view docker/backend-dev-e2e/certificates/README @ 3700:cfc06915de15

plugin email invitations: re-use existing invitation for a given email: if an invitation is done on an email which has already received an invitation, it is re-used and no new XMPP account or Libervia profile is created (the name is modified though). This is currently done in an inefficient way due to `LazyPersistentBinaryDict` limitations (all invitations are loaded and checked to find the email). A more efficient check should be easier to implement with storage changes in 0.9 .
author Goffi <goffi@goffi.org>
date Fri, 05 Nov 2021 18:11:18 +0100
parents 73e04040d577
children
line wrap: on
line source

Those certificates are used to activate TLS for end-2-end testing (to be as
close as possible as production environment), they are used in other containers
needing TLS certificates (notably Prosody).

To generate them, minica has been used. Minica can be found at https://github.com/jsha/minica.

The following commands have been used:

$ minica --domains "server1.test,*.server1.test,server2.test,server3.test,libervia-backend.test,libervia-web.test"
$ chmod 0644 minica.pem server1.test/cert.pem && chmod 0640 server1.test/key.pem

Note that certificates are valid for 2 years and 30 days, so they must be renewed after this delay.