2016-04-17 19:47:22 +08:00
#!/usr/bin/env sh
2016-04-25 20:01:37 +08:00
2018-02-10 09:03:55 +08:00
VER = 2.7.7
2016-04-13 20:37:18 +08:00
2016-04-14 21:44:26 +08:00
PROJECT_NAME = "acme.sh"
2016-04-13 20:37:18 +08:00
2016-04-14 21:44:26 +08:00
PROJECT_ENTRY = "acme.sh"
PROJECT = " https://github.com/Neilpang/ $PROJECT_NAME "
2016-03-08 20:44:12 +08:00
2016-09-02 22:37:49 +08:00
DEFAULT_INSTALL_HOME = " $HOME /. $PROJECT_NAME "
_SCRIPT_ = " $0 "
2016-10-11 20:56:59 +08:00
_SUB_FOLDERS = "dnsapi deploy"
2016-09-02 22:37:49 +08:00
2018-01-06 12:45:24 +08:00
LETSENCRYPT_CA_V1 = "https://acme-v01.api.letsencrypt.org/directory"
LETSENCRYPT_STAGING_CA_V1 = "https://acme-staging.api.letsencrypt.org/directory"
LETSENCRYPT_CA_V2 = "https://acme-v02.api.letsencrypt.org/directory"
LETSENCRYPT_STAGING_CA_V2 = "https://acme-staging-v02.api.letsencrypt.org/directory"
DEFAULT_CA = $LETSENCRYPT_CA_V1
DEFAULT_STAGING_CA = $LETSENCRYPT_STAGING_CA_V1
2017-12-07 21:32:17 +08:00
2016-11-13 21:47:58 +08:00
DEFAULT_USER_AGENT = " $PROJECT_NAME / $VER ( $PROJECT ) "
2016-09-20 19:08:02 +08:00
DEFAULT_ACCOUNT_EMAIL = ""
2016-03-19 22:04:03 +08:00
2016-11-06 23:08:45 +08:00
DEFAULT_ACCOUNT_KEY_LENGTH = 2048
DEFAULT_DOMAIN_KEY_LENGTH = 2048
2016-11-22 21:43:42 +08:00
DEFAULT_OPENSSL_BIN = "openssl"
2018-01-06 12:45:24 +08:00
_OLD_CA_HOST = "https://acme-v01.api.letsencrypt.org"
2017-06-17 17:15:37 +08:00
_OLD_STAGE_CA_HOST = "https://acme-staging.api.letsencrypt.org"
2016-03-08 20:44:12 +08:00
VTYPE_HTTP = "http-01"
VTYPE_DNS = "dns-01"
2016-06-17 13:23:44 +08:00
VTYPE_TLS = "tls-sni-01"
2018-01-06 12:45:24 +08:00
VTYPE_TLS2 = "tls-sni-02"
2016-06-17 13:23:44 +08:00
2016-09-23 23:14:03 +08:00
LOCAL_ANY_ADDRESS = "0.0.0.0"
2016-10-04 20:55:31 +08:00
MAX_RENEW = 60
2016-06-26 10:09:51 +08:00
2016-07-15 22:56:16 +08:00
DEFAULT_DNS_SLEEP = 120
2016-09-23 22:35:13 +08:00
NO_VALUE = "no"
2016-06-17 13:23:44 +08:00
W_TLS = "tls"
2016-03-08 20:44:12 +08:00
2017-02-06 20:42:54 +08:00
MODE_STATELESS = "stateless"
2016-08-07 10:21:27 +08:00
STATE_VERIFIED = "verified_ok"
2017-02-13 23:29:37 +08:00
NGINX = "nginx:"
2017-02-14 22:03:48 +08:00
NGINX_START = "#ACME_NGINX_START"
NGINX_END = "#ACME_NGINX_END"
2017-02-13 23:29:37 +08:00
2016-03-17 21:18:09 +08:00
BEGIN_CSR = "-----BEGIN CERTIFICATE REQUEST-----"
END_CSR = "-----END CERTIFICATE REQUEST-----"
BEGIN_CERT = "-----BEGIN CERTIFICATE-----"
END_CERT = "-----END CERTIFICATE-----"
2016-06-18 11:29:28 +08:00
RENEW_SKIP = 2
2016-08-13 19:22:25 +08:00
ECC_SEP = "_"
ECC_SUFFIX = " ${ ECC_SEP } ecc "
2016-09-25 21:58:59 +08:00
LOG_LEVEL_1 = 1
LOG_LEVEL_2 = 2
LOG_LEVEL_3 = 3
DEFAULT_LOG_LEVEL = " $LOG_LEVEL_1 "
2017-02-19 12:13:18 +08:00
DEBUG_LEVEL_1 = 1
DEBUG_LEVEL_2 = 2
DEBUG_LEVEL_3 = 3
DEBUG_LEVEL_DEFAULT = $DEBUG_LEVEL_1
DEBUG_LEVEL_NONE = 0
2017-02-19 13:24:00 +08:00
HIDDEN_VALUE = "[hidden](please add '--output-insecure' to see this value)"
2017-02-11 21:15:36 +08:00
SYSLOG_ERROR = "user.error"
2017-02-19 12:13:18 +08:00
SYSLOG_INFO = "user.info"
2017-02-11 21:15:36 +08:00
SYSLOG_DEBUG = "user.debug"
2017-02-19 12:13:18 +08:00
#error
2017-02-19 12:42:37 +08:00
SYSLOG_LEVEL_ERROR = 3
2017-02-19 12:13:18 +08:00
#info
2017-02-19 12:42:37 +08:00
SYSLOG_LEVEL_INFO = 6
2017-02-19 12:13:18 +08:00
#debug
2017-02-19 12:42:37 +08:00
SYSLOG_LEVEL_DEBUG = 7
2017-02-19 12:13:18 +08:00
#debug2
2017-02-19 12:42:37 +08:00
SYSLOG_LEVEL_DEBUG_2 = 8
2017-02-19 12:13:18 +08:00
#debug3
2017-02-19 12:42:37 +08:00
SYSLOG_LEVEL_DEBUG_3 = 9
2017-02-19 12:13:18 +08:00
2017-02-19 12:42:37 +08:00
SYSLOG_LEVEL_DEFAULT = $SYSLOG_LEVEL_ERROR
2017-02-19 12:13:18 +08:00
#none
SYSLOG_LEVEL_NONE = 0
2016-09-25 21:58:59 +08:00
_DEBUG_WIKI = "https://github.com/Neilpang/acme.sh/wiki/How-to-debug-acme.sh"
2016-03-08 20:44:12 +08:00
2017-02-05 23:06:06 +08:00
_PREPARE_LINK = "https://github.com/Neilpang/acme.sh/wiki/Install-preparations"
2017-02-06 20:42:54 +08:00
_STATELESS_WIKI = "https://github.com/Neilpang/acme.sh/wiki/Stateless-Mode"
2017-08-22 20:27:13 +08:00
_DNS_MANUAL_ERR = "The dns manual mode can not renew automatically, you must issue it again manually. You'd better use the other modes instead."
_DNS_MANUAL_WARN = " It seems that you are using dns manual mode. please take care: $_DNS_MANUAL_ERR "
2016-09-06 19:37:41 +08:00
__INTERACTIVE = ""
2016-11-09 19:30:39 +08:00
if [ -t 1 ] ; then
2016-09-06 19:37:41 +08:00
__INTERACTIVE = "1"
fi
2016-04-17 17:33:08 +08:00
2016-08-13 19:22:25 +08:00
__green( ) {
2017-06-18 22:13:33 +08:00
if [ " $__INTERACTIVE ${ ACME_NO_COLOR } " = "1" ] ; then
2016-09-02 20:55:11 +08:00
printf '\033[1;31;32m'
fi
2017-04-05 20:54:53 +08:00
printf -- "%b" " $1 "
2017-06-18 22:13:33 +08:00
if [ " $__INTERACTIVE ${ ACME_NO_COLOR } " = "1" ] ; then
2016-09-02 20:55:11 +08:00
printf '\033[0m'
fi
2016-08-13 19:22:25 +08:00
}
__red( ) {
2017-06-18 22:13:33 +08:00
if [ " $__INTERACTIVE ${ ACME_NO_COLOR } " = "1" ] ; then
2016-09-02 20:55:11 +08:00
printf '\033[1;31;40m'
fi
2017-04-05 20:54:53 +08:00
printf -- "%b" " $1 "
2017-06-18 22:13:33 +08:00
if [ " $__INTERACTIVE ${ ACME_NO_COLOR } " = "1" ] ; then
2016-09-02 20:55:11 +08:00
printf '\033[0m'
fi
2016-08-13 19:22:25 +08:00
}
2016-04-17 17:33:08 +08:00
2016-09-25 21:58:59 +08:00
_printargs( ) {
2016-11-29 00:11:02 +08:00
if [ -z " $NO_TIMESTAMP " ] || [ " $NO_TIMESTAMP " = "0" ] ; then
printf -- "%s" " [ $( date) ] "
fi
2016-11-09 19:30:39 +08:00
if [ -z " $2 " ] ; then
2016-11-29 00:11:02 +08:00
printf -- "%s" " $1 "
2016-08-13 19:22:25 +08:00
else
2016-11-29 00:11:02 +08:00
printf -- "%s" " $1 =' $2 ' "
2016-08-13 19:22:25 +08:00
fi
2016-09-25 21:58:59 +08:00
printf "\n"
2016-08-13 19:22:25 +08:00
}
2016-11-04 22:03:41 +08:00
_dlg_versions( ) {
echo "Diagnosis versions: "
2017-02-25 19:08:00 +08:00
echo " openssl: $ACME_OPENSSL_BIN "
2017-03-30 21:16:25 +08:00
if _exists " ${ ACME_OPENSSL_BIN :- openssl } " ; then
${ ACME_OPENSSL_BIN :- openssl } version 2>& 1
2016-11-04 22:03:41 +08:00
else
2017-02-25 19:08:00 +08:00
echo " $ACME_OPENSSL_BIN doesn't exists. "
2016-11-04 22:03:41 +08:00
fi
2016-11-09 19:30:39 +08:00
2016-11-04 22:03:41 +08:00
echo "apache:"
2016-11-09 19:30:39 +08:00
if [ " $_APACHECTL " ] && _exists " $_APACHECTL " ; then
2017-03-03 22:03:19 +08:00
$_APACHECTL -V 2>& 1
2016-11-04 22:03:41 +08:00
else
echo "apache doesn't exists."
fi
2016-11-09 19:30:39 +08:00
2017-06-15 21:44:10 +08:00
echo "nginx:"
if _exists "nginx" ; then
nginx -V 2>& 1
else
echo "nginx doesn't exists."
fi
2017-09-01 23:01:37 +08:00
echo "socat:"
if _exists "socat" ; then
socat -h 2>& 1
2016-11-04 22:03:41 +08:00
else
2017-09-01 23:01:37 +08:00
_debug "socat doesn't exists."
