Repository navigation
v0.3.21
·
125 commits
to master
since this release
追加
- ACME で証明書を取り、自動で更新できるようになりました(#208)。設定と使い方は docs/ACME.md。
- challenge:HTTP-01(
httpのルールか、80 番の小さな待ち受けhttp01_listen)、TLS-ALPN-01(terminateのルール)、DNS-01。 - DNS-01 のプロバイダ:PowerDNS の HTTP API、汎用の REST(テンプレート)、RFC 2136(TSIG。応答の署名も確かめる)、acme-dns。
_acme-challengeの CNAME をたどって委任先のゾーンに書く。TXT は必ず消し、消し残しは次の起動で消す。 - 更新:期限の 30 日前(または期間の 3 分の 1)。CA が ARI を出すときはその窓の中。失敗したら間隔を空けて取り直し、その間は今の証明書を使い続ける。
- 設定:
global.acmeのaccounts・dns_providers・resolvers。ルールは今までどおりtls.certificates[]の{acme: <resolver>, domains}。 - API:
GET /acme(状態。秘密は出さない)、POST /acme/renew・/acme/revoke・/acme/accounts/{name}/register・/deactivate(acme:write、既定で Unix ソケットからだけ)。
- challenge:HTTP-01(
- 守り
- DNS の秘密は固定の設定からファイルで指すだけで、API・応答・ログに出さない。
- アカウントと DNS のプロバイダの両方に、発行してよい名前の許可リスト(
allowed_names)。外の名前は 400。ワイルドカードは DNS-01 だけ。 - 新しいスコープ
acme:write。発行の回数の上限(既定 1 時間に 10)。acme.*・auditのログ(秘密なし)。 - 任意で、DNS の秘密を別のユーザーで動く補助プロセス(
rproxy-api acme-helper、rproxy-acme-helper.service)に持たせ、本体は秘密を読まない形にできる(docs/PERMISSIONS.md)。
- Traefik からの変換ツールが
certResolverを rproxy の ACME の設定(秘密は入れない骨組み)に変換するようになりました。
変更
- 「ACME は内蔵しない」方針を変えました。
GET /capabilitiesのfeatures.acmeは true です。 - 前の版の
global.acme(一度も動いていなかった形)は使えません。docs/ACME.md の形で書いてください。 - パッケージに
StateDirectory=rproxy(/var/lib/rproxy。ACME のアカウントの鍵と証明書の置き場所)と、補助プロセス用のrproxy-acmeユーザー・サービス(入れるだけで有効にはしない)を足しました。purge で/var/lib/rproxyと/var/lib/rproxy-acmeを消します。
Added
- Certificates can be obtained and renewed with ACME (#208). See docs/en/ACME.md.
- Challenges: HTTP-01 (an
httprule, or the smallhttp01_listenresponder on port 80), TLS-ALPN-01 (terminaterules), DNS-01. - DNS-01 providers: PowerDNS HTTP API, generic REST templates, RFC 2136 (TSIG, with signed answers verified) and acme-dns. The
_acme-challengeCNAME is followed to the delegated zone; TXT records are always removed, and leftovers are removed at the next start. - Renewal 30 days before expiry (or a third of the lifetime), inside the CA's ARI window when offered. Failures retry with backoff while the current certificate stays in use.
- Config:
accounts,dns_providersandresolversunderglobal.acme. Rules keep{acme: <resolver>, domains}intls.certificates[]. - API:
GET /acme(state, no secrets);POST /acme/renew,/acme/revoke,/acme/accounts/{name}/registerand/deactivate(acme:write, Unix socket only by default).
- Challenges: HTTP-01 (an
- Safeguards
- DNS secrets are only referenced as files in the fixed config, never in the API, responses or logs.
allowed_namesallowlists on both the account and the DNS provider; other names get 400; wildcards need DNS-01.- New scope
acme:write, an issuance rate limit (10 per hour by default),acme.*andauditlog events without secrets. - Optionally, a helper process running as another user (
rproxy-api acme-helper,rproxy-acme-helper.service) holds the DNS secrets so the main process never reads them (docs/en/PERMISSIONS.md).
- The Traefik converter maps
certResolverto an rproxy ACME skeleton (secrets left out).
Changed
- The "no built-in ACME" policy is reversed;
features.acmeinGET /capabilitiesis true. - The old
global.acmeshape (which never worked) is gone; use the shape in docs/en/ACME.md. - The package adds
StateDirectory=rproxy(/var/lib/rproxy, where ACME keys and certificates live) and anrproxy-acmeuser and helper service (installed, not enabled). Purge removes/var/lib/rproxyand/var/lib/rproxy-acme.