From 34c82cbd47767264f8416ea0302d09fb7ff4fbe6 Mon Sep 17 00:00:00 2001 From: Philipp Mieden Date: Mon, 25 Feb 2019 17:14:56 +0100 Subject: [PATCH] added a warning if errorHandler is not set, added a note on using wildcard certs in local mode --- README.md | 10 ++++++++++ TODO.md | 1 - config.go | 7 +++++-- examples/simple/main.go | 2 +- local.go | 3 +++ 5 files changed, 19 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 9b9784b..e0bc2fa 100644 --- a/README.md +++ b/README.md @@ -97,6 +97,16 @@ In order to use simplecert for local development, set the *Local* field in the c Certificates generated for local development are not checked for expiry, the certificates generated by mkcert are valid for 10 years! +**Important**: + +Using wildcard certificates in local mode does not work out of the box, since /etc/hosts doesn't support resolving wild card entries. + +You'll have to use other services like dnsmasq. Just edit dnsmasq.conf and add the following line: + + address=/yourdomain.com/127.0.0.1 + +This will resolve all requests to domains that end on *yourdomain.com* with *127.0.0.1*. + ### Host Entries To resolve the domain name for your certificate to your localhost, diff --git a/TODO.md b/TODO.md index e4007f0..3c7d5c8 100644 --- a/TODO.md +++ b/TODO.md @@ -1,4 +1,3 @@ # TODO -- test wildcard certs - add unit tests diff --git a/config.go b/config.go index b52a08f..99e6ae8 100644 --- a/config.go +++ b/config.go @@ -109,10 +109,13 @@ func CheckConfig(c *Config) error { } if c.WillRenewCertificate == nil && (c.HTTPAddress != "" || c.TLSAddress != "") { - log.Println("[WARNING] no WillRenewCertificate handler specified to handle graceful server shutdown") + log.Println("[WARNING] no WillRenewCertificate handler specified, to handle graceful server shutdown!") } if c.DidRenewCertificate == nil && (c.HTTPAddress != "" || c.TLSAddress != "") { - log.Println("[WARNING] no DidRenewCertificate handler specified to bring the service back up after renewing the certificate") + log.Println("[WARNING] no DidRenewCertificate handler specified, to bring the service back up after renewing the certificate!") + } + if c.FailedToRenewCertificate == nil { + log.Println("[WARNING] no FailedToRenewCertificate handler specified! Simplecert will fatal on errors!") } return nil diff --git a/examples/simple/main.go b/examples/simple/main.go index 71463b5..b4c5c76 100644 --- a/examples/simple/main.go +++ b/examples/simple/main.go @@ -22,5 +22,5 @@ func main() { w.Write([]byte("hello")) }) - log.Fatal(simplecert.ListenAndServeTLSLocal(":443", nil, "*.myawesomewebsite.com", "myawesomewebsite.com", "sub.myawesomewebsite.com")) + log.Fatal(simplecert.ListenAndServeTLSLocal(":443", nil, "myawesomewebsite.com", "sub.myawesomewebsite.com")) } diff --git a/local.go b/local.go index b6b5475..ccd4fb9 100644 --- a/local.go +++ b/local.go @@ -115,6 +115,9 @@ func domainsChanged(certFilePath, keyFilePath string) bool { log.Fatal("[FATAL] simplecert could not load X509 key pair: ", err) } + // log.Println("[INFO] domains in cert: ", cert.DNSNames) + // log.Println("[INFO] domains in config: ", c.Domains) + // if the number of entries is not equal, bail out. if len(cert.DNSNames) != len(c.Domains) { return true