2016-11-04 22:03:41 +08:00
fi
}
2016-08-13 19:22:25 +08:00
2017-02-11 21:15:36 +08:00
#class
_syslog( ) {
2017-02-19 12:13:18 +08:00
if [ " ${ SYS_LOG :- $SYSLOG_LEVEL_NONE } " = " $SYSLOG_LEVEL_NONE " ] ; then
2017-02-11 21:15:36 +08:00
return
fi
_logclass = " $1 "
shift
2017-04-30 16:29:20 +08:00
if [ -z " $__logger_i " ] ; then
if _contains " $( logger --help 2>& 1) " "-i" ; then
__logger_i = "logger -i"
else
__logger_i = "logger"
fi
fi
$__logger_i -t " $PROJECT_NAME " -p " $_logclass " " $( _printargs " $@ " ) " >/dev/null 2>& 1
2017-02-11 21:15:36 +08:00
}
2016-09-25 21:58:59 +08:00
_log( ) {
[ -z " $LOG_FILE " ] && return
2016-11-09 20:45:57 +08:00
_printargs " $@ " >>" $LOG_FILE "
2016-09-25 21:58:59 +08:00
}
_info( ) {
2017-02-19 12:13:18 +08:00
_log " $@ "
2017-02-19 12:42:37 +08:00
if [ " ${ SYS_LOG :- $SYSLOG_LEVEL_NONE } " -ge " $SYSLOG_LEVEL_INFO " ] ; then
2017-02-19 12:13:18 +08:00
_syslog " $SYSLOG_INFO " " $@ "
fi
2016-09-25 21:58:59 +08:00
_printargs " $@ "
2016-03-08 20:44:12 +08:00
}
_err( ) {
2017-02-19 12:13:18 +08:00
_syslog " $SYSLOG_ERROR " " $@ "
_log " $@ "
2016-11-29 00:11:02 +08:00
if [ -z " $NO_TIMESTAMP " ] || [ " $NO_TIMESTAMP " = "0" ] ; then
printf -- "%s" " [ $( date) ] " >& 2
fi
2016-11-09 19:30:39 +08:00
if [ -z " $2 " ] ; then
2016-09-28 13:13:08 +08:00
__red " $1 " >& 2
else
__red " $1 =' $2 ' " >& 2
fi
2016-09-27 21:27:43 +08:00
printf "\n" >& 2
2016-03-08 20:44:12 +08:00
return 1
}
2016-08-13 19:22:25 +08:00
_usage( ) {
2016-11-09 19:30:39 +08:00
__red " $@ " >& 2
2016-09-28 13:13:08 +08:00
printf "\n" >& 2
2016-08-13 19:22:25 +08:00
}
2016-03-19 18:18:34 +08:00
_debug( ) {
2017-02-19 12:13:18 +08:00
if [ " ${ LOG_LEVEL :- $DEFAULT_LOG_LEVEL } " -ge " $LOG_LEVEL_1 " ] ; then
_log " $@ "
2016-09-25 21:58:59 +08:00
fi
2017-02-19 12:42:37 +08:00
if [ " ${ SYS_LOG :- $SYSLOG_LEVEL_NONE } " -ge " $SYSLOG_LEVEL_DEBUG " ] ; then
2017-02-19 12:13:18 +08:00
_syslog " $SYSLOG_DEBUG " " $@ "
fi
if [ " ${ DEBUG :- $DEBUG_LEVEL_NONE } " -ge " $DEBUG_LEVEL_1 " ] ; then
_printargs " $@ " >& 2
2016-03-19 18:18:34 +08:00
fi
}
2017-02-19 13:24:00 +08:00
#output the sensitive messages
_secure_debug( ) {
if [ " ${ LOG_LEVEL :- $DEFAULT_LOG_LEVEL } " -ge " $LOG_LEVEL_1 " ] ; then
if [ " $OUTPUT_INSECURE " = "1" ] ; then
_log " $@ "
else
_log " $1 " " $HIDDEN_VALUE "
fi
fi
if [ " ${ SYS_LOG :- $SYSLOG_LEVEL_NONE } " -ge " $SYSLOG_LEVEL_DEBUG " ] ; then
_syslog " $SYSLOG_DEBUG " " $1 " " $HIDDEN_VALUE "
fi
if [ " ${ DEBUG :- $DEBUG_LEVEL_NONE } " -ge " $DEBUG_LEVEL_1 " ] ; then
if [ " $OUTPUT_INSECURE " = "1" ] ; then
_printargs " $@ " >& 2
else
_printargs " $1 " " $HIDDEN_VALUE " >& 2
fi
fi
}
2016-04-09 23:40:59 +08:00
_debug2( ) {
2017-02-19 12:13:18 +08:00
if [ " ${ LOG_LEVEL :- $DEFAULT_LOG_LEVEL } " -ge " $LOG_LEVEL_2 " ] ; then
_log " $@ "
2016-09-25 21:58:59 +08:00
fi
2017-02-19 12:42:37 +08:00
if [ " ${ SYS_LOG :- $SYSLOG_LEVEL_NONE } " -ge " $SYSLOG_LEVEL_DEBUG_2 " ] ; then
2017-02-19 12:13:18 +08:00
_syslog " $SYSLOG_DEBUG " " $@ "
fi
if [ " ${ DEBUG :- $DEBUG_LEVEL_NONE } " -ge " $DEBUG_LEVEL_2 " ] ; then
2017-02-11 21:15:36 +08:00
_printargs " $@ " >& 2
2016-04-09 23:40:59 +08:00
fi
}
2017-02-19 13:24:00 +08:00
_secure_debug2( ) {
if [ " ${ LOG_LEVEL :- $DEFAULT_LOG_LEVEL } " -ge " $LOG_LEVEL_2 " ] ; then
if [ " $OUTPUT_INSECURE " = "1" ] ; then
_log " $@ "
else
_log " $1 " " $HIDDEN_VALUE "
fi
fi
if [ " ${ SYS_LOG :- $SYSLOG_LEVEL_NONE } " -ge " $SYSLOG_LEVEL_DEBUG_2 " ] ; then
_syslog " $SYSLOG_DEBUG " " $1 " " $HIDDEN_VALUE "
fi
if [ " ${ DEBUG :- $DEBUG_LEVEL_NONE } " -ge " $DEBUG_LEVEL_2 " ] ; then
if [ " $OUTPUT_INSECURE " = "1" ] ; then
_printargs " $@ " >& 2
else
_printargs " $1 " " $HIDDEN_VALUE " >& 2
fi
fi
}
2016-08-10 21:54:08 +08:00
_debug3( ) {
2017-02-19 12:13:18 +08:00
if [ " ${ LOG_LEVEL :- $DEFAULT_LOG_LEVEL } " -ge " $LOG_LEVEL_3 " ] ; then
_log " $@ "
fi
2017-02-19 12:42:37 +08:00
if [ " ${ SYS_LOG :- $SYSLOG_LEVEL_NONE } " -ge " $SYSLOG_LEVEL_DEBUG_3 " ] ; then
2017-02-19 12:13:18 +08:00
_syslog " $SYSLOG_DEBUG " " $@ "
2016-09-25 21:58:59 +08:00
fi
2017-02-19 12:13:18 +08:00
if [ " ${ DEBUG :- $DEBUG_LEVEL_NONE } " -ge " $DEBUG_LEVEL_3 " ] ; then
2017-02-11 21:15:36 +08:00
_printargs " $@ " >& 2
2016-08-10 21:54:08 +08:00
fi
}
2017-02-19 13:24:00 +08:00
_secure_debug3( ) {
if [ " ${ LOG_LEVEL :- $DEFAULT_LOG_LEVEL } " -ge " $LOG_LEVEL_3 " ] ; then
if [ " $OUTPUT_INSECURE " = "1" ] ; then
_log " $@ "
else
_log " $1 " " $HIDDEN_VALUE "
fi
fi
if [ " ${ SYS_LOG :- $SYSLOG_LEVEL_NONE } " -ge " $SYSLOG_LEVEL_DEBUG_3 " ] ; then
_syslog " $SYSLOG_DEBUG " " $1 " " $HIDDEN_VALUE "
fi
if [ " ${ DEBUG :- $DEBUG_LEVEL_NONE } " -ge " $DEBUG_LEVEL_3 " ] ; then
if [ " $OUTPUT_INSECURE " = "1" ] ; then
_printargs " $@ " >& 2
else
_printargs " $1 " " $HIDDEN_VALUE " >& 2
fi
fi
}
2017-03-08 21:51:25 +08:00
_upper_case( ) {
# shellcheck disable=SC2018,SC2019
tr 'a-z' 'A-Z'
}
_lower_case( ) {
# shellcheck disable=SC2018,SC2019
tr 'A-Z' 'a-z'
}
2016-11-09 19:30:39 +08:00
_startswith( ) {
2016-04-16 21:52:24 +08:00
_str = " $1 "
_sub = " $2 "
2016-05-13 21:14:00 +08:00
echo " $_str " | grep " ^ $_sub " >/dev/null 2>& 1
2016-04-16 21:52:24 +08:00
}
2016-11-09 19:30:39 +08:00
_endswith( ) {
2016-08-13 19:22:25 +08:00
_str = " $1 "
_sub = " $2 "
echo " $_str " | grep -- " $_sub \$ " >/dev/null 2>& 1
}
2016-11-09 19:30:39 +08:00
_contains( ) {
2016-04-16 21:52:24 +08:00
_str = " $1 "
