Skip to content
This repository was archived by the owner on Oct 15, 2024. It is now read-only.
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
139 commits
Select commit Hold shift + click to select a range
038e4d2
Update README
akoserwal Nov 12, 2019
2bc4eb0
Update READMe
akoserwal Nov 12, 2019
6f10f22
also output sha256 digest when generating certificate
izolight Nov 24, 2019
b41fd33
update documentation with sha256 hashes
izolight Nov 24, 2019
6e8b031
push images to github/docker container registry
nickysemenza Mar 21, 2023
b4d0d87
Merge pull request #1277 from cloudflare/nicky/docker
nickysemenza Mar 28, 2023
f7af124
Respect custom x509 ext in selfsign
sthussey Apr 7, 2023
2fab338
add workflow to run goreleaser snapshot
nickysemenza Nov 30, 2022
908df50
Merge pull request #1285 from cloudflare/nicky/goreleaser-action-snap…
nickysemenza Apr 19, 2023
636ddf8
goreleaser: Add ARMv7 binaries
patrickelectric Apr 18, 2023
415a59e
Merge pull request #1282 from patrickelectric/arm
nickysemenza Apr 26, 2023
76629b5
snapshot.yml: update actions/checkout to v3
kbdharun Apr 28, 2023
e9d0790
go.yml: update actions/checkout to v3, actions/setup-go to v4
kbdharun Apr 28, 2023
5f34df7
fix architecture for docker builds
nickysemenza Apr 26, 2023
88bfcbf
Merge pull request #1288 from kbdharun/master
nickysemenza May 2, 2023
f6cb3e8
build pacakges with latest go
nickysemenza May 11, 2023
2b2dd1a
configure dependabot
ahrtr May 12, 2023
214bd57
Merge pull request #1292 from ahrtr/configure_dependabot_20230512
nickysemenza May 12, 2023
e1d1777
build(deps): bump docker/build-push-action from 3 to 4
dependabot[bot] May 12, 2023
e246148
build(deps): bump github.com/prometheus/client_golang
dependabot[bot] May 12, 2023
58b12e7
Merge pull request #1289 from cloudflare/nicky/docker-arch
nickysemenza May 12, 2023
03a86ea
build(deps): bump github.com/jmoiron/sqlx from 1.3.3 to 1.3.5
dependabot[bot] May 12, 2023
f37a685
Merge pull request #1294 from cloudflare/dependabot/go_modules/github…
nickysemenza May 12, 2023
3e4a060
Merge pull request #1293 from cloudflare/dependabot/github_actions/do…
nickysemenza May 12, 2023
c1cdc1b
Merge pull request #1296 from cloudflare/dependabot/go_modules/github…
nickysemenza May 12, 2023
04f6d3e
build(deps): bump github.com/go-sql-driver/mysql from 1.6.0 to 1.7.1
dependabot[bot] May 12, 2023
be9f3a3
build(deps): bump github.com/lib/pq from 1.10.1 to 1.10.9
dependabot[bot] May 12, 2023
4a5a64d
bump github.com/zmap/zlint/v3 from 3.1.0 to 3.4.1
ahrtr May 12, 2023
bf9636a
update lint test for bumped zlint
nickysemenza May 12, 2023
11796e1
Merge pull request #1291 from ahrtr/bump_zlint_20230512
nickysemenza May 12, 2023
0d872f6
Merge pull request #1298 from cloudflare/dependabot/go_modules/github…
nickysemenza May 12, 2023
7bcbc6d
Merge pull request #1297 from cloudflare/dependabot/go_modules/github…
nickysemenza May 12, 2023
372ef3d
build(deps): bump github.com/google/certificate-transparency-go
dependabot[bot] May 12, 2023
9618eba
Merge pull request #1295 from cloudflare/dependabot/go_modules/github…
nickysemenza May 12, 2023
b2e0b85
Merge pull request #1290 from cloudflare/nicky/golang-cross-latest
nickysemenza May 12, 2023
7479ed6
build(deps): bump github.com/stretchr/testify from 1.8.0 to 1.8.2
dependabot[bot] May 15, 2023
21c13ab
build(deps): bump golang.org/x/crypto from 0.8.0 to 0.9.0
dependabot[bot] May 15, 2023
