2015-11-19 16:26:23 +02:00
|
|
|
package acme
|
|
|
|
|
|
|
|
import (
|
2015-11-20 01:33:46 +02:00
|
|
|
"crypto/rsa"
|
2015-11-19 16:26:23 +02:00
|
|
|
"crypto/sha256"
|
2015-11-20 01:33:46 +02:00
|
|
|
"crypto/tls"
|
2015-11-19 16:26:23 +02:00
|
|
|
"encoding/hex"
|
2015-11-20 01:33:46 +02:00
|
|
|
"fmt"
|
2016-01-15 06:06:25 +02:00
|
|
|
"log"
|
2015-11-19 16:26:23 +02:00
|
|
|
)
|
|
|
|
|
|
|
|
type tlsSNIChallenge struct {
|
2015-12-05 16:53:53 +02:00
|
|
|
jws *jws
|
2015-12-27 20:08:17 +02:00
|
|
|
validate validateFunc
|
2016-01-15 06:06:25 +02:00
|
|
|
provider ChallengeProvider
|
2015-11-19 16:26:23 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
func (t *tlsSNIChallenge) Solve(chlng challenge, domain string) error {
|
2015-11-20 01:33:46 +02:00
|
|
|
// FIXME: https://github.com/ietf-wg-acme/acme/pull/22
|
|
|
|
// Currently we implement this challenge to track boulder, not the current spec!
|
2015-11-19 16:26:23 +02:00
|
|
|
|
2015-12-15 22:13:40 +02:00
|
|
|
logf("[INFO][%s] acme: Trying to solve TLS-SNI-01", domain)
|
2015-11-19 16:26:23 +02:00
|
|
|
|
|
|
|
// Generate the Key Authorization for the challenge
|
2016-01-27 03:01:39 +02:00
|
|
|
keyAuth, err := getKeyAuthorization(chlng.Token, t.jws.privKey)
|
2015-11-19 16:26:23 +02:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2016-01-15 06:06:25 +02:00
|
|
|
err = t.provider.Present(domain, chlng.Token, keyAuth)
|
2015-11-20 01:33:46 +02:00
|
|
|
if err != nil {
|
2016-01-27 02:57:55 +02:00
|
|
|
return fmt.Errorf("[%s] error presenting token: %v", domain, err)
|
2015-11-19 16:26:23 +02:00
|
|
|
}
|
2016-01-15 06:06:25 +02:00
|
|
|
defer func() {
|
|
|
|
err := t.provider.CleanUp(domain, chlng.Token, keyAuth)
|
|
|
|
if err != nil {
|
2016-01-27 02:57:55 +02:00
|
|
|
log.Printf("[%s] error cleaning up: %v", domain, err)
|
2016-01-15 06:06:25 +02:00
|
|
|
}
|
|
|
|
}()
|
2015-12-27 20:08:17 +02:00
|
|
|
return t.validate(t.jws, domain, chlng.URI, challenge{Resource: "challenge", Type: chlng.Type, Token: chlng.Token, KeyAuthorization: keyAuth})
|
2015-11-19 16:26:23 +02:00
|
|
|
}
|
|
|
|
|
2016-06-10 20:47:21 +02:00
|
|
|
// TLSSNI01ChallengeCert returns a certificate and target domain for the `tls-sni-01` challenge
|
|
|
|
func TLSSNI01ChallengeCertDomain(keyAuth string) (tls.Certificate, string, error) {
|
2015-11-20 01:33:46 +02:00
|
|
|
// generate a new RSA key for the certificates
|
2016-01-27 03:01:39 +02:00
|
|
|
tempPrivKey, err := generatePrivateKey(RSA2048)
|
2015-11-20 01:33:46 +02:00
|
|
|
if err != nil {
|
2016-06-10 20:47:21 +02:00
|
|
|
return tls.Certificate{}, "", err
|
2015-11-20 01:33:46 +02:00
|
|
|
}
|
|
|
|
rsaPrivKey := tempPrivKey.(*rsa.PrivateKey)
|
|
|
|
rsaPrivPEM := pemEncode(rsaPrivKey)
|
|
|
|
|
2016-01-15 06:06:25 +02:00
|
|
|
zBytes := sha256.Sum256([]byte(keyAuth))
|
|
|
|
z := hex.EncodeToString(zBytes[:sha256.Size])
|
2015-11-20 01:33:46 +02:00
|
|
|
domain := fmt.Sprintf("%s.%s.acme.invalid", z[:32], z[32:])
|
|
|
|
tempCertPEM, err := generatePemCert(rsaPrivKey, domain)
|
|
|
|
if err != nil {
|
2016-06-10 20:47:21 +02:00
|
|
|
return tls.Certificate{}, "", err
|
2015-11-20 01:33:46 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
certificate, err := tls.X509KeyPair(tempCertPEM, rsaPrivPEM)
|
|
|
|
if err != nil {
|
2016-06-10 20:47:21 +02:00
|
|
|
return tls.Certificate{}, "", err
|
2015-11-20 01:33:46 +02:00
|
|
|
}
|
|
|
|
|
2016-06-10 20:47:21 +02:00
|
|
|
return certificate, domain, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// TLSSNI01ChallengeCert returns a certificate for the `tls-sni-01` challenge
|
|
|
|
func TLSSNI01ChallengeCert(keyAuth string) (tls.Certificate, error) {
|
|
|
|
cert, _, err := TLSSNI01ChallengeCertDomain(keyAuth)
|
|
|
|
return cert, err
|
2015-11-20 01:33:46 +02:00
|
|
|
}
|