script dir.
[Thu Apr  5 12:39:49 CEST 2018] _SCRIPT_='/export/acme-home/acme.sh'
[Thu Apr  5 12:39:49 CEST 2018] _script='/export/acme-home/acme.sh'
[Thu Apr  5 12:39:49 CEST 2018] _script_home='/export/acme-home'
[Thu Apr  5 12:39:49 CEST 2018] Using config home:/export/acme-home
[Thu Apr  5 12:39:49 CEST 2018] LE_WORKING_DIR='/export/acme-home'
https://github.com/Neilpang/acme.sh
v2.7.8
[Thu Apr  5 12:39:49 CEST 2018] Using config home:/export/acme-home
[Thu Apr  5 12:39:49 CEST 2018] Using stage ACME_DIRECTORY: https://acme-staging.api.letsencrypt.org/directory
[Thu Apr  5 12:39:49 CEST 2018] ACME_DIRECTORY='https://acme-staging.api.letsencrypt.org/directory'
[Thu Apr  5 12:39:49 CEST 2018] _ACME_SERVER_HOST='acme-staging.api.letsencrypt.org'
[Thu Apr  5 12:39:49 CEST 2018] DOMAIN_PATH='/export/acme-certs/irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] Renew: 'irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] Le_API='https://acme-staging.api.letsencrypt.org/directory'
[Thu Apr  5 12:39:49 CEST 2018] Using config home:/export/acme-home
[Thu Apr  5 12:39:49 CEST 2018] ACME_DIRECTORY='https://acme-staging.api.letsencrypt.org/directory'
[Thu Apr  5 12:39:49 CEST 2018] _ACME_SERVER_HOST='acme-staging.api.letsencrypt.org'
[Thu Apr  5 12:39:49 CEST 2018] _main_domain='irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] _alt_domains='no'
[Thu Apr  5 12:39:49 CEST 2018] 'dns_nsupdate' does not contain 'dns'
[Thu Apr  5 12:39:49 CEST 2018] Using ACME_DIRECTORY: https://acme-staging.api.letsencrypt.org/directory
[Thu Apr  5 12:39:49 CEST 2018] _init api for server: https://acme-staging.api.letsencrypt.org/directory
[Thu Apr  5 12:39:49 CEST 2018] GET
[Thu Apr  5 12:39:49 CEST 2018] url='https://acme-staging.api.letsencrypt.org/directory'
[Thu Apr  5 12:39:49 CEST 2018] timeout=
[Thu Apr  5 12:39:49 CEST 2018] _CURL='curl -L --silent --dump-header /export/acme-home/http.header  --trace-ascii /tmp/tmp.ij05zZ20Vr  -g '
[Thu Apr  5 12:39:49 CEST 2018] ret='0'
[Thu Apr  5 12:39:49 CEST 2018] response='{
  "1hRCjay1kzI": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417",
  "key-change": "https://acme-staging.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "terms-of-service": "https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf",
    "website": "https://letsencrypt.org/docs/staging-environment/"
  },
  "new-authz": "https://acme-staging.api.letsencrypt.org/acme/new-authz",
  "new-cert": "https://acme-staging.api.letsencrypt.org/acme/new-cert",
  "new-reg": "https://acme-staging.api.letsencrypt.org/acme/new-reg",
  "revoke-cert": "https://acme-staging.api.letsencrypt.org/acme/revoke-cert"
}'
[Thu Apr  5 12:39:49 CEST 2018] ACME_KEY_CHANGE='https://acme-staging.api.letsencrypt.org/acme/key-change'
[Thu Apr  5 12:39:49 CEST 2018] ACME_NEW_AUTHZ='https://acme-staging.api.letsencrypt.org/acme/new-authz'
[Thu Apr  5 12:39:49 CEST 2018] ACME_NEW_ORDER='https://acme-staging.api.letsencrypt.org/acme/new-cert'
[Thu Apr  5 12:39:49 CEST 2018] ACME_NEW_ACCOUNT='https://acme-staging.api.letsencrypt.org/acme/new-reg'
[Thu Apr  5 12:39:49 CEST 2018] ACME_REVOKE_CERT='https://acme-staging.api.letsencrypt.org/acme/revoke-cert'
[Thu Apr  5 12:39:49 CEST 2018] ACME_AGREEMENT='https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf'
[Thu Apr  5 12:39:49 CEST 2018] ACME_NEW_NONCE
[Thu Apr  5 12:39:49 CEST 2018] ACME_VERSION
[Thu Apr  5 12:39:49 CEST 2018] Le_NextRenewTime='1528022366'
[Thu Apr  5 12:39:49 CEST 2018] _on_before_issue
[Thu Apr  5 12:39:49 CEST 2018] _chk_main_domain='irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] _chk_alt_domains
[Thu Apr  5 12:39:49 CEST 2018] 'dns_nsupdate' does not contain 'no'
[Thu Apr  5 12:39:49 CEST 2018] Le_LocalAddress
[Thu Apr  5 12:39:49 CEST 2018] d='irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] Check for domain='irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] _currentRoot='dns_nsupdate'
[Thu Apr  5 12:39:49 CEST 2018] d
[Thu Apr  5 12:39:49 CEST 2018] 'dns_nsupdate' does not contain 'apache'
[Thu Apr  5 12:39:49 CEST 2018] _saved_account_key_hash='gvpUgXAhLIHdURDHBAABz3C/L+LzZIU4JI7ofI47eA0='
[Thu Apr  5 12:39:49 CEST 2018] _saved_account_key_hash is not changed, skip register account.
[Thu Apr  5 12:39:49 CEST 2018] Read key length:
[Thu Apr  5 12:39:49 CEST 2018] _createcsr
[Thu Apr  5 12:39:49 CEST 2018] domain='irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] domainlist
[Thu Apr  5 12:39:49 CEST 2018] csrkey='/export/acme-certs/irc.ripe.net/irc.ripe.net.key'
[Thu Apr  5 12:39:49 CEST 2018] csr='/export/acme-certs/irc.ripe.net/irc.ripe.net.csr'
[Thu Apr  5 12:39:49 CEST 2018] csrconf='/export/acme-certs/irc.ripe.net/irc.ripe.net.csr.conf'
[Thu Apr  5 12:39:49 CEST 2018] Single domain='irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] _is_idn_d='irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] _idn_temp
[Thu Apr  5 12:39:49 CEST 2018] _csr_cn='irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] Getting domain auth token for each domain
