v2.41.0 (setup that closes, tests that need the right role)
A security release. Security reports sent to the project in private were
re-verified against the current code. Four were already fixed in earlier
releases. The rest are fixed here, together with a regression that a
v2.36.0 change had introduced. The advisories are published on the
repository's Security page, crediting their reporters. Also included:
Akamai Edge DNS waits long enough for its own nameservers.
Upgrade. Several of these changes alter what an operator sees. The next
section lists them.
The API contract moves to 2.32, from 2.29. Read it from
X-CertMate-API-Version on any response, or api_contract_version in
/api/health. Each step is written down beside the constant in
modules/core/constants.py.
| step | what changed |
|---|---|
| 2.30 | dns_propagation_seconds is returned by GET /api/settings (#997)
|
| 2.31 | POST /api/storage/test and POST /api/settings/test-ca-provider require admin (#999)
|
| 2.32 | setup mode refuses what outlives it, and the first admin closes it (#1001) |
2.31 and 2.32 answer existing requests differently, which the contract rule
would count as MAJOR. They are counted as the security fixes they are, on the
precedent set by 2.7.
Read this before upgrading
Setup mode ends with the first admin
A fresh instance with no credential yet (no user with local login, no
API_BEARER_TOKEN, no OIDC) serves every caller as admin, so it can be set
up. That window is now smaller and shorter.
- The first admin closes it. Creating the first admin also enables local
login, and the response says so ("local_auth_enabled": true). The setup
page no longer makes a second request. A script that still calls
POST /api/auth/configafterwards gets401, because the instance is
already closed. The end state is the same. - Until it closes, setup mode refuses deploy-hook changes, tests and runs,
certificate and key downloads, and backup creation and download
(409 SETUP_BOOTSTRAP_ONLY). Restoring and uploading a backup stay allowed,
because that is how an instance is recovered onto a fresh host.
If an instance of yours was reachable while still in setup mode, look at
its deploy hooks (Settings → Deploy) and its API keys. A hook saved in that
window was saved by whoever could reach it, and nothing recorded who.
Connection tests are admin-only
The Test connection buttons for a storage backend and for a CA provider
took a whole configuration in the request and made the server connect with
it. Saving that configuration was already admin-only; testing it needed only
operator. Both now require admin. An operator who used them gets 403.
Akamai Edge DNS waits 180 seconds, and the wait is editable
CertMate told certbot to wait 90 seconds after publishing a DNS-01 record on
Akamai Edge DNS. The Akamai plugin's own default is 180, and its
documentation suggests 240. Edge DNS takes minutes to reach all of its
nameservers, which is where Let's Encrypt looks, and orders failed with
"Some challenges have failed" (#974).
- The default is 180. An install that still has the old default stored
moves to 180 once. A value you chose stays. - Settings → DNS now shows and edits the wait for the selected provider.
Until now it could only be changed by editingsettings.jsonby hand.
Fixed
- The login page's
nextparameter could send a user to another site
after logging in, through a value the check parsed correctly and then
rebuilt differently. The v2.36.0 change to that check introduced it. The
check now verifies the exact value it returns (#998). - Setup mode (#1001) and connection tests (#999), as described above.
Documentation
- Deploy hooks. The page said references to CertMate's sensitive files
are "rejected outright". The check matches the names as written, so a glob
or a name split by quotes gets past it. It guards against accidents; it is
not a security boundary, and it never claimed to be in SECURITY.md. The
page now says so, in five languages (#1002).
How it was checked
Each report was reproduced against the release before this one, by running
its proof of concept on a real instance, before anything was changed.
- Login redirect: in Chrome, the hostile
nextnow stays on the site
after login, and a legitimate one still reaches its page. - Setup: on a fresh instance in a browser, the setup page posts the first
admin and lands on the login page without a second request. The refused
routes answer 409 in setup mode, and a hook command sent then never
executes. - Connection tests: a local listener records no connection when an
operator calls them, and still one when an admin does.
The test harness changed with this release. The shared container of the
end-to-end suite now runs with a bearer token, like any instance past its
first minutes, while the browser suite still bootstraps it the way a person
does. The real-certificate tests of the release gate ran against Let's
Encrypt staging with that harness.