2021-07-22 15:23:24 +02:00
|
|
|
package encryption
|
|
|
|
|
|
|
|
import (
|
|
|
|
"os"
|
|
|
|
"path/filepath"
|
2024-01-29 14:21:45 +01:00
|
|
|
|
|
|
|
log "github.com/sirupsen/logrus"
|
|
|
|
"golang.org/x/crypto/acme/autocert"
|
2021-07-22 15:23:24 +02:00
|
|
|
)
|
|
|
|
|
2021-08-07 12:26:07 +02:00
|
|
|
// CreateCertManager wraps common logic of generating Let's encrypt certificate.
|
2024-09-08 12:06:14 +02:00
|
|
|
func CreateCertManager(datadir string, letsencryptDomain ...string) (*autocert.Manager, error) {
|
2021-07-22 15:23:24 +02:00
|
|
|
certDir := filepath.Join(datadir, "letsencrypt")
|
|
|
|
|
|
|
|
if _, err := os.Stat(certDir); os.IsNotExist(err) {
|
2024-01-29 14:21:45 +01:00
|
|
|
err = os.MkdirAll(certDir, 0755)
|
2021-07-22 15:23:24 +02:00
|
|
|
if err != nil {
|
2022-07-25 19:55:38 +02:00
|
|
|
return nil, err
|
2021-07-22 15:23:24 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-07-25 19:55:38 +02:00
|
|
|
log.Infof("running with LetsEncrypt (%s). Cert will be stored in %s", letsencryptDomain, certDir)
|
2021-07-22 15:23:24 +02:00
|
|
|
|
2021-08-07 12:26:07 +02:00
|
|
|
certManager := &autocert.Manager{
|
2021-07-22 15:23:24 +02:00
|
|
|
Prompt: autocert.AcceptTOS,
|
|
|
|
Cache: autocert.DirCache(certDir),
|
2024-09-08 12:06:14 +02:00
|
|
|
HostPolicy: autocert.HostWhitelist(letsencryptDomain...),
|
2021-07-22 15:23:24 +02:00
|
|
|
}
|
|
|
|
|
2022-07-25 19:55:38 +02:00
|
|
|
return certManager, nil
|
2021-07-22 15:23:24 +02:00
|
|
|
}
|