Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8891d640bd | ||
|
|
7aac9ae933 | ||
|
|
19c931abb0 | ||
|
|
bcf6afad42 | ||
|
|
f7a20ac053 | ||
|
|
13613ab6d5 |
@@ -1,3 +1,15 @@
|
||||
# lego_acme_wrapper_script
|
||||
|
||||
wrapper script for lego acme
|
||||
|
||||
### Features
|
||||
- Issue certificates
|
||||
- Revoke certificates
|
||||
- Check status
|
||||
- Install Web-Servers (Nginx, HAProxy, Apache)
|
||||
- Update Lego
|
||||
|
||||
### Todo
|
||||
|
||||
- Auto create default conf file for issued certificates in Nginx (Only well conversant with Nginx)
|
||||
|
||||
+23
-20
@@ -35,8 +35,6 @@ set_env_variables() {
|
||||
export CERT_PATH=/etc/acme
|
||||
export CONTACT_MAIL=xxxxxxxxxxxxxxxxxxxxxxxx
|
||||
export DNS_PROVIDER=namecheap
|
||||
export NAMECHEAP_PROPAGATION_TIMEOUT=60
|
||||
export NAMECHEAP_POLLING_INTERVAL=2
|
||||
export NAMECHEAP_API_USER=xxxxxxxxxxxxxxxxxxxxxxxx
|
||||
export NAMECHEAP_API_KEY=xxxxxxxxxxxxxxxxxxxxxxxx
|
||||
|
||||
@@ -45,7 +43,6 @@ set_env_variables() {
|
||||
export GOPATH=$HOME/.go
|
||||
export GO_HOME=/usr/local/go
|
||||
export PATH=$PATH:$GO_HOME/bin:$GOPATH/bin
|
||||
|
||||
}
|
||||
|
||||
check_dependencies() {
|
||||
@@ -106,6 +103,7 @@ install_jq() {
|
||||
}
|
||||
|
||||
install_git() {
|
||||
### Needed for updates
|
||||
if ! command -v git 2>&1 >/dev/null; then
|
||||
install_as_sudo
|
||||
echo 'git module not installed'
|
||||
@@ -174,23 +172,17 @@ install_web_server() {
|
||||
case $option in
|
||||
"nginx")
|
||||
eval "echo $SUDO_PASS | sudo -S $install_cmd install nginx* -y"
|
||||
printf "\n\n\n"
|
||||
echo "run below command as admin on rhel type OS to allow network connections"
|
||||
echo "setsebool httpd_can_network_connect 1"
|
||||
echo_message
|
||||
exit 0
|
||||
;;
|
||||
"apache")
|
||||
eval "echo $SUDO_PASS | sudo -S $install_cmd install apach2e* -y"
|
||||
printf "\n\n\n"
|
||||
echo "run below command as admin on rhel type OS to allow network connections"
|
||||
echo "setsebool httpd_can_network_connect 1"
|
||||
echo_message
|
||||
exit 0
|
||||
;;
|
||||
"haproxy")
|
||||
eval "echo $SUDO_PASS | sudo -S $install_cmd install haproxy* -y"
|
||||
printf "\n\n\n"
|
||||
echo "run below command as admin on rhel type OS to allow network connections"
|
||||
echo "setsebool httpd_can_network_connect 1"
|
||||
echo_message
|
||||
exit 0
|
||||
;;
|
||||
esac
|
||||
@@ -198,9 +190,18 @@ install_web_server() {
|
||||
|
||||
}
|
||||
|
||||
echo_message(){
|
||||
|
||||
printf "\n\n\n"
|
||||
echo "run below command as admin if SELINUX is enabled to allow network connections"
|
||||
echo "setsebool httpd_can_network_connect 1"
|
||||
echo "Install firewall (firewall-cmd or ufw) for additional security"
|
||||
|
||||
}
|
||||
|
||||
update_lego() {
|
||||
export GO111MODULE=on
|
||||
eval "go install github.com/go-acme/lego/v4/cmd/lego@latest"
|
||||
eval "go install github.com/go-acme/lego/v4/cmd/lego@latest" 2>&1 | tee -a $LOG_FILE
|
||||
}
|
||||
|
||||
get_system_information() {
|
||||
@@ -227,7 +228,7 @@ get_os_type() {
|
||||
install_cmd="apt"
|
||||
elif [[ $os_type == *"almalinux"* ]]; then
|
||||
install_cmd="yum"
|
||||
elif [[ $os_type == *"redhat"* ]]; then
|
||||
elif [[ $os_type == *"rhel"* ]]; then
|
||||
install_cmd="yum"
|
||||
elif [[ $os_type == *"centos"* ]]; then
|
||||
install_cmd="yum"
|
||||
@@ -271,17 +272,20 @@ list() {
|
||||
autorenew() {
|
||||
|
||||
###to be used to store output from crontab renewals
|
||||
LOG_FILE="$CERT_PATH/log"
|
||||
if [ ! -d $LOG_FILE ]; then
|
||||
mkdir -p $LOG_FILE
|
||||
LOG_PATH="$CERT_PATH/log"
|
||||
DATE=$(date +%F-%H%M)
|
||||
LOG_FILE="$LOG_PATH/acme-$DATE"
|
||||
if [ ! -d $LOG_PATH ]; then
|
||||
mkdir -p $PATH
|
||||
fi
|
||||
|
||||
|
||||
for files in $(find $LEGO_PATH/certificates/*.json -type f); do
|
||||
IFS=$'\n'
|
||||
for file in $files; do
|
||||
temp_domain=$(cat $file | jq .domain | sed -e 's/^"//' -e 's/"$//')
|
||||
renew_command="$command -d $temp_domain renew"
|
||||
eval $renew_command
|
||||
eval " $renew_command" 2>&1 | tee -a $LOG_FILE
|
||||
done
|
||||
done
|
||||
|
||||
@@ -290,7 +294,6 @@ autorenew() {
|
||||
}
|
||||
|
||||
functionlist() {
|
||||
echo "Usage: {run, renew, revoke, list, update lego}"
|
||||
PS3="Select Option to enter option or and key to exit: "
|
||||
options=("run" "revoke" "renew" "list" "update lego" "install webserver")
|
||||
select option in "${options[@]}"; do
|
||||
@@ -349,7 +352,7 @@ cd $CERT_PATH
|
||||
echo "Acme Script for $DNS_PROVIDER"
|
||||
## If no parameters are given, print which are avaiable.
|
||||
echo "Usage: only dns challenge function available"
|
||||
command="lego --email $CONTACT_MAIL --dns $DNS_PROVIDER "
|
||||
command="lego --email $CONTACT_MAIL --dns $DNS_PROVIDER --dns.propagation-wait 240s "
|
||||
IFS=","
|
||||
if [ -z "$1" ]; then
|
||||
functionlist
|
||||
|
||||
Reference in New Issue
Block a user