2015-10-18 04:17:24 +02:00
|
|
|
package letsencrypt
|
2015-10-17 17:36:25 +02:00
|
|
|
|
2015-10-16 19:38:56 +02:00
|
|
|
import (
|
2015-10-17 07:30:00 +02:00
|
|
|
"bufio"
|
|
|
|
"encoding/json"
|
2015-10-16 19:38:56 +02:00
|
|
|
"errors"
|
2015-10-17 07:30:00 +02:00
|
|
|
"fmt"
|
|
|
|
"io/ioutil"
|
2015-10-17 17:36:25 +02:00
|
|
|
"net/http"
|
2015-10-17 07:30:00 +02:00
|
|
|
"os"
|
|
|
|
"strings"
|
2015-10-16 19:38:56 +02:00
|
|
|
|
2015-10-17 17:36:25 +02:00
|
|
|
"github.com/mholt/caddy/middleware"
|
|
|
|
"github.com/mholt/caddy/middleware/redirect"
|
2015-10-17 07:30:00 +02:00
|
|
|
"github.com/mholt/caddy/server"
|
2015-10-16 19:38:56 +02:00
|
|
|
"github.com/xenolf/lego/acme"
|
|
|
|
)
|
|
|
|
|
2015-10-18 04:17:24 +02:00
|
|
|
// Activate sets up TLS for each server config in configs
|
|
|
|
// as needed. It only skips the config if the cert and key
|
|
|
|
// are already provided or if plaintext http is explicitly
|
|
|
|
// specified as the port.
|
|
|
|
func Activate(configs []server.Config) ([]server.Config, error) {
|
2015-10-17 08:01:32 +02:00
|
|
|
// populate map of email address to server configs that use that email address for TLS.
|
2015-10-17 07:30:00 +02:00
|
|
|
// this will help us reduce roundtrips when getting the certs.
|
|
|
|
initMap := make(map[string][]*server.Config)
|
|
|
|
for i := 0; i < len(configs); i++ {
|
|
|
|
if configs[i].TLS.Certificate == "" && configs[i].TLS.Key == "" && configs[i].Port != "http" { // TODO: && !cfg.Host.IsLoopback()
|
|
|
|
leEmail := getEmail(configs[i])
|
|
|
|
if leEmail == "" {
|
2015-10-17 17:36:25 +02:00
|
|
|
return configs, errors.New("cannot serve HTTPS without email address OR certificate and key")
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
initMap[leEmail] = append(initMap[leEmail], &configs[i])
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-10-17 08:01:32 +02:00
|
|
|
// Loop through each email address and obtain certs; we can obtain more
|
|
|
|
// than one certificate per email address, and still save them individually.
|
2015-10-17 07:30:00 +02:00
|
|
|
for leEmail, serverConfigs := range initMap {
|
2015-10-17 08:01:32 +02:00
|
|
|
// Look up or create the LE user account
|
2015-10-18 04:17:24 +02:00
|
|
|
leUser, err := getUser(leEmail)
|
2015-10-17 07:30:00 +02:00
|
|
|
if err != nil {
|
2015-10-17 17:36:25 +02:00
|
|
|
return configs, err
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
|
2015-10-17 08:01:32 +02:00
|
|
|
// The client facilitates our communication with the CA server.
|
|
|
|
client := acme.NewClient(caURL, &leUser, rsaKeySize, exposePort)
|
2015-10-17 07:30:00 +02:00
|
|
|
|
2015-10-17 08:01:32 +02:00
|
|
|
// If not registered, the user must register an account with the CA
|
|
|
|
// and agree to terms
|
2015-10-17 07:30:00 +02:00
|
|
|
if leUser.Registration == nil {
|
|
|
|
reg, err := client.Register()
|
|
|
|
if err != nil {
|
2015-10-17 17:36:25 +02:00
|
|
|
return configs, errors.New("registration error: " + err.Error())
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
leUser.Registration = reg
|
|
|
|
|
|
|
|
// TODO: we can just do the agreement once, when registering, right?
|
|
|
|
err = client.AgreeToTos()
|
|
|
|
if err != nil {
|
2015-10-18 04:17:24 +02:00
|
|
|
saveUser(leUser) // TODO: Might as well try, right? Error check?
|
2015-10-17 17:36:25 +02:00
|
|
|
return configs, errors.New("error agreeing to terms: " + err.Error())
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
|
2015-10-18 04:17:24 +02:00
|
|
|
err = saveUser(leUser)
|
2015-10-17 07:30:00 +02:00
|
|
|
if err != nil {
|
2015-10-17 17:36:25 +02:00
|
|
|
return configs, errors.New("could not save user: " + err.Error())
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-10-17 08:01:32 +02:00
|
|
|
// collect all the hostnames into one slice
|
2015-10-17 07:30:00 +02:00
|
|
|
var hosts []string
|
|
|
|
for _, cfg := range serverConfigs {
|
|
|
|
hosts = append(hosts, cfg.Host)
|
|
|
|
}
|
|
|
|
|
2015-10-17 08:01:32 +02:00
|
|
|
// showtime: let's get free, trusted SSL certificates! yeah!
