OpenBSD CVS

CVS log for src/usr.sbin/acme-client/acme-client.conf.5


[BACK] Up to [local] / src / usr.sbin / acme-client

Request diff between arbitrary revisions


Default branch: MAIN


Revision 1.29 / (download) - annotate - [select for diffs], Mon Jan 11 07:23:42 2021 UTC (3 years, 4 months ago) by jmc
Branch: MAIN
CVS Tags: OPENBSD_7_5_BASE, OPENBSD_7_5, OPENBSD_7_4_BASE, OPENBSD_7_4, OPENBSD_7_3_BASE, OPENBSD_7_3, OPENBSD_7_2_BASE, OPENBSD_7_2, OPENBSD_7_1_BASE, OPENBSD_7_1, OPENBSD_7_0_BASE, OPENBSD_7_0, OPENBSD_6_9_BASE, OPENBSD_6_9, HEAD
Changes since 1.28: +5 -3 lines
Diff to previous 1.28 (colored)

document how to specify multiple alternative names;
modified version of diff from wolf on misc,
improved by and ok florian benno sthen

Revision 1.28 / (download) - annotate - [select for diffs], Sun Jan 3 16:32:38 2021 UTC (3 years, 5 months ago) by florian
Branch: MAIN
Changes since 1.27: +17 -2 lines
Diff to previous 1.27 (colored)

Create .1 backup files when acme-client is going to overwrite a
certificate file.
These files are not terribly big and they might become helpful if one
re-creates a certificate with additional or removed domains and
whishes to revoke the old cert (this part needs a bit of work to make
it convenient to do).
OK sthen

Revision 1.27 / (download) - annotate - [select for diffs], Fri Nov 6 20:31:58 2020 UTC (3 years, 7 months ago) by sthen
Branch: MAIN
Changes since 1.26: +8 -2 lines
Diff to previous 1.26 (colored)

mention that acme-client generates a 4096-bit or secp384r1 key if the key
file doesn't exist; ok florian jmc

Revision 1.26 / (download) - annotate - [select for diffs], Mon Sep 14 16:00:17 2020 UTC (3 years, 8 months ago) by florian
Branch: MAIN
CVS Tags: OPENBSD_6_8_BASE, OPENBSD_6_8
Changes since 1.25: +7 -2 lines
Diff to previous 1.25 (colored)

We need to be able to provide contact information to use the
buypass.com acme api.
From Bartosz Kuzma (bartosz.kuzma AT release11.com), thanks!
OK beck, deraadt

Revision 1.25 / (download) - annotate - [select for diffs], Sat May 16 16:58:11 2020 UTC (4 years ago) by jmc
Branch: MAIN
Changes since 1.24: +4 -4 lines
Diff to previous 1.24 (colored)

list example files in FILES with a short description: generally, "Example
configuration file.", but occasionally something else fit better; at the
same time, try to make the format for FILES more consistent;

original diff from clematis

Revision 1.24 / (download) - annotate - [select for diffs], Tue May 12 20:46:30 2020 UTC (4 years ago) by jmc
Branch: MAIN
Changes since 1.23: +4 -3 lines
Diff to previous 1.23 (colored)

new sentence, new line;

Revision 1.23 / (download) - annotate - [select for diffs], Sun May 10 12:06:18 2020 UTC (4 years, 1 month ago) by benno
Branch: MAIN
Changes since 1.22: +12 -5 lines
Diff to previous 1.22 (colored)

Allow to have multiple domain ... {} sextions with the same domain
name, by adding a new (optional) config option "domain name".
This can be used to create a rsa and an ecdsa key for the same domain
name.
The old domain name in the 'title' line continues to be used as domain
name in the abscence of the domain name argument, i.e. the change is
backward compatible with current config files.
tested by sthen@
ok florian@ sthen@

Revision 1.22 / (download) - annotate - [select for diffs], Mon Feb 10 13:18:21 2020 UTC (4 years, 4 months ago) by schwarze
Branch: MAIN
CVS Tags: OPENBSD_6_7_BASE, OPENBSD_6_7
Changes since 1.21: +5 -3 lines
Diff to previous 1.21 (colored)

briefly mention /etc/examples/ in the FILES section of all the
manual pages that document the corresponding configuration files;
OK jmc@, and general direction discussed with many