[Thu Apr  5 12:39:49 CEST 2018] d='irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] Getting webroot for domain='irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] _w='dns_nsupdate'
[Thu Apr  5 12:39:49 CEST 2018] _currentRoot='dns_nsupdate'
[Thu Apr  5 12:39:49 CEST 2018] Getting new-authz for domain='irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] _init api for server: https://acme-staging.api.letsencrypt.org/directory
[Thu Apr  5 12:39:49 CEST 2018] Try new-authz for the 0 time.
[Thu Apr  5 12:39:49 CEST 2018] _is_idn_d='irc.ripe.net'
[Thu Apr  5 12:39:49 CEST 2018] _idn_temp
[Thu Apr  5 12:39:49 CEST 2018] url='https://acme-staging.api.letsencrypt.org/acme/new-authz'
[Thu Apr  5 12:39:49 CEST 2018] payload='{"resource": "new-authz", "identifier": {"type": "dns", "value": "irc.ripe.net"}}'
[Thu Apr  5 12:39:49 CEST 2018] RSA key
[Thu Apr  5 12:39:49 CEST 2018] Get nonce. ACME_DIRECTORY='https://acme-staging.api.letsencrypt.org/directory'
[Thu Apr  5 12:39:49 CEST 2018] GET
[Thu Apr  5 12:39:49 CEST 2018] url='https://acme-staging.api.letsencrypt.org/directory'
[Thu Apr  5 12:39:49 CEST 2018] timeout=
[Thu Apr  5 12:39:49 CEST 2018] _CURL='curl -L --silent --dump-header /export/acme-home/http.header  --trace-ascii /tmp/tmp.GfACELoKzy  -g '
[Thu Apr  5 12:39:49 CEST 2018] ret='0'
[Thu Apr  5 12:39:49 CEST 2018] _headers='HTTP/1.1 200 OK
Server: nginx
Content-Type: application/json
Content-Length: 704
Replay-Nonce: vmwJQcpqBVrgE471RDC_oGkvSvcG97dgQyt10E7hmuw
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800
Expires: Thu, 05 Apr 2018 10:39:49 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 05 Apr 2018 10:39:49 GMT
Connection: keep-alive
'
[Thu Apr  5 12:39:49 CEST 2018] _CACHED_NONCE='vmwJQcpqBVrgE471RDC_oGkvSvcG97dgQyt10E7hmuw'
[Thu Apr  5 12:39:49 CEST 2018] nonce='vmwJQcpqBVrgE471RDC_oGkvSvcG97dgQyt10E7hmuw'
[Thu Apr  5 12:39:49 CEST 2018] POST
[Thu Apr  5 12:39:49 CEST 2018] _post_url='https://acme-staging.api.letsencrypt.org/acme/new-authz'
[Thu Apr  5 12:39:49 CEST 2018] body='{"header": {"alg": "RS256", "jwk": {"e": "AQAB", "kty": "RSA", "n": "vrdhN80RNtmhsdgZtME7Szn29O6YFzF5dxwbppKp6D2YU50ohZrNvWEwngj3-nW9A6sdc7ef5unSsSE8NjlNdvH7s1aMfCoasfWmTPdAtFzwtlvA7Dxewk1AYgB5AKzSsimkncxjTldh1IC9i_tYyGoo8LQnoqpmdqh40_c0Ad1eAC23YIpcqlqkp6ts_8slweLysHUmzSu1QbFjQjPRXbucYIoZcjsb8czwQVb9lRZjNbRlApuNdBe16-b0Ynvu_wVxA_K0SMKY-yDo3N8sk7AcZo58BBdc6wp5mQYmbrzSWtdnGBkJdHHQFeM-vwMU7_MoJXjZvt4Tf8CZg3gUqQ"}}, "protected": "eyJub25jZSI6ICJ2bXdKUWNwcUJWcmdFNDcxUkRDX29Ha3ZTdmNHOTdkZ1F5dDEwRTdobXV3IiwgInVybCI6ICJodHRwczovL2FjbWUtc3RhZ2luZy5hcGkubGV0c2VuY3J5cHQub3JnL2FjbWUvbmV3LWF1dGh6IiwgImFsZyI6ICJSUzI1NiIsICJqd2siOiB7ImUiOiAiQVFBQiIsICJrdHkiOiAiUlNBIiwgIm4iOiAidnJkaE44MFJOdG1oc2RnWnRNRTdTem4yOU82WUZ6RjVkeHdicHBLcDZEMllVNTBvaFpyTnZXRXduZ2ozLW5XOUE2c2RjN2VmNXVuU3NTRThOamxOZHZIN3MxYU1mQ29hc2ZXbVRQZEF0Rnp3dGx2QTdEeGV3azFBWWdCNUFLelNzaW1rbmN4alRsZGgxSUM5aV90WXlHb284TFFub3FwbWRxaDQwX2MwQWQxZUFDMjNZSXBjcWxxa3A2dHNfOHNsd2VMeXNIVW16U3UxUWJGalFqUFJYYnVjWUlvWmNqc2I4Y3p3UVZiOWxSWmpOYlJsQXB1TmRCZTE2LWIwWW52dV93VnhBX0swU01LWS15RG8zTjhzazdBY1pvNThCQmRjNndwNW1RWW1icnpTV3RkbkdCa0pkSEhRRmVNLXZ3TVU3X01vSlhqWnZ0NFRmOENaZzNnVXFRIn19", "payload": "eyJyZXNvdXJjZSI6ICJuZXctYXV0aHoiLCAiaWRlbnRpZmllciI6IHsidHlwZSI6ICJkbnMiLCAidmFsdWUiOiAiaXJjLnJpcGUubmV0In19", "signature": "PfQ-1TV5OZQfo7ChaEAtr80IvYg9foWjYYleWeMdmhsVz1Yz6gO2lHPQavzRDpP3Pr_p_7ve-MIrh5uxNrbCycQLZ1l1q5nsIwNtmKy8Xwe4rh7GFpVxiC2QsoZ7_V43woc_W6RflKsPfY3As_LNzTBiY4tWKyilWMizmDZvTleAWy1kIFkJGjHTWYuf7t8HNCV_G8wGhI0pqNzgW5ouLF9ipGvxL8S1tD-4rsCBev9LyroTyJDM4vutxctudedAN0nJH8TydcGkU2RoLe89LIBeC3R40z3qWSILR2Uuh0yOvv6QJJnZo53409ze7x-OTui26mO8KdHEMebztGPobA"}'
[Thu Apr  5 12:39:49 CEST 2018] _postContentType
[Thu Apr  5 12:39:49 CEST 2018] _CURL='curl -L --silent --dump-header /export/acme-home/http.header  --trace-ascii /tmp/tmp.ao11ctP8Aj  -g '
[Thu Apr  5 12:39:50 CEST 2018] _ret='0'
[Thu Apr  5 12:39:50 CEST 2018] original='{
  "identifier": {
    "type": "dns",
    "value": "irc.ripe.net"
  },
  "status": "valid",
  "expires": "2018-04-28T11:58:44Z",
  "challenges": [
    {
      "type": "dns-01",
      "status": "valid",
      "uri": "https://acme-staging.api.letsencrypt.org/acme/challenge/0CdHZBRNO_kx_pa1oT41tU6kkvZlXbYivE5KS3C1s5U/112944237",
      "token": "7qTfOxFHRVNmi2QrPls9sL6nWxvNMr7MKxNKdip1VkQ",
      "keyAuthorization": "7qTfOxFHRVNmi2QrPls9sL6nWxvNMr7MKxNKdip1VkQ.JXRgD6zVyH-ohizkWeHtLHd0dK-tfDxLdimFPnbQnMk",
      "validationRecord": [
        {
          "hostname": "irc.ripe.net"
        }
      ]
    },
    {
      "type": "http-01",
      "status": "pending",
      "uri": "https://acme-staging.api.letsencrypt.org/acme/challenge/0CdHZBRNO_kx_pa1oT41tU6kkvZlXbYivE5KS3C1s5U/112944238",
      "token": "ulnS6G8qQSYfQbFBXXM4PyxdKMK0p-dgSHrGEXE37h4"
    }
  ],
  "combinations": [
    [
      0
    ],
    [
      1
    ]
  ]
}'
[Thu Apr  5 12:39:50 CEST 2018] responseHeaders='HTTP/1.1 100 Continue
Expires: Thu, 05 Apr 2018 10:39:50 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache

HTTP/1.1 201 Created
Server: nginx
Content-Type: application/json
Content-Length: 930
Boulder-Requester: 5829535
Link: <https://acme-staging.api.letsencrypt.org/acme/new-cert>;rel="next"
Location: https://acme-staging.api.letsencrypt.org/acme/authz/0CdHZBRNO_kx_pa1oT41tU6kkvZlXbYivE5KS3C1s5U
Replay-Nonce: _ediVmwNkDVu0_6CBCeeUubuuhBDdYw_8usBeSjyYMM
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800
Expires: Thu, 05 Apr 2018 10:39:50 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 05 Apr 2018 10:39:50 GMT
Connection: keep-alive
'
[Thu Apr  5 12:39:50 CEST 2018] response='{"identifier":{"type":"dns","value":"irc.ripe.net"},"status":"valid","expires":"2018-04-28T11:58:44Z","challenges":[{"type":"dns-01","status":"valid","uri":"https://acme-staging.api.letsencrypt.org/acme/challenge/0CdHZBRNO_kx_pa1oT41tU6kkvZlXbYivE5KS3C1s5U/112944237","token":"7qTfOxFHRVNmi2QrPls9sL6nWxvNMr7MKxNKdip1VkQ","keyAuthorization":"7qTfOxFHRVNmi2QrPls9sL6nWxvNMr7MKxNKdip1VkQ.JXRgD6zVyH-ohizkWeHtLHd0dK-tfDxLdimFPnbQnMk","validationRecord":[{"hostname":"irc.ripe.net"}]},{"type":"http-01","status":"pending","uri":"https://acme-staging.api.letsencrypt.org/acme/challenge/0CdHZBRNO_kx_pa1oT41tU6kkvZlXbYivE5KS3C1s5U/112944238","token":"ulnS6G8qQSYfQbFBXXM4PyxdKMK0p-dgSHrGEXE37h4"}],"combinations":[[0],[1]]}'
[Thu Apr  5 12:39:50 CEST 2018] code='201'
[Thu Apr  5 12:39:50 CEST 2018] The new-authz request is ok.
[Thu Apr  5 12:39:50 CEST 2018] entry='"type":"dns-01","status":"valid","uri":"https://acme-staging.api.letsencrypt.org/acme/challenge/0CdHZBRNO_kx_pa1oT41tU6kkvZlXbYivE5KS3C1s5U/112944237","token":"7qTfOxFHRVNmi2QrPls9sL6nWxvNMr7MKxNKdip1VkQ","keyAuthorization":"7qTfOxFHRVNmi2QrPls9sL6nWxvNMr7MKxNKdip1VkQ.JXRgD6zVyH-ohizkWeHtLHd0dK-tfDxLdimFPnbQnMk","validationRecord":[{"hostname":"irc.ripe.net"'
[Thu Apr  5 12:39:50 CEST 2018] token='7qTfOxFHRVNmi2QrPls9sL6nWxvNMr7MKxNKdip1VkQ'
[Thu Apr  5 12:39:50 CEST 2018] uri='https://acme-staging.api.letsencrypt.org/acme/challenge/0CdHZBRNO_kx_pa1oT41tU6kkvZlXbYivE5KS3C1s5U/112944237'
[Thu Apr  5 12:39:50 CEST 2018] keyauthorization='7qTfOxFHRVNmi2QrPls9sL6nWxvNMr7MKxNKdip1VkQ.JXRgD6zVyH-ohizkWeHtLHd0dK-tfDxLdimFPnbQnMk'
[Thu Apr  5 12:39:50 CEST 2018] irc.ripe.net is already verified.
[Thu Apr  5 12:39:50 CEST 2018] keyauthorization='verified_ok'
[Thu Apr  5 12:39:50 CEST 2018] dvlist='irc.ripe.net#verified_ok#https://acme-staging.api.letsencrypt.org/acme/challenge/0CdHZBRNO_kx_pa1oT41tU6kkvZlXbYivE5KS3C1s5U/112944237#dns-01#dns_nsupdate'
[Thu Apr  5 12:39:50 CEST 2018] d
[Thu Apr  5 12:39:50 CEST 2018] vlist='irc.ripe.net#verified_ok#https://acme-staging.api.letsencrypt.org/acme/challenge/0CdHZBRNO_kx_pa1oT41tU6kkvZlXbYivE5KS3C1s5U/112944237#dns-01#dns_nsupdate,'
[Thu Apr  5 12:39:50 CEST 2018] d='irc.ripe.net'
[Thu Apr  5 12:39:50 CEST 2018] irc.ripe.net is already verified, skip dns-01.
[Thu Apr  5 12:39:50 CEST 2018] ok, let's start to verify
[Thu Apr  5 12:39:50 CEST 2018] irc.ripe.net is already verified, skip dns-01.
[Thu Apr  5 12:39:50 CEST 2018] pid
[Thu Apr  5 12:39:50 CEST 2018] No need to restore nginx, skip.
[Thu Apr  5 12:39:50 CEST 2018] _clearupdns
[Thu Apr  5 12:39:50 CEST 2018] skip dns.
[Thu Apr  5 12:39:50 CEST 2018] Verify finished, start to sign.
[Thu Apr  5 12:39:50 CEST 2018] i='2'
[Thu Apr  5 12:39:50 CEST 2018] j='15'
[Thu Apr  5 12:39:50 CEST 2018] url='https://acme-staging.api.letsencrypt.org/acme/new-cert'
[Thu Apr  5 12:39:50 CEST 2018] payload='{"resource": "new-cert", "csr": "MIICkzCCAXsCAQAwFzEVMBMGA1UEAwwMaXJjLnJpcGUubmV0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0CbFiwbaFdNQY2Z7wKBcJyHT28l-x9hGO4eNXjQLNefO1EgdjOWyPUILPjWHIK1iuodYzn5yIR3idBOtQlsAsZEnxPVBENYw3zxNz0JKGesLI3ptciTRTB5a1GAZ53l1xRe2GSry3LkcCgtRIsjYBoB0ZrehWQTkj33w-AzFoFGda7qZWx09WHZxTNs0ECYBnMg1xPJdxF3dEQKSgtkJH8X9vjOd7lpUZoVPhTcplP_GVuRvO6UAxK5UFpySJTOko4pQxAoNu-bXY65R5NV1MOwU7ISMj_CM3bFo6nAse54Z8ua_IDRY3z3x-NGg6jEx4BSMEV8dDQOCp7Z-mX5HMwIDAQABoDcwNQYJKoZIhvcNAQkOMSgwJjALBgNVHQ8EBAMCBeAwFwYDVR0RBBAwDoIMaXJjLnJpcGUubmV0MA0GCSqGSIb3DQEBCwUAA4IBAQADxtYff2YNgzcDPk_W1yaW_xo7Qqs10ZrRP1ROsT1_hRrrYTh-k11_XJ8PpTDmKx83yQBRaeoKC8ieFxHdin9p72b01Pfa7DlHL9TM0J-g6RAZIV9BQNve1nzUZe2Sc4c3O1VUcAdemlc7wSw5mRxWZSVqZdB9XvO5MDvE4KfZDcn3u-lkObOQeqkf0tYRifD_758xauPkXh8rafThRe1DkDLfQN-e9p1roQdV580sN8pWjThxYn6F5IuWopjjfLRuKrYQI-O3arsKiaQ1fWUJ565YZTx6q4if3iU8g_hCjOGdZbFnN_5h_anfCt6RNY5lAeyhia0JlJ7EdGdkJKFu"}'
[Thu Apr  5 12:39:50 CEST 2018] Use cached jwk for file: /export/acme-home/ca/acme-staging.api.letsencrypt.org/account.key
[Thu Apr  5 12:39:50 CEST 2018] Use _CACHED_NONCE='_ediVmwNkDVu0_6CBCeeUubuuhBDdYw_8usBeSjyYMM'
[Thu Apr  5 12:39:50 CEST 2018] nonce='_ediVmwNkDVu0_6CBCeeUubuuhBDdYw_8usBeSjyYMM'
[Thu Apr  5 12:39:50 CEST 2018] POST
[Thu Apr  5 12:39:50 CEST 2018] _post_url='https://acme-staging.api.letsencrypt.org/acme/new-cert'
