6842 Commits

Author SHA1 Message Date
neil
fa763db105 dns_pleskxml.sh: use grep -F when matching interpolated values
fulldomain/txtvalue/root_domain_name were interpolated into grep
regex patterns; match them as fixed strings instead.

from https://github.com/acmesh-official/acme.sh/pull/7031
2026-07-10 12:05:28 +08:00
neil
90b4795bb1 issue: strip the trailing dot of a fully-qualified alias domain
A trailing dot in --domain-alias/--challenge-alias was passed through
to the dnsapi hook verbatim. Providers with exact-match record-name
lookups (e.g. Cloudflare's name= filter) then never find the record,
so rm never deletes it and relic TXT records accumulate on every issue.
Stripping in issue() also fixes certs with a dotted alias already
saved in domain.conf.

fix https://github.com/acmesh-official/acme.sh/issues/4636
2026-07-10 11:22:20 +08:00
neil
534a1714dc dns_me.sh: use LC_ALL=C so the request date header is always English
LC_ALL in the environment overrides both LC_TIME and LANG, so LANG=C
alone still produced localized day/month names on non-English systems
and DNS Made Easy rejected the request date header. An LC_ALL=C
command prefix beats every locale variable (same pattern as
dns_oci.sh).

Fixes #4272. Closes #4271. Thanks to @Nickinthebox.
2026-07-10 11:20:08 +08:00
neil
45c0ad4112 Add _cleardeployconf to clear deploy hook keys from domain conf
Mirrors _clearaccountconf_mutable: clears the SAVED_ prefixed key and
the legacy unprefixed key. Replaces the local copy in synology_dsm.sh
and the direct _cleardomainconf call in multideploy.sh.

Closes #4722. Thanks to @sg1888.
2026-07-10 11:05:40 +08:00
neil
83b52e0cd7 notify/smtp.sh: add --crlf so curl sends CRLF line endings
Postfix with smtpd_forbid_bare_newline (default hardening since 3.9,
after SMTP smuggling) rejects the message with
"521 5.5.2 Error: bare <LF> received". RFC 5321 requires CRLF.
The python sender is unaffected (smtplib already emits CRLF).

fix https://github.com/acmesh-official/acme.sh/issues/7104
2026-07-10 10:38:52 +08:00
neil
bed15ba844 dns_freedns.sh: use grep -E, BRE \| alternation is a GNU extension
OpenBSD grep treats \| in a BRE as a literal | character, so
_freedns_domain_id never matched any row and every domain lookup
failed with "Domain not found". Switch to ERE with -E, keeping the
parens escaped so the (.*) suffix branch still requires literal
parentheses and does not widen the match (e.g. searching example.com
must not match example.company).

Reported-by: @katiekloss @boretom
Ref: https://github.com/acmesh-official/acme.sh/issues/2305
2026-07-10 10:23:59 +08:00
invario
1324dcd472 Docker: update crontab used (#7111)
Signed-off-by: invario <67800603+invario@users.noreply.github.com>
2026-07-10 10:10:44 +08:00
lwohn-creo
cf3eab95ee Add creoline API as DNS provider (#7100)
* New Banner

Updated README to include responsive images for dark and light modes.

* acme-sh-creoline-as-dns-provider

* acme-sh-creoline-as-dns-provider - Review changes implemented according code review

* acme-sh-creoline-as-dns-provider - Review changes implemented according second code review, minding --cron

* acme-sh-creoline-as-dns-provider - Remove debug code

* acme-sh-creoline-as-dns-provider - shfmt formatting according Code of conduct

---------

Co-authored-by: neil <github@neilpang.com>
Co-authored-by: ZeroSSL-Andreas <andreas.schuster@hidglobal.com>
Co-authored-by: Steven Kauschke <s.kauschke@creoline.com>
2026-07-10 10:07:12 +08:00
neil
ca118be754 issue.yml: match tracking issue title variants 2026-07-10 10:02:59 +08:00
Marvo2011
b1b539695f Merge pull request #7026 from Marvo2011/dev
Update SelfHost DNS provider
2026-07-06 21:30:13 +08:00
neil
347cc207cd Merge pull request #7096 from acmesh-official/dev
one-click revert and ban
2026-07-06 17:40:51 +08:00
neil
cc64a73230 one-click revert and ban 2026-07-06 17:39:56 +08:00
neil
1651a5a609 Merge pull request #7095 from acmesh-official/dev
sync
2026-07-06 16:37:03 +08:00
neil
f2b37b32ff add more events 2026-07-06 16:36:16 +08:00
neil
73df21abc4 clean 2026-07-06 16:30:41 +08:00
neil
0c76c1f211 Merge pull request #7094 from acmesh-official/dev
wiki-guard: use WIKI_GUARD_TOKEN (PAT with read:org) to enumerate org…
2026-07-06 16:28:12 +08:00
neil
919492df13 wiki-guard: use WIKI_GUARD_TOKEN (PAT with read:org) to enumerate org write members 2026-07-06 16:27:26 +08:00
neil
e00d3cfde3 Merge pull request #7092 from acmesh-official/dev
wiki-guard: log the number of write-access members loaded
2026-07-06 15:24:23 +08:00
neil
e4eaa59063 wiki-guard: log the number of write-access members loaded 2026-07-06 15:23:45 +08:00
neil
4187ec23c1 Merge pull request #7091 from acmesh-official/dev
wiki-guard: trust repo/org members with write access in all rule checks
2026-07-06 15:12:22 +08:00
neil
2b5a19d34a wiki-guard: trust repo/org members with write access in all rule checks 2026-07-06 15:11:35 +08:00
neil
9f0ef7abcd Merge pull request #7090 from acmesh-official/dev
sync
2026-07-06 14:28:08 +08:00
neil
dc1b06006f issue.yml: assign and label "Report bugs to" tracking issues instead of posting the upgrade boilerplate 2026-07-06 14:27:00 +08:00
neil
8585d9f4a7 wiki-monitor: skip notification for the maintainer's own wiki changes 2026-07-06 14:23:51 +08:00
neil
0e2659b768 Merge pull request #7088 from acmesh-official/dev
add wiki-guard workflow: auto-restore wiki pages deleted or renamed b…
2026-07-06 13:37:00 +08:00
neil
ca8ab7f8b5 add wiki-guard workflow: auto-restore wiki pages deleted or renamed by non-maintainer 2026-07-06 13:35:37 +08:00
neil
f50401a342 Merge pull request #7086 from acmesh-official/dev
sync
2026-07-06 10:37:29 +08:00
Simon V.
ff9b969bdb Add support for Account Key Rollover (#7080)
* add wiki

* feat: add support for account key rollover

* Place --update-account-key next to --update-account

* fix shfmt

* fix shfmt

* fix shfmt

* Fix from review

* fix shfmt

* fix from review

* fix review

---------

Co-authored-by: neil <gitpc@neilpang.com>
2026-07-06 10:22:36 +08:00
Oliver Mueller
1f778e6ef1 deploy/ssh: return non-zero when a server deployment fails (#6795)
ssh_deploy() ignored the result of _ssh_deploy and always returned
success, so a failed transfer to one (or all) of the servers in
DEPLOY_SSH_SERVER was silently swallowed. Track the return code across
the loop and return non-zero if any server failed, letting the caller
handle notification.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-06 10:11:58 +08:00
PM Extra
58423df3e8 retry failed install and deploy on renew (#7083)
* retry failed install and deploy on renew

* fix notify level for renew retry failures
2026-07-05 23:33:57 +08:00
LaoDC
8f3c1701f3 Add LaoDC DNS API (dns_laodc) (#6974)
* Added LaoDC API Module

* Cleaned up debug and info
revised get subdomain to filter by TXT records.

* Added commet to _get_root

* Removed PATCH logic of updating acme records as this doesn't work for wildcard DNS.

Revised rm() function to do explicit record matching.

* Revised _get_root() to handle different scenarios.

Fixed _laodc_api() function to check if query failed to run.
added basic json sanitation to handle \ and " in $value
unset _H2 _H3 after call as per request from copilot.

* fixed indentation of case statement block

* fixed condition checking.

_get_root should start at 1 so full fqdn can be tested
$? was being reference after export command failing response checks
removed export txtvalue
fixed docs link and issues link

* Verify key for both add and rm

* fixed dns alias condition check
validate key returns 1 if failed.

---------

Co-authored-by: neil <github@neilpang.com>
Co-authored-by: LaoDC <git@laodc.com>
2026-07-05 23:30:26 +08:00
neil
2a175f97e8 toPkcs8: support --password and re-export the pkcs8 file on renewal (#4134) 2026-07-05 18:04:24 +08:00
neil
d3af3315da dnsapi/dns_edgedns: use the system clock for the request timestamp (#3973) 2026-07-05 18:02:34 +08:00
neil
7b6d96387c migrate the legacy ACMEDNS_UPDATE_URL from the account conf (#3899) 2026-07-05 17:48:33 +08:00
neil
cabe432539 add bash completion for commands and parameters, installed via --install (#307) 2026-07-05 17:39:50 +08:00
neil
1746fbdb25 support multiple account emails (#1309)
ACCOUNT_EMAIL / --email now accepts a comma- or space-separated list
and registers all of them as ACME contact entries. The ZeroSSL EAB
endpoint takes a single address, so the first one is used there.
2026-07-05 17:37:40 +08:00
neil
d2b3772631 deploy/panos: do not commit when the cert or key import failed (#4716)
Committing after a failed import leaves a mismatched cert/key pair on
the firewall (PAN-OS does not validate the pair at commit time), which
can lock the admin out of the https management interface.
2026-07-05 17:13:59 +08:00
neil
e964157bff _install_win_taskscheduler: zero-pad the minute in the schtasks /ST value (#4950) 2026-07-05 17:13:24 +08:00
neil
934711e51d notify/aws_ses: add container/instance IAM role auth (IMDSv2)
aws_ses_send calls `_use_container_role || _use_instance_role` when no
static AWS keys are set, but those functions were never defined -- only
_use_metadata was -- so role-based auth silently fell through to the
"no api key" error. Add both, using the current IMDSv2-capable versions
from dns_aws.sh, and set the IMDSv2 token header in _use_metadata so the
credential fetch works on IMDSv2-only instances.

Closes #4742
2026-07-05 17:09:51 +08:00
neil
7def43481a dns_regru: require a dot boundary in root zone matching
_get_root matched a registered domain anywhere as a substring of the
challenge domain, so with both "test.com.ru" and "subtest.com.ru" in the
account, issuing for subtest.com.ru wrongly picked test.com.ru as the
root (it is a substring of "sub-test.com.ru"). Anchor the match to a '.'
boundary so a shorter domain no longer matches a longer subdomain label.

Fixes the issue reported in #5036 (thanks @koledas)
Closes #5036
2026-07-05 16:57:59 +08:00
neil
defd64022d dnsapi/dns_namecom: probe the root zone with GetDomain instead of listing all domains
The domain list is paginated at 1000 entries per page and only the
first page was fetched, so accounts with more than 1000 domains never
found the root zone.

fix https://github.com/acmesh-official/acme.sh/issues/5051
2026-07-05 16:53:14 +08:00
neil
4256e3532b _regAccount: error out clearly when the eab-hmac-key cannot be base64-decoded
An undecodable key (e.g. broken LibreSSL base64 -d -A) used to produce
the cryptic "Usage: _hmac hashalg secret [outputhex]" and an empty EAB
signature that the CA rejects with 403.

https://github.com/acmesh-official/acme.sh/issues/4082
2026-07-05 16:32:57 +08:00
neil
1f94fd7fd5 add Apache workflow to test the --apache mode
Runs le_test_apache from acmetest against Pebble, with Apache
listening on Pebble's HTTP-01 validation port.
2026-07-05 16:31:51 +08:00
neil
507baff2ef deploy/docker: allow setting key file mode and owner in the container
The docker deploy hook copied the key file preserving the source mode
(root:root 0600), so a non-root container service (uid >= 1000) could not
read it. Add DEPLOY_DOCKER_CONTAINER_KEY_MODE and
DEPLOY_DOCKER_CONTAINER_KEY_OWNER, applied via chmod/chown inside the
container after the key is copied and before the reload command.

Closes #5333
2026-07-05 16:30:46 +08:00
neil
504540e67c dnsapi/dns_autodns: escape XML special characters in credentials (#5317) 2026-07-05 16:29:58 +08:00
neil
cacafc9c23 add Nginx workflow to test the --nginx mode
Runs le_test_nginx from acmetest against Pebble: nginx listens on
Pebble's HTTP-01 validation port with an aaPanel/BT style
"location ^~ /" reverse proxy block, the regression case of #6125.
2026-07-05 16:18:37 +08:00
laineus
24895a15c8 Add dns_muumuu: muumuu-domain.com DNS API (#7012)
* Add dns_muumuu: muumuu-domain.com DNS API

* Fix: remove local keyword for POSIX sh compatibility

* Fix: lowercase fulldomain for API compatibility

* Style: use echo instead of printf for lower_case (consistent with other plugins)

* Fix: prefix rest vars, clear _H4/_H5, guard record_id, update Issues URL
2026-07-05 16:05:33 +08:00
neil
1cd63e1480 _createcsr: omit CN from the CSR subject when it exceeds 64 characters (#4867) 2026-07-05 16:02:52 +08:00
neil
31b13caf8b DNS.yml: fix workflow warnings
- replace deprecated set-output with GITHUB_OUTPUT
- untap aws/tap before brew install to silence tap trust warning
- inject safe.directory=* for cygwin git so the checkout post step
  no longer fails with dubious ownership (exit 128)
2026-07-05 15:51:38 +08:00
neil
1e2cd50fc9 deploy/haproxy: use printf instead of "echo -e" for the stats socket payload
dash's echo has no -e flag and sends a literal "-e " prefix to the
socket, so haproxy rejects the command and the hot update always fails
on Debian/Ubuntu (/bin/sh = dash). Also accept "Transaction updated",
which haproxy replies when an uncommitted transaction already exists.

fix https://github.com/acmesh-official/acme.sh/issues/6165
2026-07-05 15:44:26 +08:00