diff options
| author | Lucas Savva <lucas@m1cr0man.com> | 2021-11-27 00:03:35 +0000 |
|---|---|---|
| committer | Lucas Savva <lucas@m1cr0man.com> | 2021-12-26 16:44:09 +0000 |
| commit | a7f00013280416ce889d841e675526b8cb96a0ee (patch) | |
| tree | 25899bc2f7446223fe52dfd7128f7c64d8d3b01c /pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch | |
| parent | 87403a0b078d62245de7d619f2b71d2a0c78675a (diff) | |
nixos/acme: Check for revoked certificates
Closes #129838
It is possible for the CA to revoke a cert that has not yet
expired. We must run lego to validate this before expiration,
but we must still ignore failures on unexpired certs to retain
compatibility with #85794
Also changed domainHash logic such that a renewal will only
be attempted at all if domains are unchanged, and do a full
run otherwises. Resolves #147540 but will be partially
reverted when go-acme/lego#1532 is resolved + available.
Diffstat (limited to 'pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch')
0 files changed, 0 insertions, 0 deletions
