mirror of
https://github.com/gosticks/simplecert.git
synced 2026-10-06 06:37:04 +00:00
added a warning if errorHandler is not set, added a note on using wildcard certs in local mode
This commit is contained in:
@@ -97,6 +97,16 @@ In order to use simplecert for local development, set the *Local* field in the c
|
||||
Certificates generated for local development are not checked for expiry,
|
||||
the certificates generated by mkcert are valid for 10 years!
|
||||
|
||||
**Important**:
|
||||
|
||||
Using wildcard certificates in local mode does not work out of the box, since /etc/hosts doesn't support resolving wild card entries.
|
||||
|
||||
You'll have to use other services like dnsmasq. Just edit dnsmasq.conf and add the following line:
|
||||
|
||||
address=/yourdomain.com/127.0.0.1
|
||||
|
||||
This will resolve all requests to domains that end on *yourdomain.com* with *127.0.0.1*.
|
||||
|
||||
### Host Entries
|
||||
|
||||
To resolve the domain name for your certificate to your localhost,
|
||||
|
||||
@@ -109,10 +109,13 @@ func CheckConfig(c *Config) error {
|
||||
}
|
||||
|
||||
if c.WillRenewCertificate == nil && (c.HTTPAddress != "" || c.TLSAddress != "") {
|
||||
log.Println("[WARNING] no WillRenewCertificate handler specified to handle graceful server shutdown")
|
||||
log.Println("[WARNING] no WillRenewCertificate handler specified, to handle graceful server shutdown!")
|
||||
}
|
||||
if c.DidRenewCertificate == nil && (c.HTTPAddress != "" || c.TLSAddress != "") {
|
||||
log.Println("[WARNING] no DidRenewCertificate handler specified to bring the service back up after renewing the certificate")
|
||||
log.Println("[WARNING] no DidRenewCertificate handler specified, to bring the service back up after renewing the certificate!")
|
||||
}
|
||||
if c.FailedToRenewCertificate == nil {
|
||||
log.Println("[WARNING] no FailedToRenewCertificate handler specified! Simplecert will fatal on errors!")
|
||||
}
|
||||
|
||||
return nil
|
||||
|
||||
@@ -22,5 +22,5 @@ func main() {
|
||||
w.Write([]byte("hello"))
|
||||
})
|
||||
|
||||
log.Fatal(simplecert.ListenAndServeTLSLocal(":443", nil, "*.myawesomewebsite.com", "myawesomewebsite.com", "sub.myawesomewebsite.com"))
|
||||
log.Fatal(simplecert.ListenAndServeTLSLocal(":443", nil, "myawesomewebsite.com", "sub.myawesomewebsite.com"))
|
||||
}
|
||||
|
||||
@@ -115,6 +115,9 @@ func domainsChanged(certFilePath, keyFilePath string) bool {
|
||||
log.Fatal("[FATAL] simplecert could not load X509 key pair: ", err)
|
||||
}
|
||||
|
||||
// log.Println("[INFO] domains in cert: ", cert.DNSNames)
|
||||
// log.Println("[INFO] domains in config: ", c.Domains)
|
||||
|
||||
// if the number of entries is not equal, bail out.
|
||||
if len(cert.DNSNames) != len(c.Domains) {
|
||||
return true
|
||||
|
||||
Reference in New Issue
Block a user