_sub = " $2 "
2016-08-13 19:22:25 +08:00
echo " $_str " | grep -- " $_sub " >/dev/null 2>& 1
2016-04-16 21:52:24 +08:00
}
2016-05-03 20:41:40 +08:00
_hasfield( ) {
_str = " $1 "
_field = " $2 "
_sep = " $3 "
2016-11-09 19:30:39 +08:00
if [ -z " $_field " ] ; then
2016-08-13 19:22:25 +08:00
_usage "Usage: str field [sep]"
2016-05-03 20:41:40 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
if [ -z " $_sep " ] ; then
2016-05-03 20:41:40 +08:00
_sep = ","
fi
2016-11-09 19:30:39 +08:00
2017-03-29 09:16:22 +08:00
for f in $( echo " $_str " | tr " $_sep " ' ' ) ; do
2016-11-09 19:30:39 +08:00
if [ " $f " = " $_field " ] ; then
2016-09-15 10:41:47 +08:00
_debug2 " ' $_str ' contains ' $_field ' "
2016-05-03 20:41:40 +08:00
return 0 #contains ok
fi
done
2016-09-15 10:41:47 +08:00
_debug2 " ' $_str ' does not contain ' $_field ' "
2017-04-17 19:08:34 +08:00
return 1 #not contains
2016-05-03 20:41:40 +08:00
}
2017-07-02 17:02:54 +08:00
# str index [sep]
2016-11-09 19:30:39 +08:00
_getfield( ) {
2016-09-23 23:14:03 +08:00
_str = " $1 "
_findex = " $2 "
_sep = " $3 "
2016-11-09 19:30:39 +08:00
if [ -z " $_findex " ] ; then
2016-09-23 23:14:03 +08:00
_usage "Usage: str field [sep]"
return 1
fi
2016-11-09 19:30:39 +08:00
if [ -z " $_sep " ] ; then
2016-09-23 23:14:03 +08:00
_sep = ","
fi
2016-11-09 22:28:12 +08:00
_ffi = " $_findex "
2016-11-09 19:30:39 +08:00
while [ " $_ffi " -gt "0" ] ; do
2016-11-09 22:28:12 +08:00
_fv = " $( echo " $_str " | cut -d " $_sep " -f " $_ffi " ) "
2016-11-09 19:30:39 +08:00
if [ " $_fv " ] ; then
2016-09-23 23:14:03 +08:00
printf -- "%s" " $_fv "
return 0
fi
2016-11-09 20:45:57 +08:00
_ffi = " $( _math " $_ffi " - 1) "
2016-09-23 23:14:03 +08:00
done
2016-11-09 19:30:39 +08:00
2016-09-23 23:14:03 +08:00
printf -- "%s" " $_str "
}
2016-11-09 19:30:39 +08:00
_exists( ) {
2016-03-19 18:18:34 +08:00
cmd = " $1 "
2016-11-09 19:30:39 +08:00
if [ -z " $cmd " ] ; then
2016-08-13 19:22:25 +08:00
_usage "Usage: _exists cmd"
2016-03-19 18:18:34 +08:00
return 1
fi
2016-11-17 13:17:29 +08:00
if eval type type >/dev/null 2>& 1; then
eval type " $cmd " >/dev/null 2>& 1
elif command >/dev/null 2>& 1; then
2016-05-13 21:14:00 +08:00
command -v " $cmd " >/dev/null 2>& 1
2016-11-17 13:20:20 +08:00
else
2016-11-11 21:13:33 +08:00
which " $cmd " >/dev/null 2>& 1
2016-04-16 19:38:11 +08:00
fi
2016-03-19 18:18:34 +08:00
ret = " $? "
2016-08-25 10:45:41 +08:00
_debug3 " $cmd exists= $ret "
2016-03-19 18:18:34 +08:00
return $ret
}
2016-04-17 17:33:08 +08:00
#a + b
2016-11-09 19:30:39 +08:00
_math( ) {
2016-11-12 10:58:20 +08:00
_m_opts = " $@ "
printf "%s" " $(( $_m_opts )) "
2016-04-17 17:33:08 +08:00
}
_h_char_2_dec( ) {
_ch = $1
case " ${ _ch } " in
2016-11-09 19:30:39 +08:00
a | A)
2016-05-13 21:14:00 +08:00
printf "10"
2016-11-09 19:30:39 +08:00
; ;
b | B)
2016-05-13 21:14:00 +08:00
printf "11"
2016-11-09 19:30:39 +08:00
; ;
c | C)
2016-05-13 21:14:00 +08:00
printf "12"
2016-11-09 19:30:39 +08:00
; ;
d | D)
2016-05-13 21:14:00 +08:00
printf "13"
2016-11-09 19:30:39 +08:00
; ;
e | E)
2016-05-13 21:14:00 +08:00
printf "14"
2016-11-09 19:30:39 +08:00
; ;
f | F)
2016-05-13 21:14:00 +08:00
printf "15"
2016-11-09 19:30:39 +08:00
; ;
2016-04-17 17:33:08 +08:00
*)
2016-05-13 21:14:00 +08:00
printf "%s" " $_ch "
2016-11-09 19:30:39 +08:00
; ;
2016-05-13 21:14:00 +08:00
esac
2016-04-17 17:33:08 +08:00
}
2016-08-14 22:37:21 +08:00
_URGLY_PRINTF = ""
2016-11-09 19:30:39 +08:00
if [ " $( printf '\x41' ) " != 'A' ] ; then
2016-08-14 22:37:21 +08:00
_URGLY_PRINTF = 1
fi
2017-05-29 17:07:59 +08:00
_ESCAPE_XARGS = ""
2017-06-23 18:11:11 +08:00
if _exists xargs && [ " $( printf %s '\\x41' | xargs printf ) " = 'A' ] ; then
2017-05-29 17:07:59 +08:00
_ESCAPE_XARGS = 1
fi
2016-03-08 20:44:12 +08:00
_h2b( ) {
2017-12-02 19:54:33 +08:00
if _exists xxd && xxd -r -p 2>/dev/null; then
2017-05-17 13:16:53 +08:00
return
fi
2016-03-08 20:44:12 +08:00
hex = $( cat)
2017-05-20 11:02:48 +08:00
ic = ""
jc = ""
2017-05-17 13:16:53 +08:00
_debug2 _URGLY_PRINTF " $_URGLY_PRINTF "
if [ -z " $_URGLY_PRINTF " ] ; then
2017-05-29 17:07:59 +08:00
if [ " $_ESCAPE_XARGS " ] && _exists xargs; then
2017-05-20 11:02:48 +08:00
_debug2 "xargs"
2017-05-26 14:58:52 +08:00
echo " $hex " | _upper_case | sed 's/\([0-9A-F]\{2\}\)/\\\\\\x\1/g' | xargs printf
2017-05-20 11:02:48 +08:00
else
2017-05-26 14:58:52 +08:00
for h in $( echo " $hex " | _upper_case | sed 's/\([0-9A-F]\{2\}\)/ \1/g' ) ; do
2017-05-20 11:02:48 +08:00
if [ -z " $h " ] ; then
break
fi
printf " \x $h %s "
done
fi
2017-05-17 13:16:53 +08:00
else
2017-05-26 14:58:52 +08:00
for c in $( echo " $hex " | _upper_case | sed 's/\([0-9A-F]\)/ \1/g' ) ; do
2017-05-20 11:02:48 +08:00
if [ -z " $ic " ] ; then
ic = $c
continue
2016-04-17 17:33:08 +08:00
fi
2017-05-20 11:02:48 +08:00
jc = $c
2016-05-13 21:14:00 +08:00
ic = " $( _h_char_2_dec " $ic " ) "
jc = " $( _h_char_2_dec " $jc " ) "
2016-11-11 22:00:15 +08:00
printf '\' " $( printf "%o" " $( _math " $ic " \* 16 + $jc ) " ) " "%s"
2017-05-20 11:02:48 +08:00
ic = ""
jc = ""
2017-05-17 13:16:53 +08:00
done
fi
2016-11-11 21:13:33 +08:00
2016-03-08 20:44:12 +08:00
}
2017-01-30 12:07:50 +08:00
_is_solaris( ) {
_contains " ${ __OS__ : = $( uname -a) } " "solaris" || _contains " ${ __OS__ : = $( uname -a) } " "SunOS"
}
2017-02-05 13:16:51 +08:00
#_ascii_hex str
#this can only process ascii chars, should only be used when od command is missing as a backup way.
_ascii_hex( ) {
_debug2 "Using _ascii_hex"
_str = " $1 "
_str_len = ${# _str }
_h_i = 1
while [ " $_h_i " -le " $_str_len " ] ; do
_str_c = " $( printf "%s" " $_str " | cut -c " $_h_i " ) "
printf " %02x" " ' $_str_c "
_h_i = " $( _math " $_h_i " + 1) "
done
}
2017-01-30 12:07:50 +08:00
#stdin output hexstr splited by one space
#input:"abc"
#output: " 61 62 63"
_hex_dump( ) {
2017-02-10 20:55:25 +08:00
if _exists od; then
od -A n -v -t x1 | tr -s " " | sed 's/ $//' | tr -d "\r\t\n"
elif _exists hexdump; then
_debug3 "using hexdump"
hexdump -v -e '/1 ""' -e '/1 " %02x" ""'
elif _exists xxd; then
_debug3 "using xxd"
xxd -ps -c 20 -i | sed "s/ 0x/ /g" | tr -d ",\n" | tr -s " "
else
_debug3 "using _ascii_hex"
2017-02-05 13:16:51 +08:00
str = $( cat)
_ascii_hex " $str "
fi
2017-01-30 12:07:50 +08:00
}
#url encode, no-preserved chars
#A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
#41 42 43 44 45 46 47 48 49 4a 4b 4c 4d 4e 4f 50 51 52 53 54 55 56 57 58 59 5a
#a b c d e f g h i j k l m n o p q r s t u v w x y z
#61 62 63 64 65 66 67 68 69 6a 6b 6c 6d 6e 6f 70 71 72 73 74 75 76 77 78 79 7a
#0 1 2 3 4 5 6 7 8 9 - _ . ~
#30 31 32 33 34 35 36 37 38 39 2d 5f 2e 7e
#stdin stdout
_url_encode( ) {
_hex_str = $( _hex_dump)
_debug3 "_url_encode"
_debug3 "_hex_str" " $_hex_str "
for _hex_code in $_hex_str ; do
#upper case
case " ${ _hex_code } " in
2017-01-30 12:25:56 +08:00
"41" )
printf "%s" "A"
; ;
"42" )
printf "%s" "B"
; ;
"43" )
printf "%s" "C"
; ;
"44" )
printf "%s" "D"
; ;
"45" )
printf "%s" "E"
; ;
"46" )
printf "%s" "F"
; ;
"47" )
printf "%s" "G"
; ;
"48" )
printf "%s" "H"
; ;
"49" )
printf "%s" "I"
; ;
"4a" )
printf "%s" "J"
; ;
"4b" )
printf "%s" "K"
; ;
"4c" )
printf "%s" "L"
; ;
"4d" )
printf "%s" "M"
; ;
"4e" )
printf "%s" "N"
; ;
"4f" )
printf "%s" "O"
; ;
"50" )
printf "%s" "P"
; ;
"51" )
printf "%s" "Q"
; ;
"52" )
printf "%s" "R"
; ;
"53" )
printf "%s" "S"
; ;
"54" )
printf "%s" "T"
; ;
"55" )
printf "%s" "U"
; ;
"56" )
printf "%s" "V"
; ;
"57" )
printf "%s" "W"
; ;
"58" )
printf "%s" "X"
; ;
"59" )
printf "%s" "Y"
; ;
"5a" )
printf "%s" "Z"
; ;
#lower case
"61" )
printf "%s" "a"
; ;
"62" )
printf "%s" "b"
; ;
"63" )
printf "%s" "c"
; ;
"64" )
printf "%s" "d"
; ;
"65" )
printf "%s" "e"
; ;
"66" )
printf "%s" "f"
; ;
"67" )
printf "%s" "g"
; ;
"68" )
printf "%s" "h"
; ;
"69" )
printf "%s" "i"
; ;
"6a" )
printf "%s" "j"
; ;
"6b" )
printf "%s" "k"
; ;
"6c" )
printf "%s" "l"
; ;
"6d" )
printf "%s" "m"
; ;
"6e" )
printf "%s" "n"
; ;
"6f" )
printf "%s" "o"
; ;
"70" )
printf "%s" "p"
; ;
"71" )
printf "%s" "q"
; ;
"72" )
printf "%s" "r"
; ;
"73" )
printf "%s" "s"
; ;
"74" )
printf "%s" "t"
; ;
"75" )
printf "%s" "u"
; ;
"76" )
printf "%s" "v"
; ;
"77" )
printf "%s" "w"
; ;
"78" )
printf "%s" "x"
; ;
"79" )
printf "%s" "y"
; ;
"7a" )
printf "%s" "z"
; ;
#numbers
"30" )
printf "%s" "0"
; ;
"31" )
printf "%s" "1"
; ;
"32" )
printf "%s" "2"
; ;
"33" )
printf "%s" "3"
; ;
"34" )
printf "%s" "4"
; ;
"35" )
printf "%s" "5"
; ;
"36" )
printf "%s" "6"
; ;
"37" )
printf "%s" "7"
; ;
"38" )
printf "%s" "8"
; ;
"39" )
printf "%s" "9"
; ;
"2d" )
printf "%s" "-"
; ;
"5f" )
printf "%s" "_"
; ;
"2e" )
printf "%s" "."
; ;
"7e" )
printf "%s" "~"
; ;
2017-04-17 19:08:34 +08:00
#other hex
2017-01-30 12:07:50 +08:00
*)
2017-01-30 12:25:56 +08:00
printf '%%%s' " $_hex_code "
; ;
2017-01-30 12:07:50 +08:00
esac
2016-11-20 22:57:07 +08:00
done
}
2016-03-19 18:18:34 +08:00
#options file
_sed_i( ) {
options = " $1 "
filename = " $2 "
2016-11-09 19:30:39 +08:00
if [ -z " $filename " ] ; then
2016-08-13 19:22:25 +08:00
_usage "Usage:_sed_i options filename"
2016-03-19 18:18:34 +08:00
return 1
fi
2016-04-22 20:50:43 +08:00
_debug2 options " $options "
if sed -h 2>& 1 | grep "\-i\[SUFFIX]" >/dev/null 2>& 1; then
2016-03-19 18:18:34 +08:00
_debug "Using sed -i"
2016-04-22 20:50:43 +08:00
sed -i " $options " " $filename "
2016-03-19 18:18:34 +08:00
else
_debug "No -i support in sed"
2016-05-13 21:14:00 +08:00
text = " $( cat " $filename " ) "
2016-11-09 19:30:39 +08:00
echo " $text " | sed " $options " >" $filename "
2016-03-19 18:18:34 +08:00
fi
}
2016-08-10 21:54:08 +08:00
_egrep_o( ) {
2016-11-18 20:14:08 +08:00
if ! egrep -o " $1 " 2>/dev/null; then
2016-08-10 21:54:08 +08:00
sed -n 's/.*\(' " $1 " '\).*/\1/p'
fi
}
2016-03-17 21:18:09 +08:00
#Usage: file startline endline
_getfile( ) {
filename = " $1 "
startline = " $2 "
endline = " $3 "
2016-11-09 19:30:39 +08:00
if [ -z " $endline " ] ; then
2016-08-13 19:22:25 +08:00
_usage "Usage: file startline endline"
2016-03-17 21:18:09 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
i = " $( grep -n -- " $startline " " $filename " | cut -d : -f 1) "
if [ -z " $i " ] ; then
2016-03-17 21:18:09 +08:00
_err " Can not find start line: $startline "
return 1
fi
2016-05-13 21:14:00 +08:00
i = " $( _math " $i " + 1) "
_debug i " $i "
2016-11-09 19:30:39 +08:00
j = " $( grep -n -- " $endline " " $filename " | cut -d : -f 1) "
if [ -z " $j " ] ; then
2016-03-17 21:18:09 +08:00
_err " Can not find end line: $endline "
return 1
fi
2016-05-13 21:14:00 +08:00
j = " $( _math " $j " - 1) "
_debug j " $j "
2016-11-09 19:30:39 +08:00
sed -n " $i , ${ j } p " " $filename "
2016-03-17 21:18:09 +08:00
}
#Usage: multiline
2016-03-08 20:44:12 +08:00
_base64( ) {
2016-12-27 21:29:44 +08:00
[ "" ] #urgly
2016-11-09 19:30:39 +08:00
if [ " $1 " ] ; then
2016-12-13 20:27:49 +08:00
_debug3 " base64 multiline:' $1 ' "
2017-03-30 21:16:25 +08:00
${ ACME_OPENSSL_BIN :- openssl } base64 -e
2016-03-17 21:18:09 +08:00
else
2016-12-13 20:04:43 +08:00
_debug3 "base64 single line."
