le-sni-auto.js/index.js

173 lines
5.4 KiB
JavaScript
Raw Normal View History

2016-08-10 20:37:03 -04:00
'use strict';
2016-08-12 01:59:19 -04:00
var DAY = 24 * 60 * 60 * 1000;
2018-04-19 13:29:55 -06:00
var HOUR = 60 * 60 * 1000;
2016-08-12 01:59:19 -04:00
var MIN = 60 * 1000;
var defaults = {
// don't renew before the renewWithin period
2018-04-19 13:18:40 -06:00
renewWithin: 14 * DAY
2018-04-19 13:29:55 -06:00
, _renewWithinMin: 3 * DAY
2016-08-12 01:59:19 -04:00
// renew before the renewBy period
2018-04-19 13:29:55 -06:00
, renewBy: 10 * DAY
2016-08-12 01:59:19 -04:00
, _renewByMin: Math.floor(DAY / 2)
// just to account for clock skew really
, _dropDead: 5 * MIN
};
// autoSni = { renewWithin, renewBy, getCertificates, tlsOptions, _dbg_now }
2016-08-10 20:37:03 -04:00
module.exports.create = function (autoSni) {
if (!autoSni.getCertificatesAsync) { autoSni.getCertificatesAsync = require('bluebird').promisify(autoSni.getCertificates); }
2016-08-12 01:59:19 -04:00
if (!autoSni.renewWithin) { autoSni.renewWithin = autoSni.notBefore || defaults.renewWithin; }
if (autoSni.renewWithin < defaults._renewWithinMin) {
2018-04-19 13:29:55 -06:00
throw new Error("options.renewWithin should be at least " + (defaults._renewWithinMin / DAY) + " days");
2016-08-12 01:59:19 -04:00
}
if (!autoSni.renewBy) { autoSni.renewBy = autoSni.notAfter || defaults.renewBy; }
2016-08-12 01:59:19 -04:00
if (autoSni.renewBy < defaults._renewByMin) {
2018-04-19 13:29:55 -06:00
throw new Error("options.renewBy should be at least " + (defaults._renewBy / HOUR) + " hours");
2016-08-12 01:59:19 -04:00
}
if (!autoSni.tlsOptions) { autoSni.tlsOptions = autoSni.httpsOptions || {}; }
2016-08-10 20:37:03 -04:00
2016-08-12 01:59:19 -04:00
autoSni._dropDead = defaults._dropDead;
//autoSni.renewWithin = autoSni.notBefore; // i.e. 15 days
autoSni._renewWindow = autoSni.renewWithin - autoSni.renewBy; // i.e. 1 day
//autoSni.renewRatio = autoSni.notBefore = autoSni._renewWindow; // i.e. 1/15 (6.67%)
2016-08-10 20:37:03 -04:00
var tls = require('tls');
var _autoSni = {
// in-process cache
_ipc: {}
2016-08-12 01:59:19 -04:00
, getOptions: function () {
return JSON.parse(JSON.stringify(defaults));
}
2016-08-10 20:37:03 -04:00
// cache and format incoming certs
2016-08-12 01:59:19 -04:00
, cacheCerts: function (certs) {
2016-08-10 20:37:03 -04:00
var meta = {
certs: certs
2016-08-11 02:46:53 -04:00
, tlsContext: 'string' === typeof certs.cert && tls.createSecureContext({
2016-08-10 20:37:03 -04:00
key: certs.privkey
2018-04-25 23:01:14 -06:00
// backwards/forwards compat
, cert: (certs.cert||'').replace(/[\r\n]+$/, '') + '\r\n' + certs.chain
2016-08-12 01:59:19 -04:00
, rejectUnauthorized: autoSni.tlsOptions.rejectUnauthorized
2016-08-10 20:37:03 -04:00
2016-08-12 01:59:19 -04:00
, requestCert: autoSni.tlsOptions.requestCert // request peer verification
, ca: autoSni.tlsOptions.ca // this chain is for incoming peer connctions
, crl: autoSni.tlsOptions.crl // this crl is for incoming peer connections
2016-08-10 20:37:03 -04:00
}) || { '_fake_tls_context_': true }
, subject: certs.subject
, auto: 'undefined' === typeof certs.auto ? true : certs.auto
