Arjan H
9bad889fab
Use redis for OCSP as well, in different database number
2025-02-16 16:25:27 +01:00
Arjan H
f14a2636c5
Bump boulder version to release-2025-02-04; add redis container
...
Let's Encrypt has changed the rate limiter to require redis, so we can
no longer remove it from the docker compose filei completely. But at
least we can run it once instead of four instances.
2025-02-10 19:38:38 +01:00
Arjan H
6d72d32398
Use ceremony tool for generating keys and certs; store keys on SoftHSM
...
Replace openssl certificate / CRL generation with the tool as used by
Let's Encrypt, storing the keys on SoftHSMv2, a simulated HSM (Hardware
Security Module).
Include migration of old setups where key files were also stored on
disk.
2025-01-31 20:44:48 +01:00
Arjan H
120048ff30
Bump boulder version to release-2024-12-10
2024-12-13 18:00:40 +01:00
Arjan H
cab563d1d7
Bump boulder version to release-2024-07-29
2024-08-30 16:31:07 +02:00
Arjan H
ddbaa63b5b
Bump boulder version to release-2024-05-20
2024-08-24 15:15:21 +02:00
Arjan H
4eb3ad877c
Bump boulder version to release-2024-05-06
2024-07-02 19:47:47 +02:00
Arjan H
8b116d08e2
Bump boulder version to release-2024-04-08
2024-04-09 21:00:36 +02:00
Arjan H
df520e64f7
Bump boulder version to release-2024-02-26
2024-03-03 11:41:24 +01:00
Arjan H
df3d112d42
Bump boulder version to release-2024-02-20
2024-02-23 20:18:53 +01:00
Arjan H
98871cd6e7
Suppress 'must end in IANA registered TLD' error on renewal ( #114 )
...
When using whitelist/lockdown domains, also accept them in va.extractRequestTarget().
Apparently that method only gets used on renewal but not during the original request?
2024-02-23 17:52:38 +01:00
Arjan H
bef3544d5e
Bump boulder version to release-2024-01-22
2024-01-26 20:08:22 +01:00
Arjan H
736b361228
Bump boulder version to release-2023-09-11
2023-09-20 19:26:33 +02:00
Arjan H
0cc6fb6b93
Bump boulder version to release-2023-08-14
2023-08-17 19:35:56 +02:00
Arjan H
d7f4c10fd9
Bump boulder version to release-2023-06-12
2023-06-13 18:46:42 +02:00
Arjan H
6353767d3c
Reduce akamai purger interval to save CPU cycles
2023-04-23 14:52:49 +02:00
Arjan H
0ed9d8eac2
Build and use local docker images for docker-only setup ( #41 )
...
For now, the images are still built on the target machine for testing,
in the end they need to be built in a GitHub action.
2023-04-15 09:19:17 +02:00
Arjan H
412762cc58
Bump boulder version to release-2023-04-04
2023-04-07 13:44:44 +02:00
Arjan H
780c10daeb
Bump boulder version to release-2022-10-25
2022-10-26 20:38:34 +02:00
Arjan H
40da9493d4
Bump boulder version to release-2022-10-17
2022-10-23 13:10:17 +02:00
Arjan H
516aa4b605
Add workflow to regularly test if the patches can still be applied to latest boulder
2022-09-17 12:21:56 +02:00