2017-03-30 21:16:25 +08:00
${ ACME_OPENSSL_BIN :- openssl } base64 -e | tr -d '\r\n'
2016-03-17 21:18:09 +08:00
fi
}
#Usage: multiline
_dbase64( ) {
2016-11-09 19:30:39 +08:00
if [ " $1 " ] ; then
2017-03-30 21:16:25 +08:00
${ ACME_OPENSSL_BIN :- openssl } base64 -d -A
2016-03-17 21:18:09 +08:00
else
2017-03-30 21:16:25 +08:00
${ ACME_OPENSSL_BIN :- openssl } base64 -d
2016-03-17 21:18:09 +08:00
fi
}
2016-06-17 13:23:44 +08:00
#Usage: hashalg [outputhex]
2016-03-17 21:18:09 +08:00
#Output Base64-encoded digest
_digest( ) {
alg = " $1 "
2016-11-09 19:30:39 +08:00
if [ -z " $alg " ] ; then
2016-08-13 19:22:25 +08:00
_usage "Usage: _digest hashalg"
2016-03-17 21:18:09 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
2016-06-17 13:23:44 +08:00
outputhex = " $2 "
2016-11-09 19:30:39 +08:00
2016-11-11 23:30:14 +08:00
if [ " $alg " = "sha256" ] || [ " $alg " = "sha1" ] || [ " $alg " = "md5" ] ; then
2016-11-09 19:30:39 +08:00
if [ " $outputhex " ] ; then
2017-03-30 21:16:25 +08:00
${ ACME_OPENSSL_BIN :- openssl } dgst -" $alg " -hex | cut -d = -f 2 | tr -d ' '
2016-06-17 13:23:44 +08:00
else
2017-03-30 21:16:25 +08:00
${ ACME_OPENSSL_BIN :- openssl } dgst -" $alg " -binary | _base64
2016-11-08 21:27:39 +08:00
fi
else
_err " $alg is not supported yet "
return 1
fi
}
2016-11-20 22:57:07 +08:00
#Usage: hashalg secret_hex [outputhex]
#Output binary hmac
2016-11-08 21:27:39 +08:00
_hmac( ) {
alg = " $1 "
2016-11-20 22:57:07 +08:00
secret_hex = " $2 "
2016-11-08 21:27:39 +08:00
outputhex = " $3 "
2016-11-09 19:30:39 +08:00
2016-11-20 22:57:07 +08:00
if [ -z " $secret_hex " ] ; then
2016-11-09 19:30:39 +08:00
_usage "Usage: _hmac hashalg secret [outputhex]"
2016-11-08 21:27:39 +08:00
return 1
fi
2016-08-24 18:46:23 +08:00
if [ " $alg " = "sha256" ] || [ " $alg " = "sha1" ] ; then
2016-11-09 19:30:39 +08:00
if [ " $outputhex " ] ; then
2017-03-30 21:16:25 +08:00
( ${ ACME_OPENSSL_BIN :- openssl } dgst -" $alg " -mac HMAC -macopt " hexkey: $secret_hex " 2>/dev/null || ${ ACME_OPENSSL_BIN :- openssl } dgst -" $alg " -hmac " $( printf "%s" " $secret_hex " | _h2b) " ) | cut -d = -f 2 | tr -d ' '
2016-06-17 13:23:44 +08:00
else
2017-03-30 21:16:25 +08:00
${ ACME_OPENSSL_BIN :- openssl } dgst -" $alg " -mac HMAC -macopt " hexkey: $secret_hex " -binary 2>/dev/null || ${ ACME_OPENSSL_BIN :- openssl } dgst -" $alg " -hmac " $( printf "%s" " $secret_hex " | _h2b) " -binary
2016-06-17 13:23:44 +08:00
fi
2016-03-17 21:18:09 +08:00
else
_err " $alg is not supported yet "
return 1
fi
}
#Usage: keyfile hashalg
#Output: Base64-encoded signature value
_sign( ) {
keyfile = " $1 "
alg = " $2 "
2016-11-09 19:30:39 +08:00
if [ -z " $alg " ] ; then
2016-08-13 19:22:25 +08:00
_usage "Usage: _sign keyfile hashalg"
2016-03-17 21:18:09 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
2017-03-30 21:16:25 +08:00
_sign_openssl = " ${ ACME_OPENSSL_BIN :- openssl } dgst -sign $keyfile "
2016-11-09 19:30:39 +08:00
if grep "BEGIN RSA PRIVATE KEY" " $keyfile " >/dev/null 2>& 1; then
2017-12-07 21:32:17 +08:00
$_sign_openssl -$alg | _base64
2016-11-09 19:30:39 +08:00
elif grep "BEGIN EC PRIVATE KEY" " $keyfile " >/dev/null 2>& 1; then
2017-12-07 21:32:17 +08:00
if ! _signedECText = " $( $_sign_openssl -sha$__ECC_KEY_LEN | ${ ACME_OPENSSL_BIN :- openssl } asn1parse -inform DER) " ; then
2016-11-04 23:34:06 +08:00
_err " Sign failed: $_sign_openssl "
_err " Key file: $keyfile "
2017-03-26 05:28:04 +00:00
_err " Key content: $( wc -l <" $keyfile " ) lines "
2016-11-04 23:34:06 +08:00
return 1
fi
2016-10-27 00:06:03 +08:00
_debug3 "_signedECText" " $_signedECText "
_ec_r = " $( echo " $_signedECText " | _head_n 2 | _tail_n 1 | cut -d : -f 4 | tr -d "\r\n" ) "
_debug3 "_ec_r" " $_ec_r "
_ec_s = " $( echo " $_signedECText " | _head_n 3 | _tail_n 1 | cut -d : -f 4 | tr -d "\r\n" ) "
_debug3 "_ec_s" " $_ec_s "
printf "%s" " $_ec_r $_ec_s " | _h2b | _base64
else
_err "Unknown key file format."
return 1
fi
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
}
2017-07-25 09:39:15 +01:00
#keylength or isEcc flag (empty str => not ecc)
2016-08-13 19:22:25 +08:00
_isEccKey( ) {
_length = " $1 "
2016-11-09 19:30:39 +08:00
if [ -z " $_length " ] ; then
2016-08-13 19:22:25 +08:00
return 1
fi
[ " $_length " != "1024" ] \
2016-11-09 19:30:39 +08:00
&& [ " $_length " != "2048" ] \
&& [ " $_length " != "3072" ] \
&& [ " $_length " != "4096" ] \
&& [ " $_length " != "8192" ]
2016-08-13 19:22:25 +08:00
}
2016-06-17 13:23:44 +08:00
# _createkey 2048|ec-256 file
_createkey( ) {
length = " $1 "
f = " $2 "
2016-12-10 21:32:47 +08:00
_debug2 " _createkey for file: $f "
2016-08-13 19:22:25 +08:00
eccname = " $length "
2016-11-09 19:30:39 +08:00
if _startswith " $length " "ec-" ; then
2016-11-09 21:06:22 +08:00
length = $( printf "%s" " $length " | cut -d '-' -f 2-100)
2016-06-17 13:23:44 +08:00
2016-11-09 19:30:39 +08:00
if [ " $length " = "256" ] ; then
2016-06-17 13:23:44 +08:00
eccname = "prime256v1"
fi
2016-11-09 19:30:39 +08:00
if [ " $length " = "384" ] ; then
2016-06-17 13:23:44 +08:00
eccname = "secp384r1"
fi
2016-11-09 19:30:39 +08:00
if [ " $length " = "521" ] ; then
2016-06-17 13:23:44 +08:00
eccname = "secp521r1"
fi
2016-08-13 19:22:25 +08:00
2016-06-17 13:23:44 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $length " ] ; then
length = 2048
2016-08-13 19:22:25 +08:00
fi
2016-11-09 19:30:39 +08:00
2016-08-25 22:27:48 +08:00
_debug " Use length $length "
2016-08-13 19:22:25 +08:00
2017-02-27 13:38:29 +08:00
if ! touch " $f " >/dev/null 2>& 1; then
_f_path = " $( dirname " $f " ) "
_debug _f_path " $_f_path "
if ! mkdir -p " $_f_path " ; then
_err " Can not create path: $_f_path "
return 1
fi
fi
2016-11-09 19:30:39 +08:00
if _isEccKey " $length " ; then
2016-08-25 22:27:48 +08:00
_debug " Using ec name: $eccname "
2017-03-30 21:16:25 +08:00
${ ACME_OPENSSL_BIN :- openssl } ecparam -name " $eccname " -genkey 2>/dev/null >" $f "
2016-06-17 13:23:44 +08:00
else
2016-08-25 22:27:48 +08:00
_debug " Using RSA: $length "
2017-03-30 21:16:25 +08:00
${ ACME_OPENSSL_BIN :- openssl } genrsa " $length " 2>/dev/null >" $f "
2016-06-17 13:23:44 +08:00
fi
2016-08-13 19:22:25 +08:00
2016-11-09 19:30:39 +08:00
if [ " $? " != "0" ] ; then
2016-08-13 19:22:25 +08:00
_err "Create key error."
return 1
fi
2016-06-17 13:23:44 +08:00
}
2016-10-23 14:56:52 +08:00
#domain
_is_idn( ) {
_is_idn_d = " $1 "
2016-10-23 20:36:32 +08:00
_debug2 _is_idn_d " $_is_idn_d "
2018-01-06 17:39:15 +08:00
_idn_temp = $( printf "%s" " $_is_idn_d " | tr -d '0-9' | tr -d 'a-z' | tr -d 'A-Z' | tr -d '*.,-' )
2016-10-23 20:36:32 +08:00
_debug2 _idn_temp " $_idn_temp "
[ " $_idn_temp " ]
2016-10-23 14:56:52 +08:00
}
#aa.com
#aa.com,bb.com,cc.com
_idn( ) {
__idn_d = " $1 "
2016-11-09 19:30:39 +08:00
if ! _is_idn " $__idn_d " ; then
2016-10-23 14:56:52 +08:00
printf "%s" " $__idn_d "
return 0
fi
2016-11-09 19:30:39 +08:00
if _exists idn; then
if _contains " $__idn_d " ',' ; then
2016-10-23 14:56:52 +08:00
_i_first = "1"
2016-11-09 19:30:39 +08:00
for f in $( echo " $__idn_d " | tr ',' ' ' ) ; do
2016-10-23 14:56:52 +08:00
[ -z " $f " ] && continue
2016-11-09 19:30:39 +08:00
if [ -z " $_i_first " ] ; then
2016-10-23 14:56:52 +08:00
printf "%s" ","
else
_i_first = ""
fi
2016-10-31 21:22:04 +08:00
idn --quiet " $f " | tr -d "\r\n"
2016-10-23 14:56:52 +08:00
done
else
idn " $__idn_d " | tr -d "\r\n"
fi
else
_err "Please install idn to process IDN names."
