Hi,

I've been using the native ACME client with dns-01 and the Data Plane
API as the DNS agent (OVH provider), for a certificate covering both
"sub.example.com" and "*.sub.example.com". Issuance kept failing, and
the second "acme challenge_ready" sent by the Data Plane API was
answered with "Couldn't find an ACME task using crt ... to set as
ready!".

The cause is that both authorizations share the same identifier value,
and acme_challenge_ready() marks every pending challenge matching the
domain at once. The first call therefore triggers the validation before
the second TXT record exists. Patch 2 makes each call account for a
single challenge. Patch 1 is a small related fix I noticed on the same
line: the domain comparison is a prefix match.

Both patches are against master. The code was moved into
acme_challenge_ready() for 3.5, so they won't apply as-is on 3.4 or
3.3, which have the same bug in cli_acme_chall_ready_parse(). I tested
the equivalent change on top of 3.4.5: <TEST RESULT TO FILL IN>. I can
send that 3.4 version if it helps with the backport.

For reference, two related fixes were needed on the Data Plane API side
for this setup, and are proposed there:
  - https://github.com/haproxytech/dataplaneapi/pull/417
  - https://github.com/haproxytech/dataplaneapi/pull/418

One more thing I noticed but did not try to fix: with "challenge-ready
dns", the pre-check only reads one TXT value per name, so with two
records under the same "_acme-challenge" name, one of the two checks may
never match. "cli,delay" works fine as a workaround in the meantime.

Thanks,
Jérôme

Jérôme Billiras (2):
  BUG/MINOR: acme: exact domain match in acme_challenge_ready()
  BUG/MEDIUM: acme: only mark one challenge as ready per call

 doc/configuration.txt |  6 +++++-
 doc/lua-api/index.rst |  2 ++
 src/acme.c            | 14 +++++++++-----
 3 files changed, 16 insertions(+), 6 deletions(-)

-- 
2.43.0



Reply via email to