feat(provider): add TSIG-GSS support for rfc2136

This commit is contained in:
Fu Diwei
2026-06-24 17:34:55 +08:00
committed by RHQYZ
parent 312c27dd2e
commit 29b5585854
6 changed files with 78 additions and 16 deletions
@@ -22,6 +22,9 @@ func init() {
TsigAlgorithm: credentials.TsigAlgorithm,
TsigKey: credentials.TsigKey,
TsigSecret: credentials.TsigSecret,
TsigGssRealm: credentials.TsigGssRealm,
TsigGssUsername: credentials.TsigGssUsername,
TsigGssPassword: credentials.TsigGssPassword,
DnsPropagationTimeout: options.DnsPropagationTimeout,
DnsTTL: options.DnsTTL,
})
+8 -5
View File
@@ -511,11 +511,14 @@ type AccessConfigForRegru struct {
}
type AccessConfigForRFC2136 struct {
Host string `json:"host"`
Port int32 `json:"port"`
TsigAlgorithm string `json:"tsigAlgorithm,omitempty"`
TsigKey string `json:"tsigKey,omitempty"`
TsigSecret string `json:"tsigSecret,omitempty"`
Host string `json:"host"`
Port int32 `json:"port"`
TsigAlgorithm string `json:"tsigAlgorithm,omitempty"`
TsigKey string `json:"tsigKey,omitempty"`
TsigSecret string `json:"tsigSecret,omitempty"`
TsigGssRealm string `json:"tsigGssRealm,omitempty"`
TsigGssUsername string `json:"tsigGssUsername,omitempty"`
TsigGssPassword string `json:"tsigGssPassword,omitempty"`
}
type AccessConfigForRuCenter struct {
@@ -17,6 +17,9 @@ type ChallengerConfig struct {
TsigAlgorithm string `json:"tsigAlgorithm,omitempty"`
TsigKey string `json:"tsigKey,omitempty"`
TsigSecret string `json:"tsigSecret,omitempty"`
TsigGssRealm string `json:"tsigGssRealm,omitempty"`
TsigGssUsername string `json:"tsigGssUsername,omitempty"`
TsigGssPassword string `json:"tsigGssPassword,omitempty"`
DnsPropagationTimeout int `json:"dnsPropagationTimeout,omitempty"`
DnsTTL int `json:"dnsTTL,omitempty"`
}
@@ -39,6 +42,10 @@ func NewChallenger(config *ChallengerConfig) (core.ACMEChallenger, error) {
providerConfig.TSIGAlgorithm = config.TsigAlgorithm
providerConfig.TSIGKey = config.TsigKey
providerConfig.TSIGSecret = config.TsigSecret
providerConfig.TSIGGSSRealm = config.TsigGssRealm
providerConfig.TSIGGSSUsername = config.TsigGssUsername
providerConfig.TSIGGSSPassword = config.TsigGssPassword
providerConfig.TSIGGSSKeytabFile = ""
if config.DnsPropagationTimeout != 0 {
providerConfig.PropagationTimeout = time.Duration(config.DnsPropagationTimeout) * time.Second
}
@@ -3,6 +3,7 @@ import { Form, Input, InputNumber, Select } from "antd";
import { createSchemaFieldRule } from "antd-zod";
import { z } from "zod";
import Show from "@/components/Show";
import { isHostname, isPortNumber } from "@/utils/validator";
import { useFormNestedFieldsContext } from "./_context";
@@ -15,8 +16,11 @@ const AccessConfigFormFieldsProviderRFC2136 = () => {
[parentNamePath]: getSchema({ i18n }),
});
const formRule = createSchemaFieldRule(formSchema);
const formInst = Form.useFormInstance<z.infer<typeof formSchema>>();
const initialValues = getInitialValues();
const fieldTsigAlgorithm = Form.useWatch([parentNamePath, "tsigAlgorithm"], formInst);
return (
<>
<div className="flex space-x-2">
@@ -46,23 +50,41 @@ const AccessConfigFormFieldsProviderRFC2136 = () => {
{ label: "HMAC-SHA-256", value: "hmac-sha256." },
{ label: "HMAC-SHA-384", value: "hmac-sha384." },
{ label: "HMAC-SHA-512", value: "hmac-sha512." },
{ label: "HMAC-SHA-512", value: "hmac-sha512." },
{ label: "GSS-TSIG", value: "gss-tsig." },
]}
placeholder={t("access.form.rfc2136_tsig_algorithm.placeholder")}
/>
</Form.Item>
