Compare commits
18 Commits
Author | SHA1 | Date | |
---|---|---|---|
a9efae65d6 | |||
0f09bdaf9f | |||
84177cd575 | |||
7d16ada760 | |||
b4de8cc2be | |||
68e570c32a | |||
20ea599f9d | |||
5fa530456b | |||
2cd1794e7e | |||
1f38e12bd3 | |||
1c777f6f05 | |||
aad113a8ea | |||
fff63839d1 | |||
c8d2cfd4ce | |||
dfd7edd330 | |||
4dadcf227c | |||
fce25c60ed | |||
98cc70dbfb |
1
.gitignore
vendored
1
.gitignore
vendored
@ -2,3 +2,4 @@ node_modules/
|
|||||||
coverage/
|
coverage/
|
||||||
public/
|
public/
|
||||||
pages/
|
pages/
|
||||||
|
.nogit/
|
||||||
|
4
.npmignore
Normal file
4
.npmignore
Normal file
@ -0,0 +1,4 @@
|
|||||||
|
node_modules/
|
||||||
|
coverage/
|
||||||
|
public/
|
||||||
|
pages/
|
33
README.md
33
README.md
@ -2,18 +2,18 @@
|
|||||||
acme implementation in TypeScript
|
acme implementation in TypeScript
|
||||||
|
|
||||||
## Availabililty
|
## Availabililty
|
||||||
[](https://www.npmjs.com/package/smartacme)
|
[](https://www.npmjs.com/package/smartacme)
|
||||||
[](https://GitLab.com/pushrocks/smartacme)
|
[](https://GitLab.com/umbrellazone/smartacme)
|
||||||
[](https://github.com/pushrocks/smartacme)
|
[](https://github.com/umbrellazone/smartacme)
|
||||||
[](https://pushrocks.gitlab.io/smartacme/)
|
[](https://umbrellazone.gitlab.io/smartacme/)
|
||||||
|
|
||||||
## Status for master
|
## Status for master
|
||||||
[](https://GitLab.com/pushrocks/smartacme/commits/master)
|
[](https://GitLab.com/umbrellazone/smartacme/commits/master)
|
||||||
[](https://GitLab.com/pushrocks/smartacme/commits/master)
|
[](https://GitLab.com/umbrellazone/smartacme/commits/master)
|
||||||
[](https://www.npmjs.com/package/smartacme)
|
[](https://www.npmjs.com/package/smartacme)
|
||||||
[](https://david-dm.org/pushrocks/smartacme)
|
[](https://david-dm.org/umbrellazone/smartacme)
|
||||||
[](https://www.bithound.io/github/pushrocks/smartacme/master/dependencies/npm)
|
[](https://www.bithound.io/github/umbrellazone/smartacme/master/dependencies/npm)
|
||||||
[](https://www.bithound.io/github/pushrocks/smartacme)
|
[](https://www.bithound.io/github/umbrellazone/smartacme)
|
||||||
[](https://nodejs.org/dist/latest-v6.x/docs/api/)
|
[](https://nodejs.org/dist/latest-v6.x/docs/api/)
|
||||||
[](https://nodejs.org/dist/latest-v6.x/docs/api/)
|
[](https://nodejs.org/dist/latest-v6.x/docs/api/)
|
||||||
[](http://standardjs.com/)
|
[](http://standardjs.com/)
|
||||||
@ -21,16 +21,9 @@ acme implementation in TypeScript
|
|||||||
## Usage
|
## Usage
|
||||||
Use TypeScript for best in class instellisense.
|
Use TypeScript for best in class instellisense.
|
||||||
|
|
||||||
```javascript
|
For further information read the linked docs at the top of this README.
|
||||||
import { SmartAcme } from 'smartacme'
|
|
||||||
|
|
||||||
let smac = new SmartAcme()
|
> MIT licensed | **©** [Lossless GmbH](https://lossless.gmbh)
|
||||||
|
| By using this npm module you agree to our [privacy policy](https://lossless.gmbH/privacy.html)
|
||||||
|
|
||||||
let myAccount = smac.getAccount() // optionally accepts a filePath Arg with a stored acmeaccount.json
|
[](https://umbrella.zone)
|
||||||
let myCert = myAccount.getChallenge('example.com','dns-01') // will return a dnsHash to set in your DNS record
|
|
||||||
myCert.get().then(() => {
|
|
||||||
console.log(myCert.certificate) // your certificate, ready to use in whatever way you prefer
|
|
||||||
})
|
|
||||||
```
|
|
||||||
|
|
||||||
[](https://push.rocks)
|
|
||||||
|
3
dist/index.js
vendored
3
dist/index.js
vendored
@ -2,5 +2,6 @@
|
|||||||
function __export(m) {
|
function __export(m) {
|
||||||
for (var p in m) if (!exports.hasOwnProperty(p)) exports[p] = m[p];
|
for (var p in m) if (!exports.hasOwnProperty(p)) exports[p] = m[p];
|
||||||
}
|
}
|
||||||
|
Object.defineProperty(exports, "__esModule", { value: true });
|
||||||
__export(require("./smartacme.classes.smartacme"));
|
__export(require("./smartacme.classes.smartacme"));
|
||||||
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoiaW5kZXguanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi90cy9pbmRleC50cyJdLCJuYW1lcyI6W10sIm1hcHBpbmdzIjoiOzs7O0FBQUEsbURBQTZDIn0=
|
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoiaW5kZXguanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi90cy9pbmRleC50cyJdLCJuYW1lcyI6W10sIm1hcHBpbmdzIjoiOzs7OztBQUFBLG1EQUE2QyJ9
|
21
dist/smartacme.classes.acmeaccount.d.ts
vendored
21
dist/smartacme.classes.acmeaccount.d.ts
vendored
@ -0,0 +1,21 @@
|
|||||||
|
import { SmartAcme } from './smartacme.classes.smartacme';
|
||||||
|
import { AcmeCert } from './smartacme.classes.acmecert';
|
||||||
|
/**
|
||||||
|
* class AcmeAccount represents an AcmeAccount
|
||||||
|
*/
|
||||||
|
export declare class AcmeAccount {
|
||||||
|
parentSmartAcme: SmartAcme;
|
||||||
|
location: string;
|
||||||
|
link: string;
|
||||||
|
JWK: any;
|
||||||
|
constructor(smartAcmeParentArg: SmartAcme);
|
||||||
|
/**
|
||||||
|
* register the account with letsencrypt
|
||||||
|
*/
|
||||||
|
register(): Promise<{}>;
|
||||||
|
/**
|
||||||
|
* agree to letsencrypr terms of service
|
||||||
|
*/
|
||||||
|
agreeTos(): Promise<{}>;
|
||||||
|
createAcmeCert(domainNameArg: string, countryArg?: string, countryShortArg?: string, city?: string, companyArg?: string, companyShortArg?: string): Promise<AcmeCert>;
|
||||||
|
}
|
||||||
|
73
dist/smartacme.classes.acmeaccount.js
vendored
73
dist/smartacme.classes.acmeaccount.js
vendored
@ -1 +1,72 @@
|
|||||||
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoic21hcnRhY21lLmNsYXNzZXMuYWNtZWFjY291bnQuanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi90cy9zbWFydGFjbWUuY2xhc3Nlcy5hY21lYWNjb3VudC50cyJdLCJuYW1lcyI6W10sIm1hcHBpbmdzIjoiIn0=
|
"use strict";
|
||||||
|
Object.defineProperty(exports, "__esModule", { value: true });
|
||||||
|
const q = require("smartq");
|
||||||
|
const smartacme_classes_acmecert_1 = require("./smartacme.classes.acmecert");
|
||||||
|
/**
|
||||||
|
* class AcmeAccount represents an AcmeAccount
|
||||||
|
*/
|
||||||
|
class AcmeAccount {
|
||||||
|
constructor(smartAcmeParentArg) {
|
||||||
|
this.parentSmartAcme = smartAcmeParentArg;
|
||||||
|
}
|
||||||
|
/**
|
||||||
|
* register the account with letsencrypt
|
||||||
|
*/
|
||||||
|
register() {
|
||||||
|
let done = q.defer();
|
||||||
|
this.parentSmartAcme.rawacmeClient.newReg({
|
||||||
|
contact: ['mailto:domains@lossless.org']
|
||||||
|
}, (err, res) => {
|
||||||
|
if (err) {
|
||||||
|
console.error('smartacme: something went wrong:');
|
||||||
|
console.log(err);
|
||||||
|
done.reject(err);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
this.JWK = res.body.key;
|
||||||
|
this.link = res.headers.link;
|
||||||
|
console.log(this.link);
|
||||||
|
this.location = res.headers.location;
|
||||||
|
done.resolve();
|
||||||
|
});
|
||||||
|
return done.promise;
|
||||||
|
}
|
||||||
|
/**
|
||||||
|
* agree to letsencrypr terms of service
|
||||||
|
*/
|
||||||
|
agreeTos() {
|
||||||
|
let done = q.defer();
|
||||||
|
let tosPart = this.link.split(',')[1];
|
||||||
|
let tosLinkPortion = tosPart.split(';')[0];
|
||||||
|
let url = tosLinkPortion.split(';')[0].trim().replace(/[<>]/g, '');
|
||||||
|
this.parentSmartAcme.rawacmeClient.post(this.location, { Agreement: url, resource: 'reg' }, (err, res) => {
|
||||||
|
if (err) {
|
||||||
|
console.log(err);
|
||||||
|
done.reject(err);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
done.resolve();
|
||||||
|
});
|
||||||
|
return done.promise;
|
||||||
|
}
|
||||||
|
createAcmeCert(domainNameArg, countryArg = 'Germany', countryShortArg = 'DE', city = 'Bremen', companyArg = 'Some Company', companyShortArg = 'SC') {
|
||||||
|
let done = q.defer();
|
||||||
|
let acmeCert = new smartacme_classes_acmecert_1.AcmeCert({
|
||||||
|
bit: 2064,
|
||||||
|
key: null,
|
||||||
|
domain: domainNameArg,
|
||||||
|
country: countryArg,
|
||||||
|
country_short: countryShortArg,
|
||||||
|
locality: city,
|
||||||
|
organization: companyArg,
|
||||||
|
organization_short: companyShortArg,
|
||||||
|
password: null,
|
||||||
|
unstructured: null,
|
||||||
|
subject_alt_names: null
|
||||||
|
}, this);
|
||||||
|
done.resolve(acmeCert);
|
||||||
|
return done.promise;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
exports.AcmeAccount = AcmeAccount;
|
||||||
|
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoic21hcnRhY21lLmNsYXNzZXMuYWNtZWFjY291bnQuanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi90cy9zbWFydGFjbWUuY2xhc3Nlcy5hY21lYWNjb3VudC50cyJdLCJuYW1lcyI6W10sIm1hcHBpbmdzIjoiOztBQUFBLDRCQUEyQjtBQU0zQiw2RUFBdUQ7QUFFdkQ7O0dBRUc7QUFDSDtJQUtFLFlBQVksa0JBQTZCO1FBQ3ZDLElBQUksQ0FBQyxlQUFlLEdBQUcsa0JBQWtCLENBQUE7SUFDM0MsQ0FBQztJQUVEOztPQUVHO0lBQ0gsUUFBUTtRQUNOLElBQUksSUFBSSxHQUFHLENBQUMsQ0FBQyxLQUFLLEVBQUUsQ0FBQTtRQUNwQixJQUFJLENBQUMsZUFBZSxDQUFDLGFBQWEsQ0FBQyxNQUFNLENBQ3ZDO1lBQ0UsT0FBTyxFQUFFLENBQUUsNkJBQTZCLENBQUU7U0FDM0MsRUFDRCxDQUFDLEdBQUcsRUFBRSxHQUFHO1lBQ1AsRUFBRSxDQUFDLENBQUMsR0FBRyxDQUFDLENBQUMsQ0FBQztnQkFDUixPQUFPLENBQUMsS0FBSyxDQUFDLGtDQUFrQyxDQUFDLENBQUE7Z0JBQ2pELE9BQU8sQ0FBQyxHQUFHLENBQUMsR0FBRyxDQUFDLENBQUE7Z0JBQ2hCLElBQUksQ0FBQyxNQUFNLENBQUMsR0FBRyxDQUFDLENBQUE7Z0JBQ2hCLE1BQU0sQ0FBQTtZQUNSLENBQUM7WUFDRCxJQUFJLENBQUMsR0FBRyxHQUFHLEdBQUcsQ0FBQyxJQUFJLENBQUMsR0FBRyxDQUFBO1lBQ3ZCLElBQUksQ0FBQyxJQUFJLEdBQUcsR0FBRyxDQUFDLE9BQU8sQ0FBQyxJQUFJLENBQUE7WUFDNUIsT0FBTyxDQUFDLEdBQUcsQ0FBQyxJQUFJLENBQUMsSUFBSSxDQUFDLENBQUE7WUFDdEIsSUFBSSxDQUFDLFFBQVEsR0FBRyxHQUFHLENBQUMsT0FBTyxDQUFDLFFBQVEsQ0FBQTtZQUNwQyxJQUFJLENBQUMsT0FBTyxFQUFFLENBQUE7UUFDaEIsQ0FBQyxDQUFDLENBQUE7UUFDSixNQUFNLENBQUMsSUFBSSxDQUFDLE9BQU8sQ0FBQTtJQUNyQixDQUFDO0lBRUQ7O09BRUc7SUFDSCxRQUFRO1FBQ04sSUFBSSxJQUFJLEdBQUcsQ0FBQyxDQUFDLEtBQUssRUFBRSxDQUFBO1FBQ3BCLElBQUksT0FBTyxHQUFHLElBQUksQ0FBQyxJQUFJLENBQUMsS0FBSyxDQUFDLEdBQUcsQ0FBQyxDQUFFLENBQUMsQ0FBRSxDQUFBO1FBQ3ZDLElBQUksY0FBYyxHQUFHLE9BQU8sQ0FBQyxLQUFLLENBQUMsR0FBRyxDQUFDLENBQUUsQ0FBQyxDQUFFLENBQUE7UUFDNUMsSUFBSSxHQUFHLEdBQUcsY0FBYyxDQUFDLEtBQUssQ0FBQyxHQUFHLENBQUMsQ0FBRSxDQUFDLENBQUUsQ0FBQyxJQUFJLEVBQUUsQ0FBQyxPQUFPLENBQUMsT0FBTyxFQUFFLEVBQUUsQ0FBQyxDQUFBO1FBQ3BFLElBQUksQ0FBQyxlQUFlLENBQUMsYUFBYSxDQUFDLElBQUksQ0FBQyxJQUFJLENBQUMsUUFBUSxFQUFFLEVBQUUsU0FBUyxFQUFFLEdBQUcsRUFBRSxRQUFRLEVBQUUsS0FBSyxFQUFFLEVBQUUsQ0FBQyxHQUFHLEVBQUUsR0FBRztZQUNuRyxFQUFFLENBQUMsQ0FBQyxHQUFHLENBQUMsQ0FBQyxDQUFDO2dCQUNSLE9BQU8sQ0FBQyxHQUFHLENBQUMsR0FBRyxDQUFDLENBQUE7Z0JBQ2hCLElBQUksQ0FBQyxNQUFNLENBQUMsR0FBRyxDQUFDLENBQUE7Z0JBQ2hCLE1BQU0sQ0FBQTtZQUNSLENBQUM7WUFDRCxJQUFJLENBQUMsT0FBTyxFQUFFLENBQUE7UUFDaEIsQ0FBQyxDQUFDLENBQUE7UUFDRixNQUFNLENBQUMsSUFBSSxDQUFDLE9BQU8sQ0FBQTtJQUNyQixDQUFDO0lBRUQsY0FBYyxDQUNaLGFBQXFCLEVBQ3JCLFVBQVUsR0FBRyxTQUFTLEVBQ3RCLGVBQWUsR0FBRyxJQUFJLEVBQ3RCLElBQUksR0FBRyxRQUFRLEVBQ2YsVUFBVSxHQUFHLGNBQWMsRUFDM0IsZUFBZSxHQUFHLElBQUk7UUFHdEIsSUFBSSxJQUFJLEdBQUcsQ0FBQyxDQUFDLEtBQUssRUFBWSxDQUFBO1FBQzlCLElBQUksUUFBUSxHQUFHLElBQUkscUNBQVEsQ0FDekI7WUFDRSxHQUFHLEVBQUUsSUFBSTtZQUNULEdBQUcsRUFBRSxJQUFJO1lBQ1QsTUFBTSxFQUFFLGFBQWE7WUFDckIsT0FBTyxFQUFFLFVBQVU7WUFDbkIsYUFBYSxFQUFFLGVBQWU7WUFDOUIsUUFBUSxFQUFFLElBQUk7WUFDZCxZQUFZLEVBQUUsVUFBVTtZQUN4QixrQkFBa0IsRUFBRSxlQUFlO1lBQ25DLFFBQVEsRUFBRSxJQUFJO1lBQ2QsWUFBWSxFQUFFLElBQUk7WUFDbEIsaUJBQWlCLEVBQUUsSUFBSTtTQUN4QixFQUNELElBQUksQ0FDTCxDQUFBO1FBQ0QsSUFBSSxDQUFDLE9BQU8sQ0FBQyxRQUFRLENBQUMsQ0FBQTtRQUN0QixNQUFNLENBQUMsSUFBSSxDQUFDLE9BQU8sQ0FBQTtJQUNyQixDQUFDO0NBQ0Y7QUFsRkQsa0NBa0ZDIn0=
|
78
dist/smartacme.classes.acmecert.d.ts
vendored
78
dist/smartacme.classes.acmecert.d.ts
vendored
@ -0,0 +1,78 @@
|
|||||||
|
import { IRsaKeypair } from './smartacme.classes.smartacme';
|
||||||
|
import { AcmeAccount } from './smartacme.classes.acmeaccount';
|
||||||
|
/**
|
||||||
|
* types of challenges supported by letsencrypt and this module
|
||||||
|
*/
|
||||||
|
export declare type TChallengeType = 'dns-01' | 'http-01';
|
||||||
|
/**
|
||||||
|
* values that a challenge's status can have
|
||||||
|
*/
|
||||||
|
export declare type TChallengeStatus = 'pending';
|
||||||
|
export interface ISmartAcmeChallenge {
|
||||||
|
uri: string;
|
||||||
|
status: TChallengeStatus;
|
||||||
|
type: TChallengeType;
|
||||||
|
token: string;
|
||||||
|
keyAuthorization: string;
|
||||||
|
}
|
||||||
|
export interface ISmartAcmeChallengeChosen extends ISmartAcmeChallenge {
|
||||||
|
dnsKeyHash: string;
|
||||||
|
domainName: string;
|
||||||
|
domainNamePrefixed: string;
|
||||||
|
}
|
||||||
|
export interface IAcmeCsrConstructorOptions {
|
||||||
|
bit: number;
|
||||||
|
key: string;
|
||||||
|
domain: string;
|
||||||
|
country: string;
|
||||||
|
country_short: string;
|
||||||
|
locality: string;
|
||||||
|
organization: string;
|
||||||
|
organization_short: string;
|
||||||
|
password: string;
|
||||||
|
unstructured: string;
|
||||||
|
subject_alt_names: string[];
|
||||||
|
}
|
||||||
|
/**
|
||||||
|
* class AcmeCert represents a cert for domain
|
||||||
|
*/
|
||||||
|
export declare class AcmeCert {
|
||||||
|
domainName: string;
|
||||||
|
attributes: any;
|
||||||
|
fullchain: string;
|
||||||
|
parentAcmeAccount: AcmeAccount;
|
||||||
|
csr: any;
|
||||||
|
validFrom: Date;
|
||||||
|
validTo: Date;
|
||||||
|
keypair: IRsaKeypair;
|
||||||
|
keyPairFinal: IRsaKeypair;
|
||||||
|
chosenChallenge: ISmartAcmeChallengeChosen;
|
||||||
|
dnsKeyHash: string;
|
||||||
|
constructor(optionsArg: IAcmeCsrConstructorOptions, parentAcmeAccount: AcmeAccount);
|
||||||
|
/**
|
||||||
|
* requests a challenge for a domain
|
||||||
|
* @param domainNameArg - the domain name to request a challenge for
|
||||||
|
* @param challengeType - the challenge type to request
|
||||||
|
*/
|
||||||
|
requestChallenge(challengeTypeArg?: TChallengeType): Promise<ISmartAcmeChallengeChosen>;
|
||||||
|
/**
|
||||||
|
* checks if DNS records are set, will go through a max of 30 cycles
|
||||||
|
*/
|
||||||
|
checkDns(cycleArg?: number): Promise<void>;
|
||||||
|
/**
|
||||||
|
* validates a challenge, only call after you have set the challenge at the expected location
|
||||||
|
*/
|
||||||
|
requestValidation(): Promise<void>;
|
||||||
|
/**
|
||||||
|
* requests a certificate
|
||||||
|
*/
|
||||||
|
requestCert(): Promise<{}>;
|
||||||
|
/**
|
||||||
|
* getCertificate - takes care of cooldown, validation polling and certificate retrieval
|
||||||
|
*/
|
||||||
|
getCertificate(): void;
|
||||||
|
/**
|
||||||
|
* accept a challenge - for private use only
|
||||||
|
*/
|
||||||
|
acceptChallenge(): Promise<{}>;
|
||||||
|
}
|
||||||
|
184
dist/smartacme.classes.acmecert.js
vendored
184
dist/smartacme.classes.acmecert.js
vendored
File diff suppressed because one or more lines are too long
21
dist/smartacme.classes.helper.d.ts
vendored
21
dist/smartacme.classes.helper.d.ts
vendored
@ -1,21 +0,0 @@
|
|||||||
/// <reference types="q" />
|
|
||||||
import 'typings-global';
|
|
||||||
import * as q from 'q';
|
|
||||||
import { SmartAcme } from './smartacme.classes.smartacme';
|
|
||||||
export interface IRsaKeypair {
|
|
||||||
publicKey: string;
|
|
||||||
privateKey: string;
|
|
||||||
}
|
|
||||||
export declare class SmartacmeHelper {
|
|
||||||
parentSmartAcme: SmartAcme;
|
|
||||||
constructor(smartAcmeArg: SmartAcme);
|
|
||||||
/**
|
|
||||||
* creates a keypair to use with requests and to generate JWK from
|
|
||||||
*/
|
|
||||||
createKeypair(bit?: number): IRsaKeypair;
|
|
||||||
/**
|
|
||||||
* getReg
|
|
||||||
* @executes ASYNC
|
|
||||||
*/
|
|
||||||
getReg(): q.Promise<{}>;
|
|
||||||
}
|
|
40
dist/smartacme.classes.helper.js
vendored
40
dist/smartacme.classes.helper.js
vendored
@ -1,40 +0,0 @@
|
|||||||
"use strict";
|
|
||||||
require("typings-global");
|
|
||||||
const q = require("q");
|
|
||||||
let rsaKeygen = require('rsa-keygen');
|
|
||||||
class SmartacmeHelper {
|
|
||||||
constructor(smartAcmeArg) {
|
|
||||||
this.parentSmartAcme = smartAcmeArg;
|
|
||||||
}
|
|
||||||
/**
|
|
||||||
* creates a keypair to use with requests and to generate JWK from
|
|
||||||
*/
|
|
||||||
createKeypair(bit = 2048) {
|
|
||||||
let result = rsaKeygen.generate(bit);
|
|
||||||
return {
|
|
||||||
publicKey: result.public_key,
|
|
||||||
privateKey: result.private_key
|
|
||||||
};
|
|
||||||
}
|
|
||||||
/**
|
|
||||||
* getReg
|
|
||||||
* @executes ASYNC
|
|
||||||
*/
|
|
||||||
getReg() {
|
|
||||||
let done = q.defer();
|
|
||||||
let body = { resource: 'reg' };
|
|
||||||
this.parentSmartAcme.rawacmeClient.post(this.parentSmartAcme.location, body, this.parentSmartAcme.keyPair, (err, res) => {
|
|
||||||
if (err) {
|
|
||||||
console.error('smartacme: something went wrong:');
|
|
||||||
console.log(err);
|
|
||||||
done.reject(err);
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
console.log(JSON.stringify(res.body));
|
|
||||||
done.resolve();
|
|
||||||
});
|
|
||||||
return done.promise;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
exports.SmartacmeHelper = SmartacmeHelper;
|
|
||||||
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoic21hcnRhY21lLmNsYXNzZXMuaGVscGVyLmpzIiwic291cmNlUm9vdCI6IiIsInNvdXJjZXMiOlsiLi4vdHMvc21hcnRhY21lLmNsYXNzZXMuaGVscGVyLnRzIl0sIm5hbWVzIjpbXSwibWFwcGluZ3MiOiI7QUFBQSwwQkFBdUI7QUFDdkIsdUJBQXNCO0FBQ3RCLElBQUksU0FBUyxHQUFHLE9BQU8sQ0FBQyxZQUFZLENBQUMsQ0FBQTtBQVNyQztJQUdJLFlBQVksWUFBdUI7UUFDL0IsSUFBSSxDQUFDLGVBQWUsR0FBRyxZQUFZLENBQUE7SUFDdkMsQ0FBQztJQUVEOztPQUVHO0lBQ0gsYUFBYSxDQUFDLEdBQUcsR0FBRyxJQUFJO1FBQ3BCLElBQUksTUFBTSxHQUFHLFNBQVMsQ0FBQyxRQUFRLENBQUMsR0FBRyxDQUFDLENBQUE7UUFDcEMsTUFBTSxDQUFDO1lBQ0gsU0FBUyxFQUFFLE1BQU0sQ0FBQyxVQUFVO1lBQzVCLFVBQVUsRUFBRSxNQUFNLENBQUMsV0FBVztTQUNqQyxDQUFBO0lBQ0wsQ0FBQztJQUVEOzs7T0FHRztJQUNILE1BQU07UUFDRixJQUFJLElBQUksR0FBRyxDQUFDLENBQUMsS0FBSyxFQUFFLENBQUE7UUFDcEIsSUFBSSxJQUFJLEdBQUcsRUFBRSxRQUFRLEVBQUUsS0FBSyxFQUFFLENBQUE7UUFDOUIsSUFBSSxDQUFDLGVBQWUsQ0FBQyxhQUFhLENBQUMsSUFBSSxDQUNuQyxJQUFJLENBQUMsZUFBZSxDQUFDLFFBQVEsRUFDN0IsSUFBSSxFQUFFLElBQUksQ0FBQyxlQUFlLENBQUMsT0FBTyxFQUNsQyxDQUFDLEdBQUcsRUFBRSxHQUFHO1lBQ0wsRUFBRSxDQUFDLENBQUMsR0FBRyxDQUFDLENBQUMsQ0FBQztnQkFDTixPQUFPLENBQUMsS0FBSyxDQUFDLGtDQUFrQyxDQUFDLENBQUE7Z0JBQ2pELE9BQU8sQ0FBQyxHQUFHLENBQUMsR0FBRyxDQUFDLENBQUE7Z0JBQ2hCLElBQUksQ0FBQyxNQUFNLENBQUMsR0FBRyxDQUFDLENBQUE7Z0JBQ2hCLE1BQU0sQ0FBQTtZQUNWLENBQUM7WUFDRCxPQUFPLENBQUMsR0FBRyxDQUFDLElBQUksQ0FBQyxTQUFTLENBQUMsR0FBRyxDQUFDLElBQUksQ0FBQyxDQUFDLENBQUE7WUFDckMsSUFBSSxDQUFDLE9BQU8sRUFBRSxDQUFBO1FBQ2xCLENBQUMsQ0FDSixDQUFBO1FBQ0QsTUFBTSxDQUFDLElBQUksQ0FBQyxPQUFPLENBQUE7SUFDdkIsQ0FBQztDQUNKO0FBekNELDBDQXlDQyJ9
|
|
40
dist/smartacme.classes.smartacme.d.ts
vendored
40
dist/smartacme.classes.smartacme.d.ts
vendored
@ -1,42 +1,32 @@
|
|||||||
/// <reference types="q" />
|
import { AcmeAccount } from './smartacme.classes.acmeaccount';
|
||||||
import 'typings-global';
|
/**
|
||||||
import * as q from 'q';
|
* a rsa keypair needed for account creation and subsequent requests
|
||||||
import { SmartacmeHelper, IRsaKeypair } from './smartacme.classes.helper';
|
*/
|
||||||
export declare type TChallenge = 'dns-01' | 'http-01';
|
export interface IRsaKeypair {
|
||||||
|
publicKey: string;
|
||||||
|
privateKey: string;
|
||||||
|
}
|
||||||
|
export { AcmeAccount } from './smartacme.classes.acmeaccount';
|
||||||
|
export { AcmeCert, ISmartAcmeChallenge, ISmartAcmeChallengeChosen } from './smartacme.classes.acmecert';
|
||||||
/**
|
/**
|
||||||
* class SmartAcme exports methods for maintaining SSL Certificates
|
* class SmartAcme exports methods for maintaining SSL Certificates
|
||||||
*/
|
*/
|
||||||
export declare class SmartAcme {
|
export declare class SmartAcme {
|
||||||
helper: SmartacmeHelper;
|
|
||||||
acmeUrl: string;
|
acmeUrl: string;
|
||||||
productionBool: boolean;
|
productionBool: boolean;
|
||||||
keyPair: IRsaKeypair;
|
keyPair: IRsaKeypair;
|
||||||
location: string;
|
|
||||||
link: string;
|
|
||||||
rawacmeClient: any;
|
rawacmeClient: any;
|
||||||
JWK: any;
|
|
||||||
/**
|
/**
|
||||||
* the constructor for class SmartAcme
|
* the constructor for class SmartAcme
|
||||||
*/
|
*/
|
||||||
constructor(productionArg?: boolean);
|
constructor(productionArg?: boolean);
|
||||||
|
/**
|
||||||
|
* init the smartacme instance
|
||||||
|
*/
|
||||||
|
init(): Promise<{}>;
|
||||||
/**
|
/**
|
||||||
* creates an account if not currently present in module
|
* creates an account if not currently present in module
|
||||||
* @executes ASYNC
|
* @executes ASYNC
|
||||||
*/
|
*/
|
||||||
createAccount(): q.Promise<{}>;
|
createAcmeAccount(): Promise<AcmeAccount>;
|
||||||
agreeTos(): q.Promise<{}>;
|
|
||||||
/**
|
|
||||||
* requests a challenge for a domain
|
|
||||||
* @param domainNameArg - the domain name to request a challenge for
|
|
||||||
* @param challengeType - the challenge type to request
|
|
||||||
*/
|
|
||||||
requestChallenge(domainNameArg: string, challengeTypeArg?: TChallenge): q.Promise<{}>;
|
|
||||||
/**
|
|
||||||
* getCertificate - takes care of cooldown, validation polling and certificate retrieval
|
|
||||||
*/
|
|
||||||
getCertificate(): void;
|
|
||||||
/**
|
|
||||||
* accept a challenge - for private use only
|
|
||||||
*/
|
|
||||||
private acceptChallenge(challenge);
|
|
||||||
}
|
}
|
||||||
|
119
dist/smartacme.classes.smartacme.js
vendored
119
dist/smartacme.classes.smartacme.js
vendored
File diff suppressed because one or more lines are too long
10
dist/smartacme.helpers.d.ts
vendored
Normal file
10
dist/smartacme.helpers.d.ts
vendored
Normal file
@ -0,0 +1,10 @@
|
|||||||
|
import 'typings-global';
|
||||||
|
import { IRsaKeypair } from './smartacme.classes.smartacme';
|
||||||
|
/**
|
||||||
|
* creates a keypair to use with requests and to generate JWK from
|
||||||
|
*/
|
||||||
|
export declare let createKeypair: (bit?: number) => IRsaKeypair;
|
||||||
|
/**
|
||||||
|
* prefix a domain name to make sure it complies with letsencrypt
|
||||||
|
*/
|
||||||
|
export declare let prefixName: (domainNameArg: string) => string;
|
41
dist/smartacme.helpers.js
vendored
Normal file
41
dist/smartacme.helpers.js
vendored
Normal file
@ -0,0 +1,41 @@
|
|||||||
|
"use strict";
|
||||||
|
Object.defineProperty(exports, "__esModule", { value: true });
|
||||||
|
require("typings-global");
|
||||||
|
const q = require("smartq");
|
||||||
|
const plugins = require("./smartacme.plugins");
|
||||||
|
/**
|
||||||
|
* creates a keypair to use with requests and to generate JWK from
|
||||||
|
*/
|
||||||
|
exports.createKeypair = (bit = 2048) => {
|
||||||
|
let result = plugins.rsaKeygen.generate(bit);
|
||||||
|
return {
|
||||||
|
publicKey: result.public_key,
|
||||||
|
privateKey: result.private_key
|
||||||
|
};
|
||||||
|
};
|
||||||
|
/**
|
||||||
|
* prefix a domain name to make sure it complies with letsencrypt
|
||||||
|
*/
|
||||||
|
exports.prefixName = (domainNameArg) => {
|
||||||
|
return '_acme-challenge.' + domainNameArg;
|
||||||
|
};
|
||||||
|
/**
|
||||||
|
* gets an existing registration
|
||||||
|
* @executes ASYNC
|
||||||
|
*/
|
||||||
|
let getReg = (SmartAcmeArg, location) => {
|
||||||
|
let done = q.defer();
|
||||||
|
let body = { resource: 'reg' };
|
||||||
|
SmartAcmeArg.rawacmeClient.post(location, body, SmartAcmeArg.keyPair, (err, res) => {
|
||||||
|
if (err) {
|
||||||
|
console.error('smartacme: something went wrong:');
|
||||||
|
console.log(err);
|
||||||
|
done.reject(err);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
console.log(JSON.stringify(res.body));
|
||||||
|
done.resolve();
|
||||||
|
});
|
||||||
|
return done.promise;
|
||||||
|
};
|
||||||
|
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoic21hcnRhY21lLmhlbHBlcnMuanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi90cy9zbWFydGFjbWUuaGVscGVycy50cyJdLCJuYW1lcyI6W10sIm1hcHBpbmdzIjoiOztBQUFBLDBCQUF1QjtBQUN2Qiw0QkFBMkI7QUFFM0IsK0NBQThDO0FBSzlDOztHQUVHO0FBQ1EsUUFBQSxhQUFhLEdBQUcsQ0FBQyxHQUFHLEdBQUcsSUFBSTtJQUNwQyxJQUFJLE1BQU0sR0FBRyxPQUFPLENBQUMsU0FBUyxDQUFDLFFBQVEsQ0FBQyxHQUFHLENBQUMsQ0FBQTtJQUM1QyxNQUFNLENBQUM7UUFDTCxTQUFTLEVBQUUsTUFBTSxDQUFDLFVBQVU7UUFDNUIsVUFBVSxFQUFFLE1BQU0sQ0FBQyxXQUFXO0tBQy9CLENBQUE7QUFDSCxDQUFDLENBQUE7QUFFRDs7R0FFRztBQUNRLFFBQUEsVUFBVSxHQUFHLENBQUMsYUFBcUI7SUFDNUMsTUFBTSxDQUFDLGtCQUFrQixHQUFHLGFBQWEsQ0FBQTtBQUMzQyxDQUFDLENBQUE7QUFFRDs7O0dBR0c7QUFDSCxJQUFJLE1BQU0sR0FBRyxDQUFDLFlBQXVCLEVBQUUsUUFBZ0I7SUFDckQsSUFBSSxJQUFJLEdBQUcsQ0FBQyxDQUFDLEtBQUssRUFBRSxDQUFBO0lBQ3BCLElBQUksSUFBSSxHQUFHLEVBQUUsUUFBUSxFQUFFLEtBQUssRUFBRSxDQUFBO0lBQzlCLFlBQVksQ0FBQyxhQUFhLENBQUMsSUFBSSxDQUM3QixRQUFRLEVBQ1IsSUFBSSxFQUNKLFlBQVksQ0FBQyxPQUFPLEVBQ3BCLENBQUMsR0FBRyxFQUFFLEdBQUc7UUFDUCxFQUFFLENBQUMsQ0FBQyxHQUFHLENBQUMsQ0FBQyxDQUFDO1lBQ1IsT0FBTyxDQUFDLEtBQUssQ0FBQyxrQ0FBa0MsQ0FBQyxDQUFBO1lBQ2pELE9BQU8sQ0FBQyxHQUFHLENBQUMsR0FBRyxDQUFDLENBQUE7WUFDaEIsSUFBSSxDQUFDLE1BQU0sQ0FBQyxHQUFHLENBQUMsQ0FBQTtZQUNoQixNQUFNLENBQUE7UUFDUixDQUFDO1FBQ0QsT0FBTyxDQUFDLEdBQUcsQ0FBQyxJQUFJLENBQUMsU0FBUyxDQUFDLEdBQUcsQ0FBQyxJQUFJLENBQUMsQ0FBQyxDQUFBO1FBQ3JDLElBQUksQ0FBQyxPQUFPLEVBQUUsQ0FBQTtJQUNoQixDQUFDLENBQ0YsQ0FBQTtJQUNELE1BQU0sQ0FBQyxJQUFJLENBQUMsT0FBTyxDQUFBO0FBQ3JCLENBQUMsQ0FBQSJ9
|
3
dist/smartacme.paths.js
vendored
3
dist/smartacme.paths.js
vendored
@ -1,7 +1,8 @@
|
|||||||
"use strict";
|
"use strict";
|
||||||
|
Object.defineProperty(exports, "__esModule", { value: true });
|
||||||
const path = require("path");
|
const path = require("path");
|
||||||
const smartfile = require("smartfile");
|
const smartfile = require("smartfile");
|
||||||
exports.packageDir = path.join(__dirname, '../');
|
exports.packageDir = path.join(__dirname, '../');
|
||||||
exports.assetDir = path.join(exports.packageDir, 'assets/');
|
exports.assetDir = path.join(exports.packageDir, 'assets/');
|
||||||
smartfile.fs.ensureDirSync(exports.assetDir);
|
smartfile.fs.ensureDirSync(exports.assetDir);
|
||||||
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoic21hcnRhY21lLnBhdGhzLmpzIiwic291cmNlUm9vdCI6IiIsInNvdXJjZXMiOlsiLi4vdHMvc21hcnRhY21lLnBhdGhzLnRzIl0sIm5hbWVzIjpbXSwibWFwcGluZ3MiOiI7QUFBQSw2QkFBNEI7QUFDNUIsdUNBQXNDO0FBRTNCLFFBQUEsVUFBVSxHQUFHLElBQUksQ0FBQyxJQUFJLENBQUMsU0FBUyxFQUFDLEtBQUssQ0FBQyxDQUFBO0FBQ3ZDLFFBQUEsUUFBUSxHQUFHLElBQUksQ0FBQyxJQUFJLENBQUMsa0JBQVUsRUFBQyxTQUFTLENBQUMsQ0FBQTtBQUNyRCxTQUFTLENBQUMsRUFBRSxDQUFDLGFBQWEsQ0FBQyxnQkFBUSxDQUFDLENBQUEifQ==
|
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoic21hcnRhY21lLnBhdGhzLmpzIiwic291cmNlUm9vdCI6IiIsInNvdXJjZXMiOlsiLi4vdHMvc21hcnRhY21lLnBhdGhzLnRzIl0sIm5hbWVzIjpbXSwibWFwcGluZ3MiOiI7O0FBQUEsNkJBQTRCO0FBQzVCLHVDQUFzQztBQUUzQixRQUFBLFVBQVUsR0FBRyxJQUFJLENBQUMsSUFBSSxDQUFDLFNBQVMsRUFBQyxLQUFLLENBQUMsQ0FBQTtBQUN2QyxRQUFBLFFBQVEsR0FBRyxJQUFJLENBQUMsSUFBSSxDQUFDLGtCQUFVLEVBQUMsU0FBUyxDQUFDLENBQUE7QUFDckQsU0FBUyxDQUFDLEVBQUUsQ0FBQyxhQUFhLENBQUMsZ0JBQVEsQ0FBQyxDQUFBIn0=
|
9
dist/smartacme.plugins.d.ts
vendored
Normal file
9
dist/smartacme.plugins.d.ts
vendored
Normal file
@ -0,0 +1,9 @@
|
|||||||
|
import 'typings-global';
|
||||||
|
declare let rsaKeygen: any;
|
||||||
|
declare let rawacme: any;
|
||||||
|
declare let nodeForge: any;
|
||||||
|
import * as dnsly from 'dnsly';
|
||||||
|
import * as smartdelay from 'smartdelay';
|
||||||
|
import * as smartfile from 'smartfile';
|
||||||
|
import * as smartstring from 'smartstring';
|
||||||
|
export { dnsly, rsaKeygen, rawacme, nodeForge, smartdelay, smartfile, smartstring };
|
19
dist/smartacme.plugins.js
vendored
Normal file
19
dist/smartacme.plugins.js
vendored
Normal file
@ -0,0 +1,19 @@
|
|||||||
|
"use strict";
|
||||||
|
Object.defineProperty(exports, "__esModule", { value: true });
|
||||||
|
require("typings-global"); // typings for node
|
||||||
|
let rsaKeygen = require('rsa-keygen'); // rsa keygen
|
||||||
|
exports.rsaKeygen = rsaKeygen;
|
||||||
|
let rawacme = require('rawacme'); // acme helper functions
|
||||||
|
exports.rawacme = rawacme;
|
||||||
|
let nodeForge = require('node-forge');
|
||||||
|
exports.nodeForge = nodeForge;
|
||||||
|
// push.rocks modules here
|
||||||
|
const dnsly = require("dnsly");
|
||||||
|
exports.dnsly = dnsly;
|
||||||
|
const smartdelay = require("smartdelay");
|
||||||
|
exports.smartdelay = smartdelay;
|
||||||
|
const smartfile = require("smartfile");
|
||||||
|
exports.smartfile = smartfile;
|
||||||
|
const smartstring = require("smartstring");
|
||||||
|
exports.smartstring = smartstring;
|
||||||
|
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoic21hcnRhY21lLnBsdWdpbnMuanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi90cy9zbWFydGFjbWUucGx1Z2lucy50cyJdLCJuYW1lcyI6W10sIm1hcHBpbmdzIjoiOztBQUFBLDBCQUF1QixDQUFDLG1CQUFtQjtBQUczQyxJQUFJLFNBQVMsR0FBRyxPQUFPLENBQUMsWUFBWSxDQUFDLENBQUEsQ0FBQyxhQUFhO0FBWWpELDhCQUFTO0FBWFgsSUFBSSxPQUFPLEdBQUcsT0FBTyxDQUFDLFNBQVMsQ0FBQyxDQUFBLENBQUMsd0JBQXdCO0FBWXZELDBCQUFPO0FBWFQsSUFBSSxTQUFTLEdBQUcsT0FBTyxDQUFDLFlBQVksQ0FBQyxDQUFBO0FBWW5DLDhCQUFTO0FBVlgsMEJBQTBCO0FBQzFCLCtCQUE4QjtBQU01QixzQkFBSztBQUxQLHlDQUF3QztBQVN0QyxnQ0FBVTtBQVJaLHVDQUFzQztBQVNwQyw4QkFBUztBQVJYLDJDQUEwQztBQVN4QyxrQ0FBVyJ9
|
59
docs/index.md
Normal file
59
docs/index.md
Normal file
@ -0,0 +1,59 @@
|
|||||||
|
# smartacme
|
||||||
|
acme implementation in TypeScript
|
||||||
|
|
||||||
|
## Availabililty
|
||||||
|
[](https://www.npmjs.com/package/smartacme)
|
||||||
|
[](https://GitLab.com/umbrellazone/smartacme)
|
||||||
|
[](https://github.com/umbrellazone/smartacme)
|
||||||
|
[](https://umbrellazone.gitlab.io/smartacme/)
|
||||||
|
|
||||||
|
## Status for master
|
||||||
|
[](https://GitLab.com/umbrellazone/smartacme/commits/master)
|
||||||
|
[](https://GitLab.com/umbrellazone/smartacme/commits/master)
|
||||||
|
[](https://www.npmjs.com/package/smartacme)
|
||||||
|
[](https://david-dm.org/umbrellazone/smartacme)
|
||||||
|
[](https://www.bithound.io/github/umbrellazone/smartacme/master/dependencies/npm)
|
||||||
|
[](https://www.bithound.io/github/umbrellazone/smartacme)
|
||||||
|
[](https://nodejs.org/dist/latest-v6.x/docs/api/)
|
||||||
|
[](https://nodejs.org/dist/latest-v6.x/docs/api/)
|
||||||
|
[](http://standardjs.com/)
|
||||||
|
|
||||||
|
## Usage
|
||||||
|
Use TypeScript for best in class instellisense.
