Obtain certificates, and wait for the one that matters
The public shape now works end to end: real ports, Caddy in front, and both programs that need certificates getting them from the same CA -- Caddy for the front ends over TLS-ALPN-01, the mail server for its own names over HTTP-01, which Caddy forwards on port 80. Proved in the lab against Pebble, with a DNS stub answering every name with the machine's own address, so no public name or public CA is involved: twenty checks, ending with IMAPS and submissions presenting a certificate for the mail host that verifies against the CA, and the webmail sending sign-in to the server as the first-party client the server registered. Two things the test found, both of which would have shipped: - The proxy fronted four of the server's five names. The server puts ua-auto-config in its own certificate too, so its challenge was never forwarded, one name failed, and the whole order failed with it -- leaving the mail ports on a self-signed certificate while everything else looked healthy. The list now matches what the server asks for. - Nothing waited for the certificate. An order that fails is not retried on its own and a restart does not start a new one, so the install declared itself finished over a self-signed certificate. It now waits, asks again every 45 seconds, and reports the issuer -- or says plainly that the server will keep trying once the domain resolves here, which is the ordinary case on a first install. --acme-directory and --acme-ca-root are what let a private CA be used: the root is added to the server image's own bundle and given to Caddy, because neither sees the other's trust store.
This commit is contained in:
@@ -43,7 +43,10 @@ the installer draft); the phases are there too.
|
||||
inbuxa install --local --domain example.test --install-deps --yes
|
||||
|
||||
is the shortest thing that works today: the whole suite on loopback, with no
|
||||
DNS and no certificates, on a machine that starts with nothing.
|
||||
DNS and no certificates, on a machine that starts with nothing. Without
|
||||
`--local` it takes the real ports, puts Caddy in front and obtains
|
||||
certificates -- which `e2e/cases/install-public.sh` proves against a private
|
||||
CA, with no internet and no public name involved.
|
||||
|
||||
## Building and testing
|
||||
|
||||
@@ -55,7 +58,8 @@ is tested on a throwaway virtual machine rather than on anybody's desk:
|
||||
e2e/vm/up.sh a Debian 13 machine, in qemu, as you
|
||||
e2e/vm/run.sh e2e/cases/survey.sh what it says about a machine
|
||||
e2e/vm/run.sh e2e/cases/deps.sh the offer, and taking it
|
||||
e2e/vm/run.sh e2e/cases/install-local.sh a whole suite, and signing in to it
|
||||
e2e/vm/run.sh e2e/cases/install-local.sh a whole suite, and signing in to it
|
||||
e2e/vm/run.sh e2e/cases/install-public.sh the same with real ports and certificates
|
||||
e2e/vm/down.sh remove it
|
||||
|
||||
Each case starts from a copy of the machine taken when it was new, so a run
|
||||
|
||||
Reference in New Issue
Block a user