From dc49e960dbda058b7779fbdc73f1f2e6775ec838 Mon Sep 17 00:00:00 2001 From: Robert Resch Date: Mon, 19 Apr 2021 20:46:39 +0200 Subject: [PATCH] add new used subdomains (for europe) --- .dockerignore | 8 +++++++- create_certs/Bumper_SAN.txt | 6 +++++- docs/Create_Certs.md | 36 ++++++++++++++++++++++-------------- docs/DNS_Setup.md | 9 +++++++++ 4 files changed, 43 insertions(+), 16 deletions(-) diff --git a/.dockerignore b/.dockerignore index f4a3930..8116b73 100644 --- a/.dockerignore +++ b/.dockerignore @@ -19,4 +19,10 @@ certs *.md # Other -*.yml \ No newline at end of file +*.yml + +# Github +.github + +# Python virtual environment +venv \ No newline at end of file diff --git a/create_certs/Bumper_SAN.txt b/create_certs/Bumper_SAN.txt index 9994fc3..2ffe727 100644 --- a/create_certs/Bumper_SAN.txt +++ b/create_certs/Bumper_SAN.txt @@ -3,4 +3,8 @@ ecovacs.com ecouser.net *.ecouser.net ecovacs.net -*.ecovacs.net \ No newline at end of file +*.ecovacs.net +*.ww.ecouser.net +*.dc-eu.ww.ecouser.net +*.dc.ww.ecouser.net +*.area.ww.ecouser.net \ No newline at end of file diff --git a/docs/Create_Certs.md b/docs/Create_Certs.md index daef11c..626c994 100644 --- a/docs/Create_Certs.md +++ b/docs/Create_Certs.md @@ -53,9 +53,9 @@ I get it, you don't trust create_certs and want to do it manually. The easiest ### Create a Root CA -1. Create csrconfig.txt for use in later commands +1. Create csrconfig_ca.txt for use in later commands -***csrconfig.txt*** +***csrconfig_ca.txt*** ```` [ req ] default_md = sha256 @@ -70,9 +70,9 @@ keyUsage=critical,keyCertSign,cRLSign basicConstraints=critical,CA:true,pathlen:1 ```` -1. Create certconfig.txt for use in later commands +1. Create certconfig_ca.txt for use in later commands -***certconfig.txt*** +***certconfig_ca.txt*** ```` [ req ] default_md = sha256 @@ -91,21 +91,21 @@ basicConstraints=critical,CA:true,pathlen:1 1. Generate the RSA private key - `openssl genpkey -outform PEM -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out priv.key` + `openssl genrsa -out ca.key 4096` 1. Create the CSR - `openssl req -new -nodes -key priv.key -config csrconfig.txt -out cert.csr` + `openssl req -new -nodes -key ca.key -config csrconfig_ca.txt -out ca.csr` 1. Self-sign your CSR - `openssl req -x509 -nodes -in cert.csr -days 3650 -key priv.key -config certconfig.txt -extensions req_ext -out cert.crt` + `openssl req -x509 -nodes -in ca.csr -days 1095 -key ca.key -config certconfig_ca.txt -extensions req_ext -out ca.crt` ### Create the Server Certificate -1. Create csrconfig.txt for use in later commands +1. Create csrconfig_bumper.txt for use in later commands -***csrconfig.txt*** +***csrconfig_bumper.txt*** ```` [ req ] default_md = sha256 @@ -127,11 +127,15 @@ DNS.2 = ecouser.net DNS.3 = *.ecouser.net DNS.4 = ecovacs.net DNS.5 = *.ecovacs.net +DNS.6 = *.ww.ecouser.net +DNS.7 = *.dc-eu.ww.ecouser.net +DNS.8 = *.dc.ww.ecouser.net +DNS.9 = *.area.ww.ecouser.net ```` -1. Create certconfig.txt for use in later commands +1. Create certconfig_bumper.txt for use in later commands -***certconfig.txt*** +***certconfig_bumper.txt*** ```` [ req ] default_md = sha256 @@ -155,19 +159,23 @@ DNS.2 = ecouser.net DNS.3 = *.ecouser.net DNS.4 = ecovacs.net DNS.5 = *.ecovacs.net +DNS.6 = *.ww.ecouser.net +DNS.7 = *.dc-eu.ww.ecouser.net +DNS.8 = *.dc.ww.ecouser.net +DNS.9 = *.area.ww.ecouser.net ```` 1. Generate the RSA private key - `openssl genpkey -outform PEM -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out priv.key` + `openssl genrsa -out bumper.key 4096` 1. Create the CSR - `openssl req -new -nodes -key priv.key -config csrconfig.txt -out cert.csr` + `openssl req -new -nodes -key bumper.key -config csrconfig_bumper.txt -out bumper.csr` 1. Sign your CSR with a root CA cert - `openssl x509 -req -in cert.csr -days 3650 -CA ca.crt -CAkey priv.key -extfile certconfig.txt -extensions req_ext -CAserial /tmp/tmp-10593TSH1OlVSxC7C -CAcreateserial -out cert.crt` + `openssl x509 -req -in bumper.csr -days 365 -CA ca.crt -CAkey ca.key -extfile certconfig_bumper.txt -extensions req_ext -CAcreateserial -out bumper.crt` ## Using a Custom CA/Self diff --git a/docs/DNS_Setup.md b/docs/DNS_Setup.md index a519be8..e433b8d 100644 --- a/docs/DNS_Setup.md +++ b/docs/DNS_Setup.md @@ -26,6 +26,7 @@ If overriding DNS for the top-level domains isn't an option, you'll need to conf **Note:** Depending on country, your phone/robot may be using a different domain. Most of these domains contain country-specific placeholders. Not all domains have been documented at this point, and this list will be updated as more are identified/seen. The preferred way to ensure Bumper works is to override the full domains as above. +**Note:** The app dynamically gets the required domains from the endpoint `api/appsvr/service/list` and therefore ecovacs can use different domains for different models. Replacement Examples: @@ -46,6 +47,7 @@ Replacement Examples: | `eco-{countrycode}-api.ecovacs.com` | Used for Login | | `gl-{countrycode}-api.ecovacs.com` | Used by EcoVacs Home app | | `gl-{countrycode}-openapi.ecovacs.com` | Used by EcoVacs Home app | +| `portal.ecouser.net` | Used for Login and Rest API | | `portal-{countrycode}.ecouser.net` | Used for Login and Rest API | | `portal-{region}.ecouser.net` | Used for Login and Rest API | | `portal-ww.ecouser.net` | Used for various Rest APIs | @@ -59,4 +61,11 @@ Replacement Examples: | `recommender.ecovacs.com` | Used by Ecovacs Home app | | `bigdata-international.ecovacs.com` | Telemetry/tracking | | `bigdata-northamerica.ecovacs.com` | Telemetry/tracking | +| `bigdata-europe.ecovacs.com` | Telemetry/tracking | | `bigdata-{unknown regions}.ecovacs.com` | Telemetry/tracking | +| `api-app.ww.ecouser.net` | Api for App (v2+) | +| `api-app.dc-{region}.ww.ecouser.net` | Api for App (v2+) | +| `users-base.dc-{region}.ww.ecouser.net` | Accounts for App (v2+) | +| `jmq-ngiot-{region}.dc.ww.ecouser.net` | MQTT for App (v2+) | +| `api-rop.dc-{region}.ww.ecouser.net` | App (v2+) | +| `jmq-ngiot-{region}.area.ww.ecouser.net`| App (v2+) | \ No newline at end of file