|
||||||
|
|
||||||
|
```javascript
|
||||||
|
import { SmartAcme } from 'smartacme'
|
||||||
|
|
||||||
|
let smac = new SmartAcme()
|
||||||
|
|
||||||
|
(async () => { // learn async/await, it'll make your life easier
|
||||||
|
|
||||||
|
// optionally accepts a filePath Arg with a stored acmeaccount.json
|
||||||
|
// will create an account and
|
||||||
|
let myAccount = await smac.createAcmeAccount()
|
||||||
|
|
||||||
|
// will return a dnsHash to set in your DNS record
|
||||||
|
let myCert = await myAccount.createAcmeCert('example.com')
|
||||||
|
|
||||||
|
// gets and accepts the specified challenge
|
||||||
|
// first argument optional, defaults to dns-01 (which is the cleanest method for production use)
|
||||||
|
let myChallenge = await myCert.getChallenge('dns-01')
|
||||||
|
|
||||||
|
/* ----------
|
||||||
|
Now you need to set the challenge in your DNS
|
||||||
|
myChallenge.domainNamePrefixed is the address for the record
|
||||||
|
myChallenge.dnsKeyHash is the ready to use txt record value expected by letsencrypt
|
||||||
|
-------------*/
|
||||||
|
})()
|
||||||
|
```
|
||||||
|
|
||||||
|
## Other relevant npm modules
|
||||||
|
module name | description
|
||||||
|
--- | ---
|
||||||
|
cert | a higlevel production module that uses smartacme to manage certs
|
||||||
|
smartnginx | a highlevel production tool for docker environments to manage nginx
|
||||||
|
|
||||||
|
> MIT licensed | **©** [Lossless GmbH](https://lossless.gmbh)
|
||||||
|
| By using this npm module you agree to our [privacy policy](https://lossless.gmbH/privacy.html)
|
||||||
|
|
||||||
|
[](https://umbrella.zone
|
27
package.json
27
package.json
@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "smartacme",
|
"name": "smartacme",
|
||||||
"version": "1.0.5",
|
"version": "1.0.10",
|
||||||
"description": "acme implementation in TypeScript",
|
"description": "acme implementation in TypeScript",
|
||||||
"main": "dist/index.js",
|
"main": "dist/index.js",
|
||||||
"typings": "dist/index.d.ts",
|
"typings": "dist/index.d.ts",
|
||||||
@ -9,7 +9,7 @@
|
|||||||
},
|
},
|
||||||
"repository": {
|
"repository": {
|
||||||
"type": "git",
|
"type": "git",
|
||||||
"url": "git+ssh://git@gitlab.com/pushrocks/smartacme.git"
|
"url": "git+ssh://git@gitlab.com/umbrellazone/smartacme.git"
|
||||||
},
|
},
|
||||||
"keywords": [
|
"keywords": [
|
||||||
"TypeScript",
|
"TypeScript",
|
||||||
@ -19,21 +19,24 @@
|
|||||||
"author": "Lossless GmbH",
|
"author": "Lossless GmbH",
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"bugs": {
|
"bugs": {
|
||||||
"url": "https://gitlab.com/pushrocks/smartacme/issues"
|
"url": "https://gitlab.com/umbrellazone/smartacme/issues"
|
||||||
},
|
},
|
||||||
"homepage": "https://gitlab.com/pushrocks/smartacme#README",
|
"homepage": "https://gitlab.com/umbrellazone/smartacme#README",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@types/q": "0.x.x",
|
"@types/node-forge": "^0.6.8",
|
||||||
"q": "^1.4.1",
|
"dnsly": "^2.0.4",
|
||||||
|
"node-forge": "^0.7.1",
|
||||||
"rawacme": "^0.2.1",
|
"rawacme": "^0.2.1",
|
||||||
"rsa-keygen": "^1.0.6",
|
"rsa-keygen": "^1.0.6",
|
||||||
"smartfile": "^4.1.0",
|
"smartdelay": "^1.0.1",
|
||||||
"smartstring": "^2.0.20",
|
"smartfile": "^4.1.10",
|
||||||
"typings-global": "^1.0.14"
|
"smartq": "^1.1.1",
|
||||||
|
"smartstring": "^2.0.24",
|
||||||
|
"typings-global": "^1.0.16"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@types/should": "^8.1.30",
|
"cflare": "0.0.19",
|
||||||
"should": "^11.1.1",
|
"qenv": "^1.1.3",
|
||||||
"typings-test": "^1.0.3"
|
"tapbundle": "^1.0.10"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
1
test/test.d.ts
vendored
1
test/test.d.ts
vendored
@ -1 +0,0 @@
|
|||||||
import 'typings-test';
|
|
38
test/test.js
38
test/test.js
@ -1,38 +0,0 @@
|
|||||||
"use strict";
|
|
||||||
require("typings-test");
|
|
||||||
const should = require("should");
|
|
||||||
// import the module to test
|
|
||||||
const smartacme = require("../dist/index");
|
|
||||||
describe('smartacme', function () {
|
|
||||||
let testAcme;
|
|
||||||
it('should create a valid instance', function () {
|
|
||||||
this.timeout(10000);
|
|
||||||
testAcme = new smartacme.SmartAcme();
|
|
||||||
should(testAcme).be.instanceOf(smartacme.SmartAcme);
|
|
||||||
});
|
|
||||||
it('should have created keyPair', function () {
|
|
||||||
should(testAcme.acmeUrl).be.of.type('string');
|
|
||||||
});
|
|
||||||
it('should register a new account', function (done) {
|
|
||||||
this.timeout(10000);
|
|
||||||
testAcme.createAccount().then(x => {
|
|
||||||
done();
|
|
||||||
}).catch(err => {
|
|
||||||
console.log(err);
|
|
||||||
done(err);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
it('should agree to ToS', function (done) {
|
|
||||||
this.timeout(10000);
|
|
||||||
testAcme.agreeTos().then(() => {
|
|
||||||
done();
|
|
||||||
});
|
|
||||||
});
|
|
||||||
it('should request a challenge for a domain', function (done) {
|
|
||||||
this.timeout(10000);
|
|
||||||
testAcme.requestChallenge('bleu.de').then(() => {
|
|
||||||
done();
|
|
||||||
});
|
|
||||||
});
|
|
||||||
});
|
|
||||||
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoidGVzdC5qcyIsInNvdXJjZVJvb3QiOiIiLCJzb3VyY2VzIjpbInRlc3QudHMiXSwibmFtZXMiOltdLCJtYXBwaW5ncyI6IjtBQUFBLHdCQUFxQjtBQUNyQixpQ0FBZ0M7QUFFaEMsNEJBQTRCO0FBQzVCLDJDQUEwQztBQUUxQyxRQUFRLENBQUMsV0FBVyxFQUFFO0lBQ2xCLElBQUksUUFBNkIsQ0FBQTtJQUVqQyxFQUFFLENBQUMsZ0NBQWdDLEVBQUU7UUFDakMsSUFBSSxDQUFDLE9BQU8sQ0FBQyxLQUFLLENBQUMsQ0FBQTtRQUNuQixRQUFRLEdBQUcsSUFBSSxTQUFTLENBQUMsU0FBUyxFQUFFLENBQUE7UUFDcEMsTUFBTSxDQUFDLFFBQVEsQ0FBQyxDQUFDLEVBQUUsQ0FBQyxVQUFVLENBQUMsU0FBUyxDQUFDLFNBQVMsQ0FBQyxDQUFBO0lBQ3ZELENBQUMsQ0FBQyxDQUFBO0lBRUYsRUFBRSxDQUFDLDZCQUE2QixFQUFFO1FBQzlCLE1BQU0sQ0FBQyxRQUFRLENBQUMsT0FBTyxDQUFDLENBQUMsRUFBRSxDQUFDLEVBQUUsQ0FBQyxJQUFJLENBQUMsUUFBUSxDQUFDLENBQUE7SUFDakQsQ0FBQyxDQUFDLENBQUE7SUFFRixFQUFFLENBQUMsK0JBQStCLEVBQUUsVUFBVSxJQUFJO1FBQzlDLElBQUksQ0FBQyxPQUFPLENBQUMsS0FBSyxDQUFDLENBQUE7UUFDbkIsUUFBUSxDQUFDLGFBQWEsRUFBRSxDQUFDLElBQUksQ0FBQyxDQUFDO1lBQzNCLElBQUksRUFBRSxDQUFBO1FBQ1YsQ0FBQyxDQUFDLENBQUMsS0FBSyxDQUFDLEdBQUc7WUFDUixPQUFPLENBQUMsR0FBRyxDQUFDLEdBQUcsQ0FBQyxDQUFBO1lBQ2hCLElBQUksQ0FBQyxHQUFHLENBQUMsQ0FBQTtRQUNiLENBQUMsQ0FBQyxDQUFBO0lBQ04sQ0FBQyxDQUFDLENBQUE7SUFFRixFQUFFLENBQUMscUJBQXFCLEVBQUUsVUFBUyxJQUFJO1FBQ25DLElBQUksQ0FBQyxPQUFPLENBQUMsS0FBSyxDQUFDLENBQUE7UUFDbkIsUUFBUSxDQUFDLFFBQVEsRUFBRSxDQUFDLElBQUksQ0FBQztZQUNyQixJQUFJLEVBQUUsQ0FBQTtRQUNWLENBQUMsQ0FBQyxDQUFBO0lBQ04sQ0FBQyxDQUFDLENBQUE7SUFFRixFQUFFLENBQUMseUNBQXlDLEVBQUUsVUFBUyxJQUFJO1FBQ3ZELElBQUksQ0FBQyxPQUFPLENBQUMsS0FBSyxDQUFDLENBQUE7UUFDbkIsUUFBUSxDQUFDLGdCQUFnQixDQUFDLFNBQVMsQ0FBQyxDQUFDLElBQUksQ0FBQztZQUN0QyxJQUFJLEVBQUUsQ0FBQTtRQUNWLENBQUMsQ0FBQyxDQUFBO0lBQ04sQ0FBQyxDQUFDLENBQUE7QUFDTixDQUFDLENBQUMsQ0FBQSJ9
|
|
123
test/test.ts
123
test/test.ts
@ -1,43 +1,90 @@
|
|||||||
import 'typings-test'
|
import { expect, tap } from 'tapbundle'
|
||||||
import * as should from 'should'
|
import * as cflare from 'cflare'
|
||||||
|
import * as qenv from 'qenv'
|
||||||
|
|
||||||
|
let testQenv = new qenv.Qenv(process.cwd(), process.cwd() + '/.nogit')
|
||||||
|
|
||||||
// import the module to test
|
// import the module to test
|
||||||
import * as smartacme from '../dist/index'
|
import * as smartacme from '../dist/index'
|
||||||
|
|
||||||
describe('smartacme', function () {
|
let myCflareAccount = new cflare.CflareAccount()
|
||||||
let testAcme: smartacme.SmartAcme
|
myCflareAccount.auth({
|
||||||
|
email: process.env.CF_EMAIL,
|
||||||
it('should create a valid instance', function () {
|
key: process.env.CF_KEY
|
||||||
this.timeout(10000)
|
|
||||||
testAcme = new smartacme.SmartAcme()
|
|
||||||
should(testAcme).be.instanceOf(smartacme.SmartAcme)
|
|
||||||
})
|
|
||||||
|
|
||||||
it('should have created keyPair', function () {
|
|
||||||
should(testAcme.acmeUrl).be.of.type('string')
|
|
||||||
})
|
|
||||||
|
|
||||||
it('should register a new account', function (done) {
|
|
||||||
this.timeout(10000)
|
|
||||||
testAcme.createAccount().then(x => {
|
|
||||||
done()
|
|
||||||
}).catch(err => {
|
|
||||||
console.log(err)
|
|
||||||
done(err)
|
|
||||||
})
|
|
||||||
})
|
|
||||||
|
|
||||||
it('should agree to ToS', function(done) {
|
|
||||||
this.timeout(10000)
|
|
||||||
testAcme.agreeTos().then(() => {
|
|
||||||
done()
|
|
||||||
})
|
|
||||||
})
|
|
||||||
|
|
||||||
it('should request a challenge for a domain', function(done) {
|
|
||||||
this.timeout(10000)
|
|
||||||
testAcme.requestChallenge('bleu.de').then(() => {
|
|
||||||
done()
|
|
||||||
})
|
|
||||||
})
|
|
||||||
})
|
})
|
||||||
|
|
||||||
|
let testSmartAcme: smartacme.SmartAcme
|
||||||
|
let testAcmeAccount: smartacme.AcmeAccount
|
||||||
|
let testAcmeCert: smartacme.AcmeCert
|
||||||
|
let testChallenge: smartacme.ISmartAcmeChallengeChosen
|
||||||
|
|
||||||
|
tap.test('smartacme -> should create a valid instance', async (tools) => {
|
||||||
|
tools.timeout(10000)
|
||||||
|
testSmartAcme = new smartacme.SmartAcme(false)
|
||||||
|
await testSmartAcme.init().then(async () => {
|
||||||
|
expect(testSmartAcme).to.be.instanceOf(smartacme.SmartAcme)
|
||||||
|
})
|
||||||
|
})
|
||||||
|
|
||||||
|
tap.test('smartacme -> should have created keyPair', async () => {
|
||||||
|
expect(testSmartAcme.acmeUrl).to.be.a('string')
|
||||||
|
})
|
||||||
|
|
||||||
|
tap.test('smartacme -> should register a new account', async (tools) => {
|
||||||
|
tools.timeout(10000)
|
||||||
|
await testSmartAcme.createAcmeAccount().then(async x => {
|
||||||
|
testAcmeAccount = x
|
||||||
|
})
|
||||||
|
})
|
||||||
|
|
||||||
|
tap.test('smartacme -> should create a AcmeCert', async () => {
|
||||||
|
await testAcmeAccount.createAcmeCert('test2.bleu.de').then(async x => {
|
||||||
|
testAcmeCert = x
|
||||||
|
expect(testAcmeAccount).to.be.instanceOf(smartacme.AcmeCert)
|
||||||
|
})
|
||||||
|
})
|
||||||
|
|
||||||
|
tap.test('smartacme -> should get a challenge for a AcmeCert', async (tools) => {
|
||||||
|
tools.timeout(10000)
|
||||||
|
await testAcmeCert.requestChallenge().then(async (challengeChosen) => {
|
||||||
|
console.log(challengeChosen)
|
||||||
|
testChallenge = challengeChosen
|
||||||
|
})
|
||||||
|
})
|
||||||
|
|
||||||
|
tap.test('smartacme -> should set the challenge', async (tools) => {
|
||||||
|
tools.timeout(20000)
|
||||||
|
await myCflareAccount.createRecord(
|
||||||
|
testChallenge.domainNamePrefixed,
|
||||||
|
'TXT', testChallenge.dnsKeyHash
|
||||||
|
)
|
||||||
|
})
|
||||||
|
|
||||||
|
tap.test('smartacme -> should check for a DNS record', async (tools) => {
|
||||||
|
tools.timeout(20000)
|
||||||
|
await testAcmeCert.checkDns().then(x => {
|
||||||
|
console.log(x)
|
||||||
|
})
|
||||||
|
})
|
||||||
|
|
||||||
|
tap.test('smartacme -> should accept the challenge', async (tools) => {
|
||||||
|
tools.timeout(10000)
|
||||||
|
await testAcmeCert.acceptChallenge()
|
||||||
|
})
|
||||||
|
|
||||||
|
tap.test('smartacme -> should poll for validation of a challenge', async (tools) => {
|
||||||
|
tools.timeout(10000)
|
||||||
|
await testAcmeCert.requestValidation().then(async x => {
|
||||||
|
console.log(x)
|
||||||
|
})
|
||||||
|
})
|
||||||
|
|
||||||
|
tap.test('smartacme -> should remove the challenge', async (tools) => {
|
||||||
|
tools.timeout(20000)
|
||||||
|
await myCflareAccount.removeRecord(
|
||||||
|
testChallenge.domainNamePrefixed,
|
||||||
|
'TXT'
|
||||||
|
)
|
||||||
|
})
|
||||||
|
|
||||||
|
tap.start()
|
||||||
|
@ -1,5 +1,94 @@
|
|||||||
import 'typings-global'
|
import * as q from 'smartq'
|
||||||
|
|
||||||
|
import * as plugins from './smartacme.plugins'
|
||||||
|
import * as helpers from './smartacme.helpers'
|
||||||
|
|
||||||
|
import { SmartAcme, IRsaKeypair } from './smartacme.classes.smartacme'
|
||||||
|
import { AcmeCert } from './smartacme.classes.acmecert'
|
||||||
|
|
||||||
|
/**
|
||||||
|
* class AcmeAccount represents an AcmeAccount
|
||||||
|
*/
|
||||||
export class AcmeAccount {
|
export class AcmeAccount {
|
||||||
|
parentSmartAcme: SmartAcme
|
||||||
|
location: string
|
||||||
|
link: string
|
||||||
|
JWK
|
||||||
|
constructor(smartAcmeParentArg: SmartAcme) {
|
||||||
|
this.parentSmartAcme = smartAcmeParentArg
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* register the account with letsencrypt
|
||||||
|
*/
|
||||||
|
register() {
|
||||||
|
let done = q.defer()
|
||||||
|
this.parentSmartAcme.rawacmeClient.newReg(
|
||||||
|
{
|
||||||
|
contact: [ 'mailto:domains@lossless.org' ]
|
||||||
|
},
|
||||||
|
(err, res) => {
|
||||||
|
if (err) {
|
||||||
|
console.error('smartacme: something went wrong:')
|
||||||
|
console.log(err)
|
||||||
|
done.reject(err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
this.JWK = res.body.key
|
||||||
|
this.link = res.headers.link
|
||||||
|
console.log(this.link)
|
||||||
|
this.location = res.headers.location
|
||||||
|
done.resolve()
|
||||||
|
})
|
||||||
|
return done.promise
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* agree to letsencrypr terms of service
|
||||||
|
*/
|
||||||
|
agreeTos() {
|
||||||
|
let done = q.defer()
|
||||||
|
let tosPart = this.link.split(',')[ 1 ]
|
||||||
|
let tosLinkPortion = tosPart.split(';')[ 0 ]
|
||||||
|
let url = tosLinkPortion.split(';')[ 0 ].trim().replace(/[<>]/g, '')
|
||||||
|
this.parentSmartAcme.rawacmeClient.post(this.location, { Agreement: url, resource: 'reg' }, (err, res) => {
|
||||||
|
if (err) {
|
||||||
|
console.log(err)
|
||||||
|
done.reject(err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
done.resolve()
|
||||||
|
})
|
||||||
|
return done.promise
|
||||||
|
}
|
||||||
|
|
||||||
|
createAcmeCert(
|
||||||
|
domainNameArg: string,
|
||||||
|
countryArg = 'Germany',
|
||||||
|
countryShortArg = 'DE',
|
||||||
|
city = 'Bremen',
|
||||||
|
companyArg = 'Some Company',
|
||||||
|
companyShortArg = 'SC'
|
||||||
|
|
||||||
|
) {
|
||||||
|
let done = q.defer<AcmeCert>()
|
||||||
|
let acmeCert = new AcmeCert(
|
||||||
|
{
|
||||||
|
bit: 2064,
|
||||||
|
key: null, // not needed right now
|
||||||
|
domain: domainNameArg,
|
||||||
|
country: countryArg,
|
||||||
|
country_short: countryShortArg,
|
||||||
|
locality: city,
|
||||||
|
organization: companyArg,
|
||||||
|
organization_short: companyShortArg,
|
||||||
|
password: null,
|
||||||
|
unstructured: null,
|
||||||
|
subject_alt_names: null
|
||||||
|
},
|
||||||
|
this
|
||||||
|
)
|
||||||
|
done.resolve(acmeCert)
|
||||||
|
return done.promise
|
||||||
|
}
|
||||||
}
|
}
|
@ -1,5 +1,255 @@
|
|||||||
import 'typings-global'
|
import * as q from 'smartq'
|
||||||
|
|
||||||
export class AcmeCert {
|
import * as plugins from './smartacme.plugins'
|
||||||
|
import * as helpers from './smartacme.helpers'
|
||||||
|
|
||||||
|
import { SmartAcme, IRsaKeypair } from './smartacme.classes.smartacme'
|
||||||
|
import { AcmeAccount } from './smartacme.classes.acmeaccount'
|
||||||
|
|
||||||
|
/**
|
||||||
|
* types of challenges supported by letsencrypt and this module
|
||||||
|
*/
|
||||||
|
export type TChallengeType = 'dns-01' | 'http-01'
|
||||||
|
|
||||||
|
/**
|
||||||
|
* values that a challenge's status can have
|
||||||
|
*/
|
||||||
|
export type TChallengeStatus = 'pending'
|
||||||
|
|
||||||
|
export interface ISmartAcmeChallenge {
|
||||||
|
uri: string
|
||||||
|
status: TChallengeStatus
|
||||||
|
type: TChallengeType
|
||||||
|
token: string
|
||||||
|
keyAuthorization: string
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface ISmartAcmeChallengeChosen extends ISmartAcmeChallenge {
|
||||||
|
dnsKeyHash: string
|
||||||
|
domainName: string
|
||||||
|
domainNamePrefixed: string
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface IAcmeCsrConstructorOptions {
|
||||||
|
bit: number,
|
||||||
|
key: string,
|
||||||
|
domain: string,
|
||||||
|
country: string,
|
||||||
|
country_short: string,
|
||||||
|
locality: string,
|
||||||
|
organization: string,
|
||||||
|
organization_short: string,
|
||||||
|
password: string,
|
||||||
|
unstructured: string,
|
||||||
|
subject_alt_names: string[]
|
||||||
|
}
|
||||||
|
|
||||||
|
// Dnsly instance (we really just need one)
|
||||||
|
let myDnsly = new plugins.dnsly.Dnsly('google')
|
||||||
|
|
||||||
|
/**
|
||||||
|
* class AcmeCert represents a cert for domain
|
||||||
|
*/
|
||||||
|
export class AcmeCert {
|
||||||
|
domainName: string
|
||||||
|
attributes
|
||||||
|
fullchain: string
|
||||||
|
parentAcmeAccount: AcmeAccount
|
||||||
|
csr
|
||||||
|
validFrom: Date
|
||||||
|
validTo: Date
|
||||||
|
keypair: IRsaKeypair
|
||||||
|
keyPairFinal: IRsaKeypair
|
||||||
|
chosenChallenge: ISmartAcmeChallengeChosen
|
||||||
|
dnsKeyHash: string
|
||||||
|
constructor(optionsArg: IAcmeCsrConstructorOptions, parentAcmeAccount: AcmeAccount) {
|
||||||
|
this.domainName = optionsArg.domain
|
||||||
|
this.parentAcmeAccount = parentAcmeAccount
|
||||||
|
this.keypair = helpers.createKeypair(optionsArg.bit)
|
||||||
|
let privateKeyForged = plugins.nodeForge.pki.privateKeyFromPem(this.keypair.privateKey)
|
||||||
|
let publicKeyForged = plugins.nodeForge.pki.publicKeyToPem(
|
||||||
|
plugins.nodeForge.pki.setRsaPublicKey(privateKeyForged.n, privateKeyForged.e)
|
||||||
|
)
|
||||||
|
this.keyPairFinal = {
|
||||||
|
privateKey: privateKeyForged,
|
||||||
|
publicKey: publicKeyForged
|
||||||
|
}
|
||||||
|
|
||||||
|
// set dates
|
||||||
|
this.validFrom = new Date()
|
||||||
|
this.validTo = new Date()
|
||||||
|
this.validTo.setDate(this.validFrom.getDate() + 90)
|
||||||
|
|
||||||
|
// set attributes
|
||||||
|
this.attributes = [
|
||||||
|
{ name: 'commonName', value: optionsArg.domain },
|
||||||
|
{ name: 'countryName', value: optionsArg.country },
|
||||||
|
{ shortName: 'ST', value: optionsArg.country_short },
|
||||||
|
{ name: 'localityName', value: optionsArg.locality },
|
||||||
|
{ name: 'organizationName', value: optionsArg.organization },
|
||||||
|
{ shortName: 'OU', value: optionsArg.organization_short },
|
||||||
|
{ name: 'challengePassword', value: optionsArg.password },
|
||||||
|
{ name: 'unstructuredName', value: optionsArg.unstructured }
|
||||||
|
]
|
||||||
|
|
||||||
|
// set up csr
|
||||||
|
this.csr = plugins.nodeForge.pki.createCertificationRequest()
|
||||||
|
this.csr.setSubject(this.attributes)
|
||||||
|
this.csr.setAttributes(this.attributes)
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* requests a challenge for a domain
|
||||||
|
* @param domainNameArg - the domain name to request a challenge for
|
||||||
|
* @param challengeType - the challenge type to request
|
||||||
|
*/
|
||||||
|
requestChallenge(challengeTypeArg: TChallengeType = 'dns-01') {
|
||||||
|
let done = q.defer<ISmartAcmeChallengeChosen>()
|
||||||
|
this.parentAcmeAccount.parentSmartAcme.rawacmeClient.newAuthz(
|
||||||
|
{
|
||||||
|
identifier: {
|
||||||
|
type: 'dns',
|
||||||
|
value: this.domainName
|
||||||
|
}
|
||||||
|
},
|
||||||
|
this.parentAcmeAccount.parentSmartAcme.keyPair,
|
||||||
|
(err, res) => {
|
||||||
|
if (err) {
|
||||||
|
console.error('smartacme: something went wrong:')
|
||||||
|
console.log(err)
|
||||||
|
done.reject(err)
|
||||||
|
}
|
||||||
|
let preChosenChallenge = res.body.challenges.filter(x => {
|
||||||
|
return x.type === challengeTypeArg
|
||||||
|
})[ 0 ]
|
||||||
|
|
||||||
|
/**
|
||||||
|
* the key is needed to accept the challenge
|
||||||
|
*/
|
||||||
|
let authKey: string = plugins.rawacme.keyAuthz(
|
||||||
|
preChosenChallenge.token,
|
||||||
|
this.parentAcmeAccount.parentSmartAcme.keyPair.publicKey
|
||||||
|
)
|
||||||
|
|
||||||
|
/**
|
||||||
|
* needed in case selected challenge is of type dns-01
|
||||||
|
*/
|
||||||
|
this.dnsKeyHash = plugins.rawacme.dnsKeyAuthzHash(authKey) // needed if dns challenge is chosen
|
||||||
|
/**
|
||||||
|
* the return challenge
|
||||||
|
*/
|
||||||
|
this.chosenChallenge = {
|
||||||
|
uri: preChosenChallenge.uri,
|
||||||
|
type: preChosenChallenge.type,
|
||||||
|
token: preChosenChallenge.token,
|
||||||
|
keyAuthorization: authKey,
|
||||||
|
status: preChosenChallenge.status,
|
||||||
|
dnsKeyHash: this.dnsKeyHash,
|
||||||
|
domainName: this.domainName,
|
||||||
|
domainNamePrefixed: helpers.prefixName(this.domainName)
|
||||||
|
}
|
||||||
|
done.resolve(this.chosenChallenge)
|
||||||
|
}
|
||||||
|
)
|
||||||
|
return done.promise
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* checks if DNS records are set, will go through a max of 30 cycles
|
||||||
|
*/
|
||||||
|
async checkDns(cycleArg = 1) {
|
||||||
|
let result = await myDnsly.checkUntilAvailable(helpers.prefixName(this.domainName), 'TXT', this.dnsKeyHash)
|
||||||
|
if (result) {
|
||||||
|
console.log('DNS is set!')
|
||||||
|
return
|
||||||
|
} else {
|
||||||
|
throw new Error('DNS not set!')
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* validates a challenge, only call after you have set the challenge at the expected location
|
||||||
|
*/
|
||||||
|
async requestValidation() {
|
||||||
|
let makeRequest = () => {
|
||||||
|
let done = q.defer()
|
||||||
|
this.parentAcmeAccount.parentSmartAcme.rawacmeClient.poll(this.chosenChallenge.uri, async (err, res) => {
|
||||||
|
if (err) {
|
||||||
|
console.log(err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
console.log(`Validation response:`)
|
||||||
|
console.log(JSON.stringify(res.body))
|
||||||
|
if (res.body.status === 'pending' || res.body.status === 'invalid') {
|
||||||
|
await plugins.smartdelay.delayFor(3000)
|
||||||
|
makeRequest().then((x: any) => { done.resolve(x) })
|
||||||
|
} else {
|
||||||
|
console.log('perfect!')
|
||||||
|
done.resolve(res.body)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
return done.promise
|
||||||
|
}
|
||||||
|
await makeRequest()
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* requests a certificate
|
||||||
|
*/
|
||||||
|
requestCert() {
|
||||||
|
let done = q.defer()
|
||||||
|
let payload = {
|
||||||
|
csr: plugins.rawacme.base64.encode(
|
||||||
|
plugins.rawacme.toDer(
|
||||||
|
plugins.nodeForge.pki.certificationRequestToPem(
|
||||||
|
this.csr
|
||||||
|
)
|
||||||
|
)
|
||||||
|
),
|
||||||
|
notBefore: this.validFrom.toISOString(),
|
||||||
|
notAfter: this.validTo.toISOString()
|
||||||
|
}
|
||||||
|
this.parentAcmeAccount.parentSmartAcme.rawacmeClient.newCert(
|
||||||
|
payload,
|
||||||
|
helpers.createKeypair(),
|
||||||
|
(err, res) => {
|
||||||
|
if (err) {
|
||||||
|
console.log(err)
|
||||||
|
done.reject(err)
|
||||||
|
}
|
||||||
|
console.log(res.body)
|
||||||
|
done.resolve(res.body)
|
||||||
|
})
|
||||||
|
return done.promise
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* getCertificate - takes care of cooldown, validation polling and certificate retrieval
|
||||||
|
*/
|
||||||
|
getCertificate() {
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* accept a challenge - for private use only
|
||||||
|
*/
|
||||||
|
acceptChallenge() {
|
||||||
|
let done = q.defer()
|
||||||
|
this.parentAcmeAccount.parentSmartAcme.rawacmeClient.post(
|
||||||
|
this.chosenChallenge.uri,
|
||||||
|
{
|
||||||
|
resource: 'challenge',
|
||||||
|
keyAuthorization: this.chosenChallenge.keyAuthorization
|
||||||
|
},
|
||||||
|
this.parentAcmeAccount.parentSmartAcme.keyPair,
|
||||||
|
(err, res) => {
|
||||||
|
if (err) {
|
||||||
|
console.log(err)
|
||||||
|
done.reject(err)
|
||||||
|
}
|
||||||
|
done.resolve(res.body)
|
||||||
|
}
|
||||||
|
)
|
||||||
|
return done.promise
|
||||||
|
}
|
||||||
}
|
}
|
@ -1,53 +0,0 @@
|
|||||||
import 'typings-global'
|
|
||||||
import * as q from 'q'
|
|
||||||
let rsaKeygen = require('rsa-keygen')
|
|
||||||
|
|
||||||
import { SmartAcme } from './smartacme.classes.smartacme'
|
|
||||||
|
|
||||||
export interface IRsaKeypair {
|
|
||||||
publicKey: string
|
|
||||||
privateKey: string
|
|
||||||
}
|
|
||||||
|
|
||||||
export class SmartacmeHelper {
|
|
||||||
parentSmartAcme: SmartAcme
|
|
||||||
|
|
||||||
constructor(smartAcmeArg: SmartAcme) {
|
|
||||||
this.parentSmartAcme = smartAcmeArg
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* creates a keypair to use with requests and to generate JWK from
|
|
||||||
*/
|
|
||||||
createKeypair(bit = 2048): IRsaKeypair {
|
|
||||||
let result = rsaKeygen.generate(bit)
|
|
||||||
return {
|
|
||||||
publicKey: result.public_key,
|
|
||||||
privateKey: result.private_key
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* getReg
|
|
||||||
* @executes ASYNC
|
|
||||||
*/
|
|
||||||
getReg() {
|
|
||||||
let done = q.defer()
|
|
||||||
let body = { resource: 'reg' }
|
|
||||||
this.parentSmartAcme.rawacmeClient.post(
|
|
||||||
this.parentSmartAcme.location,
|
|
||||||
body, this.parentSmartAcme.keyPair,
|
|
||||||
(err, res) => {
|
|
||||||
if (err) {
|
|
||||||
console.error('smartacme: something went wrong:')
|
|
||||||
console.log(err)
|
|
||||||
done.reject(err)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
console.log(JSON.stringify(res.body))
|
|
||||||
done.resolve()
|
|
||||||
}
|
|
||||||
)
|
|
||||||
return done.promise
|
|
||||||
}
|
|
||||||
}
|
|
@ -1,178 +1,82 @@
|
|||||||
import 'typings-global'
|
// third party modules
|
||||||
import * as q from 'q'
|
import * as q from 'smartq' // promises
|
||||||
import * as path from 'path'
|
import * as plugins from './smartacme.plugins'
|
||||||
let rsaKeygen = require('rsa-keygen')
|
import * as helpers from './smartacme.helpers'
|
||||||
import * as smartfile from 'smartfile'
|
|
||||||
import * as smartstring from 'smartstring'
|
|
||||||
let rawacme = require('rawacme')
|
|
||||||
import * as paths from './smartacme.paths'
|
|
||||||
|
|
||||||
import { SmartacmeHelper, IRsaKeypair } from './smartacme.classes.helper'
|
import { AcmeAccount } from './smartacme.classes.acmeaccount'
|
||||||
|
|
||||||
export type TChallenge = 'dns-01' | 'http-01'
|
/**
|
||||||
|
* a rsa keypair needed for account creation and subsequent requests
|
||||||
|
*/
|
||||||
|
export interface IRsaKeypair {
|
||||||
|
publicKey: string
|
||||||
|
privateKey: string
|
||||||
|
}
|
||||||
|
|
||||||
|
export { AcmeAccount } from './smartacme.classes.acmeaccount'
|
||||||
|
export { AcmeCert, ISmartAcmeChallenge, ISmartAcmeChallengeChosen } from './smartacme.classes.acmecert'
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* class SmartAcme exports methods for maintaining SSL Certificates
|
* class SmartAcme exports methods for maintaining SSL Certificates
|
||||||
*/
|
*/
|
||||||
export class SmartAcme {
|
export class SmartAcme {
|
||||||
helper: SmartacmeHelper // bundles helper methods that would clutter the main SmartAcme class
|
acmeUrl: string // the acme url to use for this instance
|
||||||
acmeUrl: string // the acme url to use
|
productionBool: boolean // a boolean to quickly know wether we are in production or not
|
||||||
productionBool: boolean // a boolean to quickly know wether we are in production or not
|
keyPair: IRsaKeypair // the keyPair needed for account creation
|
||||||
keyPair: IRsaKeypair // the keyPair needed for account creation
|
rawacmeClient
|
||||||
location: string
|
|
||||||
link: string
|
|
||||||
rawacmeClient
|
|
||||||
JWK
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* the constructor for class SmartAcme
|
* the constructor for class SmartAcme
|
||||||
*/
|
*/
|
||||||
constructor(productionArg: boolean = false) {
|
constructor(productionArg: boolean = false) {
|
||||||
this.productionBool = productionArg
|
this.productionBool = productionArg
|
||||||
this.helper = new SmartacmeHelper(this)
|
this.keyPair = helpers.createKeypair()
|
||||||
this.keyPair = this.helper.createKeypair()
|
if (this.productionBool) {
|
||||||
if (this.productionBool) {
|
this.acmeUrl = plugins.rawacme.LETSENCRYPT_URL
|
||||||
this.acmeUrl = rawacme.LETSENCRYPT_URL
|
} else {
|
||||||
} else {
|
this.acmeUrl = plugins.rawacme.LETSENCRYPT_STAGING_URL
|
||||||
this.acmeUrl = rawacme.LETSENCRYPT_STAGING_URL
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* init the smartacme instance
|
||||||
|
*/
|
||||||
|
init() {
|
||||||
|
let done = q.defer()
|
||||||
|
plugins.rawacme.createClient(
|
||||||
|
{
|
||||||
|
url: this.acmeUrl,
|
||||||
|
publicKey: this.keyPair.publicKey,
|
||||||
|
privateKey: this.keyPair.privateKey
|
||||||
|
},
|
||||||
|
(err, client) => {
|
||||||
|
if (err) {
|
||||||
|
console.error('smartacme: something went wrong:')
|
||||||
|
console.log(err)
|
||||||
|
done.reject(err)
|
||||||
|
return
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* creates an account if not currently present in module
|
|
||||||
* @executes ASYNC
|
|
||||||
*/
|
|
||||||
createAccount() {
|
|
||||||
let done = q.defer()
|
|
||||||
rawacme.createClient(
|
|
||||||
{
|
|
||||||
url: this.acmeUrl,
|
|
||||||
publicKey: this.keyPair.publicKey,
|
|
||||||
privateKey: this.keyPair.privateKey
|
|
||||||
},
|
|
||||||
(err, client) => {
|
|
||||||
if (err) {
|
|
||||||
console.error('smartacme: something went wrong:')
|
|
||||||
console.log(err)
|
|
||||||
done.reject(err)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
// make client available in class
|
|
||||||
this.rawacmeClient = client
|
|
||||||
|
|
||||||
// create the registration
|
|
||||||
client.newReg(
|
|
||||||
{
|
|
||||||
contact: ['mailto:domains@lossless.org']
|
|
||||||
},
|
|
||||||
(err, res) => {
|
|
||||||
if (err) {
|
|
||||||
console.error('smartacme: something went wrong:')
|
|
||||||
console.log(err)
|
|
||||||
done.reject(err)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
this.JWK = res.body.key
|
|
||||||
this.link = res.headers.link
|
|
||||||
console.log(this.link)
|
|
||||||
this.location = res.headers.location
|
|
||||||
done.resolve()
|
|
||||||
})
|
|
||||||
|
|
||||||
}
|
|
||||||
)
|
|
||||||
return done.promise
|
|
||||||
}
|
|
||||||
|
|
||||||
agreeTos() {
|
|
||||||
let done = q.defer()
|
|
||||||
let tosPart = this.link.split(',')[1]
|
|
||||||
let tosLinkPortion = tosPart.split(';')[0]
|
|
||||||
let url = tosLinkPortion.split(';')[0].trim().replace(/[<>]/g, '')
|
|
||||||
this.rawacmeClient.post(this.location, { Agreement: url, resource: 'reg' }, (err, res) => {
|
|
||||||
if (err) {
|
|
||||||
console.log(err)
|
|
||||||
done.reject(err)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
done.resolve()
|
|
||||||
})
|
|
||||||
return done.promise
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* requests a challenge for a domain
|
|
||||||
* @param domainNameArg - the domain name to request a challenge for
|
|
||||||
* @param challengeType - the challenge type to request
|
|
||||||
*/
|
|
||||||
requestChallenge(domainNameArg: string, challengeTypeArg: TChallenge = 'dns-01') {
|
|
||||||
let done = q.defer()
|
|
||||||
this.rawacmeClient.newAuthz(
|
|
||||||
{
|
|
||||||
identifier: {
|
|
||||||
type: 'dns',
|
|
||||||
value: domainNameArg
|
|
||||||
}
|
|
||||||
},
|
|
||||||
this.keyPair,
|
|
||||||
(err, res) => {
|
|
||||||
if (err) {
|
|
||||||
console.error('smartacme: something went wrong:')
|
|
||||||
console.log(err)
|
|
||||||
done.reject(err)
|
|
||||||
}
|
|
||||||
console.log(JSON.stringify(res.body))
|
|
||||||
let dnsChallenge = res.body.challenges.filter(x => {
|
|
||||||
return x.type === challengeTypeArg
|
|
||||||
})[0]
|
|
||||||
this.acceptChallenge(dnsChallenge)
|
|
||||||
.then(x => {
|
|
||||||
done.resolve(x)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
)
|
|
||||||
return done.promise
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* getCertificate - takes care of cooldown, validation polling and certificate retrieval
|
|
||||||
*/
|
|
||||||
getCertificate() {
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* accept a challenge - for private use only
|
|
||||||
*/
|
|
||||||
private acceptChallenge(challenge) {
|
|
||||||
let done = q.defer()
|
|
||||||
|
|
||||||
let authKey: string = rawacme.keyAuthz(challenge.token, this.keyPair.publicKey)
|
|
||||||
let dnsKeyHash: string = rawacme.dnsKeyAuthzHash(authKey) // needed if dns challenge is chosen
|
|
||||||
|
|
||||||
console.log(authKey)
|
|
||||||
|
|
||||||
this.rawacmeClient.post(
|
|
||||||
challenge.uri,
|
|
||||||
{
|
|
||||||
resource: 'challenge',
|
|
||||||
keyAuthorization: authKey
|
|
||||||
},
|
|
||||||
this.keyPair,
|
|
||||||
(err, res) => {
|
|
||||||
if (err) {
|
|
||||||
console.log(err)
|
|
||||||
done.reject(err)
|
|
||||||
}
|
|
||||||
console.log('acceptChallenge:')
|
|
||||||
console.log(JSON.stringify(res.body))
|
|
||||||
done.resolve(dnsKeyHash)
|
|
||||||
}
|
|
||||||
)
|
|
||||||
return done.promise
|
|
||||||
}
|
|
||||||
|
|
||||||
|
// make client available in class
|
||||||
|
this.rawacmeClient = client
|
||||||
|
done.resolve()
|
||||||
|
}
|
||||||
|
)
|
||||||
|
return done.promise
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* creates an account if not currently present in module
|
||||||
|
* @executes ASYNC
|
||||||
|
*/
|
||||||
|
createAcmeAccount() {
|
||||||
|
let done = q.defer<AcmeAccount>()
|
||||||
|
let acmeAccount = new AcmeAccount(this)
|
||||||
|
acmeAccount.register().then(() => {
|
||||||
|
return acmeAccount.agreeTos()
|
||||||
|
}).then(() => {
|
||||||
|
done.resolve(acmeAccount)
|
||||||
|
})
|
||||||
|
return done.promise
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
50
ts/smartacme.helpers.ts
Normal file
50
ts/smartacme.helpers.ts
Normal file
@ -0,0 +1,50 @@
|
|||||||
|
import 'typings-global'
|
||||||
|
import * as q from 'smartq'
|
||||||
|
|
||||||
|
import * as plugins from './smartacme.plugins'
|
||||||
|
|
||||||
|
import { SmartAcme, IRsaKeypair } from './smartacme.classes.smartacme'
|
||||||
|
import { AcmeAccount } from './smartacme.classes.acmeaccount'
|
||||||
|
|
||||||
|
/**
|
||||||
|
* creates a keypair to use with requests and to generate JWK from
|
||||||
|
*/
|
||||||
|
export let createKeypair = (bit = 2048): IRsaKeypair => {
|
||||||
|
let result = plugins.rsaKeygen.generate(bit)
|
||||||
|
return {
|
||||||
|
publicKey: result.public_key,
|
||||||
|
privateKey: result.private_key
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* prefix a domain name to make sure it complies with letsencrypt
|
||||||
|
*/
|
||||||
|
export let prefixName = (domainNameArg: string): string => {
|
||||||
|
return '_acme-challenge.' + domainNameArg
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* gets an existing registration
|
||||||
|
* @executes ASYNC
|
||||||
|
*/
|
||||||
|
let getReg = (SmartAcmeArg: SmartAcme, location: string) => {
|
||||||
|
let done = q.defer()
|
||||||
|
let body = { resource: 'reg' }
|
||||||
|
SmartAcmeArg.rawacmeClient.post(
|
||||||
|
location,
|
||||||
|
body,
|
||||||
|
SmartAcmeArg.keyPair,
|
||||||
|
(err, res) => {
|
||||||
|
if (err) {
|
||||||
|
console.error('smartacme: something went wrong:')
|
||||||
|
console.log(err)
|
||||||
|
done.reject(err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
console.log(JSON.stringify(res.body))
|
||||||
|
done.resolve()
|
||||||
|
}
|
||||||
|
)
|
||||||
|
return done.promise
|
||||||
|
}
|
22
ts/smartacme.plugins.ts
Normal file
22
ts/smartacme.plugins.ts
Normal file
@ -0,0 +1,22 @@
|
|||||||
|
import 'typings-global' // typings for node
|
||||||
|
|
||||||
|
import * as path from 'path' // native node path module
|
||||||
|
let rsaKeygen = require('rsa-keygen') // rsa keygen
|
||||||
|
let rawacme = require('rawacme') // acme helper functions
|
||||||
|
let nodeForge = require('node-forge')
|
||||||
|
|
||||||
|
// push.rocks modules here
|
||||||
|
import * as dnsly from 'dnsly'
|
||||||
|
import * as smartdelay from 'smartdelay'
|
||||||
|
import * as smartfile from 'smartfile'
|
||||||
|
import * as smartstring from 'smartstring'
|
||||||
|
|
||||||
|
export {
|
||||||
|
dnsly,
|
||||||
|
rsaKeygen,
|
||||||
|
rawacme,
|
||||||
|
nodeForge,
|
||||||
|
smartdelay,
|
||||||
|
smartfile,
|
||||||
|
smartstring
|
||||||
|
}
|
Reference in New Issue
Block a user