certbot4mail.sh 2.2 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677
  1. #!/bin/bash
  2. #
  3. # необходимо для работы: nginx,certbot
  4. # create new cert
  5. path_ssl="/etc/ssl";
  6. path_cert="/etc/letsencrypt/live";
  7. source "/etc/scripts/certbot4mail/certbot4mail.conf";
  8. log="/var/log/syslog";
  9. #
  10. cmd=$1;
  11. #
  12. function createCert() {
  13. for ((dmn=0; dmn != ${#domains[@]}; dmn++))
  14. do
  15. certbot certonly --webroot --agree-tos --email $adminmail -w $webcrt -d ${domains[$dmn]}
  16. done
  17. }
  18. function renew() {
  19. certbot renew;
  20. valtrue=0;
  21. rdate=$(date +%Y-%m-%d);
  22. rtime=$(date +%H:%M);
  23. for ((dmn=0; dmn != ${#domains[@]}; dmn++))
  24. do
  25. keydate=$(ls -l --time-style=long-iso $path_cert/${domains[$dmn]}/cert.pem |awk {'print$6'});
  26. keytime=$(ls -l --time-style=long-iso $path_cert/${domains[$dmn]}/cert.pem |awk {'print$7'});
  27. if [ "$keydate" = "$rdate" ] && [ "$keytime" = "$rtime" ];
  28. then
  29. ((valtrue++));
  30. cat $path_cert/${domains[$dmn]}/cert.pem > $path_ssl/private/${domains[$dmn]}.pem;
  31. cat $path_cert/${domains[$dmn]}/chain.pem >> $path_ssl/private/${domains[$dmn]}.pem;
  32. cat $path_cert/${domains[$dmn]}/fullchain.pem >> $path_ssl/private/${domains[$dmn]}.pem;
  33. cat $path_cert/${domains[$dmn]}/privkey.pem >> $path_ssl/private/${domains[$dmn]}.pem;
  34. #
  35. cp -f $path_ssl/private/${domains[$pem_index]}.pem $path_ssl/certs/${domains[$pem_index]}.pem
  36. cd $path_ssl/certs
  37. chmod 600 ${domains[$pem_index]}.pem
  38. ln -sf ${domains[$pem_index]}.pem `openssl x509 -noout -hash < ${domains[$pem_index]}.pem`.0
  39. cd $path_ssl
  40. echo "$(date) - certbot4mail.sh: update cert for ${domains[$dmn]}">> $log;
  41. fi
  42. done
  43. if [ $valtrue != 0 ];
  44. then
  45. :>/etc/ssl/crt-list.txt
  46. for ((icrt=0; icrt != ${#domains[@]}; icrt++))
  47. do
  48. echo "$path_ssl/${domains[$icrt]}.pem">>/etc/ssl/crt-list.txt
  49. done
  50. /etc/init.d/dbmail restart;
  51. /etc/init.d/stunnel4 restart;
  52. fi
  53. }
  54. case "$cmd" in
  55. ## create cert
  56. "--create" | "--create" )
  57. createCert;
  58. ;;
  59. ## update cert
  60. "--update" | "--update" )
  61. renew;
  62. ;;
  63. ## start defaults
  64. * )
  65. echo "please input pameters: certbot4mail.sh --create | --update";
  66. echo "certbot4mail.sh --create; create new certificate"
  67. echo "certbot4mail.sh --update; update certificates;"
  68. ;;
  69. esac