[Thu Apr  5 12:39:50 CEST 2018] body='{"header": {"alg": "RS256", "jwk": {"e": "AQAB", "kty": "RSA", "n": "vrdhN80RNtmhsdgZtME7Szn29O6YFzF5dxwbppKp6D2YU50ohZrNvWEwngj3-nW9A6sdc7ef5unSsSE8NjlNdvH7s1aMfCoasfWmTPdAtFzwtlvA7Dxewk1AYgB5AKzSsimkncxjTldh1IC9i_tYyGoo8LQnoqpmdqh40_c0Ad1eAC23YIpcqlqkp6ts_8slweLysHUmzSu1QbFjQjPRXbucYIoZcjsb8czwQVb9lRZjNbRlApuNdBe16-b0Ynvu_wVxA_K0SMKY-yDo3N8sk7AcZo58BBdc6wp5mQYmbrzSWtdnGBkJdHHQFeM-vwMU7_MoJXjZvt4Tf8CZg3gUqQ"}}, "protected": "eyJub25jZSI6ICJfZWRpVm13TmtEVnUwXzZDQkNlZVV1YnV1aEJEZFl3Xzh1c0JlU2p5WU1NIiwgInVybCI6ICJodHRwczovL2FjbWUtc3RhZ2luZy5hcGkubGV0c2VuY3J5cHQub3JnL2FjbWUvbmV3LWNlcnQiLCAiYWxnIjogIlJTMjU2IiwgImp3ayI6IHsiZSI6ICJBUUFCIiwgImt0eSI6ICJSU0EiLCAibiI6ICJ2cmRoTjgwUk50bWhzZGdadE1FN1N6bjI5TzZZRnpGNWR4d2JwcEtwNkQyWVU1MG9oWnJOdldFd25najMtblc5QTZzZGM3ZWY1dW5Tc1NFOE5qbE5kdkg3czFhTWZDb2FzZldtVFBkQXRGend0bHZBN0R4ZXdrMUFZZ0I1QUt6U3NpbWtuY3hqVGxkaDFJQzlpX3RZeUdvbzhMUW5vcXBtZHFoNDBfYzBBZDFlQUMyM1lJcGNxbHFrcDZ0c184c2x3ZUx5c0hVbXpTdTFRYkZqUWpQUlhidWNZSW9aY2pzYjhjendRVmI5bFJaak5iUmxBcHVOZEJlMTYtYjBZbnZ1X3dWeEFfSzBTTUtZLXlEbzNOOHNrN0FjWm81OEJCZGM2d3A1bVFZbWJyelNXdGRuR0JrSmRISFFGZU0tdndNVTdfTW9KWGpadnQ0VGY4Q1pnM2dVcVEifX0", "payload": "eyJyZXNvdXJjZSI6ICJuZXctY2VydCIsICJjc3IiOiAiTUlJQ2t6Q0NBWHNDQVFBd0Z6RVZNQk1HQTFVRUF3d01hWEpqTG5KcGNHVXVibVYwTUlJQklqQU5CZ2txaGtpRzl3MEJBUUVGQUFPQ0FROEFNSUlCQ2dLQ0FRRUEwQ2JGaXdiYUZkTlFZMlo3d0tCY0p5SFQyOGwteDloR080ZU5YalFMTmVmTzFFZ2RqT1d5UFVJTFBqV0hJSzFpdW9kWXpuNXlJUjNpZEJPdFFsc0FzWkVueFBWQkVOWXczenhOejBKS0dlc0xJM3B0Y2lUUlRCNWExR0FaNTNsMXhSZTJHU3J5M0xrY0NndFJJc2pZQm9CMFpyZWhXUVRrajMzdy1BekZvRkdkYTdxWld4MDlXSFp4VE5zMEVDWUJuTWcxeFBKZHhGM2RFUUtTZ3RrSkg4WDl2ak9kN2xwVVpvVlBoVGNwbFBfR1Z1UnZPNlVBeEs1VUZweVNKVE9rbzRwUXhBb051LWJYWTY1UjVOVjFNT3dVN0lTTWpfQ00zYkZvNm5Bc2U1NFo4dWFfSURSWTN6M3gtTkdnNmpFeDRCU01FVjhkRFFPQ3A3Wi1tWDVITXdJREFRQUJvRGN3TlFZSktvWklodmNOQVFrT01TZ3dKakFMQmdOVkhROEVCQU1DQmVBd0Z3WURWUjBSQkJBd0RvSU1hWEpqTG5KcGNHVXVibVYwTUEwR0NTcUdTSWIzRFFFQkN3VUFBNElCQVFBRHh0WWZmMllOZ3pjRFBrX1cxeWFXX3hvN1FxczEwWnJSUDFST3NUMV9oUnJyWVRoLWsxMV9YSjhQcFREbUt4ODN5UUJSYWVvS0M4aWVGeEhkaW45cDcyYjAxUGZhN0RsSEw5VE0wSi1nNlJBWklWOUJRTnZlMW56VVplMlNjNGMzTzFWVWNBZGVtbGM3d1N3NW1SeFdaU1ZxWmRCOVh2TzVNRHZFNEtmWkRjbjN1LWxrT2JPUWVxa2YwdFlSaWZEXzc1OHhhdVBrWGg4cmFmVGhSZTFEa0RMZlFOLWU5cDFyb1FkVjU4MHNOOHBXalRoeFluNkY1SXVXb3BqamZMUnVLcllRSS1PM2Fyc0tpYVExZldVSjU2NVlaVHg2cTRpZjNpVThnX2hDak9HZFpiRm5OXzVoX2FuZkN0NlJOWTVsQWV5aGlhMEpsSjdFZEdka0pLRnUifQ", "signature": "ITzJgv_7rl72qtsl4B35CdrbO56K8MEw4zPmFy_ZKbB8ttiFN4MC66QkMPtolL_jHP9KCPJf8zgIi8hcm1HMDBHnH-Bx66IM46zmRMsOrFJTxeajRzU4eRCMgI9Xmc9XBLGaon13mN-juJtcnh2Tr5RhdOYZMbxDPCZhrHBc6lRMIktySDjT-5OAObtNGJYrofOBlenyjiTcA8BvAE8m6iTAt0oFiHRXC2AtAF0r1XRe6LNz1dlDfc580QoOxc0xDnMkAR7SKVOwrReMCTv5ABibdS49jvB629o3fNo7-FxnsGn-IXtr6O_-FpnZPyo6_ExHNGkypXREjQdYWkTjYQ"}'
[Thu Apr  5 12:39:50 CEST 2018] _postContentType
[Thu Apr  5 12:39:50 CEST 2018] _CURL='curl -L --silent --dump-header /export/acme-home/http.header  --trace-ascii /tmp/tmp.rioYzNECw3  -g '
[Thu Apr  5 12:39:52 CEST 2018] _ret='0'
[Thu Apr  5 12:39:52 CEST 2018] original='MIIF5DCCBMygAwIBAgITAPoFSEB/oMlZOdm4nanUhrcTaDANBgkqhkiG9w0BAQsFADAiMSAwHgYDVQQDDBdGYWtlIExFIEludGVybWVkaWF0ZSBYMTAeFw0xODA0MDUwOTM5NTFaFw0xODA3MDQwOTM5NTFaMBcxFTATBgNVBAMTDGlyYy5yaXBlLm5ldDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANAmxYsG2hXTUGNme8CgXCch09vJfsfYRjuHjV40CzXnztRIHYzlsj1CCz41hyCtYrqHWM5+ciEd4nQTrUJbALGRJ8T1QRDWMN88Tc9CShnrCyN6bXIk0UweWtRgGed5dcUXthkq8ty5HAoLUSLI2AaAdGa3oVkE5I998PgMxaBRnWu6mVsdPVh2cUzbNBAmAZzINcTyXcRd3RECkoLZCR/F/b4zne5aVGaFT4U3KZT/xlbkbzulAMSuVBackiUzpKOKUMQKDbvm12OuUeTVdTDsFOyEjI/wjN2xaOpwLHueGfLmvyA0WN898fjRoOoxMeAUjBFfHQ0Dgqe2fpl+RzMCAwEAAaOCAxwwggMYMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUDLO7fLK1MVvHLu4XfnaXMhg249MwHwYDVR0jBBgwFoAUwMwDRrlYIMxccnDz4S7LIKb1aDowdwYIKwYBBQUHAQEEazBpMDIGCCsGAQUFBzABhiZodHRwOi8vb2NzcC5zdGctaW50LXgxLmxldHNlbmNyeXB0Lm9yZzAzBggrBgEFBQcwAoYnaHR0cDovL2NlcnQuc3RnLWludC14MS5sZXRzZW5jcnlwdC5vcmcvMBcGA1UdEQQQMA6CDGlyYy5yaXBlLm5ldDCB/gYDVR0gBIH2MIHzMAgGBmeBDAECATCB5gYLKwYBBAGC3xMBAQEwgdYwJgYIKwYBBQUHAgEWGmh0dHA6Ly9jcHMubGV0c2VuY3J5cHQub3JnMIGrBggrBgEFBQcCAjCBngyBm1RoaXMgQ2VydGlmaWNhdGUgbWF5IG9ubHkgYmUgcmVsaWVkIHVwb24gYnkgUmVseWluZyBQYXJ0aWVzIGFuZCBvbmx5IGluIGFjY29yZGFuY2Ugd2l0aCB0aGUgQ2VydGlmaWNhdGUgUG9saWN5IGZvdW5kIGF0IGh0dHBzOi8vbGV0c2VuY3J5cHQub3JnL3JlcG9zaXRvcnkvMIIBBAYKKwYBBAHWeQIEAgSB9QSB8gDwAHcA3Zk0/KXnJIDJVmh9gTSZCEmySfe1adjHvKs/XMHzbmQAAAFilWQn8AAABAMASDBGAiEA3t+NfcWzPJd4ljCt/nFMiGGG9j2l6+GAkki7siC7b/wCIQCnwOfbJA0wBadtGhJ8jUJqDGYfNcnC/QWAjOqOzAMybgB1ALDMg+Wl+X1rr3wJzChJBIcqx+iLEyxjULfG/SbhbGx3AAABYpVkKDEAAAQDAEYwRAIgXeMCpE6cHdVjhTveEe60JzLn7AuBZllYH+IOhUeygAYCIEnh4RAEp45gJ75nUei3YtztXbarBk3U2Fp24atVQjlXMA0GCSqGSIb3DQEBCwUAA4IBAQCJbUn5DLI9njSOYtDNf7/9qHDPzMWAW/bs0FA5teiLs9LxEJc5ty5duooWMsb5fJ43Noz15IwoKXL8fAUg4Pwx3zynYwy5WKMgNobELeRhE+AhBiESvdiEvRHl6rXBcyriMoNwjCDLMAbFckq0EWtQrPSUtSc0FUbN+AcFZJG7t0Al38KVreDP4PB1K5v7/ZRa8jgHa4wNzcGayx6JSJ9NyxIoQ+I3p58JkFsTS1smAdgzxLFwFTv0XeBX8YP3MmBqLgfgf6kYrmyVvGnQRIxpC33plElZHOsjzJNidhB1BNzaE5i0vZe2Qym5OAgPlKAsxZJTWt0umyqB9isYu5CN'
[Thu Apr  5 12:39:52 CEST 2018] responseHeaders='HTTP/1.1 100 Continue
Expires: Thu, 05 Apr 2018 10:39:51 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache

HTTP/1.1 201 Created
Server: nginx
Content-Type: application/pkix-cert
Content-Length: 1512
Boulder-Requester: 5829535
Link: <https://acme-staging.api.letsencrypt.org/acme/issuer-cert>;rel="up"
Location: https://acme-staging.api.letsencrypt.org/acme/cert/fa0548407fa0c95939d9b89da9d486b71368
Replay-Nonce: DQSK91SQIju-iiVT6vm8XBHZxUwrPyITs3cTd60z9jo
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800
Expires: Thu, 05 Apr 2018 10:39:52 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 05 Apr 2018 10:39:52 GMT
Connection: keep-alive
'
[Thu Apr  5 12:39:52 CEST 2018] response='MIIF5DCCBMygAwIBAgITAPoFSEB/oMlZOdm4nanUhrcTaDANBgkqhkiG9w0BAQsFADAiMSAwHgYDVQQDDBdGYWtlIExFIEludGVybWVkaWF0ZSBYMTAeFw0xODA0MDUwOTM5NTFaFw0xODA3MDQwOTM5NTFaMBcxFTATBgNVBAMTDGlyYy5yaXBlLm5ldDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANAmxYsG2hXTUGNme8CgXCch09vJfsfYRjuHjV40CzXnztRIHYzlsj1CCz41hyCtYrqHWM5+ciEd4nQTrUJbALGRJ8T1QRDWMN88Tc9CShnrCyN6bXIk0UweWtRgGed5dcUXthkq8ty5HAoLUSLI2AaAdGa3oVkE5I998PgMxaBRnWu6mVsdPVh2cUzbNBAmAZzINcTyXcRd3RECkoLZCR/F/b4zne5aVGaFT4U3KZT/xlbkbzulAMSuVBackiUzpKOKUMQKDbvm12OuUeTVdTDsFOyEjI/wjN2xaOpwLHueGfLmvyA0WN898fjRoOoxMeAUjBFfHQ0Dgqe2fpl+RzMCAwEAAaOCAxwwggMYMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUDLO7fLK1MVvHLu4XfnaXMhg249MwHwYDVR0jBBgwFoAUwMwDRrlYIMxccnDz4S7LIKb1aDowdwYIKwYBBQUHAQEEazBpMDIGCCsGAQUFBzABhiZodHRwOi8vb2NzcC5zdGctaW50LXgxLmxldHNlbmNyeXB0Lm9yZzAzBggrBgEFBQcwAoYnaHR0cDovL2NlcnQuc3RnLWludC14MS5sZXRzZW5jcnlwdC5vcmcvMBcGA1UdEQQQMA6CDGlyYy5yaXBlLm5ldDCB/gYDVR0gBIH2MIHzMAgGBmeBDAECATCB5gYLKwYBBAGC3xMBAQEwgdYwJgYIKwYBBQUHAgEWGmh0dHA6Ly9jcHMubGV0c2VuY3J5cHQub3JnMIGrBggrBgEFBQcCAjCBngyBm1RoaXMgQ2VydGlmaWNhdGUgbWF5IG9ubHkgYmUgcmVsaWVkIHVwb24gYnkgUmVseWluZyBQYXJ0aWVzIGFuZCBvbmx5IGluIGFjY29yZGFuY2Ugd2l0aCB0aGUgQ2VydGlmaWNhdGUgUG9saWN5IGZvdW5kIGF0IGh0dHBzOi8vbGV0c2VuY3J5cHQub3JnL3JlcG9zaXRvcnkvMIIBBAYKKwYBBAHWeQIEAgSB9QSB8gDwAHcA3Zk0/KXnJIDJVmh9gTSZCEmySfe1adjHvKs/XMHzbmQAAAFilWQn8AAABAMASDBGAiEA3t+NfcWzPJd4ljCt/nFMiGGG9j2l6+GAkki7siC7b/wCIQCnwOfbJA0wBadtGhJ8jUJqDGYfNcnC/QWAjOqOzAMybgB1ALDMg+Wl+X1rr3wJzChJBIcqx+iLEyxjULfG/SbhbGx3AAABYpVkKDEAAAQDAEYwRAIgXeMCpE6cHdVjhTveEe60JzLn7AuBZllYH+IOhUeygAYCIEnh4RAEp45gJ75nUei3YtztXbarBk3U2Fp24atVQjlXMA0GCSqGSIb3DQEBCwUAA4IBAQCJbUn5DLI9njSOYtDNf7/9qHDPzMWAW/bs0FA5teiLs9LxEJc5ty5duooWMsb5fJ43Noz15IwoKXL8fAUg4Pwx3zynYwy5WKMgNobELeRhE+AhBiESvdiEvRHl6rXBcyriMoNwjCDLMAbFckq0EWtQrPSUtSc0FUbN+AcFZJG7t0Al38KVreDP4PB1K5v7/ZRa8jgHa4wNzcGayx6JSJ9NyxIoQ+I3p58JkFsTS1smAdgzxLFwFTv0XeBX8YP3MmBqLgfgf6kYrmyVvGnQRIxpC33plElZHOsjzJNidhB1BNzaE5i0vZe2Qym5OAgPlKAsxZJTWt0umyqB9isYu5CN'
[Thu Apr  5 12:39:52 CEST 2018] code='201'
[Thu Apr  5 12:39:52 CEST 2018] Le_LinkCert='https://acme-staging.api.letsencrypt.org/acme/cert/fa0548407fa0c95939d9b89da9d486b71368'
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            fa:05:48:40:7f:a0:c9:59:39:d9:b8:9d:a9:d4:86:b7:13:68
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN=Fake LE Intermediate X1
        Validity
            Not Before: Apr  5 09:39:51 2018 GMT
            Not After : Jul  4 09:39:51 2018 GMT
        Subject: CN=irc.ripe.net
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:d0:26:c5:8b:06:da:15:d3:50:63:66:7b:c0:a0:
                    5c:27:21:d3:db:c9:7e:c7:d8:46:3b:87:8d:5e:34:
                    0b:35:e7:ce:d4:48:1d:8c:e5:b2:3d:42:0b:3e:35:
                    87:20:ad:62:ba:87:58:ce:7e:72:21:1d:e2:74:13:
                    ad:42:5b:00:b1:91:27:c4:f5:41:10:d6:30:df:3c:
                    4d:cf:42:4a:19:eb:0b:23:7a:6d:72:24:d1:4c:1e:
                    5a:d4:60:19:e7:79:75:c5:17:b6:19:2a:f2:dc:b9:
                    1c:0a:0b:51:22:c8:d8:06:80:74:66:b7:a1:59:04:
                    e4:8f:7d:f0:f8:0c:c5:a0:51:9d:6b:ba:99:5b:1d:
                    3d:58:76:71:4c:db:34:10:26:01:9c:c8:35:c4:f2:
                    5d:c4:5d:dd:11:02:92:82:d9:09:1f:c5:fd:be:33:
                    9d:ee:5a:54:66:85:4f:85:37:29:94:ff:c6:56:e4:
                    6f:3b:a5:00:c4:ae:54:16:9c:92:25:33:a4:a3:8a:
                    50:c4:0a:0d:bb:e6:d7:63:ae:51:e4:d5:75:30:ec:
                    14:ec:84:8c:8f:f0:8c:dd:b1:68:ea:70:2c:7b:9e:
                    19:f2:e6:bf:20:34:58:df:3d:f1:f8:d1:a0:ea:31:
                    31:e0:14:8c:11:5f:1d:0d:03:82:a7:b6:7e:99:7e:
                    47:33
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Key Encipherment
            X509v3 Extended Key Usage:
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Subject Key Identifier:
                0C:B3:BB:7C:B2:B5:31:5B:C7:2E:EE:17:7E:76:97:32:18:36:E3:D3
            X509v3 Authority Key Identifier:
                keyid:C0:CC:03:46:B9:58:20:CC:5C:72:70:F3:E1:2E:CB:20:A6:F5:68:3A