fi
}
2016-06-17 13:23:44 +08:00
#_createcsr cn san_list keyfile csrfile conf
_createcsr( ) {
_debug _createcsr
domain = " $1 "
domainlist = " $2 "
2016-09-15 10:41:47 +08:00
csrkey = " $3 "
2016-06-17 13:23:44 +08:00
csr = " $4 "
csrconf = " $5 "
_debug2 domain " $domain "
_debug2 domainlist " $domainlist "
2016-09-15 10:41:47 +08:00
_debug2 csrkey " $csrkey "
_debug2 csr " $csr "
_debug2 csrconf " $csrconf "
2016-11-09 19:30:39 +08:00
printf "[ req_distinguished_name ]\n[ req ]\ndistinguished_name = req_distinguished_name\nreq_extensions = v3_req\n[ v3_req ]\n\nkeyUsage = nonRepudiation, digitalSignature, keyEncipherment" >" $csrconf "
2016-09-23 22:35:13 +08:00
if [ -z " $domainlist " ] || [ " $domainlist " = " $NO_VALUE " ] ; then
2016-06-17 13:23:44 +08:00
#single domain
_info "Single domain" " $domain "
2018-01-06 12:45:24 +08:00
printf -- " \nsubjectAltName=DNS: $domain " >>" $csrconf "
2016-06-17 13:23:44 +08:00
else
2016-11-09 21:06:22 +08:00
domainlist = " $( _idn " $domainlist " ) "
2016-10-23 14:56:52 +08:00
_debug2 domainlist " $domainlist "
2016-11-09 19:30:39 +08:00
if _contains " $domainlist " "," ; then
2018-01-06 17:39:15 +08:00
alt = " DNS: $domain ,DNS: $( echo " $domainlist " | sed "s/,,/,/g" | sed "s/,/,DNS:/g" ) "
2016-06-17 13:23:44 +08:00
else
2018-01-06 12:45:24 +08:00
alt = " DNS: $domain ,DNS: $domainlist "
2016-06-17 13:23:44 +08:00
fi
2017-04-17 19:08:34 +08:00
#multi
2016-06-17 13:23:44 +08:00
_info "Multi domain" " $alt "
2016-11-09 19:30:39 +08:00
printf -- " \nsubjectAltName= $alt " >>" $csrconf "
2016-09-15 10:41:47 +08:00
fi
2016-12-18 05:29:27 +01:00
if [ " $Le_OCSP_Staple " ] || [ " $Le_OCSP_Stable " ] ; then
2016-12-18 03:17:35 +01:00
_savedomainconf Le_OCSP_Staple " $Le_OCSP_Staple "
2016-12-18 05:29:27 +01:00
_cleardomainconf Le_OCSP_Stable
2016-11-09 19:30:39 +08:00
printf -- "\nbasicConstraints = CA:FALSE\n1.3.6.1.5.5.7.1.24=DER:30:03:02:01:05" >>" $csrconf "
2016-06-17 13:23:44 +08:00
fi
2016-11-09 19:30:39 +08:00
2016-10-23 14:56:52 +08:00
_csr_cn = " $( _idn " $domain " ) "
_debug2 _csr_cn " $_csr_cn "
2017-02-10 18:20:15 +08:00
if _contains " $( uname -a) " "MINGW" ; then
2017-03-30 21:16:25 +08:00
${ ACME_OPENSSL_BIN :- openssl } req -new -sha256 -key " $csrkey " -subj " //CN= $_csr_cn " -config " $csrconf " -out " $csr "
2017-02-10 18:20:15 +08:00
else
2017-03-30 21:16:25 +08:00
${ ACME_OPENSSL_BIN :- openssl } req -new -sha256 -key " $csrkey " -subj " /CN= $_csr_cn " -config " $csrconf " -out " $csr "
2017-02-10 18:20:15 +08:00
fi
2016-06-17 13:23:44 +08:00
}
#_signcsr key csr conf cert
_signcsr( ) {
key = " $1 "
csr = " $2 "
conf = " $3 "
cert = " $4 "
2016-06-18 12:28:23 +08:00
_debug "_signcsr"
2016-11-09 19:30:39 +08:00
2017-03-30 21:16:25 +08:00
_msg = " $( ${ ACME_OPENSSL_BIN :- openssl } x509 -req -days 365 -in " $csr " -signkey " $key " -extensions v3_req -extfile " $conf " -out " $cert " 2>& 1) "
2016-06-18 12:28:23 +08:00
_ret = " $? "
_debug " $_msg "
return $_ret
2016-06-17 13:23:44 +08:00
}
2016-08-27 13:52:13 +08:00
#_csrfile
_readSubjectFromCSR( ) {
_csrfile = " $1 "
2016-11-09 19:30:39 +08:00
if [ -z " $_csrfile " ] ; then
2016-08-27 13:52:13 +08:00
_usage "_readSubjectFromCSR mycsr.csr"
return 1
fi
2017-06-18 10:07:23 +08:00
${ ACME_OPENSSL_BIN :- openssl } req -noout -in " $_csrfile " -subject | tr ',' "\n" | _egrep_o "CN *=.*" | cut -d = -f 2 | cut -d / -f 1 | tr -d ' \n'
2016-08-27 13:52:13 +08:00
}
#_csrfile
#echo comma separated domain list
_readSubjectAltNamesFromCSR( ) {
_csrfile = " $1 "
2016-11-09 19:30:39 +08:00
if [ -z " $_csrfile " ] ; then
2016-08-27 13:52:13 +08:00
_usage "_readSubjectAltNamesFromCSR mycsr.csr"
return 1
fi
2016-11-09 19:30:39 +08:00
2016-08-27 13:52:13 +08:00
_csrsubj = " $( _readSubjectFromCSR " $_csrfile " ) "
_debug _csrsubj " $_csrsubj "
2016-11-09 19:30:39 +08:00
2017-03-30 21:16:25 +08:00
_dnsAltnames = " $( ${ ACME_OPENSSL_BIN :- openssl } req -noout -text -in " $_csrfile " | grep "^ *DNS:.*" | tr -d ' \n' ) "
2016-08-27 13:52:13 +08:00
_debug _dnsAltnames " $_dnsAltnames "
2016-11-09 19:30:39 +08:00
if _contains " $_dnsAltnames , " " DNS: $_csrsubj , " ; then
2016-08-27 13:52:13 +08:00
_debug "AltNames contains subject"
2016-08-27 20:00:47 +08:00
_dnsAltnames = " $( printf "%s" " $_dnsAltnames , " | sed " s/DNS: $_csrsubj ,//g " ) "
2016-08-27 13:52:13 +08:00
else
_debug "AltNames doesn't contain subject"
fi
2016-11-09 19:30:39 +08:00
2016-08-27 20:00:47 +08:00
printf "%s" " $_dnsAltnames " | sed "s/DNS://g"
2016-08-27 13:52:13 +08:00
}
2017-04-17 19:08:34 +08:00
#_csrfile
2016-08-27 13:52:13 +08:00
_readKeyLengthFromCSR( ) {
_csrfile = " $1 "
2016-11-09 19:30:39 +08:00
if [ -z " $_csrfile " ] ; then
2016-08-27 20:00:47 +08:00
_usage "_readKeyLengthFromCSR mycsr.csr"
2016-08-27 13:52:13 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
2017-03-30 21:16:25 +08:00
_outcsr = " $( ${ ACME_OPENSSL_BIN :- openssl } req -noout -text -in " $_csrfile " ) "
2017-04-04 22:33:26 +08:00
_debug2 _outcsr " $_outcsr "
2016-11-09 19:30:39 +08:00
if _contains " $_outcsr " "Public Key Algorithm: id-ecPublicKey" ; then
2016-08-27 13:52:13 +08:00
_debug "ECC CSR"
2017-04-06 19:29:09 +08:00
echo " $_outcsr " | tr "\t" " " | _egrep_o "^ *ASN1 OID:.*" | cut -d ':' -f 2 | tr -d ' '
2016-08-27 13:52:13 +08:00
else
_debug "RSA CSR"
2017-06-27 19:56:43 +08:00
_rkl = " $( echo " $_outcsr " | tr "\t" " " | _egrep_o "^ *Public.Key:.*" | cut -d '(' -f 2 | cut -d ' ' -f 1) "
if [ " $_rkl " ] ; then
echo " $_rkl "
else
echo " $_outcsr " | tr "\t" " " | _egrep_o "RSA Public.Key:.*" | cut -d '(' -f 2 | cut -d ' ' -f 1
fi
2016-08-27 13:52:13 +08:00
fi
}
2016-03-13 18:17:13 +08:00
_ss( ) {
_port = " $1 "
2016-11-09 19:30:39 +08:00
if _exists "ss" ; then
2016-03-23 22:23:24 +08:00
_debug "Using: ss"
2017-07-01 21:47:30 +08:00
ss -ntpl 2>/dev/null | grep " : $_port "
2016-03-23 22:23:24 +08:00
return 0
fi
2016-11-09 19:30:39 +08:00
if _exists "netstat" ; then
2016-03-13 18:24:03 +08:00
_debug "Using: netstat"
2016-11-09 19:30:39 +08:00
if netstat -h 2>& 1 | grep "\-p proto" >/dev/null; then
2016-03-23 20:23:56 +08:00
#for windows version netstat tool
2016-09-23 23:14:03 +08:00
netstat -an -p tcp | grep "LISTENING" | grep " : $_port "
2016-03-23 20:23:56 +08:00
else
2016-11-09 19:30:39 +08:00
if netstat -help 2>& 1 | grep "\-p protocol" >/dev/null; then
2016-05-13 21:14:00 +08:00