ce41e38
Merge pull request #1299 from cloudflare/dependabot/go_modules/github…
nickysemenza May 15, 2023
e1165bb
Merge pull request #1300 from cloudflare/dependabot/go_modules/golang…
nickysemenza May 15, 2023
b946db1
reenable vcs stamping with docker image that supports it
nickysemenza May 19, 2023
726dc22
build(deps): bump github.com/stretchr/testify from 1.8.2 to 1.8.3
dependabot[bot] May 22, 2023
c21e85d
Merge pull request #1303 from cloudflare/dependabot/go_modules/github…
nickysemenza May 22, 2023
5e37590
code optimization
testwill May 31, 2023
c46cc2b
build(deps): bump github.com/zmap/zlint/v3 from 3.4.1 to 3.5.0
dependabot[bot] Jun 12, 2023
9a0778d
Add support for generating ed25519 keys and certs (#1061)
izolight Jun 12, 2023
d042e64
Merge pull request #1309 from cloudflare/dependabot/go_modules/github…
nickysemenza Jun 12, 2023
6ea8605
Merge pull request #1063 from izolight/sha256-digest
nickysemenza Jun 12, 2023
c1a100a
build(deps): bump github.com/stretchr/testify from 1.8.3 to 1.8.4
dependabot[bot] Jun 12, 2023
68e04e2
Merge pull request #1302 from cloudflare/nicky/release-with-vcs
nickysemenza Jun 12, 2023
50f8789
Merge pull request #1304 from testwill/master
nickysemenza Jun 12, 2023
b447c47
Merge pull request #1305 from cloudflare/dependabot/go_modules/github…
nickysemenza Jun 12, 2023
1ba4686
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.16 to 1.14.17
dependabot[bot] Jun 12, 2023
3513646
Merge pull request #1306 from cloudflare/dependabot/go_modules/github…
nickysemenza Jun 12, 2023
682fa4a
build(deps): bump golang.org/x/crypto from 0.9.0 to 0.10.0
dependabot[bot] Jun 19, 2023
c6ac238
build(deps): bump github.com/prometheus/client_golang
dependabot[bot] Jun 19, 2023
277c524
Merge pull request #1310 from cloudflare/dependabot/go_modules/golang…
nickysemenza Jun 19, 2023
707f415
Merge pull request #1311 from cloudflare/dependabot/go_modules/github…
nickysemenza Jun 19, 2023
6619c79
Add DER support for gernerating and parsing CSR
Jun 26, 2023
f0549e3
Merge pull request #1312 from kongweiguo/add-csr-der
nickysemenza Jun 28, 2023
8d25f25
certdb/sql: remove uses of github.com/stretchr/testify/require
thaJeztah Nov 20, 2022
0f0664a
Merge pull request #1256 from thaJeztah/remove_testify
nickysemenza Aug 1, 2023
48e8f99
build(deps): bump golang.org/x/crypto from 0.10.0 to 0.12.0
dependabot[bot] Aug 7, 2023
f4c7545
Merge pull request #1316 from cloudflare/dependabot/go_modules/golang…
nickysemenza Aug 7, 2023
b97dede
build(deps): bump golang.org/x/crypto from 0.12.0 to 0.13.0
dependabot[bot] Sep 11, 2023
ff634d9
build(deps): bump actions/checkout from 3 to 4
dependabot[bot] Sep 11, 2023
465384f
Merge pull request #1322 from cloudflare/dependabot/github_actions/ac…
nickysemenza Sep 13, 2023
c448632
build(deps): bump docker/metadata-action from 4 to 5
dependabot[bot] Sep 18, 2023
47aa9b7
build(deps): bump docker/build-push-action from 4 to 5
dependabot[bot] Sep 18, 2023
4452a0e
build(deps): bump docker/login-action from 2 to 3
dependabot[bot] Sep 18, 2023
4adaa6a
build(deps): bump docker/setup-qemu-action from 2 to 3
dependabot[bot] Sep 18, 2023
7fc015e
Merge pull request #1324 from cloudflare/dependabot/github_actions/do…
nickysemenza Sep 18, 2023
2a88d0c
Merge pull request #1321 from cloudflare/dependabot/go_modules/golang…
nickysemenza Sep 18, 2023
78df137
Merge pull request #1326 from cloudflare/dependabot/github_actions/do…
nickysemenza Sep 18, 2023
73cd6b5
Merge pull request #1325 from cloudflare/dependabot/github_actions/do…
nickysemenza Sep 18, 2023
8a40f98
build(deps): bump docker/setup-buildx-action from 2 to 3
dependabot[bot] Sep 18, 2023
e95f50e
Merge pull request #1327 from cloudflare/dependabot/github_actions/do…
nickysemenza Sep 19, 2023
947f651
Merge pull request #1323 from cloudflare/dependabot/github_actions/do…
nickysemenza Oct 6, 2023
33c9f30
build(deps): bump golang.org/x/crypto from 0.13.0 to 0.14.0
dependabot[bot] Oct 9, 2023
00ef5b9
Merge pull request #1332 from cloudflare/dependabot/go_modules/golang…
nickysemenza Oct 9, 2023
f930541
build(deps): bump github.com/prometheus/client_golang
dependabot[bot] Oct 9, 2023
73b6dc9
build(deps): bump golang.org/x/net from 0.10.0 to 0.17.0
dependabot[bot] Oct 11, 2023
0784631
Merge pull request #1333 from cloudflare/dependabot/go_modules/golang…
nickysemenza Oct 23, 2023
e33630c
Merge pull request #1330 from cloudflare/dependabot/go_modules/github…
nickysemenza Oct 23, 2023
5690a91
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.17 to 1.14.18
dependabot[bot] Nov 6, 2023
df32d88
build(deps): bump github.com/google/certificate-transparency-go
dependabot[bot] Nov 6, 2023
8b0d1b8
Merge pull request #1336 from cloudflare/dependabot/go_modules/github…
nickysemenza Nov 9, 2023
86cf475
Merge pull request #1337 from cloudflare/dependabot/go_modules/github…
nickysemenza Nov 9, 2023
d124eca
build(deps): bump golang.org/x/crypto from 0.14.0 to 0.15.0
dependabot[bot] Nov 13, 2023
f47ec3b
Merge pull request #1338 from cloudflare/dependabot/go_modules/golang…
nickysemenza Nov 14, 2023
3d88142
build(deps): bump actions/setup-go from 4 to 5
dependabot[bot] Dec 11, 2023
7af0669
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.18 to 1.14.19
dependabot[bot] Dec 18, 2023
15955d7
build(deps): bump actions/upload-artifact from 3 to 4
dependabot[bot] Dec 18, 2023
9243529
build(deps): bump golang.org/x/crypto from 0.15.0 to 0.17.0
dependabot[bot] Dec 18, 2023
7e1c6cc
Merge pull request #1346 from cloudflare/dependabot/github_actions/ac…
nickysemenza Dec 20, 2023
6d4e660
Merge pull request #1347 from cloudflare/dependabot/go_modules/golang…
nickysemenza Dec 20, 2023
319a111
Merge pull request #1345 from cloudflare/dependabot/go_modules/github…
nickysemenza Dec 20, 2023
bbcbbe3
Merge pull request #1344 from cloudflare/dependabot/github_actions/ac…
nickysemenza Dec 20, 2023
2e59ba1
build(deps): bump github.com/prometheus/client_golang
dependabot[bot] Jan 1, 2024
dac37af
Merge pull request #1350 from cloudflare/dependabot/go_modules/github…
nickysemenza Jan 2, 2024
6410467
build(deps): bump golang.org/x/crypto from 0.17.0 to 0.18.0
dependabot[bot] Jan 15, 2024
753132f
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.19 to 1.14.20
dependabot[bot] Jan 29, 2024
aa40f70
Merge pull request #1353 from cloudflare/dependabot/go_modules/github…
nickysemenza Jan 31, 2024
8af55f6
Merge pull request #1352 from cloudflare/dependabot/go_modules/golang…
nickysemenza Jan 31, 2024
71dd338
build(deps): bump codecov/codecov-action from 3 to 4
dependabot[bot] Feb 5, 2024
710546a
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.20 to 1.14.22
dependabot[bot] Feb 5, 2024
ad3f22f
Merge pull request #1354 from cloudflare/dependabot/github_actions/co…
nickysemenza Feb 8, 2024
