Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .cz.toml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,6 @@
name = "cz_conventional_commits"
tag_format = "$version"
version_scheme = "semver"
version = "0.14.3"
version = "0.15.0"
update_changelog_on_bump = false
major_version_zero = true
8 changes: 4 additions & 4 deletions .github/workflows/codeChecks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ jobs:
strategy:
max-parallel: 2
matrix:
go-version: ["1.26.7"]
go-version: ["1.27.0"]
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Expand All @@ -47,7 +47,7 @@ jobs:
strategy:
max-parallel: 2
matrix:
go-version: ["1.26.7"]
go-version: ["1.27.0"]

steps:
- name: Checkout
Expand All @@ -74,7 +74,7 @@ jobs:
strategy:
max-parallel: 2
matrix:
go-version: ["1.26.7"]
go-version: ["1.27.0"]

steps:
- name: Checkout
Expand Down Expand Up @@ -103,7 +103,7 @@ jobs:
- uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: "1.26.7"
go-version: "1.27.0"

- name: generate test coverage
run: go test ./... -coverprofile=./cover.out -covermode=atomic -coverpkg=./...
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ permissions:
env:
CGO_ENABLED: 0
DOCKER_CLI_EXPERIMENTAL: "enabled"
GO_VERSION: "1.26.7"
GO_VERSION: "1.27.0"

jobs:
code-checks:
Expand Down
1 change: 0 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,6 @@ tests
internal/requests/testdata
internal/certinfo/testdata/*Cert*
manpages
vendor

# ---> Go
# If you prefer the allow list template instead of the deny list, see community template:
Expand Down
10 changes: 10 additions & 0 deletions .golangci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -67,10 +67,20 @@ linters:
exclude: [""]
arguments: [15]

- name: epoch-naming
disabled: true

- name: unhandled-error
severity: warning
disabled: false
exclude: [""]
arguments:
- "fmt.Print"
- "fmt.Printf"
- "fmt.Println"
- "fmt.Fprint"
- "fmt.Fprintf"
- "fmt.Fprintln"

exclusions:
generated: lax
Expand Down
10 changes: 10 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,15 @@
# https-wrench - changelog

## 0.15.0 (2026-09-02)

### CI

switch to Go 1.27.0

### Feat

Certinfo: add initial support for Post Quantum Key Echange Mechanisms

## 0.14.3 (2026-08-23)

### CI
Expand Down
61 changes: 61 additions & 0 deletions Taskfile.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
version: "3"

tasks:
goreleaser:test:pkg:
internal: true
desc: Test a package installation
vars:
CONTAINER_NAME: "test-{{.Image}}-{{.Platform}}"
cmds:
- defer: docker rm -f {{.CONTAINER_NAME}}
- docker create --name {{.CONTAINER_NAME}} --platform linux/{{.Platform}} --workdir /tmp {{.Image}} sh -c 'ls -la /tmp && {{.Cmd}} && https-wrench --version'
- docker cp {{.TASKFILE_DIR}}/dist/. {{.CONTAINER_NAME}}:/tmp/
- docker start -a {{.CONTAINER_NAME}}

goreleaser:test:rpm:
desc: Tests rpm packages
vars:
RPM_INSTALL: "rpm --nodeps -ivh"
cmds:
- task: goreleaser:test:pkg
vars:
Platform: "amd64"
Image: fedora
Cmd: "{{.RPM_INSTALL}} https-wrench*_linux_amd64.rpm"
- task: goreleaser:test:pkg
vars:
Platform: "arm64"
Image: fedora
Cmd: "{{.RPM_INSTALL}} https-wrench*_linux_arm64.rpm"

goreleaser:test:deb:
desc: Tests deb packages
vars:
DPKG_INSTALL: "dpkg --ignore-depends=git -i"
cmds:
- task: goreleaser:test:pkg
vars:
Platform: "amd64"
Image: ubuntu
Cmd: "{{.DPKG_INSTALL}} https-wrench*_linux_amd64.deb"
- task: goreleaser:test:pkg
vars:
Platform: "arm64"
Image: ubuntu
Cmd: "{{.DPKG_INSTALL}} https-wrench*_linux_arm64.deb"

