Hello,

On Sat, Sep 26, 2026 at 09:25:53PM +0200, Jérôme Billiras wrote:
> Subject: [PATCH 2/2] BUG/MEDIUM: acme: only mark one challenge as ready per 
> call
> A certificate covering both a domain and its wildcard, for instance
> "example.com" and "*.example.com", gets two dns-01 authorizations from
> the ACME server. Both have the same identifier value, "example.com"
> (the wildcard one only has "wildcard": true), but each one has its own
> token, so two different TXT records must be deployed under
> "_acme-challenge.example.com".
>

What ACME provider did you used to end up with this case?

The code was done this way because our tests ended up with the same challenge
for both "example.com" and "*.example.com". So that mean we should handle both
cases.

> [...]
> @@ -3604,11 +3606,13 @@ int acme_challenge_ready(const char *crt, const char 
> *dns)
>       if (ctx->cfg->cond_ready & ACME_RDY_CLI)
>               auth = ctx->auths;
>       while (auth) {
> -             if (isteq(ist(dns), auth->dns)) {
> -                     if ((auth->ready & ACME_RDY_CLI) == 0) {
> -                             auth->ready |= ACME_RDY_CLI;
> -                             found++;
> -                     }
> +             /* Only mark one challenge per call: a domain and its wildcard
> +              * have two different challenges sharing the same <dns>.
> +              */
> +             if (!found && isteq(ist(dns), auth->dns) &&
> +                 (auth->ready & ACME_RDY_CLI) == 0) {
> +                     auth->ready |= ACME_RDY_CLI;
> +                     found++;
>               }

Something like this should do, but this is changing the behavior which was
intentional, this will probably break things for people, so we must be careful.

This also mean that the dns check can't work correctly either. I'll do more
testing.

Thanks,

-- 
William Lallemand


Reply via email to