6848 Commits

Author SHA1 Message Date
neil
504540e67c dnsapi/dns_autodns: escape XML special characters in credentials (#5317) 2026-07-05 16:29:58 +08:00
neil
cacafc9c23 add Nginx workflow to test the --nginx mode
Runs le_test_nginx from acmetest against Pebble: nginx listens on
Pebble's HTTP-01 validation port with an aaPanel/BT style
"location ^~ /" reverse proxy block, the regression case of #6125.
2026-07-05 16:18:37 +08:00
laineus
24895a15c8 Add dns_muumuu: muumuu-domain.com DNS API (#7012)
* Add dns_muumuu: muumuu-domain.com DNS API

* Fix: remove local keyword for POSIX sh compatibility

* Fix: lowercase fulldomain for API compatibility

* Style: use echo instead of printf for lower_case (consistent with other plugins)

* Fix: prefix rest vars, clear _H4/_H5, guard record_id, update Issues URL
2026-07-05 16:05:33 +08:00
neil
1cd63e1480 _createcsr: omit CN from the CSR subject when it exceeds 64 characters (#4867) 2026-07-05 16:02:52 +08:00
neil
31b13caf8b DNS.yml: fix workflow warnings
- replace deprecated set-output with GITHUB_OUTPUT
- untap aws/tap before brew install to silence tap trust warning
- inject safe.directory=* for cygwin git so the checkout post step
  no longer fails with dubious ownership (exit 128)
2026-07-05 15:51:38 +08:00
neil
1e2cd50fc9 deploy/haproxy: use printf instead of "echo -e" for the stats socket payload
dash's echo has no -e flag and sends a literal "-e " prefix to the
socket, so haproxy rejects the command and the hot update always fails
on Debian/Ubuntu (/bin/sh = dash). Also accept "Transaction updated",
which haproxy replies when an uncommitted transaction already exists.

fix https://github.com/acmesh-official/acme.sh/issues/6165
2026-07-05 15:44:26 +08:00
Jan Forman
524d96a3a8 Add WEDOS WAPI DNS API (dns_wedos) (#7072)
* Add WEDOS WAPI DNS API (dns_wedos)

* dns_wedos: fix response parsing on systems without egrep -o

* dns_wedos: report WAPI auth errors, UTC fallback for hosts ignoring TZ
2026-07-05 12:44:07 +08:00
Foster Snowhill
0eb5cc8384 dns_desec: fix advertised token variable name (#7081)
This must've been a copy-paste error from `dns_ddnss`.

Fixes: 6b7b5caf54 ("DNS provider API: structured description")
2026-07-05 12:03:48 +08:00
neil
77047eb0ef fix CSR reading on systems without a default openssl.cnf (e.g. NetBSD)
"openssl req -noout -in" aborts when the default config file is missing;
reading a CSR needs no config, so pass -config /dev/null explicitly.

Stock NetBSD does not install /etc/openssl/openssl.cnf, so --signcsr
never worked there.
2026-07-04 23:55:16 +08:00
neil
4978782fb8 renewAll: error out if CERT_HOME is not a directory
With a misconfigured $HOME / CERT_HOME the glob over "$CERT_HOME"/*.*
matches nothing, so renewAll silently does nothing and returns success --
--renew-all / --cron appears to work while renewing no certificates.
Check that CERT_HOME is a directory up front and return 1 with a clear
error instead.

Closes #4508
2026-07-04 23:40:31 +08:00
neil
9764f67619 dns_cn: convert IDN domain to punycode before API calls
Core-Networks' API rejects Unicode domain names with "invalid domain";
it requires punycode. dns_cn_add / dns_cn_rm passed the raw challenge
domain straight through, so IDN certs failed at the TXT add step
(issue #4804). Run fulldomain through _idn() in both functions. For
ASCII/punycode input _idn() is a pass-through, so non-IDN domains are
unaffected.

Fixes #4804
2026-07-04 21:58:57 +08:00
neil
988afd0f59 _isIPv4: do not glob segments, require exactly 4 octets
The unquoted splitting let a "*" segment expand against files in the
current directory, so "*.*.*.*" could pass as a valid IPv4 address
(issue 4971). The old code also accepted "", "1.2.3", "1.2.3.4.5",
"1..2.3" and bare numbers. Split with IFS under set -f, require 4
octets, and validate each as a 1-3 digit number <= 255.

Based on https://github.com/acmesh-official/acme.sh/pull/4974
fix https://github.com/acmesh-official/acme.sh/issues/4971
2026-07-04 21:34:46 +08:00
Ramon
b92516f79e add application/json to acmedns (#5066) 2026-07-04 21:07:18 +08:00
neil
fbf3b41c54 dns_inwx: fix _get_root false zone match for single-letter subdomains
_get_root matched the candidate zone with _contains (grep), which treats
the domain as a regex. For "-d g.<zone>" the candidate "g.<zone>" matched
"<string>...<zone>" because '.' matches the '>' after "string" and the 'g'
comes from the "<string>" tag, so "g.<zone>" was wrongly taken as the root
zone (sub=_acme-challenge instead of _acme-challenge.g). Anchor the match
to <string>$h</string> and escape dots so the zone is compared literally.

Fixes #5129
2026-07-04 20:28:56 +08:00
neil
ede9a86d46 Accept both 401 and 403 for deactivated account detection
RFC 8555 sec 7.3.6 requires 401 (Unauthorized) when a request is
signed by a deactivated account, which ZeroSSL follows, while
Boulder (Let's Encrypt) historically returns 403. Check both codes
in _regAccount and deactivateaccount.

fix https://github.com/acmesh-official/acme.sh/issues/5138
2026-07-04 20:21:27 +08:00
xiaopc
843a7efa7d fix(gcore_cdn): renew login api url (#5143)
https://api.gcore.com/docs/iam#tag/Account
2026-07-04 20:14:32 +08:00
neil
d3e12694b9 fix "identifiers are duplicated" when signing a CSR with a wildcard CN also present in SAN
_contains matches with grep regex, so the '*' in "DNS:*.example.com," never
matched and the subject was appended to the identifiers a second time.
Escape the wildcard before the check, the same way the sed removal already does.

fix https://github.com/acmesh-official/acme.sh/issues/5251
2026-07-04 19:56:37 +08:00
neil
a105126063 _date2time: pass date via argv to python to prevent code injection (#6463)
https://github.com/acmesh-official/acme.sh/issues/6463
2026-07-04 19:14:36 +08:00
neil
917bebd460 dns_huaweicloud: add optional HUAWEICLOUD_Region (default ap-southeast-1)
The DNS endpoint and IAM token scope project were hardcoded to
ap-southeast-1, which fails for accounts without that region enabled.

fix https://github.com/acmesh-official/acme.sh/issues/5302
2026-07-04 19:06:46 +08:00
Clément Gouin
33704fc274 Allow creation of ACME account with EAB directly from --issue command (#5087)
* formalized _eab_id and _eab_kid and added EAB parameters to _regAccount on --issue

* Update acme.sh

* Update acme.sh
2026-07-04 18:54:07 +08:00
neil
bcbfe25d08 haproxy.sh: use two-argument -header form for LibreSSL (#3438) 2026-07-04 18:50:29 +08:00
neil
bbfb6f50ae deploy/cpanel_uapi: strip YAML double quotes around wildcard domains in list_domains output
fix https://github.com/acmesh-official/acme.sh/issues/6115
2026-07-04 18:46:59 +08:00
neil
6df2d9e451 dns_da: document that special characters in DA_Api credentials must be percent-encoded
https://github.com/acmesh-official/acme.sh/issues/3468
2026-07-04 18:19:45 +08:00
neil
1a36823461 https://github.com/acmesh-official/acme.sh/issues/3201 2026-07-04 16:55:49 +08:00
wardhus
8f2a476d21 Add Calrissia.be API (#6811)
Co-authored-by: Ward <ward.hus@calrissia.com>
2026-07-04 16:54:05 +08:00
Simon V.
e64529ab50 ARI - Add support for Mass Revocation (#6953)
* ARI - Add support for Mass Revocation

* feat: update ARI each time NextRenewTime is not within the suggestedWindow

* Remove _ari_should_renew and add condition on Le_NextRenewTime

* Add support for ARI explanationURL

* Fix debug variable _d_ari

* New Banner

Updated README to include responsive images for dark and light modes.

* multiple fix

* fix

* fix shfmt

* Reset README

---------

Co-authored-by: ZeroSSL-Andreas <andreas.schuster@hidglobal.com>
2026-07-04 16:50:55 +08:00
neil
7653eaab31 fix https://github.com/acmesh-official/acme.sh/issues/4879#issuecomment-2942728895 2026-07-04 11:44:32 +08:00
neil
6cd0c00a21 extract authorizations parsing into _authorizations_from_order, fix IPv6 urls (#6326) 2026-07-04 11:23:11 +08:00
neil
b4de9e8621 fix docker deploy hook on podman, check exec ExitCode instead of response body (#4977) 2026-07-04 10:49:32 +08:00
neil
0a6abaf8a1 fix https://github.com/acmesh-official/acme.sh/issues/6388 2026-07-04 00:39:52 +08:00
Laurent Grawet
f4dc9fd9d1 haproxy.sh: allows certificate deployment to multiple hosts (#5180)
* haproxy.sh: allows certificate deployment to multiple hosts

* Update deploy/haproxy.sh

Co-authored-by: Matt Simerson <matt@tnpi.net>

* Update deploy/haproxy.sh

Co-authored-by: Matt Simerson <matt@tnpi.net>

---------

Co-authored-by: Matt Simerson <matt@tnpi.net>
2026-07-04 00:35:02 +08:00
Artur Klauser
2229330c48 Fix typo in synology_dsm.sh (#6406)
Fix typo in an error message.
2026-07-04 00:32:45 +08:00
neil
0df051577c fix https://github.com/acmesh-official/acme.sh/issues/6609 2026-07-04 00:06:26 +08:00
neil
7fb40f0ccf fix https://github.com/acmesh-official/acme.sh/issues/6609 2026-07-03 23:55:23 +08:00
neil
780f2ad5dc dns_ali: do not rely on "_url_encode upper-hex" so the signature works with older bundled libraries (e.g. Proxmox VE) https://github.com/acmesh-official/acme.sh/issues/6272 2026-07-03 23:44:22 +08:00
szakharchenko
adf69c4e7e dns_aws: Fix invalid domain logging: _error => _err (#6430)
acme.sh defines _err, not _error.
2026-07-03 23:40:39 +08:00
neil
ac5624536b dns_gd: fix root zone detection for API-restricted accounts https://github.com/acmesh-official/acme.sh/issues/4487 2026-07-03 23:34:27 +08:00
neil
b974bbd6d6 fix upgrade with a relative --home path https://github.com/acmesh-official/acme.sh/issues/6477 2026-07-03 23:34:27 +08:00
szakharchenko
0ce8c24736 dev_mythic_beasts: Fix header name: Accepts => Accept (#6428) 2026-07-03 23:25:38 +08:00
neil
20254cbaf0 dns_dnsimple: support user tokens (dnsimple_u_*) https://github.com/acmesh-official/acme.sh/issues/6491 2026-07-03 23:02:35 +08:00
neil
f4d2db64ef dns_gd: skip readback check when GoDaddy API returns UNKNOWN_DOMAIN https://github.com/acmesh-official/acme.sh/issues/6517 2026-07-03 22:49:40 +08:00
Trekky12
61400500e2 Suppress 'signal process started' message when nginx config is restored (related to issue #4995) (#6747) 2026-07-03 22:31:31 +08:00
neil
92a1b47108 forbid spaces in the --home/--config-home path https://github.com/acmesh-official/acme.sh/issues/2163 2026-07-03 22:26:50 +08:00
neil
5038d12d62 forbid using --days together with --valid-to https://github.com/acmesh-official/acme.sh/pull/6572 2026-07-03 21:55:37 +08:00
magyarsz
7e7c0ee984 Merge pull request #6720 from magyarsz/dev
Fix a logical error in the `renew` function
2026-07-03 21:42:52 +08:00
neil
92bd80c07d fix https://github.com/acmesh-official/acme.sh/issues/6914 2026-07-03 20:07:42 +08:00
neil
ad99628e50 fix https://github.com/acmesh-official/acme.sh/issues/6917 2026-07-03 20:04:32 +08:00
neil
992886c4eb Merge pull request #7078 from acmesh-official/dev
sync
2026-07-03 19:56:09 +08:00
neil
eabd23a551 fix https://github.com/acmesh-official/acme.sh/issues/6963 2026-07-03 19:38:42 +08:00
neil
1241649501 fix https://github.com/acmesh-official/acme.sh/issues/7009 2026-07-03 19:38:21 +08:00