goreleaser:test:apk:
desc: Tests apk packages
vars:
APK_INSTALL: "apk add --allow-untrusted -U"
cmds:
- task: goreleaser:test:pkg
vars:
Platform: "amd64"
Image: alpine
Cmd: "{{.APK_INSTALL}} https-wrench*_linux_amd64.apk"
- task: goreleaser:test:pkg
vars:
Platform: "arm64"
Image: alpine
Cmd: "{{.APK_INSTALL}} https-wrench*_linux_arm64.apk"
58 changes: 18 additions & 40 deletions devenv.lock
Original file line number Diff line number Diff line change
Expand Up @@ -3,11 +3,11 @@
"devenv": {
"locked": {
"dir": "src/modules",
"lastModified": 1778281489,
"narHash": "sha256-q/E8JCHXLp7+T/SfSR3vN9KjDtCi5lB0xdgh4LcEOJc=",
"lastModified": 1788303825,
"narHash": "sha256-R1tqmYSV5yVTqmy+uISsSn+eEiqgW0F49orOHCOBSts=",
"owner": "cachix",
"repo": "devenv",
"rev": "23120f1b923e80a27facbeb59433688772e854ab",
"rev": "df5c75a82c3ac3d70a13c90fb869b7e44470a118",
"type": "github"
},
"original": {
Expand Down Expand Up @@ -36,15 +36,14 @@
"git-hooks": {
"inputs": {
"flake-compat": "flake-compat",
"gitignore": "gitignore",
"nixpkgs": "nixpkgs"
},
"locked": {
"lastModified": 1776796298,
"narHash": "sha256-PcRvlWayisPSjd0UcRQbhG8Oqw78AcPE6x872cPRHN8=",
"lastModified": 1788267358,
"narHash": "sha256-nt+lUqYVpc9Y6JeMd2WmXzCDojasdadKo0mWcluvY2Y=",
"owner": "cachix",
"repo": "git-hooks.nix",
"rev": "3cfd774b0a530725a077e17354fbdb87ea1c4aad",
"rev": "27555e2624241fb116b49095df4caaee85a25691",
"type": "github"
},
"original": {
Expand All @@ -53,34 +52,13 @@
"type": "github"
}
},
"gitignore": {
"inputs": {
"nixpkgs": [
"git-hooks",
"nixpkgs"
]
},
"locked": {
"lastModified": 1709087332,
"narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=",
"owner": "hercules-ci",
"repo": "gitignore.nix",
"rev": "637db329424fd7e46cf4185293b9cc8c88c95394",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "gitignore.nix",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1770073757,
"narHash": "sha256-Vy+G+F+3E/Tl+GMNgiHl9Pah2DgShmIUBJXmbiQPHbI=",
"lastModified": 1787631388,
"narHash": "sha256-vMiXptXarfSdJb1Gkc+FYVOAibuBRj7qxGa8z68q1Uw=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "47472570b1e607482890801aeaf29bfb749884f6",
"rev": "ac6b2166e7a9375683b8e98f860f273222337b16",
"type": "github"
},
"original": {
Expand All @@ -93,11 +71,11 @@
"nixpkgs-src": {
"flake": false,
"locked": {
"lastModified": 1777826146,
"narHash": "sha256-wQ/iN5Zp5VIa3ebBibijPnLyKhor+xEbDy4d0goa9Zs=",
"lastModified": 1787394516,
"narHash": "sha256-pRGOQSClnXNI2iLUG6DYpsGvYcuw0drOutVZFTJNw90=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "73c703c22422b8951895a960959dbbaca7296492",
"rev": "c8f90650c15282fa8656a041bfbbd2403997a9a7",
"type": "github"
},
"original": {
Expand All @@ -109,11 +87,11 @@
},
"nixpkgs-stable": {
"locked": {
"lastModified": 1778003029,
"narHash": "sha256-q/nkKLDtHIyLjZpKhWk3cSK5IYsFqtMd6UtXF3ddjgA=",
"lastModified": 1782847189,
"narHash": "sha256-twXPFqFsrrY5r28Zh7Homgcp2gUMBgQ6WDS98Q/3xFI=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "0c88e1f2bdb93d5999019e99cb0e61e1fe2af4c5",
"rev": "b6018f87da91d19d0ab4cf979885689b469cdd41",
"type": "github"
},
"original": {
Expand All @@ -128,11 +106,11 @@
"nixpkgs-src": "nixpkgs-src"
},
"locked": {
"lastModified": 1778017947,
"narHash": "sha256-Qp52wvK3Bq854SSLC8cJ6H6cokQ96qhgBHcyynRjkW8=",
"lastModified": 1787753358,
"narHash": "sha256-Tl77VbWyAKrOfRNQhL6JbQtb/MLzbYa/1RG1gWWfICk=",
"owner": "cachix",
"repo": "devenv-nixpkgs",
"rev": "5941ed7aa58a1651f373ccfd5a106e1597ec8dd6",
"rev": "256551e45f6303e142ab4a98be1bf243feb77dc0",
"type": "github"
},
"original": {
Expand Down
60 changes: 51 additions & 9 deletions devenv.nix
Original file line number Diff line number Diff line change
Expand Up @@ -4,15 +4,18 @@
config,
inputs,
...
}: let
pkgs-stable = import inputs.nixpkgs-stable {system = pkgs.stdenv.system;};
in {
}:
let
pkgs-stable = import inputs.nixpkgs-stable { system = pkgs.stdenv.system; };
in
{
env = {
GUM_FORMAT_THEME = "tokyo-night";
CAROOT = "tests/certs";
EXAMPLES = "assets/examples";
ED25519_DIR = "tests/certs/ed25519_cert";
ECDSA_DIR = "tests/certs/ecdsa-cert";
MLDSA_DIR = "tests/certs/mldsa-cert";
KEY_TEST_PW = "testpassword";
CGO_ENABLE = "0";
OS76_DOCKER_REGISTRY = "registry.0.os76.xyz";
Expand Down Expand Up @@ -78,11 +81,11 @@ in {
#
# Mozilla SSL Configuration Generator
#
# https://ssl-config.mozilla.org/#server=nginx&version=1.27.3&config=intermediate&openssl=3.4.0&guideline=5.7
#
# generated 2026-09-01, TLSRef Guideline v6.0, nginx 1.27.3, OpenSSL 4.0.1, intermediate config, HSTS, gitrev=d96f668
# https://configurator.tlsref.org/#server=nginx&version=1.27.3&config=intermediate&openssl=4.0.1&hsts&guideline=6.0
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ecdh_curve X25519:prime256v1:secp384r1;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305;
ssl_ecdh_curve X25519MLKEM768:X25519:prime256v1:secp384r1;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305;
ssl_prefer_server_ciphers off;
ssl_certificate ${config.env.DEVENV_ROOT}/${config.env.CAROOT}/full-cert.pem;
ssl_certificate_key ${config.env.DEVENV_ROOT}/${config.env.CAROOT}/key.pem;
Expand Down Expand Up @@ -152,6 +155,21 @@ in {
proxy_set_header X-Forwarded-For $remote_addr;
}
}

