auto4certbot.sh 6.4 KB


  1. #!/bin/bash
  2. #
  3. # author: Koshuba V.O.
  4. # license: GPL 2.0
  5. # create 2022
  6. #
  7. version="0.2.3";
  8. sname="autocertbot";
  9. # необходимы для работы: nginx,certbot
  10. # create new cert
  11. path_ssl="/etc/ssl";
  12. path_cert="/etc/letsencrypt/live";
  13. source "/etc/scripts/certbot4nginx/auto4certbot.conf";
  14. ## - nginx
  15. nginx_enable="/etc/nginx/sites-enabled";
  16. nginx_available="/etc/nginx/sites-available";
  17. ##
  18. www_root="/tmp/letsencrypt";
  19. ##
  20. path_tmp="/tmp/certbot";
  21. ##
  22. log="/var/log/syslog";
  23. #
  24. cmd=$1;
  25. #-list enable sites
  26. scan_list=();
  27. #
  28. function createCert() {
  29. for ((dmn=0; dmn != ${#domains[@]}; dmn++))
  30. do
  31. eval local dreg="(" $(echo -e ${domains[$dmn]}) ")";
  32. certbot --update-registration -m "${dreg[1]}";
  33. ## example manual: certbot certonly --webroot --webroot-path /tmp/letsencrypt -d mydomen.ru
  34. certbot certonly --webroot --webroot-path $www_root -d ${dreg[0]}
  35. done
  36. }
  37. function renew() {
  38. certbot renew;
  39. valtrue=0;
  40. rdate=$(date +%Y-%m-%d);
  41. rtime=$(date +%H:%M);
  42. for ((dmn=0; dmn != ${#domains[@]}; dmn++))
  43. do
  44. eval local dreg="(" $(echo -e ${domains[$dmn]}) ")";
  45. keydate=$(ls -l --time-style=long-iso $path_cert/${dreg[0]}/cert.pem |awk {'print$6'});
  46. keytime=$(ls -l --time-style=long-iso $path_cert/${dreg[0]}/cert.pem |awk {'print$7'});
  47. if [ "$keydate" = "$rdate" ] && [ "$keytime" = "$rtime" ];
  48. then
  49. ((valtrue++));
  50. cat $path_cert/${dreg[0]}/cert.pem > $path_ssl/private/${dreg[0]}.pem;
  51. cat $path_cert/${dreg[0]}/chain.pem >> $path_ssl/private/${dreg[0]}.pem;
  52. cat $path_cert/${dreg[0]}/fullchain.pem >> $path_ssl/private/${dreg[0]}.pem;
  53. cat $path_cert/${dreg[0]}/privkey.pem >> $path_ssl/private/${dreg[0]}.pem;
  54. #
  55. cp -f $path_ssl/private/${dreg[0]}.pem $path_ssl/certs/${dreg[0]}.pem
  56. cd $path_ssl/certs
  57. chmod 600 ${dreg[0]}.pem
  58. ln -sf ${dreg[0]}.pem `openssl x509 -noout -hash < ${dreg[0]}.pem`.0
  59. cd $path_ssl
  60. echo "$(date) - auto4certbot.sh: update cert for ${domains[$dmn]}">> $log;
  61. fi
  62. done
  63. if [ $valtrue != 0 ];
  64. then
  65. :>/etc/ssl/crt-list.txt
  66. for ((icrt=0; icrt != ${#domains[@]}; icrt++))
  67. do
  68. echo "$path_ssl/${domains[$icrt]}.pem">>/etc/ssl/crt-list.txt
  69. done
  70. fi
  71. }
  72. function toSSL() {
  73. for ((dmn=0; dmn != ${#domains[@]}; dmn++))
  74. do
  75. eval local dreg="(" $(echo -e ${domains[$dmn]}) ")";
  76. ((valtrue++));
  77. cat $path_cert/${dreg[0]}/cert.pem > $path_ssl/private/${dreg[0]}.pem;
  78. cat $path_cert/${dreg[0]}/chain.pem >> $path_ssl/private/${dreg[0]}.pem;
  79. cat $path_cert/${dreg[0]}/fullchain.pem >> $path_ssl/private/${dreg[0]}.pem;
  80. cat $path_cert/${dreg[0]}/privkey.pem >> $path_ssl/private/${dreg[0]}.pem;
  81. #
  82. cp -f $path_ssl/private/${dreg[0]}.pem $path_ssl/certs/${dreg[0]}.pem
  83. cd $path_ssl/certs
  84. chmod 600 ${dreg[0]}.pem
  85. ln -sf ${dreg[0]}.pem `openssl x509 -noout -hash < ${dreg[0]}.pem`.0
  86. cd $path_ssl
  87. echo "$(date) - auto4certbot.sh: update certlist for ${domains[$dmn]}">> $log;
  88. done
  89. if [ $valtrue != 0 ];
  90. then
  91. echo >/etc/ssl/crt-list.txt
  92. for ((icrt=0; icrt != ${#domains[@]}; icrt++))
  93. do
  94. eval local dcrt="(" $(echo -e ${domains[$icrt]}) ")";
  95. echo "$path_ssl/private/${dcrt[0]}.pem">>/etc/ssl/crt-list.txt
  96. done
  97. fi
  98. }
  99. function downSite(){
  100. sudo systemctl stop nginx.service;
  101. eval list_www="(" $(find $nginx_enable/* -maxdepth 0 -type l -printf '%f\n') ")";
  102. for ((dwx=0; dwx != ${#list_www[@]}; dwx++))
  103. do
  104. rm $nginx_enable/${list_www[dwx]};
  105. done
  106. for ((dnm=0; dnm != ${#domains[@]}; dnm++))
  107. do
  108. eval local dcert="(" $(echo -e ${domains[$dnm]}) ")";
  109. sitename="${dcert[0]}";
  110. siteport="${dcert[2]}";
  111. createConf;
  112. done
  113. sudo systemctl start nginx.service;
  114. }
  115. function upSite(){
  116. sudo systemctl stop nginx.service;
  117. eval cert_bot="(" $(find $nginx_enable/* -maxdepth 0 -type l -printf '%f\n') ")";
  118. for ((cr=0; cr != ${#cert_bot[@]}; cr++))
  119. do
  120. rm $nginx_enable/${cert_bot[cr]};
  121. done
  122. for ((dwx=0; dwx != ${#list_www[@]}; dwx++))
  123. do
  124. ln -s $nginx_available/${list_www[dwx]} $nginx_enable/${list_www[dwx]};
  125. done
  126. sudo systemctl start nginx.service;
  127. }
  128. function createConf(){
  129. if [ ! -d $path_tmp ];
  130. then
  131. mkdir -p $path_tmp;
  132. fi
  133. if [ ! -d $www_root ];
  134. then
  135. mkdir -p $www_root/.well-known/acme-challenge;
  136. chown -R www-data:www-data $www_root;
  137. fi
  138. echo >$path_tmp/$sitename.conf;
  139. echo -e 'server { listen 0.0.0.0:'"$siteport"';' >>$path_tmp/$sitename.conf;
  140. echo -e '\n' >>$path_tmp/$sitename.conf;
  141. echo -e 'server_name '"$sitename"';' >>$path_tmp/$sitename.conf;
  142. echo -e '\n' >>$path_tmp/$sitename.conf;
  143. #echo -e 'if ($http_host != $server_name){' >> $path_tmp/$sitename.conf;
  144. #echo -e ' rewrite ^(.*)$ http://$server_name$1 redirect;'>>$path_tmp/$sitename.conf;
  145. #echo -e '}' >>$path_tmp/$sitename.conf;
  146. #echo -e '\n' >>$path_tmp/$sitename.conf;
  147. echo -e 'location /.well-known/acme-challenge {' >>$path_tmp/$sitename.conf;
  148. echo -e ' allow all;' >>$path_tmp/$sitename.conf;
  149. echo -e ' autoindex off;' >>$path_tmp/$sitename.conf;
  150. echo -e ' default_type "text/plain";' >>$path_tmp/$sitename.conf;
  151. echo -e ' root '"$www_root"';' >>$path_tmp/$sitename.conf;
  152. echo -e '}' >>$path_tmp/$sitename.conf;
  153. echo -e '\n' >>$path_tmp/$sitename.conf;
  154. echo -e 'location = /.well-known {' >>$path_tmp/$sitename.conf;
  155. echo -e ' return 404;' >>$path_tmp/$sitename.conf;
  156. echo -e '}' >>$path_tmp/$sitename.conf;
  157. echo -e '\n' >>$path_tmp/$sitename.conf;
  158. echo -e 'error_page 404 /404.html;' >>$path_tmp/$sitename.conf;
  159. echo -e 'error_page 500 502 503 504 /50x.html;' >>$path_tmp/$sitename.conf;
  160. echo -e '\n' >>$path_tmp/$sitename.conf;
  161. echo -e 'error_log /var/log/nginx/err-certbot.log;' >>$path_tmp/$sitename.conf;
  162. echo -e 'access_log /var/log/nginx/access-certbot.log;' >>$path_tmp/$sitename.conf;
  163. echo -e '}' >>$path_tmp/$sitename.conf;
  164. ln -s $path_tmp/$sitename.conf $nginx_enable/$sitename.conf
  165. }
  166. case "$cmd" in
  167. ## create cert
  168. "--create" | "--create" )
  169. downSite;
  170. createCert;
  171. upSite;
  172. toSSL;
  173. ;;
  174. ## update cert
  175. "--update" | "--update" )
  176. downSite;
  177. renew;
  178. upSite;
  179. toSSL;
  180. ;;
  181. ## update cert force
  182. "--flist" | "--flist" )
  183. toSSL;
  184. ;;
  185. ## start defaults
  186. * )
  187. echo "please input pameters: auto4certbot.sh --create | --update | --flist";
  188. echo "auto4certbot.sh --create; create new certificate"
  189. echo "auto4certbot.sh --update; update certificates;"
  190. echo "auto4certbot.sh --flist; update certificates from ssl;"
  191. ;;
  192. esac
  193. exit