mirror of
https://github.com/mjl-/mox.git
synced 2025-07-12 18:24:35 +03:00
add automated test for quickstart
with tls with acme (with pebble, a small acme server for testing), and with pregenerated keys/certs. the two mox instances are configured on their own domain. we launch a separate test container that connects to the first, submits a message for delivery to the second. we check if the message is delivered with an imap connection and the idle command.
This commit is contained in:
@ -85,7 +85,7 @@ Listeners:
|
||||
https://github.com/letsencrypt/pebble is useful for testing with ACME. Start a
|
||||
pebble instance that uses the localhost TLS cert/key created by cfssl for its
|
||||
TLS serving. Pebble generates a new CA certificate for its own use each time it
|
||||
is started. Fetch it from https://localhost:14000/root, write it to a file, and
|
||||
is started. Fetch it from https://localhost:15000/roots/0, write it to a file, and
|
||||
add it to mox.conf TLS.CA.CertFiles. See below.
|
||||
|
||||
Setup pebble, run once:
|
||||
@ -122,7 +122,7 @@ Write new CA bundle that includes pebble's temporary CA cert:
|
||||
export CURL_CA_BUNDLE=local/ca-bundle.pem # for curl
|
||||
export SSL_CERT_FILE=local/ca-bundle.pem # for go apps
|
||||
cat /etc/ssl/certs/ca-certificates.crt local/cfssl/ca.pem >local/ca-bundle.pem
|
||||
curl https://localhost:14000/root >local/pebble/ca.pem # fetch temp pebble ca, DO THIS EVERY TIME PEBBLE IS RESTARTED!
|
||||
curl https://localhost:15000/roots/0 >local/pebble/ca.pem # fetch temp pebble ca, DO THIS EVERY TIME PEBBLE IS RESTARTED!
|
||||
cat /etc/ssl/certs/ca-certificates.crt local/cfssl/ca.pem local/pebble/ca.pem >local/ca-bundle.pem # create new list that includes cfssl ca and temp pebble ca.
|
||||
rm -r local/*/data/acme/keycerts/pebble # remove existing pebble-signed certs in acme cert/key cache, they are invalid due to newly generated temp pebble ca.
|
||||
```
|
||||
|
Reference in New Issue
Block a user