Revision 1.21 / (download) - annotate - [select for diffs], Thu Jul 4 05:06:06 2019 UTC (4 years, 11 months ago) by solene
Branch: MAIN
CVS Tags: OPENBSD_6_6_BASE, OPENBSD_6_6
Changes since 1.20: +3 -3 lines
Diff to previous 1.20 (colored)

Use v02 let's encrypt API key as in the example file

ok deraadt@

Revision 1.20 / (download) - annotate - [select for diffs], Mon Jun 17 12:42:52 2019 UTC (4 years, 11 months ago) by florian
Branch: MAIN
Changes since 1.19: +9 -2 lines
Diff to previous 1.19 (colored)

    Implement elliptic curve account keys.
    OK benno
    Input & OK tb

Revision 1.19 / (download) - annotate - [select for diffs], Wed Jun 12 11:36:32 2019 UTC (5 years ago) by jmc
Branch: MAIN
Changes since 1.18: +8 -3 lines
Diff to previous 1.18 (colored)

tweak previous;

Revision 1.18 / (download) - annotate - [select for diffs], Wed Jun 12 11:09:25 2019 UTC (5 years ago) by gilles
Branch: MAIN
Changes since 1.17: +5 -3 lines
Diff to previous 1.17 (colored)

use acme-client to sign certificated with ecdsa keys

diff from Renaud Allard <renaud@allard.it>, ok to get in from florian@

Revision 1.17 / (download) - annotate - [select for diffs], Tue Jan 8 06:46:29 2019 UTC (5 years, 5 months ago) by florian
Branch: MAIN
CVS Tags: OPENBSD_6_5_BASE, OPENBSD_6_5
Changes since 1.16: +5 -43 lines
Diff to previous 1.16 (colored)

Remove missleading and outdated examples from man page.
/etc/examples/httpd.conf and /etc/examples/acme-client.conf (comming
soon) are better places.
Pointed out by & OK deraadt, OK benno

Revision 1.16 / (download) - annotate - [select for diffs], Fri Aug 3 17:48:34 2018 UTC (5 years, 10 months ago) by benno
Branch: MAIN
CVS Tags: OPENBSD_6_4_BASE, OPENBSD_6_4
Changes since 1.15: +3 -2 lines
Diff to previous 1.15 (colored)

document the default in the abscence of a certificate authority.
From Ross L Richardson

Revision 1.15 / (download) - annotate - [select for diffs], Fri Aug 3 17:46:57 2018 UTC (5 years, 10 months ago) by benno
Branch: MAIN
Changes since 1.14: +3 -2 lines
Diff to previous 1.14 (colored)

Document that domain certificate is optional.
From Ross L Richardson

Revision 1.14 / (download) - annotate - [select for diffs], Thu Aug 2 14:40:38 2018 UTC (5 years, 10 months ago) by benno
Branch: MAIN
Changes since 1.13: +8 -2 lines
Diff to previous 1.13 (colored)

According to code (and testing), each is optional but at least
one must be present.
From Ross L Richardson, thanks
ok sthen@

Revision 1.13 / (download) - annotate - [select for diffs], Sun Jul 8 15:41:17 2018 UTC (5 years, 11 months ago) by benno
Branch: MAIN
Changes since 1.12: +26 -22 lines
Diff to previous 1.12 (colored)

clarify account key (pair) vs certificate (domain) key pair, and
that the domain block really describes a certificate to manage.
from Ross L Richardson <openbsd at rlr dot id dot au>, thanks
with feedback and ok jmc and sthen

Revision 1.12 / (download) - annotate - [select for diffs], Wed Jun 13 15:08:24 2018 UTC (5 years, 11 months ago) by reyk
Branch: MAIN
Changes since 1.11: +3 -3 lines
Diff to previous 1.11 (colored)

Rename httpd.conf "root strip" option to "request strip".

"root strip" was semantically incorrect and did cause some confusion
as it never stripped the root but the client's request path.

Discussed with many.  Heads up: this is a grammar change that also
affects acme-client(1) configurations (see current.html).

