do not keep CSRs
authorRalf Jung <post@ralfj.de>
Mon, 14 Dec 2015 19:29:09 +0000 (20:29 +0100)
committerRalf Jung <post@ralfj.de>
Mon, 14 Dec 2015 19:29:09 +0000 (20:29 +0100)
letsencrypt-tiny
letsencrypt-tiny.conf.sample

index 4503a6ef4b29bac20aa4327afc7c325496efbd3d..3b89db7b9d2dcec7d7d1230ced46727a0e942a39 100755 (executable)
@@ -21,7 +21,7 @@ def keyfile(name):
 
 def csrfile(name):
     global config
 
 def csrfile(name):
     global config
-    return os.path.join(config['dirs']['csrs'], name + ".csr")
+    return os.path.join(config['dirs']['keys'], name + ".csr.tmp")
 
 def make_backup(fname):
     if os.path.exists(fname):
 
 def make_backup(fname):
     if os.path.exists(fname):
@@ -65,6 +65,8 @@ def acme(name, domains):
     make_backup(certfile(name))
     with open(certfile(name), 'wb') as f:
         f.write(signed_crt)
     make_backup(certfile(name))
     with open(certfile(name), 'wb') as f:
         f.write(signed_crt)
+    # clean up
+    os.remove(csrfile(name))
 
 def request_cert(name):
     global config
 
 def request_cert(name):
     global config
index c8c91bc56f8a7261794a30fa068aae300b6f6831..5369fdcde10b48458274cb8cdd2c811d027a8738 100644 (file)
@@ -34,7 +34,6 @@ challenge-dir = /srv/acme-challenge/
 [dirs]
 certs = /etc/ssl/mycerts/letsencrypt
 keys = /etc/ssl/private/letsencrypt
 [dirs]
 certs = /etc/ssl/mycerts/letsencrypt
 keys = /etc/ssl/private/letsencrypt
-csrs = /etc/ssl/private/letsencrypt
 backups = /etc/ssl/old/letsencrypt
 
 [files]
 backups = /etc/ssl/old/letsencrypt
 
 [files]