fix: honour CULVERT_CRL_DAYS and keep crl.pem 0644 - #59
Merged
Merged
Conversation
CULVERT_CRL_DAYS reached Easy-RSA only through the environment PKI initialisation exported, so after a restart over an existing PKI the refresh loop, update-crl and revoke-client all wrote 180-day CRLs whatever the operator configured. regenerate_local_crl now passes EASYRSA_CRL_DAYS from the config on every run, and update-crl reads it through the config cascade. Unset, it stays 180. A crl.pem that gen-crl creates from nothing is 0600 root, which OpenVPN cannot read once it has dropped to nobody. Every regeneration now leaves it 0644. revoke-client regenerates through the same function instead of its own gen-crl call, and the function is public now that three modules call it. The manager fixture moves to tests/unit/conftest.py, so the wstunnel test no longer leaves ProcessManager's signal handlers installed, and the init_pki_local tests put back the EASYRSA_* variables it exports. The release-tag test reads origin's tags with git ls-remote, so it runs in CI's shallow checkout instead of skipping.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Six follow-ups to #58.
CULVERT_CRL_DAYSwas honoured on first boot only. It reached Easy-RSA through the environmentinit_pki_localexported, so after a restart over an existing PKI the refresh loop,update-crlandrevoke-clientall wrote 180-day CRLs.regenerate_local_crlnow passesEASYRSA_CRL_DAYSfrom the config on every run, andupdate-crlreads it throughConfig.from_settings(), so a profile YAML can set it too. Unset, it is still 180.crl.pemthat gen-crl creates from nothing is 0600 root. OpenVPN drops tonobody(config/server.conf.template:107), and uid 65534 cannot open that file. Every regeneration now leaves it 0644. It is a public revocation list with nothing secret in it.revoke-clientregenerates through the library instead of its own gen-crl copy, and takes the Easy-RSA path fromlib.pki.EASYRSA_DIRinstead of its own constant._regenerate_local_crlis public asregenerate_local_crl, now that three modules call it.managerfixture moved totests/unit/conftest.py. The wstunnel test built a bareProcessManager()and left its SIGTERM, SIGINT and SIGHUP handlers installed for every test after it. Theinit_pki_localtests now put back theEASYRSA_*variables that function exports, which also outlived them.test_app_version_tracks_the_latest_releasereads origin's tags withgit ls-remoteinstead of the clone's, so it runs in CI's shallow checkout. Offline it still skips, and the changelog check beside it still guards.CRL lifetime and mode, main against this branch. Measured in the v2.1.16 image against Easy-RSA 3.2.5, each regeneration in a fresh process over a PKI first built with
CULVERT_CRL_DAYS=30. Lifetime is nextUpdate minus lastUpdate, and "nobody" is whether uid 65534 can readcrl.pem.CULVERT_CRL_DAYSinit_pki_local, unchanged)update-crlrevoke-clientupdate-crlcrl.pemmissingupdate-crl,crl.pemmissingrevoke-client,crl.pemmissingcrl.pemUnset, both write the same CRL apart from its timestamps and signature: version 2, issuer
CN=VPN CA,ecdsa-with-SHA256, and it verifies against the CA.revoke-client, main against this branch:./easyrsa gen-crl, argv listlib.pki.regenerate_local_crl,sh -cwith quoted pathsEASYRSA,EASYRSA_PKI,EASYRSA_BATCH=1EASYRSA_CRL_DAYSfrom configEASYRSAconstantlib.pki.EASYRSA_DIR, the same/usr/share/easy-rsaCULVERT_CRL_DAYS=30crl.pemcreated freshFailed to update CRL: <stderr>then a blank lineCRL regeneration failed: <stderr>, strippedThe failure was forced by making
crl.pema dangling symlink, whicheasyrsa revokeignores and gen-crl's final copy refuses. Both versions leave the certificate revoked inindex.txtand exit 1.update-crlnow logs two lines before its own,Network profileandmax-clients calculated, because it builds the config.revoke-clientalready did.tests/run-unit.sh: 598 passed, also with the files in reverse order.hyperi-ci check --strict2.12.5: exit 0, coverage 83.21%.