added a warning if errorHandler is not set, added a note on using wildcard certs in local mode

This commit is contained in:
2019-02-25 17:14:56 +01:00
parent 5881b13730
commit 34c82cbd47
5 changed files with 19 additions and 4 deletions
+10
View File
@@ -97,6 +97,16 @@ In order to use simplecert for local development, set the *Local* field in the c
Certificates generated for local development are not checked for expiry,
the certificates generated by mkcert are valid for 10 years!
**Important**:
Using wildcard certificates in local mode does not work out of the box, since /etc/hosts doesn't support resolving wild card entries.
You'll have to use other services like dnsmasq. Just edit dnsmasq.conf and add the following line:
address=/yourdomain.com/127.0.0.1
This will resolve all requests to domains that end on *yourdomain.com* with *127.0.0.1*.
### Host Entries
To resolve the domain name for your certificate to your localhost,
-1
View File
@@ -1,4 +1,3 @@
# TODO
- test wildcard certs
- add unit tests
+5 -2
View File
@@ -109,10 +109,13 @@ func CheckConfig(c *Config) error {
}
if c.WillRenewCertificate == nil && (c.HTTPAddress != "" || c.TLSAddress != "") {
log.Println("[WARNING] no WillRenewCertificate handler specified to handle graceful server shutdown")
log.Println("[WARNING] no WillRenewCertificate handler specified, to handle graceful server shutdown!")
}
if c.DidRenewCertificate == nil && (c.HTTPAddress != "" || c.TLSAddress != "") {
log.Println("[WARNING] no DidRenewCertificate handler specified to bring the service back up after renewing the certificate")
log.Println("[WARNING] no DidRenewCertificate handler specified, to bring the service back up after renewing the certificate!")
}
if c.FailedToRenewCertificate == nil {
log.Println("[WARNING] no FailedToRenewCertificate handler specified! Simplecert will fatal on errors!")
}
return nil
+1 -1
View File
@@ -22,5 +22,5 @@ func main() {
w.Write([]byte("hello"))
})
log.Fatal(simplecert.ListenAndServeTLSLocal(":443", nil, "*.myawesomewebsite.com", "myawesomewebsite.com", "sub.myawesomewebsite.com"))
log.Fatal(simplecert.ListenAndServeTLSLocal(":443", nil, "myawesomewebsite.com", "sub.myawesomewebsite.com"))
}
+3
View File
@@ -115,6 +115,9 @@ func domainsChanged(certFilePath, keyFilePath string) bool {
log.Fatal("[FATAL] simplecert could not load X509 key pair: ", err)
}
// log.Println("[INFO] domains in cert: ", cert.DNSNames)
// log.Println("[INFO] domains in config: ", c.Domains)
// if the number of entries is not equal, bail out.
if len(cert.DNSNames) != len(c.Domains) {
return true