netstat -an -p tcp | grep LISTEN | grep " : $_port "
2016-11-09 19:30:39 +08:00
elif netstat -help 2>& 1 | grep -- '-P protocol' >/dev/null; then
2016-08-10 21:54:08 +08:00
#for solaris
2016-08-10 23:13:14 +08:00
netstat -an -P tcp | grep " \. $_port " | grep "LISTEN"
2017-03-20 18:51:45 +01:00
elif netstat -help 2>& 1 | grep "\-p" >/dev/null; then
2017-03-19 17:55:26 +01:00
#for full linux
2016-05-13 21:14:00 +08:00
netstat -ntpl | grep " : $_port "
2017-03-19 17:55:26 +01:00
else
#for busybox (embedded linux; no pid support)
netstat -ntl 2>/dev/null | grep " : $_port "
2016-03-23 22:23:24 +08:00
fi
2016-03-23 20:23:56 +08:00
fi
2016-03-13 18:17:13 +08:00
return 0
fi
2016-03-23 22:23:24 +08:00
2016-03-13 18:17:13 +08:00
return 1
}
2017-07-24 14:23:01 +01:00
#outfile key cert cacert [password [name [caname]]]
_toPkcs( ) {
_cpfx = " $1 "
_ckey = " $2 "
_ccert = " $3 "
_cca = " $4 "
pfxPassword = " $5 "
pfxName = " $6 "
pfxCaname = " $7 "
if [ " $pfxCaname " ] ; then
${ ACME_OPENSSL_BIN :- openssl } pkcs12 -export -out " $_cpfx " -inkey " $_ckey " -in " $_ccert " -certfile " $_cca " -password " pass: $pfxPassword " -name " $pfxName " -caname " $pfxCaname "
elif [ " $pfxName " ] ; then
${ ACME_OPENSSL_BIN :- openssl } pkcs12 -export -out " $_cpfx " -inkey " $_ckey " -in " $_ccert " -certfile " $_cca " -password " pass: $pfxPassword " -name " $pfxName "
elif [ " $pfxPassword " ] ; then
${ ACME_OPENSSL_BIN :- openssl } pkcs12 -export -out " $_cpfx " -inkey " $_ckey " -in " $_ccert " -certfile " $_cca " -password " pass: $pfxPassword "
else
${ ACME_OPENSSL_BIN :- openssl } pkcs12 -export -out " $_cpfx " -inkey " $_ckey " -in " $_ccert " -certfile " $_cca "
fi
}
2016-08-13 19:22:25 +08:00
#domain [password] [isEcc]
2016-04-05 22:39:34 +08:00
toPkcs( ) {
domain = " $1 "
pfxPassword = " $2 "
2016-11-09 19:30:39 +08:00
if [ -z " $domain " ] ; then
2016-08-13 19:22:25 +08:00
_usage " Usage: $PROJECT_ENTRY --toPkcs -d domain [--password pfx-password] "
2016-04-05 22:39:34 +08:00
return 1
fi
2016-08-13 19:22:25 +08:00
_isEcc = " $3 "
2016-11-09 19:30:39 +08:00
2016-08-13 19:22:25 +08:00
_initpath " $domain " " $_isEcc "
2017-07-24 14:23:01 +01:00
_toPkcs " $CERT_PFX_PATH " " $CERT_KEY_PATH " " $CERT_PATH " " $CA_CERT_PATH " " $pfxPassword "
2016-11-09 19:30:39 +08:00
if [ " $? " = "0" ] ; then
2016-04-05 22:39:34 +08:00
_info " Success, Pfx is exported to: $CERT_PFX_PATH "
fi
}
2017-02-25 19:31:52 +08:00
#domain [isEcc]
toPkcs8( ) {
domain = " $1 "
if [ -z " $domain " ] ; then
_usage " Usage: $PROJECT_ENTRY --toPkcs8 -d domain [--ecc] "
return 1
fi
_isEcc = " $2 "
_initpath " $domain " " $_isEcc "
2017-03-30 21:16:25 +08:00
${ ACME_OPENSSL_BIN :- openssl } pkcs8 -topk8 -inform PEM -outform PEM -nocrypt -in " $CERT_KEY_PATH " -out " $CERT_PKCS8_PATH "
2017-02-25 19:31:52 +08:00
if [ " $? " = "0" ] ; then
_info " Success, $CERT_PKCS8_PATH "
fi
}
2017-04-17 19:08:34 +08:00
#[2048]
2016-03-08 20:44:12 +08:00
createAccountKey( ) {
_info "Creating account key"
2016-11-09 19:30:39 +08:00
if [ -z " $1 " ] ; then
2016-08-23 22:53:43 +08:00
_usage " Usage: $PROJECT_ENTRY --createAccountKey --accountkeylength 2048 "
2016-03-08 20:44:12 +08:00
return
fi
2016-11-09 19:30:39 +08:00
2016-08-23 22:53:43 +08:00
length = $1
2016-11-06 23:08:45 +08:00
_create_account_key " $length "
}
_create_account_key( ) {
2016-08-23 22:53:43 +08:00
length = $1
2016-11-09 19:30:39 +08:00
if [ -z " $length " ] || [ " $length " = " $NO_VALUE " ] ; then
2016-11-06 23:08:45 +08:00
_debug " Use default length $DEFAULT_ACCOUNT_KEY_LENGTH "
length = " $DEFAULT_ACCOUNT_KEY_LENGTH "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
2016-08-23 22:53:43 +08:00
_debug length " $length "
2016-03-08 20:44:12 +08:00
_initpath
2016-08-23 22:53:43 +08:00
2016-11-06 23:08:45 +08:00
mkdir -p " $CA_DIR "
2016-11-09 19:30:39 +08:00
if [ -f " $ACCOUNT_KEY_PATH " ] ; then
2016-03-08 20:44:12 +08:00
_info "Account key exists, skip"
return
else
#generate account key
2016-08-13 20:37:52 +08:00
_createkey " $length " " $ACCOUNT_KEY_PATH "
2016-03-08 20:44:12 +08:00
fi
}
2016-08-13 19:22:25 +08:00
#domain [length]
2016-03-08 20:44:12 +08:00
createDomainKey( ) {
_info "Creating domain key"
2016-11-09 19:30:39 +08:00
if [ -z " $1 " ] ; then
2016-08-13 19:22:25 +08:00
_usage " Usage: $PROJECT_ENTRY --createDomainKey -d domain.com [ --keylength 2048 ] "
2016-03-08 20:44:12 +08:00
return
fi
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
domain = $1
2017-05-15 20:46:02 +08:00
_cdl = $2
2016-06-17 13:23:44 +08:00
2017-05-15 20:46:02 +08:00
if [ -z " $_cdl " ] ; then
2016-11-06 23:08:45 +08:00
_debug " Use DEFAULT_DOMAIN_KEY_LENGTH= $DEFAULT_DOMAIN_KEY_LENGTH "
2017-05-15 20:46:02 +08:00
_cdl = " $DEFAULT_DOMAIN_KEY_LENGTH "
2016-11-06 23:08:45 +08:00
fi
2016-06-17 13:23:44 +08:00
2017-05-15 20:46:02 +08:00
_initpath " $domain " " $_cdl "
2016-11-09 19:30:39 +08:00
2017-07-02 18:40:11 +08:00
if [ ! -f " $CERT_KEY_PATH " ] || ( [ " $FORCE " ] && ! [ " $IS_RENEW " ] ) || [ " $Le_ForceNewDomainKey " = "1" ] ; then
2017-05-15 20:46:02 +08:00
if _createkey " $_cdl " " $CERT_KEY_PATH " ; then
_savedomainconf Le_Keylength " $_cdl "
_info " The domain key is here: $( __green $CERT_KEY_PATH ) "
fi
2016-03-08 20:44:12 +08:00
else
2016-11-09 19:30:39 +08:00
if [ " $IS_RENEW " ] ; then
2016-03-08 20:44:12 +08:00
_info "Domain key exists, skip"
return 0
else
_err "Domain key exists, do you want to overwrite the key?"
2016-04-15 21:27:32 +08:00
_err "Add '--force', and try again."
2016-03-08 20:44:12 +08:00
return 1
fi
fi
}
2016-08-13 19:22:25 +08:00
# domain domainlist isEcc
2016-03-08 20:44:12 +08:00
createCSR( ) {
_info "Creating csr"
2016-11-09 19:30:39 +08:00
if [ -z " $1 " ] ; then
2016-08-13 19:22:25 +08:00
_usage " Usage: $PROJECT_ENTRY --createCSR -d domain1.com [-d domain2.com -d domain3.com ... ] "
2016-03-08 20:44:12 +08:00
return
fi
2016-11-09 19:30:39 +08:00
2016-08-13 19:22:25 +08:00
domain = " $1 "
domainlist = " $2 "
_isEcc = " $3 "
2016-11-09 19:30:39 +08:00
2016-08-13 19:22:25 +08:00
_initpath " $domain " " $_isEcc "
2016-11-09 19:30:39 +08:00
if [ -f " $CSR_PATH " ] && [ " $IS_RENEW " ] && [ -z " $FORCE " ] ; then
2016-03-08 20:44:12 +08:00
_info "CSR exists, skip"
return
fi
2016-11-09 19:30:39 +08:00
if [ ! -f " $CERT_KEY_PATH " ] ; then
2016-08-13 19:22:25 +08:00
_err " The key file is not found: $CERT_KEY_PATH "
_err "Please create the key file first."