OK claudio@

Revision 1.11 / (download) - annotate - [select for diffs], Mon Nov 27 01:58:52 2017 UTC (6 years, 6 months ago) by florian
Branch: MAIN
CVS Tags: OPENBSD_6_3_BASE, OPENBSD_6_3
Changes since 1.10: +2 -8 lines
Diff to previous 1.10 (colored)

Deprecate agreement url config option and get the information from the
directory call. This way we don't need to update the acme-client.conf
file every time it changes. Still parse the option, ignore and warn about
it for a release. Sysmerge should be able to handle the removal.
"nice" deraadt@
OK benno

Revision 1.10 / (download) - annotate - [select for diffs], Wed Mar 29 17:16:24 2017 UTC (7 years, 2 months ago) by tj
Branch: MAIN
CVS Tags: OPENBSD_6_2_BASE, OPENBSD_6_2, OPENBSD_6_1_BASE, OPENBSD_6_1
Changes since 1.9: +3 -3 lines
Diff to previous 1.9 (colored)

account key needs to be in quotes.

ok benno deraadt

Revision 1.9 / (download) - annotate - [select for diffs], Wed Mar 22 11:14:14 2017 UTC (7 years, 2 months ago) by benno
Branch: MAIN
Changes since 1.8: +26 -1 lines
Diff to previous 1.8 (colored)

Improve manpage and config file to show the more common use case.
from Nick Holland (nick AT holland-consulting DOT net)
ok jmc@ florian@

Revision 1.8 / (download) - annotate - [select for diffs], Sat Jan 21 15:53:15 2017 UTC (7 years, 4 months ago) by jmc
Branch: MAIN
Changes since 1.7: +5 -3 lines
Diff to previous 1.7 (colored)

tweak previous;

Revision 1.7 / (download) - annotate - [select for diffs], Sat Jan 21 09:05:31 2017 UTC (7 years, 4 months ago) by benno
Branch: MAIN
Changes since 1.6: +7 -1 lines
Diff to previous 1.6 (colored)

Improve Documentation

ok florian

Revision 1.6 / (download) - annotate - [select for diffs], Sat Jan 21 09:00:29 2017 UTC (7 years, 4 months ago) by benno
Branch: MAIN
Changes since 1.5: +4 -2 lines
Diff to previous 1.5 (colored)

add option 'domain full chain certificate "path"',
revokation works, the fullchain file will be unlinked.

ok florian

Revision 1.5 / (download) - annotate - [select for diffs], Sat Jan 21 08:57:49 2017 UTC (7 years, 4 months ago) by benno
Branch: MAIN
Changes since 1.4: +4 -1 lines
Diff to previous 1.4 (colored)

document default challengedir "/var/www/acme"

Revision 1.4 / (download) - annotate - [select for diffs], Sat Jan 21 08:55:09 2017 UTC (7 years, 4 months ago) by florian
Branch: MAIN
Changes since 1.3: +4 -2 lines
Diff to previous 1.3 (colored)

Implement domain chain certificate.
OK benno

Revision 1.3 / (download) - annotate - [select for diffs], Sat Jan 21 08:43:09 2017 UTC (7 years, 4 months ago) by benno
Branch: MAIN
Changes since 1.2: +8 -5 lines
Diff to previous 1.2 (colored)

acme-client use configuration file [2 of 5]

- add challengedir option to config file
- remove -C option from command line

ok florian

Revision 1.2 / (download) - annotate - [select for diffs], Sun Sep 18 21:53:41 2016 UTC (7 years, 8 months ago) by jmc
Branch: MAIN
Changes since 1.1: +14 -25 lines
Diff to previous 1.1 (colored)

tweak previous;

Revision 1.1 / (download) - annotate - [select for diffs], Sun Sep 18 20:18:25 2016 UTC (7 years, 8 months ago) by benno
Branch: MAIN

add a config file parser to acme-client (unused at the moment, so that
it can be worked on in the tree).
ok florian@ deraadt@

This form allows you to request diff's between any two revisions of a file. You may select a symbolic revision name using the selection box or you may type in a numeric name using the type-in text box.