c53e678
Merge pull request #1355 from cloudflare/dependabot/go_modules/github…
nickysemenza Feb 8, 2024
5ac7cd9
Add unit test for custom extension supt
sthussey Feb 11, 2024
f19cf51
build(deps): bump golangci/golangci-lint-action from 3 to 4
dependabot[bot] Feb 12, 2024
ca7fd50
build(deps): bump golang.org/x/crypto from 0.18.0 to 0.19.0
dependabot[bot] Feb 12, 2024
4b17f8c
Merge pull request #1356 from cloudflare/dependabot/github_actions/go…
nickysemenza Feb 21, 2024
b7c3094
Merge pull request #1358 from cloudflare/dependabot/go_modules/golang…
nickysemenza Feb 21, 2024
02d4045
Merge pull request #1281 from sthussey/fix/selfsign-extensions
nickysemenza Feb 21, 2024
7f58e9c
Build images on base image for target platform
killianmuldoon Feb 22, 2024
0f5c14c
build(deps): bump github.com/prometheus/client_golang
dependabot[bot] Mar 4, 2024
44b96cf
Merge pull request #1360 from killianmuldoon/pr-fix-docker-build
nickysemenza Mar 5, 2024
96259aa
Merge pull request #1363 from cloudflare/dependabot/go_modules/github…
nickysemenza Mar 5, 2024
d13ac5d
build(deps): bump golang.org/x/crypto from 0.19.0 to 0.21.0
dependabot[bot] Mar 5, 2024
b4650b5
build(deps): bump github.com/go-sql-driver/mysql from 1.7.1 to 1.8.0
dependabot[bot] Mar 11, 2024
03f2681
Merge pull request #1365 from cloudflare/dependabot/go_modules/github…
nickysemenza Mar 11, 2024
361a3a5
Merge pull request #1364 from cloudflare/dependabot/go_modules/golang…
nickysemenza Mar 11, 2024
a421aee
build(deps): bump github.com/google/certificate-transparency-go
dependabot[bot] Mar 18, 2024
d6d030a
Merge pull request #1368 from cloudflare/dependabot/go_modules/github…
nickysemenza Mar 19, 2024
12a0add
Merge pull request #1055 from akoserwal/master
nickysemenza Jul 11, 2024
2adc622
Create semgrep.yml
hrushikeshdeshpande Sep 22, 2024
d3645c1
Update semgrep.yml
hrushikeshdeshpande Sep 25, 2024
91b63b5
Merge pull request #1395 from cloudflare/hrushikeshdeshpande-creating…
nickysemenza Oct 15, 2024
1a73d78
Upgrade certificate-transparency-go from v1.1.8 to v1.3.1
mitch292 Feb 7, 2025
cb0a0a3
Merge pull request #1408 from mitch292/mitch292/certificate-transpare…
vasilzhigilei Feb 7, 2025
14f61be
Revert "Upgrade certificate-transparency-go from v1.1.8 to v1.3.1"
mitch292 Feb 8, 2025
730ee58
Merge pull request #1409 from mitch292/mitch292/revert-ct-go-upgrade
mitch292 Feb 10, 2025
faaff55
Fixes #1237 partially by updating test data certificates to be valid
mitch292 Feb 8, 2025
1c1bc0b
Merge pull request #1410 from mitch292/mitch292/1237-fix-test-cases
mitch292 Feb 11, 2025
dd8f9ef
Github actions linter uses golangci-lint@v1.57
mitch292 Feb 13, 2025
6d2d0b2
Merge pull request #1412 from mitch292/mitch292/fix-linting
mitch292 Feb 14, 2025
a40f86c
Update repository to reflect required min go version of 1.20
mitch292 Feb 14, 2025
b898d2f
Merge pull request #1415 from mitch292/mitch292/go-version
mitch292 Feb 14, 2025
cd8a4de
ignore .git to .dockerignore
mschwarzl Feb 26, 2025
ed8df49
Merge pull request #1416 from cloudflare/mschwarzl/dockerignore
mschwarzl Feb 26, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
1 change: 1 addition & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -2,3 +2,4 @@ cfssl_*
*-amd64
*-386
dist/*
.git
12 changes: 12 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
version: 2
updates:
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly

- package-ecosystem: gomod
directory: /
schedule:
interval: weekly

49 changes: 33 additions & 16 deletions .github/workflows/docker-builds.yml
Original file line number Diff line number Diff line change
@@ -1,42 +1,59 @@
name: Build and publish cfssl docker image
name: cfssl docker

on:
workflow_dispatch:
push:
branches:
- "master"
tags:
- 'v*.*.*'

- "v*"
jobs:
build-and-push-image:
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
strategy:
matrix:
include:
# github container registry
- registry: "ghcr.io"
username: ${{ github.actor }}
password_secret: GITHUB_TOKEN
image: ghcr.io/cloudflare/cfssl
# docker test publish, todo: switch to service account
- registry: ""
username: nicky
password_secret: DOCKER_REGISTRY_TOKEN_NICKY
image: cfssl/cfssl
steps:
- name: Checkout repository
uses: actions/checkout@v3
uses: actions/checkout@v4
with:
fetch-depth: 0

- name: Get tag
id: cfssl
run: echo "::set-output name=tag::$(git describe --tags HEAD)"

- name: Set up QEMU
uses: docker/setup-qemu-action@v2
uses: docker/setup-qemu-action@v3

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v2
uses: docker/setup-buildx-action@v3

- name: Log in to the Docker hub
uses: docker/login-action@v2
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}

registry: ${{ matrix.registry }}
username: ${{ matrix.username }}
password: ${{ secrets[matrix.password_secret] }}
- name: Extract metadata (tags, labels) for Docker
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ matrix.image }}
- name: Build and push
uses: docker/build-push-action@v3
uses: docker/build-push-action@v5
with:
context: .
platforms: linux/amd64,linux/arm64,linux/s390x
push: true
tags: cfssl:${{ steps.cfssl.outputs.tag }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
26 changes: 18 additions & 8 deletions .github/workflows/go.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,11 @@ jobs:
runs-on: ubuntu-latest
strategy:
matrix:
go: ["1.18", "1.19"]
# starting with go 1.24 the GODEBUG=x509sha1=1 flag has been removed.
# many tests rely on sha1 certificates. After resolving #1413 we can
# run these on stable and oldstable again. Min version (1.20) can
# always be run.
go: ['1.23', '1.22', '1.20']
services:
# Label used to access the service container
postgres:
Expand Down Expand Up @@ -50,10 +54,10 @@ jobs:
- run: psql -c 'create database certdb_development;' -U postgres;
- run: mysql -e 'create database certdb_development;' -u root;
- run: mysql -e 'SET global sql_mode = 0;' -u root;
- uses: actions/checkout@v2
- uses: actions/checkout@v4

- name: Set up Go
uses: actions/setup-go@v2
uses: actions/setup-go@v5
with:
go-version: ${{ matrix.go }}

