11 Commits
Author SHA1 Message Date
agboola 3c3e81a8c7 Merge pull request 'added cloudflare DNS provider' (#6) from patch-1.4 into main
Reviewed-on: #6
2025-11-14 20:34:29 +00:00
agboola 79469bcb23 added cloudflare DNS provider 2025-11-14 20:34:21 +00:00
agboola 39ae143d33 Merge pull request 'added cloudflare DNS provider' (#5) from patch-1.3 into main
Reviewed-on: #5
2025-11-14 20:32:39 +00:00
agboola 19d6047b74 added cloudflare DNS provider
Cloudflare dns
2025-11-14 20:32:18 +00:00
agboola 35ef752233 Merge pull request 'Changes to propagation and logging' (#4) from patch-1.2 into main
Reviewed-on: #4
2025-08-27 14:14:16 +01:00
agboola 8891d640bd Changes to propagation and logging
Removed propagation timeout and polling interval and introduced "--dns.propagation-wait 240s" to allow for proper dns propagation.
This is especially useful in an environment where dns queries are cached or locked down environment. 240s (4 minutes) is enough time for proper propagation of dns records.

added the logfile to the autorenew function to properly trac if cronjobs are actually run
2025-08-27 14:13:11 +01:00
agboola 7aac9ae933 Merge pull request 'get_os_type function updated' (#3) from patch-1.1 into main
Reviewed-on: #3
2025-07-16 15:15:39 +01:00
agboola 19c931abb0 get_os_type function updated
minor changes to awk command to determin os-release type
change redhat to rhel in function
2025-07-16 15:14:32 +01:00
agboola bcf6afad42 Update README.md 2025-07-16 15:08:49 +01:00
agboola f7a20ac053 Update README.md 2025-07-16 15:08:14 +01:00
agboola 13613ab6d5 Merge pull request 'Major Changes to Script - 20250716' (#1) from patch-1 into main
Reviewed-on: #1
2025-07-16 15:02:50 +01:00
2 changed files with 69 additions and 34 deletions
+12
View File
@@ -1,3 +1,15 @@
# lego_acme_wrapper_script # lego_acme_wrapper_script
wrapper script for lego acme wrapper script for lego acme
### Features
- Issue certificates
- Revoke certificates
- Check status
- Install Web-Servers (Nginx, HAProxy, Apache)
- Update Lego
### Todo
- Auto create default conf file for issued certificates in Nginx (Only well conversant with Nginx)
+55 -32
View File
@@ -6,10 +6,10 @@
#revoked certificate names would be removed from existing list of issued certificates - done #revoked certificate names would be removed from existing list of issued certificates - done
#cron jobs would be created for renew function - done #cron jobs would be created for renew function - done
#add auto update for lego tool - (also to cron) - done, not using cron making manual from menu #add auto update for lego tool - (also to cron) - done, not using cron making manual from menu
#add install for webserver type either apache/nginx - done
#add install for webserver type either apache/nginx - pending #auto create default config file for created domains (man i really wish i can do this. lol) - pfff - I definitely will - pending
#RSYNC to different servers when renewed (either through sshkey or password think sshkey would be nicer) - pending
#auto create default config file for created domains (man i really wish i can do this. lol)
#Export to be based on user preference #Export to be based on user preference
#Enviromental Variables for certificate paths, this is to make sure certificates are always issued in same path #Enviromental Variables for certificate paths, this is to make sure certificates are always issued in same path
@@ -17,6 +17,7 @@
#Can be run without root - root only needed to install dependencies from apt/yum #Can be run without root - root only needed to install dependencies from apt/yum
#should be folder that doesn't need root permission #should be folder that doesn't need root permission
#Use case - namecheap (environment variable depends on dns provider) #Use case - namecheap (environment variable depends on dns provider)
#check out https://go-acme.github.io/lego/dns/index.html for dns provider variables #check out https://go-acme.github.io/lego/dns/index.html for dns provider variables
@@ -33,14 +34,18 @@ install_as_sudo() {
set_env_variables() { set_env_variables() {
#envs for lego #envs for lego
export CERT_PATH=/etc/acme export CERT_PATH=/etc/acme
export CONTACT_MAIL=xxxxxxxxxxxxxxxxxxxxxxxx export CONTACT_MAIL=xxxxxxxxxxxxxxxxxxxxxxxx@xxxx.xxx
export DNS_PROVIDER=namecheap export DNS_PROVIDER=cloudflare
export NAMECHEAP_PROPAGATION_TIMEOUT=60
export NAMECHEAP_POLLING_INTERVAL=2
export NAMECHEAP_API_USER=xxxxxxxxxxxxxxxxxxxxxxxx
export NAMECHEAP_API_KEY=xxxxxxxxxxxxxxxxxxxxxxxx
#envs for path #namecheap envs for lego
#export NAMECHEAP_API_USER=xxxxxxxxxxxxxxxxxxxxxxxx
#export NAMECHEAP_API_KEY=xxxxxxxxxxxxxxxxxxxxxxxx
#cloudflare envs for lego
export CLOUDFLARE_EMAIL=xxxxxxxxxxxxxxxxxxxxxxxx@xxxx.xxx
export CLOUDFLARE_DNS_API_TOKEN=xxxxxxxxxxxxxxxxxxxxxxxx
#envs for path - (i'm doing this to avoid lego being run without using this script)
export LEGO_PATH=$CERT_PATH export LEGO_PATH=$CERT_PATH
export GOPATH=$HOME/.go export GOPATH=$HOME/.go
export GO_HOME=/usr/local/go export GO_HOME=/usr/local/go
@@ -106,6 +111,7 @@ install_jq() {
} }
install_git() { install_git() {
### Needed for updates
if ! command -v git 2>&1 >/dev/null; then if ! command -v git 2>&1 >/dev/null; then
install_as_sudo install_as_sudo
echo 'git module not installed' echo 'git module not installed'
@@ -174,23 +180,17 @@ install_web_server() {
case $option in case $option in
"nginx") "nginx")
eval "echo $SUDO_PASS | sudo -S $install_cmd install nginx* -y" eval "echo $SUDO_PASS | sudo -S $install_cmd install nginx* -y"
printf "\n\n\n" echo_message
echo "run below command as admin on rhel type OS to allow network connections"
echo "setsebool httpd_can_network_connect 1"
exit 0 exit 0
;; ;;
"apache") "apache")
eval "echo $SUDO_PASS | sudo -S $install_cmd install apach2e* -y" eval "echo $SUDO_PASS | sudo -S $install_cmd install apache2* -y"
printf "\n\n\n" echo_message
echo "run below command as admin on rhel type OS to allow network connections"
echo "setsebool httpd_can_network_connect 1"
exit 0 exit 0
;; ;;
"haproxy") "haproxy")
eval "echo $SUDO_PASS | sudo -S $install_cmd install haproxy* -y" eval "echo $SUDO_PASS | sudo -S $install_cmd install haproxy* -y"
printf "\n\n\n" echo_message
echo "run below command as admin on rhel type OS to allow network connections"
echo "setsebool httpd_can_network_connect 1"
exit 0 exit 0
;; ;;
esac esac
@@ -198,9 +198,31 @@ install_web_server() {
} }
echo_message(){
printf "\n\n\n"
echo "run below command as admin if SELINUX is enabled to allow network connections"
echo "setsebool httpd_can_network_connect 1"
echo "setsebool -P haproxy_connect_any=1"
echo "Install firewall (firewall-cmd or ufw) for additional security"
}
update_lego() { update_lego() {
###to be used to store output from crontab renewals
LOG_PATH="$CERT_PATH/log"
DATE=$(date +%F-%H%M)
LOG_FILE="$LOG_PATH/lego-update-$DATE.log"
if [ ! -d $LOG_PATH ]; then
mkdir -p $LOG_PATH
fi
echo " "
eval " lego -v"
echo " "
export GO111MODULE=on export GO111MODULE=on
eval "go install github.com/go-acme/lego/v4/cmd/lego@latest" eval "go install github.com/go-acme/lego/v4/cmd/lego@latest" 2>&1 | tee -a $LOG_FILE
} }
get_system_information() { get_system_information() {
@@ -227,7 +249,7 @@ get_os_type() {
install_cmd="apt" install_cmd="apt"
elif [[ $os_type == *"almalinux"* ]]; then elif [[ $os_type == *"almalinux"* ]]; then
install_cmd="yum" install_cmd="yum"
elif [[ $os_type == *"redhat"* ]]; then elif [[ $os_type == *"rhel"* ]]; then
install_cmd="yum" install_cmd="yum"
elif [[ $os_type == *"centos"* ]]; then elif [[ $os_type == *"centos"* ]]; then
install_cmd="yum" install_cmd="yum"
@@ -271,9 +293,11 @@ list() {
autorenew() { autorenew() {
###to be used to store output from crontab renewals ###to be used to store output from crontab renewals
LOG_FILE="$CERT_PATH/log" LOG_PATH="$CERT_PATH/log"
if [ ! -d $LOG_FILE ]; then DATE=$(date +%F-%H%M)
mkdir -p $LOG_FILE LOG_FILE="$LOG_PATH/acme-$DATE.log"
if [ ! -d $LOG_PATH ]; then
mkdir -p $LOG_PATH
fi fi
for files in $(find $LEGO_PATH/certificates/*.json -type f); do for files in $(find $LEGO_PATH/certificates/*.json -type f); do
@@ -281,7 +305,7 @@ autorenew() {
for file in $files; do for file in $files; do
temp_domain=$(cat $file | jq .domain | sed -e 's/^"//' -e 's/"$//') temp_domain=$(cat $file | jq .domain | sed -e 's/^"//' -e 's/"$//')
renew_command="$command -d $temp_domain renew" renew_command="$command -d $temp_domain renew"
eval $renew_command eval " $renew_command" 2>&1 | tee -a $LOG_FILE
done done
done done
@@ -290,12 +314,11 @@ autorenew() {
} }
functionlist() { functionlist() {
echo "Usage: {run, renew, revoke, list, update lego}"
PS3="Select Option to enter option or and key to exit: " PS3="Select Option to enter option or and key to exit: "
options=("run" "revoke" "renew" "list" "update lego" "install web server") options=("issue" "revoke" "renew" "list" "update lego" "install webserver")
select option in "${options[@]}"; do select option in "${options[@]}"; do
case $option in case $option in
"run") "issue")
run run
;; ;;
"revoke") "revoke")
@@ -324,7 +347,7 @@ functionlist() {
functionvar() { functionvar() {
case $1 in case $1 in
"run") "issue")
run run
;; ;;
"revoke") "revoke")
@@ -349,7 +372,7 @@ cd $CERT_PATH
echo "Acme Script for $DNS_PROVIDER" echo "Acme Script for $DNS_PROVIDER"
## If no parameters are given, print which are avaiable. ## If no parameters are given, print which are avaiable.
echo "Usage: only dns challenge function available" echo "Usage: only dns challenge function available"
command="lego --email $CONTACT_MAIL --dns $DNS_PROVIDER " command="lego --email $CONTACT_MAIL --dns $DNS_PROVIDER --dns.propagation-wait 240s "
IFS="," IFS=","
if [ -z "$1" ]; then if [ -z "$1" ]; then
functionlist functionlist
@@ -357,4 +380,4 @@ if [ -z "$1" ]; then
else else
functionvar $1 functionvar $1
exit 0 exit 0
fi f3