Skip to content

Develop - #15

Merged
boffart merged 9 commits into
masterfrom
develop
Sep 10, 2026
Merged

boffart merged 9 commits into
masterfrom
develop

Conversation

@boffart

@boffart boffart commented Sep 10, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

Alexey Portnov and others added 9 commits May 12, 2026 13:46
cronRenewCert.php ran acme.sh --cron and then unconditionally called
GetSslMain::run(). After an upgrade from the legacy getssl client,
--cron silently no-ops (no renewal config exists yet), and run() picked
up the leftover legacy cert from db/getssl/<domain>/ and reinstalled it
into PbxSettings, logging "SSL certificate installed" while the cert was
actually the same expired file. The bug went undetected until a real
expiry hit production.

- cronRenewCert.php: detect via hasAcmeDomain() whether acme.sh already
  has a renewal config; if not, call startGetCertSsl(false) for a full
  --issue. Drop the trailing run() call — acme.sh triggers reloadCmd.php
  (--reloadcmd) on success, which already invokes run().
- GetSslMain::run() / getCertPath() / getPrivateKeyPath(): remove the
  legacy-getssl fallback. After migration the source of truth is
  acme.sh's config home; falling back to legacy paths masked the bug
  above. ECDSA (_ecc) is checked first, RSA second, then '' is returned
  so run() reports "not found" instead of reinstalling stale files.
The afterSave hook in MikoPBX core fires a publish to nchan via HTTP;
when triggered from acme.sh --reloadcmd it races with nginx reload and
fails with cURL error 56. The DB write itself has already succeeded,
so swallow the exception and log a short note instead of polluting
last-result.log with a 31-line stack trace per key.
@boffart
boffart merged commit 6f8ae56 into master Sep 10, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant