6 Commits
Author SHA1 Message Date
agboola 8891d640bd Changes to propagation and logging
Removed propagation timeout and polling interval and introduced "--dns.propagation-wait 240s" to allow for proper dns propagation.
This is especially useful in an environment where dns queries are cached or locked down environment. 240s (4 minutes) is enough time for proper propagation of dns records.

added the logfile to the autorenew function to properly trac if cronjobs are actually run
2025-08-27 14:13:11 +01:00
agboola 7aac9ae933 Merge pull request 'get_os_type function updated' (#3) from patch-1.1 into main
Reviewed-on: #3
2025-07-16 15:15:39 +01:00
agboola 19c931abb0 get_os_type function updated
minor changes to awk command to determin os-release type
change redhat to rhel in function
2025-07-16 15:14:32 +01:00
agboola bcf6afad42 Update README.md 2025-07-16 15:08:49 +01:00
agboola f7a20ac053 Update README.md 2025-07-16 15:08:14 +01:00
agboola 13613ab6d5 Merge pull request 'Major Changes to Script - 20250716' (#1) from patch-1 into main
Reviewed-on: #1
2025-07-16 15:02:50 +01:00
2 changed files with 38 additions and 23 deletions
+12
View File
@@ -1,3 +1,15 @@
# lego_acme_wrapper_script
wrapper script for lego acme
### Features
- Issue certificates
- Revoke certificates
- Check status
- Install Web-Servers (Nginx, HAProxy, Apache)
- Update Lego
### Todo
- Auto create default conf file for issued certificates in Nginx (Only well conversant with Nginx)
+23 -20
View File
@@ -35,8 +35,6 @@ set_env_variables() {
export CERT_PATH=/etc/acme
export CONTACT_MAIL=xxxxxxxxxxxxxxxxxxxxxxxx
export DNS_PROVIDER=namecheap
export NAMECHEAP_PROPAGATION_TIMEOUT=60
export NAMECHEAP_POLLING_INTERVAL=2
export NAMECHEAP_API_USER=xxxxxxxxxxxxxxxxxxxxxxxx
export NAMECHEAP_API_KEY=xxxxxxxxxxxxxxxxxxxxxxxx
@@ -45,7 +43,6 @@ set_env_variables() {
export GOPATH=$HOME/.go
export GO_HOME=/usr/local/go
export PATH=$PATH:$GO_HOME/bin:$GOPATH/bin
}
check_dependencies() {
@@ -106,6 +103,7 @@ install_jq() {
}
install_git() {
### Needed for updates
if ! command -v git 2>&1 >/dev/null; then
install_as_sudo
echo 'git module not installed'
@@ -174,23 +172,17 @@ install_web_server() {
case $option in
"nginx")
eval "echo $SUDO_PASS | sudo -S $install_cmd install nginx* -y"
printf "\n\n\n"
echo "run below command as admin on rhel type OS to allow network connections"
echo "setsebool httpd_can_network_connect 1"
echo_message
exit 0
;;
"apache")
eval "echo $SUDO_PASS | sudo -S $install_cmd install apach2e* -y"
printf "\n\n\n"
echo "run below command as admin on rhel type OS to allow network connections"
echo "setsebool httpd_can_network_connect 1"
echo_message
exit 0
;;
"haproxy")
eval "echo $SUDO_PASS | sudo -S $install_cmd install haproxy* -y"
printf "\n\n\n"
echo "run below command as admin on rhel type OS to allow network connections"
echo "setsebool httpd_can_network_connect 1"
echo_message
exit 0
;;
esac
@@ -198,9 +190,18 @@ install_web_server() {
}
echo_message(){
printf "\n\n\n"
echo "run below command as admin if SELINUX is enabled to allow network connections"
echo "setsebool httpd_can_network_connect 1"
echo "Install firewall (firewall-cmd or ufw) for additional security"
}
update_lego() {
export GO111MODULE=on
eval "go install github.com/go-acme/lego/v4/cmd/lego@latest"
eval "go install github.com/go-acme/lego/v4/cmd/lego@latest" 2>&1 | tee -a $LOG_FILE
}
get_system_information() {
@@ -227,7 +228,7 @@ get_os_type() {
install_cmd="apt"
elif [[ $os_type == *"almalinux"* ]]; then
install_cmd="yum"
elif [[ $os_type == *"redhat"* ]]; then
elif [[ $os_type == *"rhel"* ]]; then
install_cmd="yum"
elif [[ $os_type == *"centos"* ]]; then
install_cmd="yum"
@@ -271,17 +272,20 @@ list() {
autorenew() {
###to be used to store output from crontab renewals
LOG_FILE="$CERT_PATH/log"
if [ ! -d $LOG_FILE ]; then
mkdir -p $LOG_FILE
LOG_PATH="$CERT_PATH/log"
DATE=$(date +%F-%H%M)
LOG_FILE="$LOG_PATH/acme-$DATE"
if [ ! -d $LOG_PATH ]; then
mkdir -p $PATH
fi
for files in $(find $LEGO_PATH/certificates/*.json -type f); do
IFS=$'\n'
for file in $files; do
temp_domain=$(cat $file | jq .domain | sed -e 's/^"//' -e 's/"$//')
renew_command="$command -d $temp_domain renew"
eval $renew_command
eval " $renew_command" 2>&1 | tee -a $LOG_FILE
done
done
@@ -290,7 +294,6 @@ autorenew() {
}
functionlist() {
echo "Usage: {run, renew, revoke, list, update lego}"
PS3="Select Option to enter option or and key to exit: "
options=("run" "revoke" "renew" "list" "update lego" "install webserver")
select option in "${options[@]}"; do
@@ -349,7 +352,7 @@ cd $CERT_PATH
echo "Acme Script for $DNS_PROVIDER"
## If no parameters are given, print which are avaiable.
echo "Usage: only dns challenge function available"
command="lego --email $CONTACT_MAIL --dns $DNS_PROVIDER "
command="lego --email $CONTACT_MAIL --dns $DNS_PROVIDER --dns.propagation-wait 240s "
IFS=","
if [ -z "$1" ]; then
functionlist