<Form.Item name={[parentNamePath, "tsigKey"]} initialValue={initialValues.tsigKey} label={t("access.form.rfc2136_tsig_key.label")} rules={[formRule]}>
<Input allowClear autoComplete="new-password" placeholder={t("access.form.rfc2136_tsig_key.placeholder")} />
</Form.Item>
<Show when={fieldTsigAlgorithm !== "gss-tsig."}>
<Form.Item name={[parentNamePath, "tsigKey"]} initialValue={initialValues.tsigKey} label={t("access.form.rfc2136_tsig_key.label")} rules={[formRule]}>
<Input allowClear autoComplete="new-password" placeholder={t("access.form.rfc2136_tsig_key.placeholder")} />
</Form.Item>
<Form.Item
name={[parentNamePath, "tsigSecret"]}
initialValue={initialValues.tsigSecret}
label={t("access.form.rfc2136_tsig_secret.label")}
rules={[formRule]}
>
<Input.Password allowClear autoComplete="new-password" placeholder={t("access.form.rfc2136_tsig_secret.placeholder")} />
</Form.Item>
<Form.Item
name={[parentNamePath, "tsigSecret"]}
initialValue={initialValues.tsigSecret}
label={t("access.form.rfc2136_tsig_secret.label")}
rules={[formRule]}
>
<Input.Password allowClear autoComplete="new-password" placeholder={t("access.form.rfc2136_tsig_secret.placeholder")} />
</Form.Item>
</Show>
<Show when={fieldTsigAlgorithm === "gss-tsig."}>
<Form.Item name={[parentNamePath, "tsigGssRealm"]} label={t("access.form.rfc2136_tsig_gss_realm.label")} rules={[formRule]}>
<Input allowClear placeholder={t("access.form.rfc2136_tsig_gss_realm.placeholder")} />
</Form.Item>
<Form.Item name={[parentNamePath, "tsigGssUsername"]} label={t("access.form.rfc2136_tsig_gss_username.label")} rules={[formRule]}>
<Input allowClear autoComplete="new-password" placeholder={t("access.form.rfc2136_tsig_gss_username.placeholder")} />
</Form.Item>
<Form.Item name={[parentNamePath, "tsigGssPassword"]} label={t("access.form.rfc2136_tsig_gss_password.label")} rules={[formRule]}>
<Input allowClear autoComplete="new-password" placeholder={t("access.form.rfc2136_tsig_gss_password.placeholder")} />
</Form.Item>
</Show>
</>
);
};
@@ -86,6 +108,9 @@ const getSchema = ({ i18n = getI18n() }: { i18n: ReturnType<typeof getI18n> }) =
tsigAlgorithm: z.string().nonempty(),
tsigKey: z.string().nullish(),
tsigSecret: z.string().nullish(),
tsigGssRealm: z.string().nullish(),
tsigGssUsername: z.string().nullish(),
tsigGssPassword: z.string().nullish(),
});
};
+12
View File
@@ -1162,6 +1162,18 @@
"label": "TSIG authentication secret (Optional)",
"placeholder": "Please enter TSIG authentication secret"
},
"rfc2136_tsig_gss_realm": {
"label": "GSS-TSIG Kerberos realm (Optional)",
"placeholder": "Please enter GSS-TSIG Kerberos realm"
},
"rfc2136_tsig_gss_username": {
"label": "GSS-TSIG Kerberos username (Optional)",
"placeholder": "Please enter GSS-TSIG Kerberos username"
},
"rfc2136_tsig_gss_password": {
"label": "GSS-TSIG Kerberos password (Optional)",
"placeholder": "Please enter GSS-TSIG Kerberos password"
},
"rucenter_username": {
"label": "Ru-Center username",
"placeholder": "Please enter Ru-Center username"
+12
View File
@@ -1162,6 +1162,18 @@
"label": "TSIG 认证密钥 Secret(可选)",
"placeholder": "请输入 TSIG 认证密钥 Secret"
},
"rfc2136_tsig_gss_realm": {
"label": "GSS-TSIG Kerberos 领域(可选)",
"placeholder": "请输入 GSS-TSIG Kerberos 领域"
},
"rfc2136_tsig_gss_username": {
"label": "GSS-TSIG Kerberos 用户名(可选)",
"placeholder": "请输入 GSS-TSIG Kerberos 用户名"
},
"rfc2136_tsig_gss_password": {
"label": "GSS-TSIG Kerberos 密码(可选)",
"placeholder": "请输入 GSS-TSIG Kerberos 密码"
},
"rucenter_username": {
"label": "Ru-Center 用户名",
"placeholder": "请输入 Ru-Center 用户名"