summaryrefslogtreecommitdiff
path: root/caddyconfig/httpcaddyfile
diff options
context:
space:
mode:
authorMatthew Holt <mholt@users.noreply.github.com>2021-02-02 17:23:52 -0700
committerMatthew Holt <mholt@users.noreply.github.com>2021-02-02 17:23:52 -0700
commitbf50d7010a26468791f4397c0f0c4f9a8ed1d6a2 (patch)
tree6956ee718cea0976e2fe23e5867010655cb2df0f /caddyconfig/httpcaddyfile
parent8ec90f1c402b5e1aa1eea59e45f700aeb45da6ba (diff)
acmeserver: Support custom CAs from Caddyfile
The HTTP Caddyfile adapter can now configure the PKI app, and the acme_server directive can now be used to specify a custom CA used for issuing certificates. More customization options can follow later as needed.
Diffstat (limited to 'caddyconfig/httpcaddyfile')
-rw-r--r--caddyconfig/httpcaddyfile/httptype.go10
-rw-r--r--caddyconfig/httpcaddyfile/pkiapp.go41
2 files changed, 51 insertions, 0 deletions
diff --git a/caddyconfig/httpcaddyfile/httptype.go b/caddyconfig/httpcaddyfile/httptype.go
index 0a5149f..a32acab 100644
--- a/caddyconfig/httpcaddyfile/httptype.go
+++ b/caddyconfig/httpcaddyfile/httptype.go
@@ -28,6 +28,7 @@ import (
"github.com/caddyserver/caddy/v2/caddyconfig"
"github.com/caddyserver/caddy/v2/caddyconfig/caddyfile"
"github.com/caddyserver/caddy/v2/modules/caddyhttp"
+ "github.com/caddyserver/caddy/v2/modules/caddypki"
"github.com/caddyserver/caddy/v2/modules/caddytls"
)
@@ -219,6 +220,12 @@ func (st ServerType) Setup(inputServerBlocks []caddyfile.ServerBlock,
return nil, warnings, err
}
+ // then make the PKI app
+ pkiApp, warnings, err := st.buildPKIApp(pairings, options, warnings)
+ if err != nil {
+ return nil, warnings, err
+ }
+
// extract any custom logs, and enforce configured levels
var customLogs []namedCustomLog
var hasDefaultLog bool
@@ -259,6 +266,9 @@ func (st ServerType) Setup(inputServerBlocks []caddyfile.ServerBlock,
if !reflect.DeepEqual(tlsApp, &caddytls.TLS{CertificatesRaw: make(caddy.ModuleMap)}) {
cfg.AppsRaw["tls"] = caddyconfig.JSON(tlsApp, &warnings)
}
+ if !reflect.DeepEqual(pkiApp, &caddypki.PKI{CAs: make(map[string]*caddypki.CA)}) {
+ cfg.AppsRaw["pki"] = caddyconfig.JSON(pkiApp, &warnings)
+ }
if storageCvtr, ok := options["storage"].(caddy.StorageConverter); ok {
cfg.StorageRaw = caddyconfig.JSONModuleObject(storageCvtr,
"module",
diff --git a/caddyconfig/httpcaddyfile/pkiapp.go b/caddyconfig/httpcaddyfile/pkiapp.go
new file mode 100644
index 0000000..3abcc6b
--- /dev/null
+++ b/caddyconfig/httpcaddyfile/pkiapp.go
@@ -0,0 +1,41 @@
+// Copyright 2015 Matthew Holt and The Caddy Authors
+//
+// Licensed under the Apache License, Version 2.0 (the "License");
+// you may not use this file except in compliance with the License.
+// You may obtain a copy of the License at
+//
+// http://www.apache.org/licenses/LICENSE-2.0
+//
+// Unless required by applicable law or agreed to in writing, software
+// distributed under the License is distributed on an "AS IS" BASIS,
+// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+// See the License for the specific language governing permissions and
+// limitations under the License.
+
+package httpcaddyfile
+
+import (
+ "github.com/caddyserver/caddy/v2/caddyconfig"
+ "github.com/caddyserver/caddy/v2/modules/caddypki"
+)
+
+func (st ServerType) buildPKIApp(
+ pairings []sbAddrAssociation,
+ options map[string]interface{},
+ warnings []caddyconfig.Warning,
+) (*caddypki.PKI, []caddyconfig.Warning, error) {
+
+ pkiApp := &caddypki.PKI{CAs: make(map[string]*caddypki.CA)}
+
+ for _, p := range pairings {
+ for _, sblock := range p.serverBlocks {
+ // find all the CAs that were defined and add them to the app config
+ for _, caCfgValue := range sblock.pile["pki.ca"] {
+ ca := caCfgValue.Value.(*caddypki.CA)
+ pkiApp.CAs[ca.ID] = ca
+ }
+ }
+ }
+
+ return pkiApp, warnings, nil
+}