git » chasquid » commit a09963d

chasquid: support `key.pem` private filename

author ThinkChaos
2025-08-14 02:12:04 UTC
committer Alberto Bertogli
2026-09-27 19:41:16 UTC
parent f69fdc1b1aa0735cb5b2e9a08e43875f13350e75

chasquid: support `key.pem` private filename

Lego, the ACME client used by the NixOS ACME module, names the private
keys `key.pem`.
Auto-detect that filename so Chasquid just works with Lego & NixOS ACME.

https://go-acme.github.io/lego/
https://wiki.nixos.org/wiki/ACME

chasquid.go +26 -3

diff --git a/chasquid.go b/chasquid.go
index 18040e2..5be3e96 100644
--- a/chasquid.go
+++ b/chasquid.go
@@ -269,18 +269,41 @@ func loadCert(name, dir string, s *smtpsrv.Server) {
 		log.Infof("    skipping: %v", err)
 		return
 	}
-	keyPath := filepath.Join(dir, "privkey.pem")
-	if _, err := os.Stat(keyPath); err != nil {
+
+	keyPath, err := findCertKey(dir)
+	if err != nil {
 		log.Infof("    skipping: %v", err)
 		return
 	}
 
-	err := s.AddCerts(certPath, keyPath)
+	err = s.AddCerts(certPath, keyPath)
 	if err != nil {
 		log.Fatalf("    %v", err)
 	}
 }
 
+func findCertKey(dir string) (string, error) {
+	keyFiles := []string{
+		// Lego (NixOS ACME module).
+		"key.pem",
+		// Letsencrypt Certbot.
+		"privkey.pem",
+	}
+
+	var err error
+
+	for _, name := range keyFiles {
+		keyPath := filepath.Join(dir, name)
+
+		_, err = os.Stat(keyPath)
+		if err == nil {
+			return keyPath, nil
+		}
+	}
+
+	return "", err
+}
+
 // Helper to load a single domain configuration into the server.
 func loadDomain(name, dir string, s *smtpsrv.Server) {
 	s.AddDomain(name)