summaryrefslogtreecommitdiffstats
path: root/dehydrated (unfollow)
Commit message (Collapse)AuthorFilesLines
2 daysUpdating dehydrated todo.HEADmainDaniel Baumann1-0/+1
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
5 daysUpdating copyright notices for 2024.Daniel Baumann15-15/+15
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2024-02-06Also listing certificate name when sending nsupdate in dehydrated-nsupdate ↵Daniel Baumann1-1/+1
hook to be more verbose. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2024-02-06Updating error messages if dependencies are not there to list all programs ↵Daniel Baumann1-2/+2
in dehydrated-nsupdate hook. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2023-11-20Updating copyright notices for 2023.Daniel Baumann15-15/+15
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2023-06-28Correcting wrong ocsp variable in dehydrated hook.Daniel Baumann1-1/+1
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2023-06-27Generalizing extra ocsp symlinks too in dehydrated hooks.Daniel Baumann1-4/+3
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2023-06-19Creating relative links for extra certificates in deploy_cert.extra ↵Daniel Baumann1-4/+4
dehydrated hook. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2023-06-19Adding root_intermediate_cert to exit_hook.extra-cleanup dehydrated hook.Daniel Baumann1-1/+1
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2023-06-19Generalizing extra file generation for any number of components as needed by ↵Daniel Baumann1-6/+11
redis in deploy_cert.extra dehydrated hook. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2023-06-19Stripping empty lines from partial files when using short chain in ↵Daniel Baumann1-1/+1
deploy_cert.extra dehydrated hook. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2023-06-19Updating chain coments in deploy_cert.extra dehydrated hook.Daniel Baumann1-4/+6
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2023-06-17Adding preferred chain compatibility in deploy_cert.extra dehydrated hook.Daniel Baumann1-7/+39
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2023-06-17Adding freeradius to dehydrated service-reload hook.Daniel Baumann1-1/+9
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2023-06-17Removing superfluous dot in output-message of dehydrated-nsupdate.Daniel Baumann1-1/+1
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2023-06-17Updating dehydrated todo.Daniel Baumann1-0/+2
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2023-02-19Completely stop and start apache in dehydrated hook to ensure OCSP renewals.Daniel Baumann1-1/+2
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-11-22Adding dehydrated hook to cleanup extra files.Daniel Baumann1-0/+77
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-11-22Using shortnames for extra certificates in dehydrated extra hooks.Daniel Baumann2-22/+19
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-11-22Using certdir variable in dehydrated hook instead of hardcoded path.Daniel Baumann1-4/+4
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-11-08Correcting cosmetic typo in dehydrated extra-cert hook output.Daniel Baumann1-2/+2
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-10-30Improving CA filename prefix in dehydrated deploy_cert.extra hook.Daniel Baumann1-4/+4
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-10-30Improving comment in dehydrated deploy_cert.chrony hook.Daniel Baumann1-1/+1
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-10-30Correcting file handling errors in dehydrated deploy_cert.extra hook.Daniel Baumann1-3/+3
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-10-28Providing individual root and intermediate certificate files in dehydrated ↵Daniel Baumann1-3/+18
extra hook. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-10-04Updating dehydrated TODO file.Daniel Baumann1-2/+1
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-09-06Updating dig alternative handling similar to nsupdate for consistency.Daniel Baumann1-2/+12
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-09-06Temporarily passing tsig string to bind in dehydrated-nsupdate to unbreak ↵Daniel Baumann1-3/+21
bind support, bind requires a different keyfile format as knot. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-09-06Improving wording of TSIG lookup hierarchy in dehydrated-nsupdate.1.Daniel Baumann1-1/+1
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-07-07Reworking fix-permission dehydrated hook.Daniel Baumann1-6/+4
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-07-07Reworking service-reload dehydrated hook.Daniel Baumann1-27/+73
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-07-07Adding postfix to service-reload dehydrated hook.Daniel Baumann1-0/+9
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-07-07Reworking chrony workaround (#1013882) now that we know it's going to be ↵Daniel Baumann2-12/+5
permanent. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-07-07Merging the different extra certificate files into one dehydrated hook ↵Daniel Baumann4-61/+25
handling all extra copies. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-07-04Adding privkey-fullchain hooks as used by postfix for dehydrated.Daniel Baumann2-0/+55
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-06-26Adding dehydrated hook to workaround certificate handling in chrony (#1013882).Daniel Baumann1-0/+42
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-06-25Updating dehydrated-tools TODO file.Daniel Baumann1-0/+1
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-06-14Updating dehydrated-tools TODO file.Daniel Baumann1-3/+1
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-06-14Completing existing dehydrated-tools manpages.Daniel Baumann3-79/+133
Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-06-14Handling comments in TSIG keyfiles in dehydrated-nsupdate to support ↵Daniel Baumann1-1/+4
disabling TSIG for individual records. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-06-14Adding support for individual TSIG files per record, zone, and nameserver ↵Daniel Baumann1-5/+30
rather than having one global key for all updates in dehydrated-nsupdate. Signed-off-by: Daniel Baumann <daniel.baumann@open-infrastructure.net>
2022-06-14Adding quotes arround some variables in dehydrated-tools to prevent globbing ↵Daniel Baumann2-6/+6
and word splitting. Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
2022-06-11Only restarting kresd in dehydrated exit_hook.service-reload if tls is ↵Daniel Baumann1-1/+1
configured. Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
2022-06-05Handling ipv4-only/ipv6-only nameservers on ipv4-only/ipv6-only systems.Daniel Baumann2-3/+35
Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
2022-05-07Updating dehydrated todo file.Daniel Baumann1-0/+1
Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
2022-04-30Restarting kresd threads only if at least one exists to support building ↵Daniel Baumann1-10/+13
chroots in dehydrated service-reload hook. Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
2022-04-30Avoid failing if /var/lib/dehydrated/certs doesn't exist in dehydrated ↵Daniel Baumann1-0/+5
fix-permissions hook. Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
2022-04-14Using a variable to keep the list of services to restart in dehydrated hook ↵Daniel Baumann1-1/+3
for easier readability. Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
2022-04-14Adding knot-resolver handling in dehydrated service-reload hook.Daniel Baumann1-0/+15
Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>
2022-04-14Adding knot to list of services to restart in dehydrated hook.Daniel Baumann1-1/+1
Signed-off-by: Daniel Baumann <mail@daniel-baumann.ch>