Timothe Litt
568e3373fc
Add delimiter to INVALID PRIVATE_KEY_ALG message
9 years ago
Timothe Litt
134456b968
Fix misleading error message saving certificates to file.
9 years ago
Timothe Litt
49d837de53
Improve message from curl error code 60
Issue #288
9 years ago
Yannic Haupenthal
d0447886c9
Add OCSP Must-Staple
This implements a new variable OCSP_MUST_STAPLE which adds the OCSP Must-Staple detail to the SAN section of the CSR.
If the openssl version is >= 1.1.0, one can also use "tlsfeature = status_request".
See [this blog post](https://scotthelme.co.uk/ocsp-must-staple/ ) for more details.
9 years ago
srvrco
cb7779102a
issue #243 additional compatibility with bash 3.0
9 years ago
srvrco
33f6eb9963
maintain compatibility with bash 3.0 Issue #243
9 years ago
srvrco
3dd1b35807
issue #232 use neutral locale for date formatting
9 years ago
srvrco
51f59b5276
issue #231 mingw bugfix and typos in debug messages
9 years ago
srvrco
df3285deee
bugfix - deleting csr ( #227 ) and check domain/private key different ( #228 )
9 years ago
srvrco
60e04aeeaa
added drill, dig or host as alternatives to nslookup
9 years ago
srvrco
7c8e517164
force renew if FORCE_RENEWAL file exists #214
9 years ago
srvrco
ed519319f7
Created check_config function to list all obvious config issues
9 years ago
srvrco
e9ec9067e8
add additional config checks
9 years ago
srvrco
0ef348b5e7
ignore expiry if upgrading from staging to live server
9 years ago
srvrco
c3f380e527
include key types in config check
9 years ago
srvrco
b901b9d3ec
dont loop over domains for DNS_ADD_COMMAND check
9 years ago
srvrco
f9696802e0
updated history
9 years ago
srvrco
0c519f52e0
add check config function
9 years ago
srvrco
d76f4952ea
small typo, and modified formatting
9 years ago
micheloe
b3988013e8
Added explicit sorting on old file versions
9 years ago
micheloe
c854baffd7
Added option to limit amount of old versions to keep (2.01)
9 years ago
srvrco
5e5d501082
stable release 2.00
9 years ago
micheloe
c0d6c8e962
tidied up upgrade tmpfile handling (1.95)
9 years ago
micheloe
e150ad067a
fix leftover tmpfiles in upgrade routine (1.94)
9 years ago
srvrco
9fc0928d33
update checks to work with openssl in FIPS mode (1.93)
9 years ago
Felipe Zipitria
510ba53c16
check generated keys without depending on inside text
In openssl FIPS mode, files don't have the "[RSA|EC] PRIVATE KEY" text inside when the private key is generated.
Therefore, grep will not find the words and fails with invalid key file.
Resolves : #204
9 years ago
srvrco
e6da3ddbbd
bug fix for copying tokens to multiple locations
9 years ago
srvrco
511ccd4285
allow copying files to multiple locations (1.91)
9 years ago
srvrco
058818239e
included IGNORE_DIRECTORY_DOMAIN option #196
9 years ago
srvrco
fa83fe5d6b
bug fix for CA #197
9 years ago
srvrco
cfef4019e0
allow user to ignore permission preservation with nfsv3 shares #195
9 years ago
srvrco
4a701c35c8
updated DOMAIN_PEM_LOCATION when using DUAL_RSA_ECDSA #190
9 years ago
srvrco
196bd2c4b1
added fullchain to archive ( #194 ) and CSR_SUBJECT variable ( #193 )
9 years ago
srvrco
fb9e16cfd6
bugfix CSR renewal when no SANS #191 and when using MINGW #189
9 years ago
uwedisch
61bb285d97
add HTTP_TOKEN_CHECK_WAIT option (1.84)
If someone is running load balanced servers that use the same certificate there is some time needed to wait until the token is replicated within the server instances.
9 years ago
srvrco
568bb725a7
add PREVENT_NON_INTERACTIVE_RENEWAL option
9 years ago
srvrco
73a1a4a4eb
bug fix DOMAIN_KEY_CERT generation
9 years ago
srvrco
f08636d4ed
Add SKIP_HTTP_TOKEN_CHECK option (Issue #170 )
9 years ago
dedinext
71fb8226c1
Correct spelling
9 years ago
dedinext
2e7b552e6e
Add and comment optional sshuserid for ssh ACL
9 years ago
srvrco
36e3428ac5
bug fix openssl v1.1.0 ( #166 ) and DOMAIN_PEM_LOCATION ( #167 )
9 years ago
srvrco
724d30a132
updating to a consistent style guide
9 years ago
srvrco
bb85f9f052
added TOKEN_USER_ID #162 and updated for latest shellcheck
9 years ago
srvrco
f0d6d26d86
Reduce long lines, and remove echo from update #163
9 years ago
srvrco
6822a0e648
remove only specified DNS token #161
9 years ago
srvrco
f857fa6f70
fix warning message if cert doesn't exist
9 years ago
Christian Schrötter
5ed5f251b4
Hide error message if cert file does not exist.
9 years ago
srvrco
d94daecc75
bug fix - issue #157 not recognising EC keys on some versions of openssl
9 years ago
srvrco
408a72e6aa
Date formatting for busybox
9 years ago
srvrco
96c8b9bc4e
Improvements on portability
9 years ago