Skip to content

v0.3.21

Choose a tag to compare

@github-actions github-actions released this 06 Oct 18:29
· 125 commits to master since this release
e919404

追加

  • ACME で証明書を取り、自動で更新できるようになりました(#208)。設定と使い方は docs/ACME.md。
    • challenge:HTTP-01(http のルールか、80 番の小さな待ち受け http01_listen)、TLS-ALPN-01(terminate のルール)、DNS-01。
    • DNS-01 のプロバイダ:PowerDNS の HTTP API、汎用の REST(テンプレート)、RFC 2136(TSIG。応答の署名も確かめる)、acme-dns。_acme-challenge の CNAME をたどって委任先のゾーンに書く。TXT は必ず消し、消し残しは次の起動で消す。
    • 更新:期限の 30 日前(または期間の 3 分の 1)。CA が ARI を出すときはその窓の中。失敗したら間隔を空けて取り直し、その間は今の証明書を使い続ける。
    • 設定:global.acme の accounts・dns_providers・resolvers。ルールは今までどおり tls.certificates[] の {acme: <resolver>, domains}。
    • API:GET /acme(状態。秘密は出さない)、POST /acme/renew・/acme/revoke・/acme/accounts/{name}/register・/deactivate(acme:write、既定で Unix ソケットからだけ)。
  • 守り
    • DNS の秘密は固定の設定からファイルで指すだけで、API・応答・ログに出さない。
    • アカウントと DNS のプロバイダの両方に、発行してよい名前の許可リスト(allowed_names)。外の名前は 400。ワイルドカードは DNS-01 だけ。
    • 新しいスコープ acme:write。発行の回数の上限(既定 1 時間に 10)。acme.*・audit のログ(秘密なし)。
    • 任意で、DNS の秘密を別のユーザーで動く補助プロセス(rproxy-api acme-helper、rproxy-acme-helper.service)に持たせ、本体は秘密を読まない形にできる(docs/PERMISSIONS.md)。
  • Traefik からの変換ツールが certResolver を rproxy の ACME の設定(秘密は入れない骨組み)に変換するようになりました。

変更

  • 「ACME は内蔵しない」方針を変えました。GET /capabilities の features.acme は true です。
  • 前の版の global.acme(一度も動いていなかった形)は使えません。docs/ACME.md の形で書いてください。
  • パッケージに StateDirectory=rproxy(/var/lib/rproxy。ACME のアカウントの鍵と証明書の置き場所)と、補助プロセス用の rproxy-acme ユーザー・サービス(入れるだけで有効にはしない)を足しました。purge で /var/lib/rproxy と /var/lib/rproxy-acme を消します。

UI: TCP-UDP-rproxy-ui v0.3.21


Added

  • Certificates can be obtained and renewed with ACME (#208). See docs/en/ACME.md.
    • Challenges: HTTP-01 (an http rule, or the small http01_listen responder on port 80), TLS-ALPN-01 (terminate rules), DNS-01.
    • DNS-01 providers: PowerDNS HTTP API, generic REST templates, RFC 2136 (TSIG, with signed answers verified) and acme-dns. The _acme-challenge CNAME is followed to the delegated zone; TXT records are always removed, and leftovers are removed at the next start.
    • Renewal 30 days before expiry (or a third of the lifetime), inside the CA's ARI window when offered. Failures retry with backoff while the current certificate stays in use.
    • Config: accounts, dns_providers and resolvers under global.acme. Rules keep {acme: <resolver>, domains} in tls.certificates[].
    • API: GET /acme (state, no secrets); POST /acme/renew, /acme/revoke, /acme/accounts/{name}/register and /deactivate (acme:write, Unix socket only by default).
  • Safeguards
    • DNS secrets are only referenced as files in the fixed config, never in the API, responses or logs.
    • allowed_names allowlists on both the account and the DNS provider; other names get 400; wildcards need DNS-01.
    • New scope acme:write, an issuance rate limit (10 per hour by default), acme.* and audit log events without secrets.
    • Optionally, a helper process running as another user (rproxy-api acme-helper, rproxy-acme-helper.service) holds the DNS secrets so the main process never reads them (docs/en/PERMISSIONS.md).
  • The Traefik converter maps certResolver to an rproxy ACME skeleton (secrets left out).

Changed

  • The "no built-in ACME" policy is reversed; features.acme in GET /capabilities is true.
  • The old global.acme shape (which never worked) is gone; use the shape in docs/en/ACME.md.
  • The package adds StateDirectory=rproxy (/var/lib/rproxy, where ACME keys and certificates live) and an rproxy-acme user and helper service (installed, not enabled). Purge removes /var/lib/rproxy and /var/lib/rproxy-acme.

UI: TCP-UDP-rproxy-ui v0.3.21