Compare commits

..

No commits in common. "master" and "v3.0.0" have entirely different histories.

5 changed files with 210 additions and 111 deletions

View File

@ -1,27 +1,24 @@
# [greenlock-challenge-manual](https://git.coolaj86.com/coolaj86/greenlock-challenge-manual.js) | [Greenlock](https://git.coolaj86.com/coolaj86/greenlock.js) (library)
| [Greenlock CLI](https://git.coolaj86.com/coolaj86/greenlock-cli.js)
| [greenlock-express](https://git.coolaj86.com/coolaj86/greenlock-express.js)
| [greenlock-koa](https://git.coolaj86.com/coolaj86/greenlock-koa.js)
| [greenlock-hapi](https://git.coolaj86.com/coolaj86/greenlock-hapi.js)
|
| A [Root](https://rootprojects.org) Project | le-challenge-manual
===================
An extremely simple reference implementation A [Root](https://rootprojects.org) Project
of an ACME (Let's Encrypt) challenge strategy
for [Greenlock](https://git.coolaj86.com/coolaj86/greenlock-express.js) v2.7+ (and v3).
* Prints the ACME challenge details to the terminal A manual cli-based strategy for [Greenlock](https://git.coolaj86.com/coolaj86/greenlock-express.js) v2.7+ (and v3).
* (waits for you to hit enter before continuing)
* Asks you to enter the challenge response.
* Let's you know it's safe to remove the challenge.
Other ACME Challenge Reference Implementations: Prints the ACME challenge Token and Key and then waits for you to hit enter before continuing.
* [**greenlock-challenge-manual**](https://git.coolaj86.com/coolaj86/greenlock-challenge-manual.js)
* [greenlock-challenge-http](https://git.coolaj86.com/coolaj86/greenlock-challenge-http.js)
* [greenlock-challenge-dns](https://git.coolaj86.com/coolaj86/greenlock-challenge-dns.js)
Install Install
------- -------
```bash ```bash
npm install --save greenlock-challenge-manual@3.x npm install --save le-challenge-manual@3.x
``` ```
Usage Usage
@ -32,9 +29,9 @@ var Greenlock = require('greenlock');
Greenlock.create({ Greenlock.create({
... ...
, challenges: { 'http-01': require('greenlock-challenge-manual') , challenges: { 'http-01': require('le-challenge-manual')
, 'dns-01': require('greenlock-challenge-manual') , 'dns-01': require('le-challenge-manual')
, 'tls-alpn-01': require('greenlock-challenge-manual') , 'tls-alpn-01': require('le-challenge-manual')
} }
... ...
}); });

