More efficient challenge waiting

This commit is contained in:
Fang-Pen Lin
2025-12-01 18:51:48 -08:00
parent a2774bd18e
commit 27d027519b
2 changed files with 20 additions and 11 deletions
+19 -11
View File
@@ -797,21 +797,25 @@ def select_challenge(
return challenges[0] return challenges[0]
def serve_challenge( def serve_challenges(
context: Context, context: Context,
challenge: messages.ChallengeBody, challenges: list[messages.ChallengeBody],
): ):
if hasattr(context, "web_server"): if hasattr(context, "web_server"):
context.web_server.shutdown_and_server_close() context.web_server.shutdown_and_server_close()
response, validation = challenge.response_and_validation( resources = set()
context.acme_client.net.key for challenge in challenges:
) response, validation = challenge.response_and_validation(
resource = standalone.HTTP01RequestHandler.HTTP01Resource( context.acme_client.net.key
chall=challenge.chall, response=response, validation=validation )
) resources.add(
standalone.HTTP01RequestHandler.HTTP01Resource(
chall=challenge.chall, response=response, validation=validation
)
)
# TODO: make port configurable # TODO: make port configurable
servers = standalone.HTTP01DualNetworkedServers(("0.0.0.0", 8087), {resource}) servers = standalone.HTTP01DualNetworkedServers(("0.0.0.0", 8087), resources)
servers.serve_forever() servers.serve_forever()
context.web_server = servers context.web_server = servers
@@ -865,6 +869,7 @@ def step_impl(
f"Expected OrderResource but got {type(order)!r} at {order_var_path!r}" f"Expected OrderResource but got {type(order)!r} at {order_var_path!r}"
) )
challenges = {}
for domain in order.body.identifiers: for domain in order.body.identifiers:
logger.info( logger.info(
"Selecting challenge for domain %s with type %s ...", "Selecting challenge for domain %s with type %s ...",
@@ -877,6 +882,7 @@ def step_impl(
domain=domain.value, domain=domain.value,
order_var_path=order_var_path, order_var_path=order_var_path,
) )
print("@" * 20, domain, challenge.chall.path)
logger.info( logger.info(
"Found challenge for domain %s with type %s, challenge=%s", "Found challenge for domain %s with type %s, challenge=%s",
domain.value, domain.value,
@@ -889,8 +895,10 @@ def step_impl(
domain.value, domain.value,
challenge_type, challenge_type,
) )
serve_challenge(context=context, challenge=challenge) challenges[domain] = challenge
serve_challenges(context=context, challenges=list(challenges.values()))
for domain, challenge in challenges.items():
logger.info( logger.info(
"Notifying challenge for domain %s with type %s ...", domain, challenge_type "Notifying challenge for domain %s with type %s ...", domain, challenge_type
) )
@@ -900,7 +908,7 @@ def step_impl(
@then("I serve challenge response for {var_path} at {hostname}") @then("I serve challenge response for {var_path} at {hostname}")
def step_impl(context: Context, var_path: str, hostname: str): def step_impl(context: Context, var_path: str, hostname: str):
challenge = eval_var(context, var_path, as_json=False) challenge = eval_var(context, var_path, as_json=False)
serve_challenge(context=context, challenge=challenge) serve_challenges(context=context, challenges=[challenge])
@then("I tell ACME server that {var_path} is ready to be verified") @then("I tell ACME server that {var_path} is ready to be verified")
@@ -111,6 +111,7 @@ export const pkiAcmeChallengeServiceFactory = ({
if (challengeResponseBody.trimEnd() !== expectedChallengeResponseBody) { if (challengeResponseBody.trimEnd() !== expectedChallengeResponseBody) {
throw new AcmeIncorrectResponseError({ message: "ACME challenge response is not correct" }); throw new AcmeIncorrectResponseError({ message: "ACME challenge response is not correct" });
} }
logger.info({ challengeId }, "ACME challenge response is correct, marking challenge as valid");
await acmeChallengeDAL.markAsValidCascadeById(challengeId); await acmeChallengeDAL.markAsValidCascadeById(challengeId);
} catch (exp) { } catch (exp) {
if (retryCount >= 2) { if (retryCount >= 2) {