Obtain certificates, and wait for the one that matters

The public shape now works end to end: real ports, Caddy in front, and both
programs that need certificates getting them from the same CA -- Caddy for
the front ends over TLS-ALPN-01, the mail server for its own names over
HTTP-01, which Caddy forwards on port 80.

Proved in the lab against Pebble, with a DNS stub answering every name with
the machine's own address, so no public name or public CA is involved:
twenty checks, ending with IMAPS and submissions presenting a certificate
for the mail host that verifies against the CA, and the webmail sending
sign-in to the server as the first-party client the server registered.

Two things the test found, both of which would have shipped:

- The proxy fronted four of the server's five names. The server puts
  ua-auto-config in its own certificate too, so its challenge was never
  forwarded, one name failed, and the whole order failed with it -- leaving
  the mail ports on a self-signed certificate while everything else looked
  healthy. The list now matches what the server asks for.

- Nothing waited for the certificate. An order that fails is not retried on
  its own and a restart does not start a new one, so the install declared
  itself finished over a self-signed certificate. It now waits, asks again
  every 45 seconds, and reports the issuer -- or says plainly that the
  server will keep trying once the domain resolves here, which is the
  ordinary case on a first install.

--acme-directory and --acme-ca-root are what let a private CA be used: the
root is added to the server image's own bundle and given to Caddy, because
neither sees the other's trust store.
This commit is contained in:
2026-09-22 19:11:52 -07:00
parent 7141e565ea
commit 8725d8c11b
6 changed files with 263 additions and 14 deletions
+8
View File
@@ -46,6 +46,9 @@ install flags:
--proxy WHICH caddy | snippets | none (default: caddy)
--dir PATH where the installation lives; default: /var/lib/inbuxa
--local loopback evaluation: no public ports, no certificates
--acme-directory URL a private ACME CA, for testing the certificate path
--acme-ca-root PATH that CA's root, which both the server and the proxy
are made to trust
--install-deps install what the chosen shapes need and this
machine lacks, rather than refusing over it
--dry-run print the plan and stop
@@ -107,6 +110,8 @@ func install(args []string) int {
fs.StringVar(&o.Dir, "dir", "", "")
fs.BoolVar(&o.Local, "local", false, "")
fs.BoolVar(&o.InstallDeps, "install-deps", false, "")
fs.StringVar(&o.ACMEDirectory, "acme-directory", "", "")
fs.StringVar(&o.ACMECARoot, "acme-ca-root", "", "")
if err := fs.Parse(args); err != nil {
return 2
}
@@ -164,6 +169,9 @@ func install(args []string) int {
if res.WebmailURL != "" {
fmt.Printf(" webmail %s\n", res.WebmailURL)
}
if res.Certificate != "" {
fmt.Printf(" certificate issued by %s\n", res.Certificate)
}
if res.ZoneFile != "" {
fmt.Printf(" dns records %s\n", res.ZoneFile)
}