summaryrefslogtreecommitdiffstats
path: root/dehydrated (follow)
Commit message (Collapse)AuthorAgeFilesLines
* Also listing certificate name when sending nsupdate in dehydrated-nsupdate ↵HEADmainDaniel Baumann2024-02-061-1/+1
| | | | | | hook to be more verbose. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Updating error messages if dependencies are not there to list all programs ↵Daniel Baumann2024-02-061-2/+2
| | | | | | in dehydrated-nsupdate hook. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Updating copyright notices for 2023.Daniel Baumann2023-11-2015-15/+15
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Correcting wrong ocsp variable in dehydrated hook.Daniel Baumann2023-06-281-1/+1
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Generalizing extra ocsp symlinks too in dehydrated hooks.Daniel Baumann2023-06-271-4/+3
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Creating relative links for extra certificates in deploy_cert.extra ↵Daniel Baumann2023-06-191-4/+4
| | | | | | dehydrated hook. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Adding root_intermediate_cert to exit_hook.extra-cleanup dehydrated hook.Daniel Baumann2023-06-191-1/+1
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Generalizing extra file generation for any number of components as needed by ↵Daniel Baumann2023-06-191-6/+11
| | | | | | redis in deploy_cert.extra dehydrated hook. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Stripping empty lines from partial files when using short chain in ↵Daniel Baumann2023-06-191-1/+1
| | | | | | deploy_cert.extra dehydrated hook. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Updating chain coments in deploy_cert.extra dehydrated hook.Daniel Baumann2023-06-191-4/+6
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Adding preferred chain compatibility in deploy_cert.extra dehydrated hook.Daniel Baumann2023-06-171-7/+39
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Adding freeradius to dehydrated service-reload hook.Daniel Baumann2023-06-171-1/+9
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Removing superfluous dot in output-message of dehydrated-nsupdate.Daniel Baumann2023-06-171-1/+1
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Updating dehydrated todo.Daniel Baumann2023-06-171-0/+2
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Completely stop and start apache in dehydrated hook to ensure OCSP renewals.Daniel Baumann2023-02-191-1/+2
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Adding dehydrated hook to cleanup extra files.Daniel Baumann2022-11-221-0/+77
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Using shortnames for extra certificates in dehydrated extra hooks.Daniel Baumann2022-11-222-22/+19
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Using certdir variable in dehydrated hook instead of hardcoded path.Daniel Baumann2022-11-221-4/+4
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Correcting cosmetic typo in dehydrated extra-cert hook output.Daniel Baumann2022-11-081-2/+2
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Improving CA filename prefix in dehydrated deploy_cert.extra hook.Daniel Baumann2022-10-301-4/+4
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Improving comment in dehydrated deploy_cert.chrony hook.Daniel Baumann2022-10-301-1/+1
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Correcting file handling errors in dehydrated deploy_cert.extra hook.Daniel Baumann2022-10-301-3/+3
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Providing individual root and intermediate certificate files in dehydrated ↵Daniel Baumann2022-10-281-3/+18
| | | | | | extra hook. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Updating dehydrated TODO file.Daniel Baumann2022-10-041-2/+1
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Updating dig alternative handling similar to nsupdate for consistency.Daniel Baumann2022-09-061-2/+12
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Temporarily passing tsig string to bind in dehydrated-nsupdate to unbreak ↵Daniel Baumann2022-09-061-3/+21
| | | | | | bind support, bind requires a different keyfile format as knot. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Improving wording of TSIG lookup hierarchy in dehydrated-nsupdate.1.Daniel Baumann2022-09-061-1/+1
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Reworking fix-permission dehydrated hook.Daniel Baumann2022-07-071-6/+4
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Reworking service-reload dehydrated hook.Daniel Baumann2022-07-071-27/+73
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Adding postfix to service-reload dehydrated hook.Daniel Baumann2022-07-071-0/+9
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Reworking chrony workaround (#1013882) now that we know it's going to be ↵Daniel Baumann2022-07-072-12/+5
| | | | | | permanent. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Merging the different extra certificate files into one dehydrated hook ↵Daniel Baumann2022-07-074-61/+25
| | | | | | handling all extra copies. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Adding privkey-fullchain hooks as used by postfix for dehydrated.Daniel Baumann2022-07-042-0/+55
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Adding dehydrated hook to workaround certificate handling in chrony (#1013882).Daniel Baumann2022-06-261-0/+42
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Updating dehydrated-tools TODO file.Daniel Baumann2022-06-251-0/+1
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Updating dehydrated-tools TODO file.Daniel Baumann2022-06-141-3/+1
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Completing existing dehydrated-tools manpages.Daniel Baumann2022-06-143-79/+133
| | | | Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Handling comments in TSIG keyfiles in dehydrated-nsupdate to support ↵Daniel Baumann2022-06-141-1/+4
| | | | | | disabling TSIG for individual records. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Adding support for individual TSIG files per record, zone, and nameserver ↵Daniel Baumann2022-06-141-5/+30
| | | | | | rather than having one global key for all updates in dehydrated-nsupdate. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
* Adding quotes arround some variables in dehydrated-tools to prevent globbing ↵Daniel Baumann2022-06-142-6/+6
| | | | | | and word splitting. Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
* Only restarting kresd in dehydrated exit_hook.service-reload if tls is ↵Daniel Baumann2022-06-111-1/+1
| | | | | | configured. Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
* Handling ipv4-only/ipv6-only nameservers on ipv4-only/ipv6-only systems.Daniel Baumann2022-06-052-3/+35
| | | | Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
* Updating dehydrated todo file.Daniel Baumann2022-05-071-0/+1
| | | | Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
* Restarting kresd threads only if at least one exists to support building ↵Daniel Baumann2022-04-301-10/+13
| | | | | | chroots in dehydrated service-reload hook. Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
* Avoid failing if /var/lib/dehydrated/certs doesn't exist in dehydrated ↵Daniel Baumann2022-04-301-0/+5
| | | | | | fix-permissions hook. Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
* Using a variable to keep the list of services to restart in dehydrated hook ↵Daniel Baumann2022-04-141-1/+3
| | | | | | for easier readability. Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
* Adding knot-resolver handling in dehydrated service-reload hook.Daniel Baumann2022-04-141-0/+15
| | | | Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
* Adding knot to list of services to restart in dehydrated hook.Daniel Baumann2022-04-141-1/+1
| | | | Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
* Temporarily reverting json support in dehydrated-nsupdate, not ready just yet.Daniel Baumann2022-01-052-43/+4
| | | | Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
* Updating copyright notices for 2022.Daniel Baumann2022-01-0513-13/+13
| | | | Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>