lego/acme/tls_sni_challenge.go

81 lines
1.9 KiB
Go
Raw Normal View History

2015-11-19 14:26:23 +00:00
package acme
import (
"crypto/rsa"
2015-11-19 14:26:23 +00:00
"crypto/sha256"
"crypto/tls"
2015-11-19 14:26:23 +00:00
"encoding/hex"
"fmt"
"net/http"
2015-11-19 14:26:23 +00:00
)
type tlsSNIChallenge struct {
jws *jws
validate func(j *jws, uri string, chlng challenge) error
optPort string
2015-11-19 14:26:23 +00:00
}
func (t *tlsSNIChallenge) Solve(chlng challenge, domain string) error {
// FIXME: https://github.com/ietf-wg-acme/acme/pull/22
// Currently we implement this challenge to track boulder, not the current spec!
2015-11-19 14:26:23 +00:00
2015-12-15 20:13:40 +00:00
logf("[INFO][%s] acme: Trying to solve TLS-SNI-01", domain)
2015-11-19 14:26:23 +00:00
// Generate the Key Authorization for the challenge
keyAuth, err := getKeyAuthorization(chlng.Token, &t.jws.privKey.PublicKey)
if err != nil {
return err
}
cert, err := t.generateCertificate(keyAuth)
if err != nil {
return err
}
// Allow for CLI port override
port := ":443"
if t.optPort != "" {
port = ":" + t.optPort
}
tlsConf := new(tls.Config)
tlsConf.Certificates = []tls.Certificate{cert}
2015-11-19 14:26:23 +00:00
listener, err := tls.Listen("tcp", port, tlsConf)
if err != nil {
return fmt.Errorf("Could not start HTTPS server for challenge -> %v", err)
2015-11-19 14:26:23 +00:00
}
defer listener.Close()
2015-11-19 14:26:23 +00:00
go http.Serve(listener, nil)
2015-11-19 14:26:23 +00:00
return t.validate(t.jws, chlng.URI, challenge{Resource: "challenge", Type: chlng.Type, Token: chlng.Token, KeyAuthorization: keyAuth})
2015-11-19 14:26:23 +00:00
}
func (t *tlsSNIChallenge) generateCertificate(keyAuth string) (tls.Certificate, error) {
zBytes := sha256.Sum256([]byte(keyAuth))
z := hex.EncodeToString(zBytes[:sha256.Size])
// generate a new RSA key for the certificates
tempPrivKey, err := generatePrivateKey(rsakey, 2048)
if err != nil {
return tls.Certificate{}, err
}
rsaPrivKey := tempPrivKey.(*rsa.PrivateKey)
rsaPrivPEM := pemEncode(rsaPrivKey)
domain := fmt.Sprintf("%s.%s.acme.invalid", z[:32], z[32:])
tempCertPEM, err := generatePemCert(rsaPrivKey, domain)
if err != nil {
return tls.Certificate{}, err
}
certificate, err := tls.X509KeyPair(tempCertPEM, rsaPrivPEM)
if err != nil {
return tls.Certificate{}, err
}
return certificate, nil
}