|
2015-10-17 07:30:00 +02:00
|
|
|
certificates, err := client.ObtainCertificates(hosts)
|
|
|
|
if err != nil {
|
2015-10-17 17:36:25 +02:00
|
|
|
return configs, errors.New("error obtaining certs: " + err.Error())
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
|
2015-10-17 08:01:32 +02:00
|
|
|
// ... that's it. save the certs, keys, and update server configs.
|
2015-10-17 07:30:00 +02:00
|
|
|
for _, cert := range certificates {
|
2015-10-18 04:17:24 +02:00
|
|
|
os.MkdirAll(storage.Site(cert.Domain), 0700)
|
2015-10-17 08:01:32 +02:00
|
|
|
|
2015-10-17 07:30:00 +02:00
|
|
|
// Save cert
|
2015-10-18 04:17:24 +02:00
|
|
|
err = saveCertificate(cert.Certificate, storage.SiteCertFile(cert.Domain))
|
2015-10-17 07:30:00 +02:00
|
|
|
if err != nil {
|
2015-10-17 17:36:25 +02:00
|
|
|
return configs, err
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// Save private key
|
2015-10-18 04:17:24 +02:00
|
|
|
err = ioutil.WriteFile(storage.SiteKeyFile(cert.Domain), cert.PrivateKey, 0600)
|
2015-10-17 07:30:00 +02:00
|
|
|
if err != nil {
|
2015-10-17 17:36:25 +02:00
|
|
|
return configs, err
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// Save cert metadata
|
|
|
|
jsonBytes, err := json.MarshalIndent(&CertificateMeta{URL: cert.CertURL, Domain: cert.Domain}, "", "\t")
|
|
|
|
if err != nil {
|
2015-10-17 17:36:25 +02:00
|
|
|
return configs, err
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
2015-10-18 04:17:24 +02:00
|
|
|
err = ioutil.WriteFile(storage.SiteMetaFile(cert.Domain), jsonBytes, 0600)
|
2015-10-17 07:30:00 +02:00
|
|
|
if err != nil {
|
2015-10-17 17:36:25 +02:00
|
|
|
return configs, err
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// it all comes down to this: filling in the file path of a valid certificate automatically
|
|
|
|
for _, cfg := range serverConfigs {
|
2015-10-18 04:17:24 +02:00
|
|
|
cfg.TLS.Certificate = storage.SiteCertFile(cfg.Host)
|
|
|
|
cfg.TLS.Key = storage.SiteKeyFile(cfg.Host)
|
2015-10-17 17:06:05 +02:00
|
|
|
cfg.TLS.Enabled = true
|
|
|
|
cfg.Port = "https"
|
2015-10-17 17:36:25 +02:00
|
|
|
|
|
|
|
// Is there a plaintext HTTP config for the same host? If not, make
|
|
|
|
// one and have it redirect all requests to this HTTPS host.
|
|
|
|
var plaintextHostFound bool
|
|
|
|
for _, otherCfg := range configs {
|
|
|
|
if cfg.Host == otherCfg.Host && otherCfg.Port == "http" {
|
|
|
|
plaintextHostFound = true
|
|
|
|
break
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if !plaintextHostFound {
|
|
|
|
// Make one that redirects to HTTPS for all requests
|
2015-10-17 19:15:43 +02:00
|
|
|
configs = append(configs, redirPlaintextHost(*cfg))
|
2015-10-17 17:36:25 +02:00
|
|
|
}
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-10-17 17:36:25 +02:00
|
|
|
return configs, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// redirPlaintextHost returns a new virtualhost configuration for a server
|
|
|
|
// that redirects the plaintext HTTP host of cfg to cfg, which is assumed
|
|
|
|
// to be the secure (HTTPS) host.
|
|
|
|
func redirPlaintextHost(cfg server.Config) server.Config {
|
|
|
|
redirMidware := func(next middleware.Handler) middleware.Handler {
|
|
|
|
return redirect.Redirect{Next: next, Rules: []redirect.Rule{
|
|
|
|
{
|
|
|
|
FromScheme: "http",
|
|
|
|
FromPath: "/",
|
|
|
|
To: "https://" + cfg.Host + "{uri}",
|
|
|
|
Code: http.StatusMovedPermanently,
|
|
|
|
},
|
|
|
|
}}
|
|
|
|
}
|
|
|
|
|
|
|
|
return server.Config{
|
|
|
|
Host: cfg.Host,
|
|
|
|
Port: "http",
|
|
|
|
Middleware: map[string][]middleware.Middleware{
|
|
|
|
"/": []middleware.Middleware{redirMidware},
|
|
|
|
},
|
|
|
|
}
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
|
2015-10-17 08:01:32 +02:00
|
|
|
// getEmail does everything it can to obtain an email
|
|
|
|
// address from the user to use for TLS for cfg. If it
|
|
|
|
// cannot get an email address, it returns empty string.
