Skip to main content

Module script_hook

Module script_hook 

Source
Expand description

The contract every custom hook in this server runs under: one script, a cleared environment, JSON on stdin, an exit code for the verdict.

Three subsystems delegate to an operator-supplied script — signer::custom (issue/revoke/crl/renewal_info), filter::custom (connection/identifiers) and notify::custom (one event). They differ in what they put in the environment, what they do with stdout, and how they read the exit code. They differ in nothing else.

What they shared was a security contract — clear the environment so a script cannot read the RFC 2136 TSIG secret or the SMTP password, restore a minimal PATH, kill the child when its deadline passes — written out three times, token for token. That is exactly the kind of thing that has to exist once: a hardening applied to one copy is silently absent from the other two, and nobody reviewing one of them can tell.