Expand All @@ -64,15 +68,21 @@ jobs:
- run: ./bin/goose -path certdb/mysql up;
- name: Test
run: ./test.sh
- uses: codecov/codecov-action@v3
- uses: codecov/codecov-action@v4

golangci:
name: lint
runs-on: ubuntu-latest
steps:
- uses: actions/setup-go@v3
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version: 1.18
- uses: actions/checkout@v3
go-version: "1.20"
- name: golangci-lint
uses: golangci/golangci-lint-action@v3
uses: golangci/golangci-lint-action@v6
with:
# There is a breaking change in 1.58 that causes the linter not to recognize
# internal imports or standard library imports and results in linting errors
# that cannot be ignored.
# e.g certdb/certdb.go:5:2: could not import encoding/json (Config.Importer.Import(encoding/json) returned nil but no error) (typecheck)
version: v1.57
24 changes: 24 additions & 0 deletions .github/workflows/semgrep.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
on:
pull_request: {}
workflow_dispatch: {}
push:
branches:
- main
- master
schedule:
- cron: '0 0 * * *'
name: Semgrep config
jobs:
semgrep:
name: semgrep/ci
runs-on: ubuntu-latest
env:
SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}
SEMGREP_URL: https://cloudflare.semgrep.dev
SEMGREP_APP_URL: https://cloudflare.semgrep.dev
SEMGREP_VERSION_CHECK_URL: https://cloudflare.semgrep.dev/api/check-version
container:
image: semgrep/semgrep
steps:
- uses: actions/checkout@v4
- run: semgrep ci
18 changes: 18 additions & 0 deletions .github/workflows/snapshot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
name: Image snapshots

on:
push:
pull_request:
branches: [master]

jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- run: make snapshot
- name: Archive snapshot artifacts
uses: actions/upload-artifact@v4
with:
name: binaries
path: dist/
2 changes: 0 additions & 2 deletions .golangci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,4 @@ linters:
- gosimple
- ineffassign
- unused
- deadcode
- errcheck
- varcheck
8 changes: 8 additions & 0 deletions .goreleaser.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ builds:
- linux
goarch:
- amd64
- arm
- arm64
- s390x
main: ./cmd/cfssl
Expand Down Expand Up @@ -60,6 +61,7 @@ builds:
- linux
goarch:
- amd64
- arm
- arm64
- s390x
main: ./cmd/cfssl-bundle
Expand Down Expand Up @@ -96,6 +98,7 @@ builds:
- linux
goarch:
- amd64
- arm
- arm64
- s390x
main: ./cmd/cfssl-certinfo
Expand Down Expand Up @@ -132,6 +135,7 @@ builds:
- linux
goarch:
- amd64
- arm
- arm64
- s390x
main: ./cmd/cfssl-newkey
Expand Down Expand Up @@ -168,6 +172,7 @@ builds:
- linux
goarch:
- amd64
- arm
- arm64
- s390x
main: ./cmd/cfssl-scan
Expand Down Expand Up @@ -204,6 +209,7 @@ builds:
- linux
goarch:
- amd64
- arm
- arm64
- s390x
main: ./cmd/cfssljson
Expand Down Expand Up @@ -240,6 +246,7 @@ builds:
- linux
goarch:
- amd64
- arm
- arm64
- s390x
main: ./cmd/mkbundle
Expand Down Expand Up @@ -276,6 +283,7 @@ builds:
- linux
goarch:
- amd64
- arm
- arm64
- s390x
main: ./cmd/multirootca
Expand Down
9 changes: 8 additions & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,11 @@
FROM --platform=${BUILDPLATFORM} golang:1.19.3
FROM --platform=${TARGETPLATFORM} golang:1.20

ARG TARGETPLATFORM
ARG BUILDPLATFORM
RUN echo "I am running on $BUILDPLATFORM, building for $TARGETPLATFORM"

LABEL org.opencontainers.image.source https://github.com/cloudflare/cfssl
LABEL org.opencontainers.image.description "Cloudflare's PKI toolkit"

ARG TARGETOS
ARG TARGETARCH
Expand Down
2 changes: 1 addition & 1 deletion Dockerfile.alpine
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM golang:1.16.15-alpine3.15@sha256:9743f230f26d1e300545f0330fd4a514f554c535d967563ee77bf634906502b6 as builder
FROM golang:1.20-alpine AS builder

WORKDIR /workdir
COPY . /workdir
Expand Down
13 changes: 3 additions & 10 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ snapshot:
--rm \
-v $(PWD):/cross \
-w /cross \
ghcr.io/gythialy/golang-cross:v1.18 --rm-dist --snapshot --skip-publish
ghcr.io/goreleaser/goreleaser-cross:latest --clean --snapshot --skip=publish

.PHONY: github-release
github-release:
Expand All @@ -71,17 +71,10 @@ github-release:
-e GITHUB_TOKEN=$(GITHUB_TOKEN) \
-v $(PWD):/cross \
-w /cross \
ghcr.io/gythialy/golang-cross:v1.18 --rm-dist

.PHONY: docker-build
docker-build:
docker build -f Dockerfile -t cfssl/cfssl:$(VERSION) .
.PHONY: docker-push
docker-push:
docker push cfssl/cfssl:$(VERSION)
ghcr.io/goreleaser/goreleaser-cross:latest --clean

.PHONY: release
release: github-release docker-build docker-push
release: github-release

BUILD_PATH := $(CURDIR)/build
INSTALL_PATH := $(BUILD_PATH)/usr/local/bin
Expand Down
30 changes: 4 additions & 26 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@

CFSSL is CloudFlare's PKI/TLS swiss army knife. It is both a command line
tool and an HTTP API server for signing, verifying, and bundling TLS
certificates. It requires Go 1.16+ to build.
certificates. It requires Go 1.20+ to build.

Note that certain linux distributions have certain algorithms removed
(RHEL-based distributions in particular), so the golang from the
Expand All @@ -30,12 +30,13 @@ CFSSL consists of:
### Building

Building cfssl requires a
[working Go 1.16+ installation](http://golang.org/doc/install).
[working Go 1.20+ installation](http://golang.org/doc/install).

```
$ git clone git@github.com:cloudflare/cfssl.git
$ cd cfssl
$ make
$ make install
```

The resulting binaries will be in the bin folder:
Expand All @@ -60,32 +61,9 @@ You can set the `GOOS` and `GOARCH` environment variables to have Go cross compi

### Installation

Installation requires a [working Go 1.16+ installation](http://golang.org/doc/install).
Installation requires a [working Go 1.20+ installation](http://golang.org/doc/install).
Alternatively, [prebuilt binaries are available](https://github.com/cloudflare/cfssl/releases)

```
$ go get github.com/cloudflare/cfssl/cmd/cfssl
```

will download, build, and install the CFSSL tool.

To install any of the other utility programs that are
in this repo (for instance `cfssljson` in this case):

```
$ go get github.com/cloudflare/cfssl/cmd/cfssljson
```

This will download, build, and install the CFSSLJSON tool.

And to simply install __all__ of the programs in this repo:

```
$ go get github.com/cloudflare/cfssl/cmd/...
```

if you are above go 1.18:

```
$ go install github.com/cloudflare/cfssl/cmd/...@latest
```
Expand Down
1 change: 0 additions & 1 deletion api/bundle/bundle_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -184,7 +184,6 @@ var bundleTests = []bundleTest{
}

func TestBundle(t *testing.T) {
t.Skip("expired cert https://github.com/cloudflare/cfssl/issues/1237")
for i, test := range bundleTests {
resp, body := testBundleFile(t, test.Domain, test.IP, test.CertFile, test.KeyFile, test.Flavor)
if resp.StatusCode != test.ExpectedHTTPStatus {
Expand Down
Loading