New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[stable12] Handle SSL certificate verifications for others than Let's Encrypt #8184

Merged
merged 1 commit into from Feb 8, 2018

Conversation

Projects
None yet
3 participants
@robert-scheck
Contributor

robert-scheck commented Feb 5, 2018

Backport of #8182

Do no longer (wrongly) rewrite URLs like

for automated SSL certificate verifications. All (common commercial) certificate authorities (CA) except Let's Encrypt (via ACME) seem to use "pki-validation" rather "acme-challenge" for their domain control validation (DCV).

Signed-off-by: Robert Scheck robert@fedoraproject.org

Handle SSL certificate verifications for others than Let's Encrypt
Do no longer (wrongly) rewrite URLs like

  * http://example.net/.well-known/pki-validation/file.txt (Comodo)
  * http://example.net/.well-known/pki-validation/fileauth.txt (DigiCert, Thawte, GeoTrust)
  * http://example.net/.well-known/pki-validation/gsdv.txt (GlobalSign)
  * http://example.net/.well-known/pki-validation/starfield.htm (Starfield, GoDaddy)
  * http://example.net/.well-known/pki-validation/swisssign-check.txt (SwissSign)

for automated SSL certificate verifications. All (common commercial)
certificate authorities (CA) except Let's Encrypt (via ACME) seem to
use "pki-validation" rather "acme-challenge" for their domain control
validation (DCV).

Signed-off-by: Robert Scheck <robert@fedoraproject.org>

@robert-scheck robert-scheck changed the title from Handle SSL certificate verifications for others than Let's Encrypt to [stable12] Handle SSL certificate verifications for others than Let's Encrypt Feb 5, 2018

@codecov

This comment has been minimized.

codecov bot commented Feb 5, 2018

Codecov Report

Merging #8184 into stable12 will increase coverage by <.01%.
The diff coverage is 0%.

@@              Coverage Diff               @@
##             stable12    #8184      +/-   ##
==============================================
+ Coverage       53.83%   53.84%   +<.01%     
  Complexity      22761    22761              
==============================================
  Files            1385     1385              
  Lines           87150    87150              
  Branches         1331     1331              
==============================================
+ Hits            46920    46925       +5     
+ Misses          40230    40225       -5
Impacted Files Coverage Δ Complexity Δ
lib/private/Setup.php 12.39% <0%> (ø) 50 <0> (ø) ⬇️
core/js/js.js 61.83% <0%> (+0.55%) 0% <0%> (ø) ⬇️

@rullzer rullzer requested a review from nickvergessen Feb 8, 2018

@MorrisJobke MorrisJobke merged commit e328ced into nextcloud:stable12 Feb 8, 2018

2 of 3 checks passed

codecov/patch 0% of diff hit (target 53.83%)
Details
codecov/project 53.84% (+<.01%) compared to 6b4ddfd
Details
continuous-integration/drone/pr the build was successful
Details

@MorrisJobke MorrisJobke referenced this pull request Mar 9, 2018

Merged

12.0.6 RC 1 #8750

2 of 2 tasks complete
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment