2016-04-10 13:56:13 +00:00
|
|
|
# Cert
|
2016-06-18 12:59:46 +00:00
|
|
|
Easily obain SSL certificates from LetsEncrypt. Supports DNS-01 challenge. TypeScript ready.
|
|
|
|
|
2016-07-21 13:02:51 +00:00
|
|
|
## Status
|
|
|
|
[![build status](https://gitlab.com/pushrocks/cert/badges/master/build.svg)](https://gitlab.com/pushrocks/cert/commits/master)
|
|
|
|
|
2016-06-18 12:59:46 +00:00
|
|
|
## Usage
|
|
|
|
|
|
|
|
```typescript
|
|
|
|
import {Cert} from "cert";
|
|
|
|
|
2016-06-18 13:42:09 +00:00
|
|
|
let myCert = new Cert({
|
2016-06-18 14:03:46 +00:00
|
|
|
cfEmail: "some@cloudflare.email",
|
|
|
|
cfKey: "someCloudflareApiKey",
|
|
|
|
sslDir: "someOutputPath", // NOTE: if you already have certificates, make sure you put them in here, so cert only requires the missing ones
|
2016-06-18 14:14:57 +00:00
|
|
|
gitOriginRepo: "git@githhub.com/someuser/somereopo" // good for persistence in highly volatile environments like docker
|
2016-06-18 12:59:46 +00:00
|
|
|
});
|
|
|
|
|
2016-07-22 00:12:49 +00:00
|
|
|
myCert.getDomainCert("example.com"); // returns promise
|
2016-06-18 13:59:03 +00:00
|
|
|
```
|
|
|
|
|
2016-07-22 00:12:49 +00:00
|
|
|
> **Note:** cert supports async parallel cert fetching. If called twice for the same domain, only the first one will trigger.
|
|
|
|
|
2016-07-21 12:58:05 +00:00
|
|
|
## sslDir
|
2016-06-18 14:14:57 +00:00
|
|
|
to use the certificates it is important to understand what the structure of the ssl directory looks like.
|
|
|
|
|
2016-07-21 12:58:05 +00:00
|
|
|
## using a git origin repo.
|
2016-06-18 14:14:57 +00:00
|
|
|
Often times you want to keep track of certificates in order to keep them
|
|
|
|
even if the point of initial certificate request is gone. Imagine you have a dockerenvironement
|
|
|
|
and you keep starting new container versions for the same domain. YOu ideally want to use a proxy
|
|
|
|
that handles SSL managemet for you. But even the proxy needs to be updated from time to time.
|
|
|
|
|
|
|
|
So you need some kind of persistence between versions. This is why you can sync up all certificates to a git repo over ssh
|
2016-07-21 12:58:05 +00:00
|
|
|
Just make sure your id_rsa is in place for the node user and is allowed for the origin repo.
|
|
|
|
|
|
|
|
## Environment
|
|
|
|
Since cert relies on [letsencrypt.sh](https://github.com/lukas2511/letsencrypt.sh) in the background bash is needed on the system.
|
|
|
|
If you plan on using this on Windows check out [npmdocker](https://www.npmjs.com/package/npmdocker) which runs node programs in docker.
|
|
|
|
As of summer 2016 Windows will also ship with bash nativly included.
|