193
index.js
View File

@ -3,12 +3,17 @@
var Challenge = module.exports; var Challenge = module.exports;
// IMPORTANT
//
// These are all PROMISIFIED by Greenlock in such a way that
// it doesn't matter whether you return synchronously, asynchronously,
// or even node-style callback thunk.
//
// Typically you should be using a promise or async function,
// but choose whichever makes sense for you.
Challenge.create = function (config) { Challenge.create = function (config) {
// If your implementation needs config options, set them. Otherwise, don't bother (duh). // If your implementation needs config options, set them. Otherwise, don't bother (duh).
var http01 = require('greenlock-challenge-http').create(config);
var dns01 = require('greenlock-challenge-dns').create(config);
var challenger = {}; var challenger = {};
// Note: normally you'd implement these right here, but for the sake of // Note: normally you'd implement these right here, but for the sake of
@ -16,13 +21,11 @@ Challenge.create = function (config) {
// call out to set the challenge, wherever // call out to set the challenge, wherever
challenger.set = function (opts, cb) { challenger.set = function (opts, cb) {
// Note: this can be defined as a thunk (like this) or a Promise
var ch = opts.challenge; var ch = opts.challenge;
if ('http-01' === ch.type) { if ('http-01' === ch.type) {
return http01.set(opts, cb); return Challenge._setHttp(opts, cb);
} else if ('dns-01' === ch.type) { } else if ('dns-01' === ch.type) {
return dns01.set(opts, cb); return Challenge._setDns(opts, cb);
} else { } else {
return Challenge._setAny(opts, cb); return Challenge._setAny(opts, cb);
} }
@ -30,30 +33,27 @@ Challenge.create = function (config) {
// call out to remove the challenge, wherever // call out to remove the challenge, wherever
challenger.remove = function (opts) { challenger.remove = function (opts) {
// Note: this can be defined synchronously (like this) or as a Promise, or a thunk
var ch = opts.challenge; var ch = opts.challenge;
if ('http-01' === ch.type) { if ('http-01' === ch.type) {
return http01.remove(opts); return Challenge._removeHttp(opts);
} else if ('dns-01' === ch.type) { } else if ('dns-01' === ch.type) {
return dns01.remove(opts); return Challenge._removeDns(opts);
} else { } else {
return Challenge._removeAny(opts); return Challenge._removeAny(opts);
} }
}; };
// only really useful for http // only really useful for http,
// (and tls-alpn-01, which isn't implemented yet) // but probably not so much in this context...
// (though you can test it and it'll work)
challenger.get = function (opts) { challenger.get = function (opts) {
// Note: this can be defined as a Promise (like this) or synchronously, or a thunk
var ch = opts.challenge; var ch = opts.challenge;
if ('http-01' === ch.type) { if ('http-01' === ch.type) {
return http01.get(opts); return Challenge._getHttp(opts);
} else if ('dns-01' === ch.type) { } else if ('dns-01' === ch.type) {
return dns01.get(opts); return Challenge._getDns(opts);
} else { } else {
return Challenge._get(opts); return Challenge._getAny(opts);
} }
}; };
@ -64,66 +64,159 @@ Challenge.create = function (config) {
return challenger; return challenger;
}; };
Challenge._setAny = function (args, cb) { // Show the user the token and key and wait for them to be ready to continue
Challenge._setHttp = function (args, cb) {
// Using a node-style callback "thunk" in this example, because that makes
var ch = args.challenge; var ch = args.challenge;
console.info("[ACME " + ch.type + " '" + ch.altname + "' CHALLENGE]"); console.info("[ACME http-01 '" + ch.altname + "' CHALLENGE]");
console.info("Your mission (since you chose to accept it):"); console.info("Your mission (since you chose to accept it):");
console.info("You must, by whatever means necessary, use the following information" console.info("First, you must create a file with the following name and contents.");
+ " to make a device or service ready to respond to a '" + ch.type + "' request."); console.info("Then, by any means necessary, you cause that file to appear at the specified URL.");
console.info(""); console.info("");
console.info(JSON.stringify(ch, null, 2).replace(/^/gm, '\t')); console.info("\tFilename: " + ch.token);
console.info("\tContents: " + ch.keyAuthorization);
// TODO let acme-v2 handle generating this url
console.info('\tURL: http://' + ch.altname + '/.well-known/acme-challenge/' + ch.token);
console.info("");
console.info("And, if you need additional information for debugging:");
console.info("");
console.info(JSON.stringify(httpChallengeToJson(ch), null, 2).replace(/^/gm, '\t'));
console.info("");
console.info("This message won't self-destruct, but you may press hit the any as soon as you're ready to continue...");
console.info(""); console.info("");
console.info("Press the any key once the response is ready to continue with the '" + ch.type + "' challenge process");
console.info("[Press the ANY key to continue...]"); console.info("[Press the ANY key to continue...]");
process.stdin.resume(); process.stdin.resume();
process.stdin.once('data', function () { process.stdin.once('data', function () {
process.stdin.pause(); process.stdin.pause();
cb(null, null); cb(null);
}); });
}; };
Challenge._setDns = function (args, cb) {