server {
server_name _;
root ${config.env.DEVENV_ROOT};
ssl_certificate ${config.env.DEVENV_ROOT}/${config.env.MLDSA_DIR}/mldsa.crt;
ssl_certificate_key ${config.env.DEVENV_ROOT}/${config.env.MLDSA_DIR}/mldsa.key;
listen 9447 ssl;
listen [::]:9447 ssl;
http2 on;
location / {
proxy_pass http://localhost:8080;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $remote_addr;
}
}
'';
};

Expand All @@ -164,7 +182,7 @@ in {
test -d ${config.env.DEVENV_ROOT}/tests && rm -rf ${config.env.DEVENV_ROOT}/tests
create-certs
'';
before = ["devenv:processes:nginx"];
before = [ "devenv:processes:nginx" ];
};

scripts.hello.exec = ''
Expand Down Expand Up @@ -241,12 +259,36 @@ in {

test -f $ED25519_DIR/ed25519.crt || openssl req -new -x509 -key $ED25519_DIR/ed25519.key -days 365 -out $ED25519_DIR/ed25519.crt \
-subj "/CN=example.com/O=Example Org" -addext "subjectAltName=DNS:example.com,IP:127.0.0.1"

# MLDSA_DIR=$CAROOT/mldsa-cert
test -d $MLDSA_DIR || mkdir $MLDSA_DIR
test -f $MLDSA_DIR/mldsa.key || openssl genpkey -algorithm ML-DSA-65 -out $MLDSA_DIR/mldsa.key
test -f $MLDSA_DIR/mldsa.pub || openssl pkey -in $MLDSA_DIR/mldsa.key -pubout -out $MLDSA_DIR/mldsa.pub

test -f $MLDSA_DIR/encrypted.mldsa.key || openssl pkey -in $MLDSA_DIR/mldsa.key -out $MLDSA_DIR/encrypted.mldsa.key -aes256 -passout pass:$KEY_TEST_PW
test -f $MLDSA_DIR/encrypted.mldsa.pub || openssl pkey -passin pass:$KEY_TEST_PW -in $MLDSA_DIR/encrypted.mldsa.key -pubout -out $MLDSA_DIR/encrypted.mldsa.pub

test -f $MLDSA_DIR/mldsa.crt || openssl req -new -x509 -key $MLDSA_DIR/mldsa.key -days 365 -out $MLDSA_DIR/mldsa.crt \
-subj "/CN=example.com/O=Example Org" \
-addext "subjectAltName=DNS:example.com,DNS:localhost,IP:127.0.0.1"
'';

scripts.test-curl.exec = ''
curl "https://localhost:9443/get" -k -v
'';

scripts.certinfo-pq-vhost = {
description = "Connect to the local ML-DSA nginx vhost (:9447) and print cert + TLS info";
exec = ''
gum format "## PQ vhost TLS (localhost:9447, ML-DSA-65)"
./dist/https-wrench certinfo \
--tls-endpoint localhost:9447 \
--tls-servername example.com \
--ca-bundle "$MLDSA_DIR/mldsa.crt" \
--tls-info
'';
};

scripts.test-cmd-root-version.exec = ''
gum format "## Command root --version"
./dist/https-wrench --version 2>&1 | grep -E '[0-9]\.+'
Expand Down Expand Up @@ -705,7 +747,7 @@ in {
'';

enterShell = ''
gum format "# Devenv shell"
echo "https-wrench devenv ready"
go version
create-certs
'';
Expand Down
Loading
Loading