Commit Graph

74 Commits

Author SHA1 Message Date
Arjan H
f000abb97d Issuer cert can now also be ECDSA
Apparently the cfssl issue was resolved at some time
2022-06-03 10:08:57 +02:00
Arjan H
cfac480241 Retain new certificatesPerFQDNSetFast in rate-limit-policies.yml 2022-05-11 18:46:58 +02:00
Arjan H
3ef8777b63 Fix rate-limit-policies.yml generation with multiple domains (#45) 2022-05-11 18:24:23 +02:00
Arjan H
de64d833ef Fix rate-limit-policies.yml generation with multiple domains (#45) 2022-05-11 18:10:18 +02:00
Arjan H
578c63afac Bump boulder version to release-2022-05-02 2022-05-03 20:08:10 +02:00
Arjan H
6a67044372 Option to import backup instead of setting up from scratch on new install (#44) 2022-04-29 19:24:34 +02:00
Arjan H
286a7667a1 Fix cron log icon; improve troubleshooting info 2022-04-29 19:24:34 +02:00
Arjan H
960bd72567 Update troubleshooting log locations (#43) 2022-04-23 11:26:15 +02:00
Arjan H
b9a35633d9 Make backup files downloadable (#44) 2022-04-23 11:19:30 +02:00
Arjan H
9e411e03b5 Improve cronjob logging; expose cron log in web gui 2022-04-23 11:11:30 +02:00
Arjan H
e64c5e4c1f More docker-only refactoring and fixes (#37) 2022-04-19 19:08:30 +02:00
Arjan H
091e532308 Move commander service from host to docker container (#37 #38) 2022-04-17 19:36:46 +02:00
Arjan H
99d8bbe6be Generate new cert when changing fqdn 2022-04-16 19:14:10 +02:00
Arjan H
169b147078 Extract code patching to separate script 2022-04-15 11:12:12 +02:00
Arjan H
69fc88c689 Make update from gui more robust 2022-04-14 20:43:13 +02:00
Arjan H
1d2eea47c7 Update go.mod to go 1.17 2022-04-13 19:06:43 +02:00
Arjan H
cf0531e82b Fix handling of special characters in organization name (#40)
E.g. a-umlaut
2022-04-12 21:26:10 +02:00
Arjan H
954d9bb014 Run nginx as docker container instead of on the host system (#36) 2022-04-02 13:01:52 +02:00
Arjan H
669c107c89 Remove changes to obsolete wfe.json and v1_integration.py (#32) 2022-02-16 20:56:13 +01:00
Arjan H
7773183208 Cosmetic: update year 2022-02-01 21:21:37 +01:00
Arjan H
d80cd3958c Remove CRLF from uploaded PEM certificate (#31) 2022-02-01 20:20:11 +01:00
Andrea Spagnolo
388b0de650 fixed the creation of the hostname-policy.yaml file when use Whitelist option 2022-01-31 06:58:28 +01:00
Arjan H
dda8ecd4ba Downgrade some errors to warnings on dashboard 2021-12-05 10:12:29 +01:00
Arjan H
b5cdcbb414 Fix cert-checker for whitelist/lockdown domains 2021-12-05 10:02:15 +01:00
Arjan H
d7c1cbe118 Make initial setup process a bit more clear 2021-12-04 19:08:52 +01:00
Arjan H
fcab9f6b2d Add comment to hostname-policy.yaml for whitelist/lockdown section 2021-12-04 13:40:49 +01:00
Arjan H
503d1e51ef Enable more than one local domain to issue certificates for (#24) 2021-12-03 20:34:01 +01:00
Arjan H
af69bd5ff4 Encode freshly generated keys to base64 (#27)
On the very first run, the authorization and encryption keys are generated as []byte but they should be
stored base64 encoded so they match the value as loaded in consecutive runs
2021-11-29 19:51:06 +01:00
Arjan H
5b90b99955 Remove explicit maxConnectionAge from CA grpc config (#26)
Both grpc sections in ca-a.json and ca-b.json are the only places with a maxConnectionAge configured, and these seem to be the cause of the many "failed to complete security handshake" / "operation was canceled" audit error messsages.
2021-11-07 10:15:50 +01:00
Arjan H
d045cd4639 Bump boulder version to release-2021-11-02 2021-11-06 09:26:29 +01:00
Arjan H
7b91eba163 Stop sharing admin session with ALL users (#27)
Decode the authorization and encryption keys fetched from the config file ase they are base64 but need to be a []byte. Fixes #27
2021-11-03 07:43:35 +01:00
Arjan H
9bb689143d Make initial setup phase more robust 2021-08-29 17:19:24 +02:00
Arjan H
1cc796999a Make initial setup phase more robust 2021-08-24 19:26:56 +02:00
Arjan H
64f7f23ec5 Show more information on page to diagnose initial problems 2021-08-22 17:22:06 +02:00
Arjan H
91081cff63 Install zip if not present (#18) 2021-06-01 08:44:52 +02:00
Arjan H
033b4a0e4f Don't show dbdata backups as restorable from gui 2021-05-22 18:19:10 +02:00
Arjan H
ab1a67bb64 Bump boulder version to release-2021-03-29 2021-05-21 21:54:28 +02:00
Arjan H
8db02e2d38 Backup database as part of update 2021-05-20 18:47:39 +02:00
Arjan H
2dac04c1c4 Show revoked+expired certificates in both the revoked and the expired lists 2021-03-06 11:51:12 +01:00
Arjan H
d9c78c5376 Tweak description string of whitelist mode 2021-03-03 17:27:28 +01:00
Arjan H
b2a0738816 Fix config substitutions for whitelist mode (#15) 2021-03-03 17:27:28 +01:00
Arjan H
6856989e4d Hold off on starting boulder until setup wizzard is completed
#15
2021-02-28 20:27:46 +01:00
Arjan H
933c0dadb5 Make config substitutions more robust
#15
2021-02-27 10:02:46 +01:00
Arjan H
75f8883835 Minor tweaks 2021-02-23 20:25:00 +01:00
Arjan H
319949831b Fix query buildup when combining tables 2021-02-14 16:17:11 +01:00
Arjan H
4d7a50dcae Deal with old table names not existing on fresh installations 2021-02-14 13:03:05 +01:00
Arjan H
49fb197f32 Some code cleanups 2021-02-14 10:58:48 +01:00
Arjan H
8246b14dcd Handle some more error situations 2021-02-13 11:23:05 +01:00
Arjan H
f922d2e6f5 Convert to go module because of issue with hcl/printer in GOPATH mode
cannot find package "github.com/hashicorp/hcl/hcl/printer" in any of:
        /usr/local/go/src/github.com/hashicorp/hcl/hcl/printer (from $GOROOT)
        /go/src/github.com/hashicorp/hcl/hcl/printer (from $GOPATH)
2021-02-13 11:23:05 +01:00
Arjan H
51aec5f6c1 Cosmetic: update year 2021-01-15 20:14:34 +01:00