Skip to content

Acme parsing error - Multiple certificationResolvers #62

Description

@petrleocompel

Classification

  • Serious bug

Reproducibility

  • Always

Docker information

Client:
Version: 24.0.5
Context: default
Debug Mode: false
Server:
Containers: 14
Running: 14
Paused: 0
Stopped: 0
Images: 26
Server Version: 24.0.5
Storage Driver: overlay2
Backing Filesystem: xfs
Supports d_type: true
Using metacopy: false
Native Overlay Diff: true
userxattr: false
Logging Driver: journald
Cgroup Driver: systemd
Cgroup Version: 2
Plugins:
Volume: local
Network: bridge host ipvlan macvlan null overlay
Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog
Swarm: inactive
Runtimes: io.containerd.runc.v2 runc
Default Runtime: runc
Init Binary: /usr/libexec/docker/docker-init
containerd version:
runc version:
init version:
Security Options:
seccomp
Profile: builtin
selinux
cgroupns
Kernel Version: 6.5.11-300.fc39.x86_64
Operating System: Fedora CoreOS 39.20231119.3.0
OSType: linux
Architecture: x86_64
CPUs: 8
Total Memory: 15.6GiB
Name: cac
ID: 63493c27-f150-4b61-a3db-f6880880998b
Docker Root Dir: /var/lib/docker
Debug Mode: false
Username: petrleocompel
Experimental: false
Insecure Registries:
127.0.0.0/8
Live Restore Enabled: true
docker images mailserver2/mailserver --digests --filter "dangling=false"
REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
mailserver2/mailserver 1.1.15 sha256:c85fc055d805333a18210fa6d8fc7227a2f0d3dff519b2cfa805bc0410b61c63 d7b64bc841d8 6 months ago 421MB
docker images traefik --digests --filter "dangling=false"
REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
traefik 2.10 sha256:c5181ddf303f1ccfd4bd6d1d9c4867b0500efb6089a0f9ccb16612438f6e934f 64586c703ab1 5 weeks ago 153MB

Description

Wildcard letsencrypt certificate cannot throws error in parsing.

Steps to reproduce

  1. Wildcard domain configuration with traefik:2.10

Expected results

Parsing correctly PEM

Actual results

Acme certificate is present in JSON but cannot be parsed..

Debugging information

[INFO] MariaDB/PostgreSQL hostname not found in /etc/hosts
[INFO] Container IP found, adding a new record in /etc/hosts
[INFO] Redis hostname not found in /etc/hosts
[INFO] Container IP found, adding a new record in /etc/hosts
[INFO] Search for SSL certificates generated by Traefik
[INFO] acme.json found with Traefik v2 format, dumping into pem files
[ERROR] The certificate for mail.xxx.xx or the private key was not found !
[INFO] Don't forget to add a new traefik frontend rule to generate a certificate for mail.xxx.xx subdomain
[INFO] Look /mnt/docker/traefik/acme/dump.log and 'docker logs traefik' for more information
[INFO] Starting services

dump.log

[INFO] acme.json found with Traefik v2 format, dumping into pem files
Could not read private key from <stdin>
40E79918CB7F0000:error:1E08010C:DECODER routines:OSSL_DECODER_from_bio:unsupported:../crypto/encode_decode/decoder_lib.c:101:No supported data to decode. Input type: PEM

Configuration (docker-compose.yml, traefik.toml...etc)

docker-compose.yml

Mailserver:
....labels:
- "traefik.enable=true"
- "traefik.docker.network=http_network"
- "traefik.http.routers.spam.entrypoints=websecure"
- "traefik.http.routers.spam.rule=Host(`spam.${MAILSERVER_DOMAIN}`)"
- "traefik.http.routers.spam.service=spam"
- "traefik.http.routers.spam.tls=true"
- "traefik.http.routers.spam.tls.certresolver=letsencrypt"
- "traefik.http.routers.spam.tls.domains[0].main=xxx.xx"
- "traefik.http.routers.spam.tls.domains[0].sans=*.xxx.xx"

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
       blocks
      (function() {
      function addCopyButtons() {
      document.querySelectorAll('pre code').forEach(function(codeBlock) {
      if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
      codeBlock.parentElement.setAttribute('data-copy-added', 'true');
      var btn = document.createElement('button');
      btn.textContent = 'Copy';
      btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
      btn.onmouseover = function() { this.style.opacity = '1'; };
      btn.onmouseout = function() { this.style.opacity = '0.7'; };
      btn.onclick = function() {
      navigator.clipboard.writeText(codeBlock.textContent).then(function() {
      btn.textContent = 'Copied!';
      setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
      });
      };
      codeBlock.parentElement.style.position = 'relative';
      codeBlock.parentElement.appendChild(btn);
      });
      }
      addCopyButtons();
      // Re-run on dynamic content
      var observer = new MutationObserver(addCopyButtons);
      observer.observe(document.body, { childList: true, subtree: true });
      })();
      }
      } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
      })();
      (function(){
      try {
      var __m = "github.com";
      var __re = new RegExp('^' + "github\\.com" + '
      Acme parsing error - Multiple `certificationResolvers` · Issue #62 · mailserver2/mailserver · GitHub
      Skip to content

      Acme parsing error - Multiple certificationResolvers #62

      Description

      @petrleocompel

      Classification

      • Serious bug

      Reproducibility

      • Always

      Docker information

      Client:
      Version: 24.0.5
      Context: default
      Debug Mode: false
      Server:
      Containers: 14
      Running: 14
      Paused: 0
      Stopped: 0
      Images: 26
      Server Version: 24.0.5
      Storage Driver: overlay2
      Backing Filesystem: xfs
      Supports d_type: true
      Using metacopy: false
      Native Overlay Diff: true
      userxattr: false
      Logging Driver: journald
      Cgroup Driver: systemd
      Cgroup Version: 2
      Plugins:
      Volume: local
      Network: bridge host ipvlan macvlan null overlay
      Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog
      Swarm: inactive
      Runtimes: io.containerd.runc.v2 runc
      Default Runtime: runc
      Init Binary: /usr/libexec/docker/docker-init
      containerd version:
      runc version:
      init version:
      Security Options:
      seccomp
      Profile: builtin
      selinux
      cgroupns
      Kernel Version: 6.5.11-300.fc39.x86_64
      Operating System: Fedora CoreOS 39.20231119.3.0
      OSType: linux
      Architecture: x86_64
      CPUs: 8
      Total Memory: 15.6GiB
      Name: cac
      ID: 63493c27-f150-4b61-a3db-f6880880998b
      Docker Root Dir: /var/lib/docker
      Debug Mode: false
      Username: petrleocompel
      Experimental: false
      Insecure Registries:
      127.0.0.0/8
      Live Restore Enabled: true
      docker images mailserver2/mailserver --digests --filter "dangling=false"
      REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
      mailserver2/mailserver 1.1.15 sha256:c85fc055d805333a18210fa6d8fc7227a2f0d3dff519b2cfa805bc0410b61c63 d7b64bc841d8 6 months ago 421MB
      docker images traefik --digests --filter "dangling=false"
      REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
      traefik 2.10 sha256:c5181ddf303f1ccfd4bd6d1d9c4867b0500efb6089a0f9ccb16612438f6e934f 64586c703ab1 5 weeks ago 153MB
      

      Description

      Wildcard letsencrypt certificate cannot throws error in parsing.

      Steps to reproduce

      1. Wildcard domain configuration with traefik:2.10

      Expected results

      Parsing correctly PEM

      Actual results

      Acme certificate is present in JSON but cannot be parsed..

      Debugging information

      [INFO] MariaDB/PostgreSQL hostname not found in /etc/hosts
      [INFO] Container IP found, adding a new record in /etc/hosts
      [INFO] Redis hostname not found in /etc/hosts
      [INFO] Container IP found, adding a new record in /etc/hosts
      [INFO] Search for SSL certificates generated by Traefik
      [INFO] acme.json found with Traefik v2 format, dumping into pem files
      [ERROR] The certificate for mail.xxx.xx or the private key was not found !
      [INFO] Don't forget to add a new traefik frontend rule to generate a certificate for mail.xxx.xx subdomain
      [INFO] Look /mnt/docker/traefik/acme/dump.log and 'docker logs traefik' for more information
      [INFO] Starting services
      

      dump.log

      [INFO] acme.json found with Traefik v2 format, dumping into pem files
      Could not read private key from <stdin>
      40E79918CB7F0000:error:1E08010C:DECODER routines:OSSL_DECODER_from_bio:unsupported:../crypto/encode_decode/decoder_lib.c:101:No supported data to decode. Input type: PEM
      

      Configuration (docker-compose.yml, traefik.toml...etc)

      docker-compose.yml

      Mailserver:
      ....labels:
      - "traefik.enable=true"
      - "traefik.docker.network=http_network"
      - "traefik.http.routers.spam.entrypoints=websecure"
      - "traefik.http.routers.spam.rule=Host(`spam.${MAILSERVER_DOMAIN}`)"
      - "traefik.http.routers.spam.service=spam"
      - "traefik.http.routers.spam.tls=true"
      - "traefik.http.routers.spam.tls.certresolver=letsencrypt"
      - "traefik.http.routers.spam.tls.domains[0].main=xxx.xx"
      - "traefik.http.routers.spam.tls.domains[0].sans=*.xxx.xx"

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        No labels
        No labels

        Type

        No type

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Acme parsing error - Multiple `certificationResolvers` · Issue #62 · mailserver2/mailserver · GitHub
          Skip to content

          Acme parsing error - Multiple certificationResolvers #62

          Description

          @petrleocompel

          Classification

          • Serious bug

          Reproducibility

          • Always

          Docker information

          Client:
          Version: 24.0.5
          Context: default
          Debug Mode: false
          Server:
          Containers: 14
          Running: 14
          Paused: 0
          Stopped: 0
          Images: 26
          Server Version: 24.0.5
          Storage Driver: overlay2
          Backing Filesystem: xfs
          Supports d_type: true
          Using metacopy: false
          Native Overlay Diff: true
          userxattr: false
          Logging Driver: journald
          Cgroup Driver: systemd
          Cgroup Version: 2
          Plugins:
          Volume: local
          Network: bridge host ipvlan macvlan null overlay
          Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog
          Swarm: inactive
          Runtimes: io.containerd.runc.v2 runc
          Default Runtime: runc
          Init Binary: /usr/libexec/docker/docker-init
          containerd version:
          runc version:
          init version:
          Security Options:
          seccomp
          Profile: builtin
          selinux
          cgroupns
          Kernel Version: 6.5.11-300.fc39.x86_64
          Operating System: Fedora CoreOS 39.20231119.3.0
          OSType: linux
          Architecture: x86_64
          CPUs: 8
          Total Memory: 15.6GiB
          Name: cac
          ID: 63493c27-f150-4b61-a3db-f6880880998b
          Docker Root Dir: /var/lib/docker
          Debug Mode: false
          Username: petrleocompel
          Experimental: false
          Insecure Registries:
          127.0.0.0/8
          Live Restore Enabled: true
          docker images mailserver2/mailserver --digests --filter "dangling=false"
          REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
          mailserver2/mailserver 1.1.15 sha256:c85fc055d805333a18210fa6d8fc7227a2f0d3dff519b2cfa805bc0410b61c63 d7b64bc841d8 6 months ago 421MB
          docker images traefik --digests --filter "dangling=false"
          REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
          traefik 2.10 sha256:c5181ddf303f1ccfd4bd6d1d9c4867b0500efb6089a0f9ccb16612438f6e934f 64586c703ab1 5 weeks ago 153MB
          

          Description

          Wildcard letsencrypt certificate cannot throws error in parsing.

          Steps to reproduce

          1. Wildcard domain configuration with traefik:2.10

          Expected results

          Parsing correctly PEM

          Actual results

          Acme certificate is present in JSON but cannot be parsed..

          Debugging information

          [INFO] MariaDB/PostgreSQL hostname not found in /etc/hosts
          [INFO] Container IP found, adding a new record in /etc/hosts
          [INFO] Redis hostname not found in /etc/hosts
          [INFO] Container IP found, adding a new record in /etc/hosts
          [INFO] Search for SSL certificates generated by Traefik
          [INFO] acme.json found with Traefik v2 format, dumping into pem files
          [ERROR] The certificate for mail.xxx.xx or the private key was not found !
          [INFO] Don't forget to add a new traefik frontend rule to generate a certificate for mail.xxx.xx subdomain
          [INFO] Look /mnt/docker/traefik/acme/dump.log and 'docker logs traefik' for more information
          [INFO] Starting services
          

          dump.log

          [INFO] acme.json found with Traefik v2 format, dumping into pem files
          Could not read private key from <stdin>
          40E79918CB7F0000:error:1E08010C:DECODER routines:OSSL_DECODER_from_bio:unsupported:../crypto/encode_decode/decoder_lib.c:101:No supported data to decode. Input type: PEM
          

          Configuration (docker-compose.yml, traefik.toml...etc)

          docker-compose.yml

          Mailserver:
          ....labels:
          - "traefik.enable=true"
          - "traefik.docker.network=http_network"
          - "traefik.http.routers.spam.entrypoints=websecure"
          - "traefik.http.routers.spam.rule=Host(`spam.${MAILSERVER_DOMAIN}`)"
          - "traefik.http.routers.spam.service=spam"
          - "traefik.http.routers.spam.tls=true"
          - "traefik.http.routers.spam.tls.certresolver=letsencrypt"
          - "traefik.http.routers.spam.tls.domains[0].main=xxx.xx"
          - "traefik.http.routers.spam.tls.domains[0].sans=*.xxx.xx"

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            No labels
            No labels

            Type

            No type

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Acme parsing error - Multiple `certificationResolvers` · Issue #62 · mailserver2/mailserver · GitHub
              Skip to content

              Acme parsing error - Multiple certificationResolvers #62

              Description

              @petrleocompel

              Classification

              • Serious bug

              Reproducibility

              • Always

              Docker information

              Client:
              Version: 24.0.5
              Context: default
              Debug Mode: false
              Server:
              Containers: 14
              Running: 14
              Paused: 0
              Stopped: 0
              Images: 26
              Server Version: 24.0.5
              Storage Driver: overlay2
              Backing Filesystem: xfs
              Supports d_type: true
              Using metacopy: false
              Native Overlay Diff: true
              userxattr: false
              Logging Driver: journald
              Cgroup Driver: systemd
              Cgroup Version: 2
              Plugins:
              Volume: local
              Network: bridge host ipvlan macvlan null overlay
              Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog
              Swarm: inactive
              Runtimes: io.containerd.runc.v2 runc
              Default Runtime: runc
              Init Binary: /usr/libexec/docker/docker-init
              containerd version:
              runc version:
              init version:
              Security Options:
              seccomp
              Profile: builtin
              selinux
              cgroupns
              Kernel Version: 6.5.11-300.fc39.x86_64
              Operating System: Fedora CoreOS 39.20231119.3.0
              OSType: linux
              Architecture: x86_64
              CPUs: 8
              Total Memory: 15.6GiB
              Name: cac
              ID: 63493c27-f150-4b61-a3db-f6880880998b
              Docker Root Dir: /var/lib/docker
              Debug Mode: false
              Username: petrleocompel
              Experimental: false
              Insecure Registries:
              127.0.0.0/8
              Live Restore Enabled: true
              docker images mailserver2/mailserver --digests --filter "dangling=false"
              REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
              mailserver2/mailserver 1.1.15 sha256:c85fc055d805333a18210fa6d8fc7227a2f0d3dff519b2cfa805bc0410b61c63 d7b64bc841d8 6 months ago 421MB
              docker images traefik --digests --filter "dangling=false"
              REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
              traefik 2.10 sha256:c5181ddf303f1ccfd4bd6d1d9c4867b0500efb6089a0f9ccb16612438f6e934f 64586c703ab1 5 weeks ago 153MB
              

              Description

              Wildcard letsencrypt certificate cannot throws error in parsing.

              Steps to reproduce

              1. Wildcard domain configuration with traefik:2.10

              Expected results

              Parsing correctly PEM

              Actual results

              Acme certificate is present in JSON but cannot be parsed..

              Debugging information

              [INFO] MariaDB/PostgreSQL hostname not found in /etc/hosts
              [INFO] Container IP found, adding a new record in /etc/hosts
              [INFO] Redis hostname not found in /etc/hosts
              [INFO] Container IP found, adding a new record in /etc/hosts
              [INFO] Search for SSL certificates generated by Traefik
              [INFO] acme.json found with Traefik v2 format, dumping into pem files
              [ERROR] The certificate for mail.xxx.xx or the private key was not found !
              [INFO] Don't forget to add a new traefik frontend rule to generate a certificate for mail.xxx.xx subdomain
              [INFO] Look /mnt/docker/traefik/acme/dump.log and 'docker logs traefik' for more information
              [INFO] Starting services
              

              dump.log

              [INFO] acme.json found with Traefik v2 format, dumping into pem files
              Could not read private key from <stdin>
              40E79918CB7F0000:error:1E08010C:DECODER routines:OSSL_DECODER_from_bio:unsupported:../crypto/encode_decode/decoder_lib.c:101:No supported data to decode. Input type: PEM
              

              Configuration (docker-compose.yml, traefik.toml...etc)

              docker-compose.yml

              Mailserver:
              ....labels:
              - "traefik.enable=true"
              - "traefik.docker.network=http_network"
              - "traefik.http.routers.spam.entrypoints=websecure"
              - "traefik.http.routers.spam.rule=Host(`spam.${MAILSERVER_DOMAIN}`)"
              - "traefik.http.routers.spam.service=spam"
              - "traefik.http.routers.spam.tls=true"
              - "traefik.http.routers.spam.tls.certresolver=letsencrypt"
              - "traefik.http.routers.spam.tls.domains[0].main=xxx.xx"
              - "traefik.http.routers.spam.tls.domains[0].sans=*.xxx.xx"

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                No labels
                No labels

                Type

                No type

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Acme parsing error - Multiple `certificationResolvers` · Issue #62 · mailserver2/mailserver · GitHub
                  Skip to content

                  Acme parsing error - Multiple certificationResolvers #62

                  Description

                  @petrleocompel

                  Classification

                  • Serious bug

                  Reproducibility

                  • Always

                  Docker information

                  Client:
                  Version: 24.0.5
                  Context: default
                  Debug Mode: false
                  Server:
                  Containers: 14
                  Running: 14
                  Paused: 0
                  Stopped: 0
                  Images: 26
                  Server Version: 24.0.5
                  Storage Driver: overlay2
                  Backing Filesystem: xfs
                  Supports d_type: true
                  Using metacopy: false
                  Native Overlay Diff: true
                  userxattr: false
                  Logging Driver: journald
                  Cgroup Driver: systemd
                  Cgroup Version: 2
                  Plugins:
                  Volume: local
                  Network: bridge host ipvlan macvlan null overlay
                  Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog
                  Swarm: inactive
                  Runtimes: io.containerd.runc.v2 runc
                  Default Runtime: runc
                  Init Binary: /usr/libexec/docker/docker-init
                  containerd version:
                  runc version:
                  init version:
                  Security Options:
                  seccomp
                  Profile: builtin
                  selinux
                  cgroupns
                  Kernel Version: 6.5.11-300.fc39.x86_64
                  Operating System: Fedora CoreOS 39.20231119.3.0
                  OSType: linux
                  Architecture: x86_64
                  CPUs: 8
                  Total Memory: 15.6GiB
                  Name: cac
                  ID: 63493c27-f150-4b61-a3db-f6880880998b
                  Docker Root Dir: /var/lib/docker
                  Debug Mode: false
                  Username: petrleocompel
                  Experimental: false
                  Insecure Registries:
                  127.0.0.0/8
                  Live Restore Enabled: true
                  docker images mailserver2/mailserver --digests --filter "dangling=false"
                  REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
                  mailserver2/mailserver 1.1.15 sha256:c85fc055d805333a18210fa6d8fc7227a2f0d3dff519b2cfa805bc0410b61c63 d7b64bc841d8 6 months ago 421MB
                  docker images traefik --digests --filter "dangling=false"
                  REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
                  traefik 2.10 sha256:c5181ddf303f1ccfd4bd6d1d9c4867b0500efb6089a0f9ccb16612438f6e934f 64586c703ab1 5 weeks ago 153MB
                  

                  Description

                  Wildcard letsencrypt certificate cannot throws error in parsing.

                  Steps to reproduce

                  1. Wildcard domain configuration with traefik:2.10

                  Expected results

                  Parsing correctly PEM

                  Actual results

                  Acme certificate is present in JSON but cannot be parsed..

                  Debugging information

                  [INFO] MariaDB/PostgreSQL hostname not found in /etc/hosts
                  [INFO] Container IP found, adding a new record in /etc/hosts
                  [INFO] Redis hostname not found in /etc/hosts
                  [INFO] Container IP found, adding a new record in /etc/hosts
                  [INFO] Search for SSL certificates generated by Traefik
                  [INFO] acme.json found with Traefik v2 format, dumping into pem files
                  [ERROR] The certificate for mail.xxx.xx or the private key was not found !
                  [INFO] Don't forget to add a new traefik frontend rule to generate a certificate for mail.xxx.xx subdomain
                  [INFO] Look /mnt/docker/traefik/acme/dump.log and 'docker logs traefik' for more information
                  [INFO] Starting services
                  

                  dump.log

                  [INFO] acme.json found with Traefik v2 format, dumping into pem files
                  Could not read private key from <stdin>
                  40E79918CB7F0000:error:1E08010C:DECODER routines:OSSL_DECODER_from_bio:unsupported:../crypto/encode_decode/decoder_lib.c:101:No supported data to decode. Input type: PEM
                  

                  Configuration (docker-compose.yml, traefik.toml...etc)

                  docker-compose.yml

                  Mailserver:
                  ....labels:
                  - "traefik.enable=true"
                  - "traefik.docker.network=http_network"
                  - "traefik.http.routers.spam.entrypoints=websecure"
                  - "traefik.http.routers.spam.rule=Host(`spam.${MAILSERVER_DOMAIN}`)"
                  - "traefik.http.routers.spam.service=spam"
                  - "traefik.http.routers.spam.tls=true"
                  - "traefik.http.routers.spam.tls.certresolver=letsencrypt"
                  - "traefik.http.routers.spam.tls.domains[0].main=xxx.xx"
                  - "traefik.http.routers.spam.tls.domains[0].sans=*.xxx.xx"

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    No labels
                    No labels

                    Type

                    No type

                    Projects

                    No projects

                      Milestone

                      No milestone

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Acme parsing error - Multiple `certificationResolvers` · Issue #62 · mailserver2/mailserver · GitHub
                      Skip to content

                      Acme parsing error - Multiple certificationResolvers #62

                      Description

                      @petrleocompel

                      Classification

                      • Serious bug

                      Reproducibility

                      • Always

                      Docker information

                      Client:
                      Version: 24.0.5
                      Context: default
                      Debug Mode: false
                      Server:
                      Containers: 14
                      Running: 14
                      Paused: 0
                      Stopped: 0
                      Images: 26
                      Server Version: 24.0.5
                      Storage Driver: overlay2
                      Backing Filesystem: xfs
                      Supports d_type: true
                      Using metacopy: false
                      Native Overlay Diff: true
                      userxattr: false
                      Logging Driver: journald
                      Cgroup Driver: systemd
                      Cgroup Version: 2
                      Plugins:
                      Volume: local
                      Network: bridge host ipvlan macvlan null overlay
                      Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog
                      Swarm: inactive
                      Runtimes: io.containerd.runc.v2 runc
                      Default Runtime: runc
                      Init Binary: /usr/libexec/docker/docker-init
                      containerd version:
                      runc version:
                      init version:
                      Security Options:
                      seccomp
                      Profile: builtin
                      selinux
                      cgroupns
                      Kernel Version: 6.5.11-300.fc39.x86_64
                      Operating System: Fedora CoreOS 39.20231119.3.0
                      OSType: linux
                      Architecture: x86_64
                      CPUs: 8
                      Total Memory: 15.6GiB
                      Name: cac
                      ID: 63493c27-f150-4b61-a3db-f6880880998b
                      Docker Root Dir: /var/lib/docker
                      Debug Mode: false
                      Username: petrleocompel
                      Experimental: false
                      Insecure Registries:
                      127.0.0.0/8
                      Live Restore Enabled: true
                      docker images mailserver2/mailserver --digests --filter "dangling=false"
                      REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
                      mailserver2/mailserver 1.1.15 sha256:c85fc055d805333a18210fa6d8fc7227a2f0d3dff519b2cfa805bc0410b61c63 d7b64bc841d8 6 months ago 421MB
                      docker images traefik --digests --filter "dangling=false"
                      REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
                      traefik 2.10 sha256:c5181ddf303f1ccfd4bd6d1d9c4867b0500efb6089a0f9ccb16612438f6e934f 64586c703ab1 5 weeks ago 153MB
                      

                      Description

                      Wildcard letsencrypt certificate cannot throws error in parsing.

                      Steps to reproduce

                      1. Wildcard domain configuration with traefik:2.10

                      Expected results

                      Parsing correctly PEM

                      Actual results

                      Acme certificate is present in JSON but cannot be parsed..

                      Debugging information

                      [INFO] MariaDB/PostgreSQL hostname not found in /etc/hosts
                      [INFO] Container IP found, adding a new record in /etc/hosts
                      [INFO] Redis hostname not found in /etc/hosts
                      [INFO] Container IP found, adding a new record in /etc/hosts
                      [INFO] Search for SSL certificates generated by Traefik
                      [INFO] acme.json found with Traefik v2 format, dumping into pem files
                      [ERROR] The certificate for mail.xxx.xx or the private key was not found !
                      [INFO] Don't forget to add a new traefik frontend rule to generate a certificate for mail.xxx.xx subdomain
                      [INFO] Look /mnt/docker/traefik/acme/dump.log and 'docker logs traefik' for more information
                      [INFO] Starting services
                      

                      dump.log

                      [INFO] acme.json found with Traefik v2 format, dumping into pem files
                      Could not read private key from <stdin>
                      40E79918CB7F0000:error:1E08010C:DECODER routines:OSSL_DECODER_from_bio:unsupported:../crypto/encode_decode/decoder_lib.c:101:No supported data to decode. Input type: PEM
                      

                      Configuration (docker-compose.yml, traefik.toml...etc)

                      docker-compose.yml

                      Mailserver:
                      ....labels:
                      - "traefik.enable=true"
                      - "traefik.docker.network=http_network"
                      - "traefik.http.routers.spam.entrypoints=websecure"
                      - "traefik.http.routers.spam.rule=Host(`spam.${MAILSERVER_DOMAIN}`)"
                      - "traefik.http.routers.spam.service=spam"
                      - "traefik.http.routers.spam.tls=true"
                      - "traefik.http.routers.spam.tls.certresolver=letsencrypt"
                      - "traefik.http.routers.spam.tls.domains[0].main=xxx.xx"
                      - "traefik.http.routers.spam.tls.domains[0].sans=*.xxx.xx"

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        No labels
                        No labels

                        Type

                        No type

                        Projects

                        No projects

                          Milestone

                          No milestone

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Acme parsing error - Multiple `certificationResolvers` · Issue #62 · mailserver2/mailserver · GitHub
                          Skip to content

                          Acme parsing error - Multiple certificationResolvers #62

                          Description

                          @petrleocompel

                          Classification

                          • Serious bug

                          Reproducibility

                          • Always

                          Docker information

                          Client:
                          Version: 24.0.5
                          Context: default
                          Debug Mode: false
                          Server:
                          Containers: 14
                          Running: 14
                          Paused: 0
                          Stopped: 0
                          Images: 26
                          Server Version: 24.0.5
                          Storage Driver: overlay2
                          Backing Filesystem: xfs
                          Supports d_type: true
                          Using metacopy: false
                          Native Overlay Diff: true
                          userxattr: false
                          Logging Driver: journald
                          Cgroup Driver: systemd
                          Cgroup Version: 2
                          Plugins:
                          Volume: local
                          Network: bridge host ipvlan macvlan null overlay
                          Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog
                          Swarm: inactive
                          Runtimes: io.containerd.runc.v2 runc
                          Default Runtime: runc
                          Init Binary: /usr/libexec/docker/docker-init
                          containerd version:
                          runc version:
                          init version:
                          Security Options:
                          seccomp
                          Profile: builtin
                          selinux
                          cgroupns
                          Kernel Version: 6.5.11-300.fc39.x86_64
                          Operating System: Fedora CoreOS 39.20231119.3.0
                          OSType: linux
                          Architecture: x86_64
                          CPUs: 8
                          Total Memory: 15.6GiB
                          Name: cac
                          ID: 63493c27-f150-4b61-a3db-f6880880998b
                          Docker Root Dir: /var/lib/docker
                          Debug Mode: false
                          Username: petrleocompel
                          Experimental: false
                          Insecure Registries:
                          127.0.0.0/8
                          Live Restore Enabled: true
                          docker images mailserver2/mailserver --digests --filter "dangling=false"
                          REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
                          mailserver2/mailserver 1.1.15 sha256:c85fc055d805333a18210fa6d8fc7227a2f0d3dff519b2cfa805bc0410b61c63 d7b64bc841d8 6 months ago 421MB
                          docker images traefik --digests --filter "dangling=false"
                          REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
                          traefik 2.10 sha256:c5181ddf303f1ccfd4bd6d1d9c4867b0500efb6089a0f9ccb16612438f6e934f 64586c703ab1 5 weeks ago 153MB
                          

                          Description

                          Wildcard letsencrypt certificate cannot throws error in parsing.

                          Steps to reproduce

                          1. Wildcard domain configuration with traefik:2.10

                          Expected results

                          Parsing correctly PEM

                          Actual results

                          Acme certificate is present in JSON but cannot be parsed..

                          Debugging information

                          [INFO] MariaDB/PostgreSQL hostname not found in /etc/hosts
                          [INFO] Container IP found, adding a new record in /etc/hosts
                          [INFO] Redis hostname not found in /etc/hosts
                          [INFO] Container IP found, adding a new record in /etc/hosts
                          [INFO] Search for SSL certificates generated by Traefik
                          [INFO] acme.json found with Traefik v2 format, dumping into pem files
                          [ERROR] The certificate for mail.xxx.xx or the private key was not found !
                          [INFO] Don't forget to add a new traefik frontend rule to generate a certificate for mail.xxx.xx subdomain
                          [INFO] Look /mnt/docker/traefik/acme/dump.log and 'docker logs traefik' for more information
                          [INFO] Starting services
                          

                          dump.log

                          [INFO] acme.json found with Traefik v2 format, dumping into pem files
                          Could not read private key from <stdin>
                          40E79918CB7F0000:error:1E08010C:DECODER routines:OSSL_DECODER_from_bio:unsupported:../crypto/encode_decode/decoder_lib.c:101:No supported data to decode. Input type: PEM
                          

                          Configuration (docker-compose.yml, traefik.toml...etc)

                          docker-compose.yml

                          Mailserver:
                          ....labels:
                          - "traefik.enable=true"
                          - "traefik.docker.network=http_network"
                          - "traefik.http.routers.spam.entrypoints=websecure"
                          - "traefik.http.routers.spam.rule=Host(`spam.${MAILSERVER_DOMAIN}`)"
                          - "traefik.http.routers.spam.service=spam"
                          - "traefik.http.routers.spam.tls=true"
                          - "traefik.http.routers.spam.tls.certresolver=letsencrypt"
                          - "traefik.http.routers.spam.tls.domains[0].main=xxx.xx"
                          - "traefik.http.routers.spam.tls.domains[0].sans=*.xxx.xx"

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            No labels
                            No labels

                            Type

                            No type

                            Projects

                            No projects

                              Milestone

                              No milestone

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Acme parsing error - Multiple `certificationResolvers` · Issue #62 · mailserver2/mailserver · GitHub
                              Skip to content