2016-08-10 20:37:03 -04:00
// stagger renewal time by a little bit of randomness
2016-08-12 01:59:19 -04:00
, renewAt: (certs.expiresAt - (autoSni.renewWithin - (autoSni._renewWindow * Math.random())))
2016-08-10 20:37:03 -04:00
// err just barely on the side of safety
2016-08-12 01:59:19 -04:00
, expiresNear: certs.expiresAt - autoSni._dropDead
2016-08-10 20:37:03 -04:00
};
var link = { subject: certs.subject };
certs.altnames.forEach(function (domain) {
autoSni._ipc[domain] = link;
});
autoSni._ipc[certs.subject] = meta;
return meta;
}
, uncacheCerts: function (certs) {
certs.altnames.forEach(function (domain) {
delete autoSni._ipc[domain];
});
delete autoSni._ipc[certs.subject];
}
2016-08-10 20:37:03 -04:00
// automate certificate registration on request
, sniCallback: function (domain, cb) {
var certMeta = autoSni._ipc[domain];
var promise;
var now = (autoSni._dbg_now || Date.now());
if (certMeta && !certMeta.then && certMeta.subject !== domain) {
2016-08-11 02:46:53 -04:00
//log(autoSni.debug, "LINK CERT", domain);
certMeta = autoSni._ipc[certMeta.subject];
2016-08-10 20:37:03 -04:00
}
if (!certMeta) {
2016-08-11 02:46:53 -04:00
//log(autoSni.debug, "NO CERT", domain);
2016-08-10 20:37:03 -04:00
// we don't have a cert and must get one
promise = autoSni.getCertificatesAsync(domain, null).then(autoSni.cacheCerts);
autoSni._ipc[domain] = promise;
}
else if (certMeta.then) {
//log(autoSni.debug, "PROMISED CERT", domain);
// we are already getting a cert
promise = certMeta
2016-08-10 20:37:03 -04:00
}
else if (now >= certMeta.expiresNear) {
2016-08-11 02:46:53 -04:00
//log(autoSni.debug, "EXPIRED CERT");
2016-08-10 20:37:03 -04:00
// we have a cert, but it's no good for the average user
promise = autoSni.getCertificatesAsync(domain, certMeta.certs).then(autoSni.cacheCerts);
autoSni._ipc[certMeta.subject] = promise;
2016-08-10 20:37:03 -04:00
} else {
// it's time to renew the cert
if (certMeta.auto && now >= certMeta.renewAt) {
2016-08-11 02:46:53 -04:00
//log(autoSni.debug, "RENEWABLE CERT");
2016-08-10 20:37:03 -04:00
// give the cert some time (2-5 min) to be validated and replaced before trying again
certMeta.renewAt = (autoSni._dbg_now || Date.now()) + (2 * MIN) + (3 * MIN * Math.random());
// let the update happen in the background
2016-08-12 01:59:19 -04:00
autoSni.getCertificatesAsync(domain, certMeta.certs).then(autoSni.cacheCerts);
2016-08-10 20:37:03 -04:00
}
// return the valid cert right away
cb(null, certMeta.tlsContext);
return;
}
// promise the non-existent or expired cert
promise.then(function (certMeta) {
2016-08-10 20:37:03 -04:00
cb(null, certMeta.tlsContext);
2016-08-11 02:46:53 -04:00
}, function (err) {
2018-04-19 13:18:40 -06:00
// console.error('ERROR in le-sni-auto:');
// console.error(err.stack || err);
2016-08-11 02:46:53 -04:00
cb(err);
// don't reuse this promise
delete autoSni._ipc[certMeta && certMeta.subject ? certMeta.subject : domain];
2016-08-11 02:46:53 -04:00
});
2016-08-10 20:37:03 -04:00
}
};
Object.keys(_autoSni).forEach(function (key) {
autoSni[key] = _autoSni[key];
});
_autoSni = null;
return autoSni;
};