Certificats Let's Encrypt
Find a file
Alex Gaynor efaec60e6b Switched from using urllib2 to requests.
urllib2 is a security hazzard, it does not perform certificate checks against a trust root by default, nor does it perform service_identity checks.

Also, requests has a prettier API.
2014-11-18 08:13:06 -08:00
attic New README for Let's Encrypt 2014-11-17 15:34:00 -08:00
letsencrypt Switched from using urllib2 to requests. 2014-11-18 08:13:06 -08:00
.gitignore Move protocol and client into Python modules 2012-08-12 07:49:45 +03:00
.gitmodules Move files that are specific to the trustify protocol into the attic 2014-11-14 18:16:40 -08:00
EULA Formatting changes before demo 2014-11-13 01:49:32 -08:00
letsencrypt.py Add --help option 2014-11-18 03:20:42 -08:00
LICENSE.txt Add a license for launch: Apache 2.0 2014-11-17 15:28:27 -08:00
MANIFEST.in More documentation 2014-11-18 02:42:56 -08:00
README.md README formatting 2014-11-18 03:14:49 -08:00
setup.py Switched from using urllib2 to requests. 2014-11-18 08:13:06 -08:00

This is the Let's Encrypt Agent DEVELOPER PREVIEW repository.

DO NOT RUN THIS CODE ON A PRODUCTION WEBSERVER. IT WILL INSTALL CERTIFICATES SIGNED BY A TEST CA, AND WILL CAUSE CERT WARNINGS FOR USERS.

This code intended for testing, demonstration, and integration engineering with OSes and hosting platforms. Currently the code works with Linux and Apache, though we will be expanding it to other platforms.

Running the demo code on Ubuntu

sudo apt-get install python-pip python-crypto python-dev python-jsonschema python-augeas gcc python-m2crypto python-dialog

sudo pip install jose

sudo ./letsencrypt.py

Hint: on Debian testing/unstable, python-dialog is unavailable and you may need to do sudo pip install pythondialog=2.7 (lets-encrypt does not yet handle debian unstable's Apache2 conf layout, either...)

Command line usage

sudo ./letsencrypt.py (default authentication mode using pythondialog)

options --text (text mode)
--privkey= (specify privatekey file to use to generate the certificate)
--csr= (Use a specific CSR. If this is specified, privkey must also be
specified with the correct private key for the CSR)
--server (list the ACME CA server address)
--revoke (revoke a certificate)
--view-checkpoints (Used to view available checkpoints and see what
configuration changes have been made)
--rollback=X (Revert the configuration X number of checkpoints)
--redirect (Automatically redirect all HTTP traffic to HTTPS for the newly
authenticated vhost)
--no-redirect (Skip the HTTPS redirect question, allowing both HTTP and
HTTPS)
--agree-eula (Skip the end user agreement screen)