                              Acme parsing error - Multiple certificationResolvers #62

                              Description

                              @petrleocompel

                              Classification

                              • Serious bug

                              Reproducibility

                              • Always

                              Docker information

                              Client:
                              Version: 24.0.5
                              Context: default
                              Debug Mode: false
                              Server:
                              Containers: 14
                              Running: 14
                              Paused: 0
                              Stopped: 0
                              Images: 26
                              Server Version: 24.0.5
                              Storage Driver: overlay2
                              Backing Filesystem: xfs
                              Supports d_type: true
                              Using metacopy: false
                              Native Overlay Diff: true
                              userxattr: false
                              Logging Driver: journald
                              Cgroup Driver: systemd
                              Cgroup Version: 2
                              Plugins:
                              Volume: local
                              Network: bridge host ipvlan macvlan null overlay
                              Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog
                              Swarm: inactive
                              Runtimes: io.containerd.runc.v2 runc
                              Default Runtime: runc
                              Init Binary: /usr/libexec/docker/docker-init
                              containerd version:
                              runc version:
                              init version:
                              Security Options:
                              seccomp
                              Profile: builtin
                              selinux
                              cgroupns
                              Kernel Version: 6.5.11-300.fc39.x86_64
                              Operating System: Fedora CoreOS 39.20231119.3.0
                              OSType: linux
                              Architecture: x86_64
                              CPUs: 8
                              Total Memory: 15.6GiB
                              Name: cac
                              ID: 63493c27-f150-4b61-a3db-f6880880998b
                              Docker Root Dir: /var/lib/docker
                              Debug Mode: false
                              Username: petrleocompel
                              Experimental: false
                              Insecure Registries:
                              127.0.0.0/8
                              Live Restore Enabled: true
                              docker images mailserver2/mailserver --digests --filter "dangling=false"
                              REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
                              mailserver2/mailserver 1.1.15 sha256:c85fc055d805333a18210fa6d8fc7227a2f0d3dff519b2cfa805bc0410b61c63 d7b64bc841d8 6 months ago 421MB
                              docker images traefik --digests --filter "dangling=false"
                              REPOSITORY TAG DIGEST IMAGE ID CREATED SIZE
                              traefik 2.10 sha256:c5181ddf303f1ccfd4bd6d1d9c4867b0500efb6089a0f9ccb16612438f6e934f 64586c703ab1 5 weeks ago 153MB
                              

                              Description

                              Wildcard letsencrypt certificate cannot throws error in parsing.

                              Steps to reproduce

                              1. Wildcard domain configuration with traefik:2.10

                              Expected results

                              Parsing correctly PEM

                              Actual results

                              Acme certificate is present in JSON but cannot be parsed..

                              Debugging information

                              [INFO] MariaDB/PostgreSQL hostname not found in /etc/hosts
                              [INFO] Container IP found, adding a new record in /etc/hosts
                              [INFO] Redis hostname not found in /etc/hosts
                              [INFO] Container IP found, adding a new record in /etc/hosts
                              [INFO] Search for SSL certificates generated by Traefik
                              [INFO] acme.json found with Traefik v2 format, dumping into pem files
                              [ERROR] The certificate for mail.xxx.xx or the private key was not found !
                              [INFO] Don't forget to add a new traefik frontend rule to generate a certificate for mail.xxx.xx subdomain
                              [INFO] Look /mnt/docker/traefik/acme/dump.log and 'docker logs traefik' for more information
                              [INFO] Starting services
                              

                              dump.log

                              [INFO] acme.json found with Traefik v2 format, dumping into pem files
                              Could not read private key from <stdin>
                              40E79918CB7F0000:error:1E08010C:DECODER routines:OSSL_DECODER_from_bio:unsupported:../crypto/encode_decode/decoder_lib.c:101:No supported data to decode. Input type: PEM
                              

                              Configuration (docker-compose.yml, traefik.toml...etc)

                              docker-compose.yml

                              Mailserver:
                              ....labels:
                              - "traefik.enable=true"
                              - "traefik.docker.network=http_network"
                              - "traefik.http.routers.spam.entrypoints=websecure"
                              - "traefik.http.routers.spam.rule=Host(`spam.${MAILSERVER_DOMAIN}`)"
                              - "traefik.http.routers.spam.service=spam"
                              - "traefik.http.routers.spam.tls=true"
                              - "traefik.http.routers.spam.tls.certresolver=letsencrypt"
                              - "traefik.http.routers.spam.tls.domains[0].main=xxx.xx"
                              - "traefik.http.routers.spam.tls.domains[0].sans=*.xxx.xx"

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                No labels
                                No labels

                                Type

                                No type

                                Projects

                                No projects

                                  Milestone

                                  No milestone

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions