mirror of
https://github.com/go-gitea/gitea.git
synced 2026-09-24 19:08:36 +02:00
enhance(acme): add configurable ACME profile (#39375)
Adds server-side ACME profile configuration so operators can select a non-default ACME profile. This covers issuers such as Let's Encrypt where raw-IP certificate issuance requires the `shortlived` profile. Fixes: #39374 Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: techknowlogick <164197+techknowlogick@users.noreply.github.com> Co-authored-by: techknowlogick <techknowlogick@gitea.com> Co-authored-by: silverwind <me@silverwind.io>
This commit is contained in:
@@ -83,6 +83,7 @@ func runACME(listenAddr string, m http.Handler) error {
|
||||
TrustedRoots: certPool,
|
||||
Email: setting.AcmeEmail,
|
||||
Agreed: setting.AcmeTOS,
|
||||
Profile: setting.AcmeProfile,
|
||||
DisableHTTPChallenge: !enableHTTPChallenge,
|
||||
DisableTLSALPNChallenge: !enableTLSALPNChallenge,
|
||||
ListenHost: setting.HTTPAddr,
|
||||
|
||||
@@ -261,6 +261,9 @@
|
||||
;; Can be left blank to initialize at first run and use the cached value
|
||||
;ACME_EMAIL =
|
||||
;;
|
||||
;; ACME profile to request from the CA (e.g. "shortlived" for raw-IP certificates)
|
||||
;ACME_PROFILE =
|
||||
;;
|
||||
;; ACME live directory (not to be confused with ACME directory URL: ACME_URL)
|
||||
;; (Refer to caddy's ACME manager https://github.com/caddyserver/certmagic)
|
||||
;ACME_DIRECTORY = https
|
||||
|
||||
@@ -101,6 +101,7 @@ var (
|
||||
AcmeLiveDirectory string
|
||||
AcmeEmail string
|
||||
AcmeURL string
|
||||
AcmeProfile string
|
||||
AcmeCARoot string
|
||||
SSLMinimumVersion string
|
||||
SSLMaximumVersion string
|
||||
@@ -171,6 +172,7 @@ func loadServerFrom(rootCfg ConfigProvider) {
|
||||
Protocol = HTTPS
|
||||
if EnableAcme {
|
||||
AcmeURL = sec.Key("ACME_URL").MustString("")
|
||||
AcmeProfile = sec.Key("ACME_PROFILE").MustString("")
|
||||
AcmeCARoot = sec.Key("ACME_CA_ROOT").MustString("")
|
||||
|
||||
if sec.HasKey("ACME_ACCEPTTOS") {
|
||||
|
||||
Reference in New Issue
Block a user