|
2015-10-17 07:30:00 +02:00
|
|
|
func getEmail(cfg server.Config) string {
|
2015-10-17 08:01:32 +02:00
|
|
|
// First try the tls directive from the Caddyfile
|
2015-10-17 07:30:00 +02:00
|
|
|
leEmail := cfg.TLS.LetsEncryptEmail
|
|
|
|
if leEmail == "" {
|
2015-10-17 08:01:32 +02:00
|
|
|
// Then try memory (command line flag or typed by user previously)
|
2015-10-18 04:17:24 +02:00
|
|
|
leEmail = DefaultEmail
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
if leEmail == "" {
|
2015-10-17 08:01:32 +02:00
|
|
|
// Then try to get most recent user email ~/.caddy/users file
|
|
|
|
// TODO: Probably better to open the user's json file and read the email out of there...
|
2015-10-18 04:17:24 +02:00
|
|
|
userDirs, err := ioutil.ReadDir(storage.Users())
|
2015-10-17 08:01:32 +02:00
|
|
|
if err == nil {
|
|
|
|
var mostRecent os.FileInfo
|
|
|
|
for _, dir := range userDirs {
|
|
|
|
if !dir.IsDir() {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
if mostRecent == nil || dir.ModTime().After(mostRecent.ModTime()) {
|
|
|
|
mostRecent = dir
|
|
|
|
}
|
|
|
|
}
|
2015-10-18 04:17:24 +02:00
|
|
|
if mostRecent != nil {
|
|
|
|
leEmail = mostRecent.Name()
|
|
|
|
}
|
2015-10-17 08:01:32 +02:00
|
|
|
}
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
if leEmail == "" {
|
2015-10-17 08:01:32 +02:00
|
|
|
// Alas, we must bother the user and ask for an email address
|
2015-10-17 07:30:00 +02:00
|
|
|
reader := bufio.NewReader(os.Stdin)
|
2015-10-17 08:01:32 +02:00
|
|
|
fmt.Print("Email address: ") // TODO: More explanation probably, and show ToS?
|
2015-10-17 07:30:00 +02:00
|
|
|
var err error
|
|
|
|
leEmail, err = reader.ReadString('\n')
|
|
|
|
if err != nil {
|
|
|
|
return ""
|
|
|
|
}
|
2015-10-18 04:17:24 +02:00
|
|
|
DefaultEmail = leEmail
|
2015-10-17 07:30:00 +02:00
|
|
|
}
|
|
|
|
return strings.TrimSpace(leEmail)
|
|
|
|
}
|
|
|
|
|
2015-10-18 04:17:24 +02:00
|
|
|
var (
|
|
|
|
// Let's Encrypt account email to use if none provided
|
|
|
|
DefaultEmail string
|
2015-10-16 19:38:56 +02:00
|
|
|
|
2015-10-18 04:17:24 +02:00
|
|
|
// Whether user has agreed to the Let's Encrypt SA
|
|
|
|
Agreed bool
|
|
|
|
)
|
2015-10-17 07:30:00 +02:00
|
|
|
|
2015-10-18 04:17:24 +02:00
|
|
|
// Some essential values related to the Let's Encrypt process
|
|
|
|
const (
|
|
|
|
// Size of RSA keys in bits
|
|
|
|
rsaKeySize = 2048
|
2015-10-16 19:38:56 +02:00
|
|
|
|
2015-10-18 04:17:24 +02:00
|
|
|
// The base URL to the Let's Encrypt CA
|
|
|
|
caURL = "http://192.168.99.100:4000"
|
2015-10-17 07:30:00 +02:00
|
|
|
|
2015-10-18 04:17:24 +02:00
|
|
|
// The port to expose to the CA server for Simple HTTP Challenge
|
|
|
|
exposePort = "5001"
|
|
|
|
)
|
2015-10-17 07:30:00 +02:00
|
|
|
|
2015-10-18 04:17:24 +02:00
|
|
|
// KeySize represents the length of a key in bits
|
|
|
|
type KeySize int
|
2015-10-17 07:30:00 +02:00
|
|
|
|
2015-10-18 04:17:24 +02:00
|
|
|
// Key sizes
|
|
|
|
const (
|
|
|
|
ECC_224 KeySize = 224
|
|
|
|
ECC_256 = 256
|
|
|
|
RSA_2048 = 2048
|
|
|
|
RSA_4096 = 4096
|
|
|
|
)
|
2015-10-17 07:30:00 +02:00
|
|
|
|
|
|
|
type CertificateMeta struct {
|
|
|
|
Domain, URL string
|
2015-10-16 19:38:56 +02:00
|
|
|
}
|