• Bug#1102030: lacme: wildcard subjectAltName rejected with "Warning: Ign

    From Sam Birch@21:1/5 to All on Fri Apr 4 03:20:01 2025
    Package: lacme
    Version: 0.8.2-1
    Severity: wishlist

    Dear Maintainer,

    With this certificate config file:

    [main]
    certificate = /etc/ssl/lacme/main.pem
    certificate-chain = /etc/ssl/lacme/main-fullchain.pem
    certificate-key = /etc/ssl/lacme/main.key
    subject = /CN=host.domainA.example
    subjectAltName = DNS:*.domainB.example
    owner = root:ssl-cert
    notify = /usr/bin/systemctl reload nginx

    And this command:

    lacme newOrder

    lacme complains:

    [main] Warning: Ignoring invalid domain *.domainB.example

    (Domain names changed for privacy.)

    I am not sure what would need to happen to support wildcard certs, but I
    would very much enjoy having that support.

    Thanks,
    -sam

    P.S.: I am sorry that I am reporting from a somewhat old Ubuntu system. I looked in your git repo and the same behavior seems to be present in the
    latest version of lacme.

    -- System Information:
    Debian Release: trixie/sid
    APT prefers noble-updates
    APT policy: (500, 'noble-updates'), (500, 'noble-security'), (500, 'noble'), (100, 'noble-backports')
    Architecture: amd64 (x86_64)

    Kernel: Linux 6.8.0-57-generic (SMP w/12 CPU threads; PREEMPT)
    Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE
    Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
    Shell: /bin/sh linked to /usr/bin/dash
    Init: systemd (via /run/systemd/system)
    LSM: AppArmor: enabled

    Versions of packages lacme depends on:
    ii adduser 3.137ubuntu1
    ii libconfig-tiny-perl 2.30-1
    ii libjson-perl 4.10000-1
    ii libnet-ssleay-perl 1.94-1build4
    ii libtimedate-perl 2.3300-2
    ii libwww-perl 6.76-1
    ii openssl 3.0.13-0ubuntu3.5
    ii perl 5.38.2-3.2build2.1

    Versions of packages lacme recommends:
    ii lacme-accountd 0.8.2-1
    ii liblwp-protocol-https-perl 6.13-1

    lacme suggests no packages.

    -- no debconf information

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)