certbot4mail.sh 3.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125
  1. #!/bin/bash
  2. #
  3. # необходимо для работы: nginx,certbot
  4. # create new cert
  5. path_ssl="/etc/ssl";
  6. path_cert="/etc/letsencrypt/live";
  7. source "/etc/scripts/certbot4mail/certbot4mail.conf";
  8. log="/var/log/syslog";
  9. #
  10. cmd=$1;
  11. #
  12. function createCert() {
  13. for ((dmn=0; dmn != ${#domains[@]}; dmn++))
  14. do
  15. certbot certonly --webroot --agree-tos --email $adminmail -w $webcrt -d ${domains[$dmn]}
  16. done
  17. }
  18. function renew() {
  19. certbot renew;
  20. valtrue=0;
  21. rdate=$(date +%Y-%m-%d);
  22. rtime=$(date +%H:%M);
  23. for ((dmn=0; dmn != ${#domains[@]}; dmn++))
  24. do
  25. keydate=$(ls -l --time-style=long-iso $path_cert/${domains[$dmn]}/cert.pem |awk {'print$6'});
  26. keytime=$(ls -l --time-style=long-iso $path_cert/${domains[$dmn]}/cert.pem |awk {'print$7'});
  27. if [ "$keydate" = "$rdate" ] && [ "$keytime" = "$rtime" ];
  28. then
  29. ((valtrue++));
  30. cat $path_cert/${domains[$dmn]}/cert.pem > $path_ssl/private/${domains[$dmn]}.pem;
  31. cat $path_cert/${domains[$dmn]}/chain.pem >> $path_ssl/private/${domains[$dmn]}.pem;
  32. cat $path_cert/${domains[$dmn]}/fullchain.pem >> $path_ssl/private/${domains[$dmn]}.pem;
  33. cat $path_cert/${domains[$dmn]}/privkey.pem >> $path_ssl/private/${domains[$dmn]}.pem;
  34. # to postfix
  35. cat $path_cert/${dreg[0]}/fullchain.pem >> $path_ssl/manual/fullchain.pem;
  36. cat $path_cert/${dreg[0]}/privkey.pem >> $path_ssl/manual/privkey.pem;
  37. #
  38. cp -f $path_ssl/private/${domains[$pem_index]}.pem $path_ssl/certs/${domains[$pem_index]}.pem
  39. cd $path_ssl/certs
  40. chmod 600 ${domains[$pem_index]}.pem
  41. ln -sf ${domains[$pem_index]}.pem `openssl x509 -noout -hash < ${domains[$pem_index]}.pem`.0
  42. cd $path_ssl
  43. echo "$(date) - certbot4mail.sh: update cert for ${domains[$dmn]}">> $log;
  44. fi
  45. done
  46. if [ $valtrue != 0 ];
  47. then
  48. :>/etc/ssl/crt-list.txt
  49. for ((icrt=0; icrt != ${#domains[@]}; icrt++))
  50. do
  51. echo "$path_ssl/${domains[$icrt]}.pem">>/etc/ssl/crt-list.txt
  52. done
  53. /etc/init.d/dbmail restart;
  54. /etc/init.d/stunnel4 restart;
  55. /etc/init.d/postfix restart;
  56. fi
  57. }
  58. function toSSL() {
  59. for ((dmn=0; dmn != ${#domains[@]}; dmn++))
  60. do
  61. eval local dreg="(" $(echo -e ${domains[$dmn]}) ")";
  62. ((valtrue++));
  63. cat $path_cert/${dreg[0]}/cert.pem > $path_ssl/private/${dreg[0]}.pem;
  64. cat $path_cert/${dreg[0]}/chain.pem >> $path_ssl/private/${dreg[0]}.pem;
  65. cat $path_cert/${dreg[0]}/fullchain.pem >> $path_ssl/private/${dreg[0]}.pem;
  66. cat $path_cert/${dreg[0]}/privkey.pem >> $path_ssl/private/${dreg[0]}.pem;
  67. # to postfix
  68. cat $path_cert/${dreg[0]}/fullchain.pem >> $path_ssl/manual/fullchain.pem;
  69. cat $path_cert/${dreg[0]}/privkey.pem >> $path_ssl/manual/privkey.pem;
  70. #
  71. cp -f $path_ssl/private/${dreg[0]}.pem $path_ssl/certs/${dreg[0]}.pem
  72. cd $path_ssl/certs
  73. chmod 600 ${dreg[0]}.pem
  74. ln -sf ${dreg[0]}.pem `openssl x509 -noout -hash < ${dreg[0]}.pem`.0
  75. cd $path_ssl
  76. echo "$(date) - auto4certbot.sh: update certlist for ${domains[$dmn]}">> $log;
  77. done
  78. if [ $valtrue != 0 ];
  79. then
  80. :>/etc/ssl/crt-list.txt
  81. for ((icrt=0; icrt != ${#domains[@]}; icrt++))
  82. do
  83. echo "$path_ssl/${domains[$icrt]}.pem">>/etc/ssl/crt-list.txt
  84. done
  85. /etc/init.d/dbmail restart;
  86. /etc/init.d/stunnel4 restart;
  87. /etc/init.d/postfix restart;
  88. fi
  89. }
  90. case "$cmd" in
  91. ## create cert
  92. "--create" | "--create" )
  93. createCert;
  94. ;;
  95. ## update cert
  96. "--update" | "--update" )
  97. renew;
  98. ;;
  99. ## update cert force
  100. "--flist" | "--flist" )
  101. toSSL;
  102. ;;
  103. ## start defaults
  104. * )
  105. echo "please input pameters: auto4certbot.sh --create | --update | --flist";
  106. echo "auto4certbot.sh --create; create new certificate"
  107. echo "auto4certbot.sh --update; update certificates;"
  108. echo "auto4certbot.sh --flist; update certificates from ssl;"
  109. ;;
  110. esac