Pico ACME: tiny ACMEv2 client
Project description
pico acme
The tiniest python package to get ACMEv2 certs from Let's Encrypt.
Supports only single domains and DNS challenge. Currently implements AWS Route 53 but you can trivially implement your own provider.
Licensed under Apache 2.0 as this reuses some code from certbot.
quick start
Install from PyPI:
pip install pico-acme
(Note that you need to install boto3
separately to use route53
.)
new.py
:
ROUTE53_HOSTED_ZONE_ID = "..."
ACCOUNT_EMAIL = "domains@example.com"
DOMAIN = "example.com"
# create account, get cert, and save details
import pico_acme
from pico_acme import route53
# register an acme account
acme_client = pico_acme.register_account(ACCOUNT_EMAIL, agree_tos=True)
# create a private key and certificate signing request
key_pem = pico_acme.make_key()
csr_pem = pico_acme.make_csr(key_pem, [DOMAIN])
# get functions for upserting and cleaning up DNS records in AWS Route 53
upsert, clean = route53.route53_upsert_cleanup(ROUTE53_HOSTED_ZONE_ID)
# perform DNS-01 challenge to get the full chain as PEM
fullchain_pem = pico_acme.perform_dns01(acme_client, DOMAIN, csr_pem, upsert, clean)
# save account for later
with open("pico_acme_account.json", "w") as f:
f.write(pico_acme.serialize_account(acme_client))
# save private key for later
with open("key.pem", "wb") as f:
f.write(key_pem)
# save the cert for later
with open("fullchain.pem", "w") as f:
f.write(fullchain_pem)
renew.py
:
ROUTE53_HOSTED_ZONE_ID = "..."
DOMAIN = "example.com"
# later, load account, private key, and renew cert
import pico_acme
from pico_acme import route53
# load account
with open("pico_acme_account.json") as f:
acme_client = pico_acme.deserialize_account(f.read())
# load private key
with open("key.pem", "rb") as f:
key_pem = f.read()
# make a new certificate signing request
csr_pem = pico_acme.make_csr(key_pem, [DOMAIN])
# get functions for upserting and cleaning up DNS records in AWS Route 53
upsert, clean = route53.route53_upsert_cleanup(ROUTE53_HOSTED_ZONE_ID)
# perform DNS-01 challenge to get the full chain as PEM
fullchain_pem = pico_acme.perform_dns01(acme_client, DOMAIN, csr_pem, upsert, clean)
# save the cert for later
with open("fullchain.pem", "w") as f:
f.write(fullchain_pem)
architecture & features
The perform_dns01
takes two callables, upsert(record, value)
which should set the value value
(the verification string) in record record
(e.g. _acme-challenge.example.com
), and clean(record, value)
which should clean these up. See the route53.py
implementation for details.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file pico_acme-0.0.4.tar.gz
.
File metadata
- Download URL: pico_acme-0.0.4.tar.gz
- Upload date:
- Size: 9.5 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.2 CPython/3.8.10
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | d7a83ed61691a6b0931054c5e6ee2ab966ec6deae300afb47f89a260327463f4 |
|
MD5 | c26fd568e98371f6f9b30a1c7833e658 |
|
BLAKE2b-256 | 2667750225606bfe39950d192d344cdc3844f9722efc38274781770607b93efd |
File details
Details for the file pico_acme-0.0.4-py3-none-any.whl
.
File metadata
- Download URL: pico_acme-0.0.4-py3-none-any.whl
- Upload date:
- Size: 9.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.2 CPython/3.8.10
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 78a62922ab6c34ab470f90e2cff8b0db2585b8287679ea268734292caf68921a |
|
MD5 | 231e8a81dfc629b64acc2ecae00cf9c5 |
|
BLAKE2b-256 | c0ef6856d23231422ea30a2c750df3579cd3a1ef68cd688395267c8586be4885 |