// Using a node-style callback "thunk" in this example, because that makes
var ch = args.challenge;
console.info("[ACME dns-01 '" + ch.altname + "' CHALLENGE]");
console.info("Your mission (since you chose to accept it):");
console.info("First, you must create a DNS record with the following parameters:");
console.info("");
console.info(ch.dnsHost + "\tTXT\t" + ch.dnsKeyAuthorization + "\tTTL 60");
console.info("");
console.info("Next, wait, no... there is no next. That's it - but here's some stuff anyway:");
console.info("");
console.info(JSON.stringify(dnsChallengeToJson(ch), null, 2).replace(/^/gm, '\t'));
console.info("");
console.info("[Press the ANY key to continue...]");
process.stdin.resume();
process.stdin.once('data', function () {
process.stdin.pause();
cb(null);
});
};
Challenge._setAny = function (args, cb) {
var ch = args.challenge;
console.info("[ACME " + ch.type + " '" + ch.altname + "' CHALLENGE]");
console.info("There's no quippy pre-programmed response for this type of challenge.");
console.info("I have no idea what you intend to do, but I'll tell you everything I know:");
console.info("");
console.info(JSON.stringify(ch, null, 2).replace(/^/gm, '\t'));
console.info("");
console.info("[Press the ANY key to continue...]");
process.stdin.resume();
process.stdin.on('data', function () {
process.stdin.pause();
cb(null);
});
};
// might as well tell the user that whatever they were setting up has been checked
Challenge._removeHttp = function (args) {
var ch = args.challenge;
console.info("");
console.info("Challenge for '" + ch.altname + "' complete. You can delete this file now:");
console.info('\thttp://' + ch.altname + '/.well-known/acme-challenge/' + ch.token);
console.info("");
// this can return null or a Promise null
// (or callback null, just like the set() above)
return null;
};
Challenge._removeDns = function (args) {
var ch = args.challenge;
console.info("");
console.info("Challenge for '" + ch.altname + "' complete. You can remove this record now:");
console.info("\t" + ch.dnsHost + "\tTXT\t" + ch.dnsKeyAuthorization + "\tTTL 60");
console.info("");
// this can return null or a Promise null
// (or callback null, just like the set() above)
return null;
};
Challenge._removeAny = function (args) { Challenge._removeAny = function (args) {
var ch = args.challenge; var ch = args.challenge;
console.info(""); console.info("");
console.info("[ACME " + ch.type + " '" + ch.altname + "' COMPLETE]: " + ch.status); console.info("Challenge for '" + ch.altname + "' complete. You can now undo what you did.");
console.info("You may now undo whatever you did to create and ready the response.");
console.info(""); console.info("");
// this can return null or a Promise null
// (or callback null, just like set() above)
return null; return null;
}; };
// This can be used for http-01 and tls-alpn-01 (when it's available), but not dns-01. // nothing to do here, that's why it's manual
// And not all http-01 or tls-alpn-01 strategies will need to implement this. Challenge._get = function (args, cb) {
Challenge._get = function (args) { console.info("");
var ch = args.challenge; console.info("Woah! Hey, guess what!? That's right you guessed it:");
console.info("It's time to painstakingly type out the ACME challenge response with your bear hands. Yes. Your bear hands.");
if (!Challenge._getCache[ch.altname + ':' + ch.token]) { process.stdout.write("> ");
Challenge._getCache[ch.altname + ':' + ch.token] = true;
console.info("");
console.info("[ACME " + ch.type + " '" + ch.altname + "' REQUEST]: " + ch.status);
console.info("The '" + ch.type + "' challenge request has arrived!");
console.info("It's now time to painstakingly type out the expected response object with your bear hands.");
console.log("Yes. Your bear hands.");
console.log('ex: { "keyAuthorization": "xxxxxxxx.yyyyyyyy" }');
process.stdout.write("> ");
}
// Using a promise here just to show that Promises are support
// (in fact, they're the default)
return new Promise(function (resolve, reject) { return new Promise(function (resolve, reject) {
process.stdin.resume(); process.stdin.resume();
process.stdin.once('error', reject); process.stdin.on('error', reject);
process.stdin.once('data', function (chunk) { process.stdin.on('data', function (chunk) {
process.stdin.pause(); process.stdin.pause();
var result = chunk.toString('utf8').trim(); var result = chunk.toString();
try { try {
result = JSON.parse(result); result = JSON.parse(result);
} catch(e) { } catch(e) {
args.challenge.keyAuthorization = result; args.keyAuthorization = result;
result = args.challenge;
} }
resolve(result); cb(null);
}); });
}); });
}; };
// Because the ACME server will hammer us with requests, and that's confusing during a manual test:
Challenge._getCache = {}; function httpChallengeToJson(ch) {
return {
type: ch.type
, altname: ch.altname
, identifier: ch.identifier
, wildcard: false
, expires: ch.expires
, token: ch.token
, thumbprint: ch.thumbprint
, keyAuthorization: ch.keyAuthorization
};
}
function dnsChallengeToJson(ch) {
return {
type: ch.type
, altname: '*.example.com'
, identifier: ch.identifier
, wildcard: ch.wildcard
, expires: ch.expires
, token: ch.token
, thumbprint: ch.thumbprint
, keyAuthorization: ch.keyAuthorization
, dnsHost: ch.dnsHost
, dnsAuthorization: ch.dnsAuthorization
};
}