            Authority Information Access:
                OCSP - URI:http://ocsp.stg-int-x1.letsencrypt.org
                CA Issuers - URI:http://cert.stg-int-x1.letsencrypt.org/

            X509v3 Subject Alternative Name:
                DNS:irc.ripe.net
            X509v3 Certificate Policies:
                Policy: 2.23.140.1.2.1
                Policy: 1.3.6.1.4.1.44947.1.1.1
                  CPS: http://cps.letsencrypt.org
                  User Notice:
                    Explicit Text: This Certificate may only be relied upon by Relying Parties and only in accordance with the Certificate Policy found at https://letsencrypt.org/repository/

            CT Precertificate SCTs:
                Signed Certificate Timestamp:
                    Version   : v1(0)
                    Log ID    : DD:99:34:FC:A5:E7:24:80:C9:56:68:7D:81:34:99:08:
                                49:B2:49:F7:B5:69:D8:C7:BC:AB:3F:5C:C1:F3:6E:64
                    Timestamp : Apr  5 10:39:51.792 2018 GMT
                    Extensions: none
                    Signature : ecdsa-with-SHA256
                                30:46:02:21:00:DE:DF:8D:7D:C5:B3:3C:97:78:96:30:
                                AD:FE:71:4C:88:61:86:F6:3D:A5:EB:E1:80:92:48:BB:
                                B2:20:BB:6F:FC:02:21:00:A7:C0:E7:DB:24:0D:30:05:
                                A7:6D:1A:12:7C:8D:42:6A:0C:66:1F:35:C9:C2:FD:05:
                                80:8C:EA:8E:CC:03:32:6E
                Signed Certificate Timestamp:
                    Version   : v1(0)
                    Log ID    : B0:CC:83:E5:A5:F9:7D:6B:AF:7C:09:CC:28:49:04:87:
                                2A:C7:E8:8B:13:2C:63:50:B7:C6:FD:26:E1:6C:6C:77
                    Timestamp : Apr  5 10:39:51.857 2018 GMT
                    Extensions: none
                    Signature : ecdsa-with-SHA256
                                30:44:02:20:5D:E3:02:A4:4E:9C:1D:D5:63:85:3B:DE:
                                11:EE:B4:27:32:E7:EC:0B:81:66:59:58:1F:E2:0E:85:
                                47:B2:80:06:02:20:49:E1:E1:10:04:A7:8E:60:27:BE:
                                67:51:E8:B7:62:DC:ED:5D:B6:AB:06:4D:D4:D8:5A:76:
                                E1:AB:55:42:39:57
    Signature Algorithm: sha256WithRSAEncryption
         89:6d:49:f9:0c:b2:3d:9e:34:8e:62:d0:cd:7f:bf:fd:a8:70:
         cf:cc:c5:80:5b:f6:ec:d0:50:39:b5:e8:8b:b3:d2:f1:10:97:
         39:b7:2e:5d:ba:8a:16:32:c6:f9:7c:9e:37:36:8c:f5:e4:8c:
         28:29:72:fc:7c:05:20:e0:fc:31:df:3c:a7:63:0c:b9:58:a3:
         20:36:86:c4:2d:e4:61:13:e0:21:06:21:12:bd:d8:84:bd:11:
         e5:ea:b5:c1:73:2a:e2:32:83:70:8c:20:cb:30:06:c5:72:4a:
         b4:11:6b:50:ac:f4:94:b5:27:34:15:46:cd:f8:07:05:64:91:
         bb:b7:40:25:df:c2:95:ad:e0:cf:e0:f0:75:2b:9b:fb:fd:94:
         5a:f2:38:07:6b:8c:0d:cd:c1:9a:cb:1e:89:48:9f:4d:cb:12:
         28:43:e2:37:a7:9f:09:90:5b:13:4b:5b:26:01:d8:33:c4:b1:
         70:15:3b:f4:5d:e0:57:f1:83:f7:32:60:6a:2e:07:e0:7f:a9:
         18:ae:6c:95:bc:69:d0:44:8c:69:0b:7d:e9:94:49:59:1c:eb:
         23:cc:93:62:76:10:75:04:dc:da:13:98:b4:bd:97:b6:43:29:
         b9:38:08:0f:94:a0:2c:c5:92:53:5a:dd:2e:9b:2a:81:f6:2b:
         18:bb:90:8d
[Thu Apr  5 12:39:52 CEST 2018] Cert success.
-----BEGIN CERTIFICATE-----
MIIF5DCCBMygAwIBAgITAPoFSEB/oMlZOdm4nanUhrcTaDANBgkqhkiG9w0BAQsF
ADAiMSAwHgYDVQQDDBdGYWtlIExFIEludGVybWVkaWF0ZSBYMTAeFw0xODA0MDUw
OTM5NTFaFw0xODA3MDQwOTM5NTFaMBcxFTATBgNVBAMTDGlyYy5yaXBlLm5ldDCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANAmxYsG2hXTUGNme8CgXCch
09vJfsfYRjuHjV40CzXnztRIHYzlsj1CCz41hyCtYrqHWM5+ciEd4nQTrUJbALGR
J8T1QRDWMN88Tc9CShnrCyN6bXIk0UweWtRgGed5dcUXthkq8ty5HAoLUSLI2AaA
dGa3oVkE5I998PgMxaBRnWu6mVsdPVh2cUzbNBAmAZzINcTyXcRd3RECkoLZCR/F
/b4zne5aVGaFT4U3KZT/xlbkbzulAMSuVBackiUzpKOKUMQKDbvm12OuUeTVdTDs
FOyEjI/wjN2xaOpwLHueGfLmvyA0WN898fjRoOoxMeAUjBFfHQ0Dgqe2fpl+RzMC
AwEAAaOCAxwwggMYMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcD
AQYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUDLO7fLK1MVvHLu4X
fnaXMhg249MwHwYDVR0jBBgwFoAUwMwDRrlYIMxccnDz4S7LIKb1aDowdwYIKwYB
BQUHAQEEazBpMDIGCCsGAQUFBzABhiZodHRwOi8vb2NzcC5zdGctaW50LXgxLmxl
dHNlbmNyeXB0Lm9yZzAzBggrBgEFBQcwAoYnaHR0cDovL2NlcnQuc3RnLWludC14
MS5sZXRzZW5jcnlwdC5vcmcvMBcGA1UdEQQQMA6CDGlyYy5yaXBlLm5ldDCB/gYD
VR0gBIH2MIHzMAgGBmeBDAECATCB5gYLKwYBBAGC3xMBAQEwgdYwJgYIKwYBBQUH
AgEWGmh0dHA6Ly9jcHMubGV0c2VuY3J5cHQub3JnMIGrBggrBgEFBQcCAjCBngyB
m1RoaXMgQ2VydGlmaWNhdGUgbWF5IG9ubHkgYmUgcmVsaWVkIHVwb24gYnkgUmVs
eWluZyBQYXJ0aWVzIGFuZCBvbmx5IGluIGFjY29yZGFuY2Ugd2l0aCB0aGUgQ2Vy
dGlmaWNhdGUgUG9saWN5IGZvdW5kIGF0IGh0dHBzOi8vbGV0c2VuY3J5cHQub3Jn
L3JlcG9zaXRvcnkvMIIBBAYKKwYBBAHWeQIEAgSB9QSB8gDwAHcA3Zk0/KXnJIDJ
Vmh9gTSZCEmySfe1adjHvKs/XMHzbmQAAAFilWQn8AAABAMASDBGAiEA3t+NfcWz
PJd4ljCt/nFMiGGG9j2l6+GAkki7siC7b/wCIQCnwOfbJA0wBadtGhJ8jUJqDGYf
NcnC/QWAjOqOzAMybgB1ALDMg+Wl+X1rr3wJzChJBIcqx+iLEyxjULfG/SbhbGx3
AAABYpVkKDEAAAQDAEYwRAIgXeMCpE6cHdVjhTveEe60JzLn7AuBZllYH+IOhUey
gAYCIEnh4RAEp45gJ75nUei3YtztXbarBk3U2Fp24atVQjlXMA0GCSqGSIb3DQEB
CwUAA4IBAQCJbUn5DLI9njSOYtDNf7/9qHDPzMWAW/bs0FA5teiLs9LxEJc5ty5d
uooWMsb5fJ43Noz15IwoKXL8fAUg4Pwx3zynYwy5WKMgNobELeRhE+AhBiESvdiE
vRHl6rXBcyriMoNwjCDLMAbFckq0EWtQrPSUtSc0FUbN+AcFZJG7t0Al38KVreDP
4PB1K5v7/ZRa8jgHa4wNzcGayx6JSJ9NyxIoQ+I3p58JkFsTS1smAdgzxLFwFTv0
XeBX8YP3MmBqLgfgf6kYrmyVvGnQRIxpC33plElZHOsjzJNidhB1BNzaE5i0vZe2
Qym5OAgPlKAsxZJTWt0umyqB9isYu5CN
-----END CERTIFICATE-----
[Thu Apr  5 12:39:52 CEST 2018] Your cert is in  /export/acme-certs/irc.ripe.net/irc.ripe.net.cer
[Thu Apr  5 12:39:52 CEST 2018] Your cert key is in  /export/acme-certs/irc.ripe.net/irc.ripe.net.key
[Thu Apr  5 12:39:52 CEST 2018] Le_LinkIssuer='https://acme-staging.api.letsencrypt.org/acme/issuer-cert'
[Thu Apr  5 12:39:52 CEST 2018] _link_issuer_retry='0'
[Thu Apr  5 12:39:52 CEST 2018] GET
[Thu Apr  5 12:39:52 CEST 2018] url='https://acme-staging.api.letsencrypt.org/acme/issuer-cert'
[Thu Apr  5 12:39:52 CEST 2018] timeout=
[Thu Apr  5 12:39:52 CEST 2018] _CURL='curl -L --silent --dump-header /export/acme-home/http.header  --trace-ascii /tmp/tmp.RQ92AF16mC  -g '
[Thu Apr  5 12:39:52 CEST 2018] ret='0'
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            8b:e1:2a:0e:59:44:ed:3c:54:64:31:f0:97:61:4f:e5
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN=Fake LE Root X1
        Validity
            Not Before: May 23 22:07:59 2016 GMT
            Not After : May 23 22:07:59 2036 GMT
        Subject: CN=Fake LE Intermediate X1
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:ed:58:ac:92:0e:7e:eb:59:97:39:82:08:f3:dd:
                    90:74:f2:33:b8:c6:d8:b7:bb:32:0d:7c:3e:6c:43:
                    b2:e3:ee:1c:de:b5:44:fe:c1:0a:1b:fa:25:d2:66:
                    48:67:bf:1f:88:bd:d6:d7:17:9f:f2:b7:c6:96:3e:
                    95:0a:9c:fc:a6:a0:bc:6c:62:22:39:81:00:4b:c4:
                    d0:f3:21:e7:34:38:86:9f:95:6a:80:af:6f:66:ec:
                    9f:3e:34:db:40:a4:43:7c:9d:91:67:7f:76:e1:7a:
                    16:56:ec:0c:66:4b:59:b4:66:74:ac:74:7c:34:17:
                    0f:9b:82:2c:4f:83:63:10:f6:4f:68:79:f1:5e:a9:
                    af:bb:2a:a7:65:cf:96:db:ad:46:15:da:fa:25:c6:
                    10:c5:b6:72:38:32:1f:01:89:60:8d:c4:31:f5:1e:
                    2c:ea:f8:62:82:70:7b:22:9c:36:56:ba:b0:aa:75:
                    ea:ff:69:f2:41:9d:0b:3e:48:14:8b:e8:c5:40:a4:
                    7b:7e:77:7e:73:8c:10:fd:d9:f3:b6:25:ee:7a:76:
                    13:1f:cc:28:0e:29:77:89:df:8d:16:85:6d:d3:8c:
                    3d:73:a8:b6:57:79:a0:b2:50:d4:67:7c:e9:96:65:
                    5f:27:12:1b:47:38:56:d4:09:4e:eb:fc:a9:23:31:
                    93:bd
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Subject Key Identifier:
                C0:CC:03:46:B9:58:20:CC:5C:72:70:F3:E1:2E:CB:20:A6:F5:68:3A
            Authority Information Access:
                OCSP - URI:http://ocsp.stg-root-x1.letsencrypt.org/
                CA Issuers - URI:http://cert.stg-root-x1.letsencrypt.org/

