Compare commits

...

5 Commits

66
renew_cert.sh Normal file → Executable file
View File

@ -4,8 +4,8 @@ path="$( cd "$(dirname "$0")" ; pwd -P )"
############# #############
# variables # variables
acme_dir=/srv/certs/acme-challenge/.well-known/acme-challenge acme_dir=/docker/certs/acme-challenge/.well-known/acme-challenge
opt_dir=/srv/certs/.opt opt_dir=/docker/certs/.opt
account_key=$opt_dir/account.key account_key=$opt_dir/account.key
acme_tiny=$opt_dir/acme_tiny.py acme_tiny=$opt_dir/acme_tiny.py
openssl_conf=$opt_dir/openssl.conf openssl_conf=$opt_dir/openssl.conf
@ -14,6 +14,7 @@ openssl_conf=$opt_dir/openssl.conf
# script # script
main() {
# stop script if receive SIGINT (ctrl-c) # stop script if receive SIGINT (ctrl-c)
trap "exit" INT trap "exit" INT
@ -37,42 +38,54 @@ if [ ! -d "$acme_dir" ]; then
exit 1 exit 1
fi fi
if [ ! -f "$account_key" ]; then if [ ! -s "$account_key" ]; then
echo "Account Key doesn't exists!" echo "Account Key doesn't exists!"
exit 1 exit 1
fi fi
if [ ! -f "$acme_tiny" ]; then if [ ! -s "$acme_tiny" ]; then
echo "Python script acme_tiny.py is missing. Downloading... " echo -n "Python script acme_tiny.py is missing. Downloading... "
wget -qo $acme_tiny https://raw.githubusercontent.com/diafygi/acme-tiny/4.0.4/acme_tiny.py wget -qO "$acme_tiny" https://raw.githubusercontent.com/diafygi/acme-tiny/5.0.1/acme_tiny.py
if [ $? != 0 ]; then if [ $? != 0 ]; then
echo "Could not download acme_tiny.py script." echo -ne "\nCould not download acme_tiny.py script.\n"
rm -rf $acme_tiny rm -f "$acme_tiny"
exit 1 exit 1
fi fi
echo "Finished" echo -ne "Finished\n"
fi fi
acme_dir=${acme_dir%/} acme_dir=${acme_dir%/}
opt_dir=${opt_dir%/} opt_dir=${opt_dir%/}
# check if python is installed # check if python is installed
command -v python >/dev/null 2>&1 || { echo >&2 "I require python but it's not installed. Aborting."; exit 1; } command -v python >/dev/null 2>&1 || { echo >&2 "Python is required but it's not installed. Aborting."; exit 1; }
counter=0 counter=0
for arg in "$@" for arg in "$@"
do do
process_renewal
if [ $? == 0 ]; then
echo "Certificate successfully created!"
counter=$((counter+1))
fi
done
echo "$counter new certificates created!"
}
process_renewal() (
arg="$path/${arg%/}" arg="$path/${arg%/}"
if [ ! -d "$arg" ]; then if [ ! -d "$arg" ]; then
echo "Folder $arg doesn't exists!" echo "Folder $arg doesn't exists!"
continue return 1
fi fi
if [ ! -f "$arg/domain.conf" ]; then if [ ! -s "$arg/domain.conf" ]; then
echo "Configuration file doen't exists!" echo "Configuration file doen't exists!"
continue return 1
fi fi
# load configuration variables # load configuration variables
@ -82,19 +95,20 @@ do
# check domain.conf variables # check domain.conf variables
if [ -z "$NAME" ]; then if [ -z "$NAME" ]; then
echo "No name given for domain \"$arg\"". echo "No name given for domain \"$arg\"".
continue return 1
fi fi
echo "Processing certificate \"$NAME\"..."
if [ ${#DOMAINS[@]} -eq 0 ]; then if [ ${#DOMAINS[@]} -eq 0 ]; then
echo "No domains given for \"$NAME\"." echo "No domains given for \"$NAME\"."
continue return 1
fi fi
# domain key # domain key
key="$arg/$NAME.key" key="$arg/$NAME.key"
if [ ! -f "$key" ]; then if [ ! -s "$key" ]; then
echo "Domain key doesn't exists. Generating..." echo "Domain key doesn't exists. Generating..."
openssl genrsa 4096 > "$key" openssl genrsa 4096 > "$key"
#openssl ecparam -out "$key" -name secp384r1 -genkey #openssl ecparam -out "$key" -name secp384r1 -genkey
@ -103,7 +117,7 @@ do
# domain csr # domain csr
csr="$arg/$NAME.csr" csr="$arg/$NAME.csr"
if [ ! -f "$csr" ]; then if [ ! -s "$csr" ]; then
echo "Domain csr file doesn't exists. Generating..." echo "Domain csr file doesn't exists. Generating..."
if [ ${#DOMAINS[@]} -eq 1 ]; then if [ ${#DOMAINS[@]} -eq 1 ]; then
# single domain # single domain
@ -119,7 +133,7 @@ do
if [ $? != 0 ]; then if [ $? != 0 ]; then
echo "Creating csr/key files FAILED for \"$NAME\"!" echo "Creating csr/key files FAILED for \"$NAME\"!"
continue return 1
fi fi
# get certificate # get certificate
@ -128,14 +142,18 @@ do
if [ $? != 0 ]; then if [ $? != 0 ]; then
rm -rf $arg/tmp.pem rm -rf $arg/tmp.pem
echo "Getting certificate for \"$NAME\" FAILED!" echo "Getting certificate for \"$NAME\" FAILED!"
continue return 1
fi fi
if [ -s "$arg/tmp.pem" ]; then
mv -f "$arg/tmp.pem" "$arg/$NAME.pem" mv -f "$arg/tmp.pem" "$arg/$NAME.pem"
else
echo "New certificate for \"$NAME\" doesn't exists or is empty"
rm -rf "$arg/tmp.pem"
return 1
fi
echo "Certificate for \"$NAME\" successfully created!" return 0
counter=$((counter+1)) )
done main "$@"; exit
echo "$counter new certificates created!"