diff --git a/common/tls/acme.go b/common/tls/acme.go index d576fc6b1..7491255a1 100644 --- a/common/tls/acme.go +++ b/common/tls/acme.go @@ -69,10 +69,21 @@ func startACME(ctx context.Context, logger logger.Logger, options option.Inbound Storage: storage, Logger: zapLogger, } + profile := options.Profile + if profile == "" && acmeServer == certmagic.LetsEncryptProductionCA { + for _, domain := range options.Domain { + if certmagic.SubjectIsIP(domain) { + profile = "shortlived" + break + } + } + } + acmeConfig := certmagic.ACMEIssuer{ CA: acmeServer, Email: options.Email, Agreed: true, + Profile: profile, DisableHTTPChallenge: options.DisableHTTPChallenge, DisableTLSALPNChallenge: options.DisableTLSALPNChallenge, AltHTTPPort: int(options.AlternativeHTTPPort), diff --git a/option/acme.go b/option/acme.go index 79260b5df..31efffce1 100644 --- a/option/acme.go +++ b/option/acme.go @@ -24,6 +24,7 @@ type ACMECertificateProviderOptions struct { ExternalAccount *ACMEExternalAccountOptions `json:"external_account,omitempty"` DNS01Challenge *ACMEProviderDNS01ChallengeOptions `json:"dns01_challenge,omitempty"` KeyType ACMEKeyType `json:"key_type,omitempty"` + Profile string `json:"profile,omitempty"` HTTPClient *HTTPClientOptions `json:"http_client,omitempty"` } diff --git a/option/tls_acme.go b/option/tls_acme.go index 6dd8fa708..636abc6ec 100644 --- a/option/tls_acme.go +++ b/option/tls_acme.go @@ -20,6 +20,7 @@ type InboundACMEOptions struct { AlternativeTLSPort uint16 `json:"alternative_tls_port,omitempty"` ExternalAccount *ACMEExternalAccountOptions `json:"external_account,omitempty"` DNS01Challenge *ACMEDNS01ChallengeOptions `json:"dns01_challenge,omitempty"` + Profile string `json:"profile,omitempty"` } type ACMEExternalAccountOptions struct { diff --git a/service/acme/service.go b/service/acme/service.go index b29be131f..b73ffb9da 100644 --- a/service/acme/service.go +++ b/service/acme/service.go @@ -112,11 +112,22 @@ func NewCertificateProvider(ctx context.Context, logger log.ContextLogger, tag s config.KeySource = certmagic.StandardKeyGenerator{KeyType: keyType} } + profile := options.Profile + if profile == "" && acmeServer == certmagic.LetsEncryptProductionCA { + for _, domain := range options.Domain { + if certmagic.SubjectIsIP(domain) { + profile = "shortlived" + break + } + } + } + acmeIssuer := certmagic.ACMEIssuer{ CA: acmeServer, Email: options.Email, AccountKeyPEM: options.AccountKey, Agreed: true, + Profile: profile, DisableHTTPChallenge: options.DisableHTTPChallenge, DisableTLSALPNChallenge: options.DisableTLSALPNChallenge, AltHTTPPort: int(options.AlternativeHTTPPort),