            X509v3 Authority Key Identifier:
                keyid:C1:26:74:A4:8A:44:A0:E6:FA:20:28:D8:5C:23:9A:45:88:18:79:E0

    Signature Algorithm: sha256WithRSAEncryption
         05:84:ae:e0:89:7e:7c:8d:0c:61:4e:36:39:39:84:8f:ed:47:
         a9:0e:43:bf:20:1e:c8:20:3a:b0:6b:99:77:08:c5:50:67:95:
         3a:fd:cd:9c:bc:9f:a1:fb:94:3a:31:1b:63:98:ab:14:20:ed:
         9e:ff:b4:72:4b:a4:51:93:7d:97:3e:10:d9:88:d6:19:4a:56:
         e1:34:ee:de:27:93:b1:a0:bd:00:5b:c2:4a:03:47:27:25:92:
         56:d5:af:07:95:c3:c6:ca:9a:c2:5d:4a:cc:7c:f3:c2:bd:77:
         d9:b1:76:ae:d1:ad:6b:34:aa:56:a2:bd:13:4e:ec:18:73:02:
         7f:ec:e9:0d:05:43:55:51:ad:a9:93:c7:c1:7d:ca:a9:4b:5e:
         7c:4e:b6:d5:bf:11:23:a5:42:97:8a:03:df:43:a5:7f:ca:63:
         bb:31:b8:24:a0:45:44:57:25:cc:b4:63:a3:f8:7b:22:49:1f:
         8d:9f:30:0d:ae:df:68:e8:d5:5f:1e:a7:f9:e5:10:db:d7:08:
         30:2c:eb:f3:fa:cd:58:74:bd:a5:81:86:40:a2:62:63:6c:66:
         54:2f:61:d7:61:fd:f5:7c:9f:cd:61:3d:bd:be:73:28:fd:cc:
         54:6e:a7:79:7d:61:49:da:3b:3c:40:1b:f5:fa:91:84:79:2a:
         56:ca:94:bc:99:48:46:6b:d7:bd:52:93:c0:d0:8f:dd:e0:a3:
         44:20:88:3d:30:2f:8d:5f:b8:9e:2e:fc:ea:25:f0:c0:56:0d:
         cf:c9:77:3e:63:cb:0b:24:17:58:6a:21:9c:9f:22:06:6f:b9:
         9e:4e:ce:db:29:da:3d:55:b4:53:65:be:a6:dd:b0:49:5b:af:
         74:33:39:cc:6b:f6:7f:d9:6d:35:65:22:61:91:c9:d6:69:8e:
         f7:b8:d2:63:fe:98:7d:d3:94:1f:ae:a2:46:d4:2d:0e:41:c1:
         45:d9:0d:06:c3:1b:0f:e1:26:d9:38:01:95:db:47:35:22:41:
         7c:1d:e9:9b:d1:5b:96:03:9c:27:41:52:59:c5:03:58:9e:ef:
         3b:4f:8d:4d:79:60:ad:1a:1f:45:3e:a9:57:2c:33:c5:5a:3a:
         74:d0:f4:5b:36:25:4d:67:94:56:c3:b8:d3:12:6a:86:05:10:
         44:44:7d:60:b3:8b:c4:9d:0e:e8:2f:22:d3:11:71:00:c2:8e:
         b5:27:68:74:c0:77:44:8c:2d:ed:11:50:d2:ec:ad:9f:96:79:
         32:a9:18:86:53:08:dc:9d:6d:3d:14:e9:d6:71:2d:f5:fc:86:
         b2:90:4e:3b:4e:60:8b:5e:3c:41:ab:29:fb:73:7e:b2:fa:8a:
         a2:6a:10:82:53:68:03:15
[Thu Apr  5 12:39:52 CEST 2018] The intermediate CA cert is in  /export/acme-certs/irc.ripe.net/ca.cer
[Thu Apr  5 12:39:52 CEST 2018] And the full chain certs is there:  /export/acme-certs/irc.ripe.net/fullchain.cer
[Thu Apr  5 12:39:52 CEST 2018] _on_issue_success
[Thu Apr  5 12:39:52 CEST 2018] 'dns_nsupdate' does not contain 'dns'```


@Neilpang
Copy link
Member

Neilpang commented Apr 6, 2018

--deploy-hook is only valid for --deploy command.

@Neilpang Neilpang closed this as completed Apr 6, 2018
@trompx
Copy link

trompx commented Apr 9, 2018

Would it be possible to have a deploy-hook similar to the certbot one which triggers only on successful certificates generation / renewal ?
From my understanding the pre and post hook of acme.sh triggers at each attemps. As stated here https://github.com/Neilpang/acme.sh/wiki/Using-'--pre-hook',-'--post-hook',-'--renew-hook'-and-'--reload-cmd', unless it is not explained correctly, I don't see the use to close re-open a server only on an attempt as it may fails. We should execute that action only if new certificates have been issued/renewed successfully.

@gitbobo
Copy link

gitbobo commented Oct 30, 2018

--deploy-hook is only valid for --deploy command.

@Neilpang ,cannot find any document about --deploy in wiki.
@trompx ,the link is blank.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants