acme_challenge_ready() compares the domain passed on the CLI (or via the
Lua ACME.challenge_ready() function) with strncmp() limited to the
length of the authorization's domain. This is a prefix match: with a
certificate covering "example.com" and "example.com.au", signaling
"example.com.au" also marks the "example.com" challenge as ready.

Use isteq() so that only the exact domain matches.

This should be backported to 3.3. The code was moved into
acme_challenge_ready() in 3.5, so the fix has to be applied to
cli_acme_chall_ready_parse() in older versions.
---
 src/acme.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/src/acme.c b/src/acme.c
index dbf1d1f..63f6959 100644
--- a/src/acme.c
+++ b/src/acme.c
@@ -3604,7 +3604,7 @@ int acme_challenge_ready(const char *crt, const char *dns)
        if (ctx->cfg->cond_ready & ACME_RDY_CLI)
                auth = ctx->auths;
        while (auth) {
-               if (strncmp(dns, auth->dns.ptr, auth->dns.len) == 0) {
+               if (isteq(ist(dns), auth->dns)) {
                        if ((auth->ready & ACME_RDY_CLI) == 0) {
                                auth->ready |= ACME_RDY_CLI;
                                found++;
-- 
2.43.0



Reply via email to