19
package-lock.json generated
View File

@ -1,18 +1,5 @@
{ {
"name": "greenlock-challenge-manual", "name": "le-challenge-manual",
"version": "3.0.4", "version": "2.1.1",
"lockfileVersion": 1, "lockfileVersion": 1
"requires": true,
"dependencies": {
"greenlock-challenge-dns": {
"version": "3.0.4",
"resolved": "https://registry.npmjs.org/greenlock-challenge-dns/-/greenlock-challenge-dns-3.0.4.tgz",
"integrity": "sha512-CJI9RAtrZl9ICldyU5cRGzb1/wIbS3O+MJy9z7gKb7fLDNF7Wmw9Fv2agBLSOtIPr7TYgyyesvt8ppA4OIS+yg=="
},
"greenlock-challenge-http": {
"version": "3.0.1",
"resolved": "https://registry.npmjs.org/greenlock-challenge-http/-/greenlock-challenge-http-3.0.1.tgz",
"integrity": "sha512-u+r8VtT+Qve0wucVZEPivFRT7DP+Jfl7McGMbna0BFVvAc+NJyOJGyvBa6aGDi4qgEhx7pjh0yCsCEKDHI2zDw=="
}
}
} }

View File

@ -1,21 +1,22 @@
{ {
"name": "greenlock-challenge-manual", "name": "le-challenge-manual",
"version": "3.0.4", "version": "3.0.0",
"description": "A cli-based strategy for node-letsencrypt. Prints the ACME challenge Token and Key and then waits for you to hit enter before continuing.", "description": "A cli-based strategy for node-letsencrypt. Prints the ACME challenge Token and Key and then waits for you to hit enter before continuing.",
"main": "index.js", "main": "index.js",
"homepage": "https://git.coolaj86.com/coolaj86/greenlock-challenge-manual.js", "homepage": "https://git.coolaj86.com/coolaj86/le-challenge-manual.js",
"scripts": { "scripts": {
"test": "node test.js" "test": "node test.js"
}, },
"repository": { "repository": {
"type": "git", "type": "git",
"url": "https://git.coolaj86.com/coolaj86/greenlock-challenge-manual.js.git" "url": "https://git.coolaj86.com/coolaj86/le-challenge-manual.js.git"
}, },
"keywords": [ "keywords": [
"Let's Encrypt", "le-challenge",
"ACME", "le-challenge-",
"challenge",
"manual", "manual",
"acme",
"letsencrypt",
"certbot", "certbot",
"cli", "cli",
"commandline" "commandline"
@ -23,10 +24,6 @@
"author": "AJ ONeal <coolaj86@gmail.com> (https://coolaj86.com/)", "author": "AJ ONeal <coolaj86@gmail.com> (https://coolaj86.com/)",
"license": "MPL-2.0", "license": "MPL-2.0",
"bugs": { "bugs": {
"url": "https://git.coolaj86.com/coolaj86/greenlock-challenge-manual.js/issues" "url": "https://git.coolaj86.com/coolaj86/le-challenge-manual.js/issues"
},
"dependencies": {
"greenlock-challenge-dns": "^3.0.3",
"greenlock-challenge-http": "^3.0.0"
} }
} }

55
test.js
View File

@ -1,25 +1,50 @@
'use strict'; 'use strict';
/*global Promise*/
var tester = require('greenlock-challenge-test'); var challenge = require('./').create({});
var challenger = require('./').create({}); var opts = challenge.getOptions && challenge.getOptions() || challenge.options;
// The dry-run tests can pass on, literally, 'example.com' function run() {
// but the integration tests require that you have control over the domain // this will cause the prompt to appear
var domain = 'example.com'; return new Promise(function (resolve, reject) {
var wildname = '*.example.com'; challenge.set(opts, function () {
// this will cause the final completion message to appear
tester.test('http-01', domain, challenger).then(function () { return Promise.resolve(challenge.remove(opts)).then(resolve).catch(reject);
console.info("PASS http-01"); });
return tester.test('dns-01', wildname, challenger).then(function () {
console.info("PASS dns-01");
}); });
}
opts.challenge = {
type: 'http-01'
, identifier: { type: 'dns', value: 'example.com' }
, wildcard: false
, expires: '2012-01-01T12:00:00.000Z'
, token: 'abc123'
, thumbprint: '<<account key thumbprint>>'
, keyAuthorization: 'abc123.xxxx'
, dnsHost: '_acme-challenge.example.com'
, dnsAuthorization: 'yyyy'
, altname: 'example.com'
};
run(opts).then(function () {
opts.challenge = {
type: 'dns-01'
, identifier: { type: 'dns', value: 'example.com' }
, wildcard: true
, expires: '2012-01-01T12:00:00.000Z'
, token: 'abc123'
, thumbprint: '<<account key thumbprint>>'
, keyAuthorization: 'abc123.xxxx'
, dnsHost: '_acme-challenge.example.com'
, dnsAuthorization: 'yyyy'
, altname: '*.example.com'
};
return run(opts);
}).then(function () { }).then(function () {
return tester.test('fake-01', domain, challenger).then(function () { console.info("PASS");
console.info("PASS fake-01");
});
}).catch(function (err) { }).catch(function (err) {
console.error("FAIL"); console.error("FAIL");
console.error(err); console.error(err);
process.exit(20); process.exit(17);
}); });