return 1
fi
2016-06-17 13:23:44 +08:00
_createcsr " $domain " " $domainlist " " $CERT_KEY_PATH " " $CSR_PATH " " $DOMAIN_SSL_CONF "
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
}
2017-01-29 11:47:04 +08:00
_url_replace( ) {
2016-11-09 21:06:22 +08:00
tr '/+' '_-' | tr -d '= '
2016-03-08 20:44:12 +08:00
}
_time2str( ) {
2017-03-05 19:56:06 +08:00
#Linux
2016-11-09 21:06:22 +08:00
if date -u -d@" $1 " 2>/dev/null; then
2016-03-08 20:44:12 +08:00
return
fi
2016-11-09 19:30:39 +08:00
2017-03-05 19:56:06 +08:00
#BSD
2016-11-09 21:06:22 +08:00
if date -u -r " $1 " 2>/dev/null; then
2016-03-08 20:44:12 +08:00
return
fi
2016-11-09 19:30:39 +08:00
2016-08-10 21:54:08 +08:00
#Soaris
2016-11-09 19:30:39 +08:00
if _exists adb; then
2016-11-11 22:36:16 +08:00
_t_s_a = $( echo " 0t ${ 1 } =Y " | adb)
echo " $_t_s_a "
2016-08-10 21:54:08 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-08-17 12:50:28 +02:00
#Busybox
if echo " $1 " | awk '{ print strftime("%c", $0); }' 2>/dev/null; then
return
fi
2016-03-08 20:44:12 +08:00
}
2016-05-23 22:02:43 +08:00
_normalizeJson( ) {
sed "s/\" *: *\([\"{\[]\)/\":\1/g" | sed "s/^ *\([^ ]\)/\1/" | tr -d "\r\n"
}
2016-03-09 23:16:46 +08:00
_stat( ) {
#Linux
2016-11-09 19:30:39 +08:00
if stat -c '%U:%G' " $1 " 2>/dev/null; then
2016-03-09 23:16:46 +08:00
return
fi
2016-11-09 19:30:39 +08:00
2016-03-09 23:16:46 +08:00
#BSD
2016-11-09 19:30:39 +08:00
if stat -f '%Su:%Sg' " $1 " 2>/dev/null; then
2016-03-09 23:16:46 +08:00
return
fi
2016-11-09 19:30:39 +08:00
return 1 #error, 'stat' not found
2016-03-09 23:16:46 +08:00
}
2016-03-15 21:27:47 +08:00
#keyfile
_calcjwk( ) {
keyfile = " $1 "
2016-11-09 19:30:39 +08:00
if [ -z " $keyfile " ] ; then
2016-08-13 19:22:25 +08:00
_usage "Usage: _calcjwk keyfile"
2016-03-15 21:27:47 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
if [ " $JWK_HEADER " ] && [ " $__CACHED_JWK_KEY_FILE " = " $keyfile " ] ; then
2016-10-29 12:14:48 +08:00
_debug2 " Use cached jwk for file: $__CACHED_JWK_KEY_FILE "
return 0
fi
2016-11-09 19:30:39 +08:00
if grep "BEGIN RSA PRIVATE KEY" " $keyfile " >/dev/null 2>& 1; then
2016-03-15 21:27:47 +08:00
_debug "RSA key"
2017-03-30 21:16:25 +08:00
pub_exp = $( ${ ACME_OPENSSL_BIN :- openssl } rsa -in " $keyfile " -noout -text | grep "^publicExponent:" | cut -d '(' -f 2 | cut -d 'x' -f 2 | cut -d ')' -f 1)
2016-11-09 19:30:39 +08:00
if [ " ${# pub_exp } " = "5" ] ; then
2016-03-15 21:27:47 +08:00
pub_exp = 0$pub_exp
fi
2016-08-10 21:54:08 +08:00
_debug3 pub_exp " $pub_exp "
2016-11-09 19:30:39 +08:00
2016-11-09 21:06:22 +08:00
e = $( echo " $pub_exp " | _h2b | _base64)
2016-08-10 21:54:08 +08:00
_debug3 e " $e "
2016-11-09 19:30:39 +08:00
2017-03-30 21:16:25 +08:00
modulus = $( ${ ACME_OPENSSL_BIN :- openssl } rsa -in " $keyfile " -modulus -noout | cut -d '=' -f 2)
2016-08-10 21:54:08 +08:00
_debug3 modulus " $modulus "
2017-01-29 11:47:04 +08:00
n = " $( printf "%s" " $modulus " | _h2b | _base64 | _url_replace) "
2016-12-13 20:04:43 +08:00
_debug3 n " $n "
2016-03-15 21:27:47 +08:00
jwk = '{"e": "' $e '", "kty": "RSA", "n": "' $n '"}'
2016-08-10 21:54:08 +08:00
_debug3 jwk " $jwk "
2016-11-09 19:30:39 +08:00
2016-10-28 18:07:04 +08:00
JWK_HEADER = '{"alg": "RS256", "jwk": ' $jwk '}'
JWK_HEADERPLACE_PART1 = '{"nonce": "'
2018-01-06 12:45:24 +08:00
JWK_HEADERPLACE_PART2 = '", "alg": "RS256"'
2016-11-09 19:30:39 +08:00
elif grep "BEGIN EC PRIVATE KEY" " $keyfile " >/dev/null 2>& 1; then
2016-03-15 21:27:47 +08:00
_debug "EC key"
2017-03-30 21:16:25 +08:00
crv = " $( ${ ACME_OPENSSL_BIN :- openssl } ec -in " $keyfile " -noout -text 2>/dev/null | grep "^NIST CURVE:" | cut -d ":" -f 2 | tr -d " \r\n" ) "
2016-08-10 21:54:08 +08:00
_debug3 crv " $crv "
2017-12-07 21:32:17 +08:00
__ECC_KEY_LEN = $( echo " $crv " | cut -d "-" -f 2)
if [ " $__ECC_KEY_LEN " = "521" ] ; then
__ECC_KEY_LEN = 512
fi
_debug3 __ECC_KEY_LEN " $__ECC_KEY_LEN "
2016-11-09 19:30:39 +08:00
if [ -z " $crv " ] ; then
2016-11-04 22:45:50 +08:00
_debug "Let's try ASN1 OID"
2017-03-30 21:16:25 +08:00
crv_oid = " $( ${ ACME_OPENSSL_BIN :- openssl } ec -in " $keyfile " -noout -text 2>/dev/null | grep "^ASN1 OID:" | cut -d ":" -f 2 | tr -d " \r\n" ) "
2016-11-04 22:53:33 +08:00
_debug3 crv_oid " $crv_oid "
2016-11-04 22:45:50 +08:00
case " ${ crv_oid } " in
"prime256v1" )
2016-11-09 19:30:39 +08:00
crv = "P-256"
2017-12-07 21:32:17 +08:00
__ECC_KEY_LEN = 256
2016-11-09 19:30:39 +08:00
; ;
2016-11-04 22:45:50 +08:00
"secp384r1" )
2016-11-09 19:30:39 +08:00
crv = "P-384"
2017-12-07 21:32:17 +08:00
__ECC_KEY_LEN = 384
2016-11-09 19:30:39 +08:00
; ;
2016-11-04 22:45:50 +08:00
"secp521r1" )
2016-11-09 19:30:39 +08:00
crv = "P-521"
2017-12-07 21:32:17 +08:00
__ECC_KEY_LEN = 512
2016-11-09 19:30:39 +08:00
; ;
2016-11-04 22:45:50 +08:00
*)
2016-11-09 19:30:39 +08:00
_err " ECC oid : $crv_oid "
return 1
; ;
2016-11-04 22:47:45 +08:00
esac
2016-11-04 22:45:50 +08:00
_debug3 crv " $crv "
fi
2016-11-09 19:30:39 +08:00
2017-03-30 21:16:25 +08:00
pubi = " $( ${ ACME_OPENSSL_BIN :- openssl } ec -in " $keyfile " -noout -text 2>/dev/null | grep -n pub: | cut -d : -f 1) "
2016-11-09 21:18:47 +08:00
pubi = $( _math " $pubi " + 1)
2016-08-10 21:54:08 +08:00
_debug3 pubi " $pubi "
2016-11-09 19:30:39 +08:00
2017-03-30 21:16:25 +08:00
pubj = " $( ${ ACME_OPENSSL_BIN :- openssl } ec -in " $keyfile " -noout -text 2>/dev/null | grep -n "ASN1 OID:" | cut -d : -f 1) "
2016-11-09 21:18:47 +08:00
pubj = $( _math " $pubj " - 1)
2016-08-10 21:54:08 +08:00
_debug3 pubj " $pubj "
2016-11-09 19:30:39 +08:00
2017-03-30 21:16:25 +08:00
pubtext = " $( ${ ACME_OPENSSL_BIN :- openssl } ec -in " $keyfile " -noout -text 2>/dev/null | sed -n " $pubi , ${ pubj } p " | tr -d " \n\r" ) "
2016-08-10 21:54:08 +08:00
_debug3 pubtext " $pubtext "
2016-11-09 19:30:39 +08:00
2016-11-09 20:45:57 +08:00
xlen = " $( printf "%s" " $pubtext " | tr -d ':' | wc -c) "
2016-11-09 21:18:47 +08:00
xlen = $( _math " $xlen " / 4)
2016-08-10 21:54:08 +08:00
_debug3 xlen " $xlen "
2016-04-17 17:33:08 +08:00
2016-10-27 00:06:03 +08:00
xend = $( _math " $xlen " + 1)
2016-11-09 21:06:22 +08:00
x = " $( printf "%s" " $pubtext " | cut -d : -f 2-" $xend " ) "
2016-08-10 21:54:08 +08:00
_debug3 x " $x "
2016-11-09 19:30:39 +08:00
2017-01-29 11:47:04 +08:00
x64 = " $( printf "%s" " $x " | tr -d : | _h2b | _base64 | _url_replace) "
2016-08-10 21:54:08 +08:00
_debug3 x64 " $x64 "
2016-04-17 17:33:08 +08:00
2016-05-13 21:14:00 +08:00
xend = $( _math " $xend " + 1)
2016-11-09 21:06:22 +08:00
y = " $( printf "%s" " $pubtext " | cut -d : -f " $xend " -10000) "
2016-08-10 21:54:08 +08:00
_debug3 y " $y "
2016-11-09 19:30:39 +08:00
2017-01-29 11:47:04 +08:00
y64 = " $( printf "%s" " $y " | tr -d : | _h2b | _base64 | _url_replace) "
2016-08-10 21:54:08 +08:00
_debug3 y64 " $y64 "
2016-11-09 19:30:39 +08:00
2016-10-29 12:14:48 +08:00
jwk = '{"crv": "' $crv '", "kty": "EC", "x": "' $x64 '", "y": "' $y64 '"}'
2016-08-10 21:54:08 +08:00
_debug3 jwk " $jwk "
2016-11-09 19:30:39 +08:00
2017-12-07 21:32:17 +08:00
JWK_HEADER = '{"alg": "ES' $__ECC_KEY_LEN '", "jwk": ' $jwk '}'
2016-10-28 18:07:04 +08:00
JWK_HEADERPLACE_PART1 = '{"nonce": "'
2018-01-06 12:45:24 +08:00
JWK_HEADERPLACE_PART2 = '", "alg": "ES' $__ECC_KEY_LEN '"'
2016-03-15 21:27:47 +08:00
else
_err "Only RSA or EC key is supported."
return 1
fi
2016-10-28 18:07:04 +08:00
_debug3 JWK_HEADER " $JWK_HEADER "
2016-10-29 12:14:48 +08:00
__CACHED_JWK_KEY_FILE = " $keyfile "
2016-03-15 21:27:47 +08:00
}
2016-08-14 22:37:21 +08:00
2016-08-25 21:46:31 +08:00
_time( ) {
date -u "+%s"
}
2016-08-14 22:37:21 +08:00
2017-02-06 19:30:53 +08:00
_utc_date( ) {
date -u "+%Y-%m-%d %H:%M:%S"
}
2016-08-14 22:37:21 +08:00
_mktemp( ) {
2016-11-09 19:30:39 +08:00
if _exists mktemp; then
if mktemp 2>/dev/null; then
2016-11-01 20:29:58 +08:00
return 0
2016-11-09 19:30:39 +08:00
elif _contains " $( mktemp 2>& 1) " "-t prefix" && mktemp -t " $PROJECT_NAME " 2>/dev/null; then
2016-09-27 23:43:18 +08:00
#for Mac osx
2016-11-01 20:29:58 +08:00
return 0
2016-09-27 21:27:43 +08:00
fi
2016-08-14 22:37:21 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -d "/tmp" ] ; then
2016-08-25 21:46:31 +08:00
echo " /tmp/ ${ PROJECT_NAME } wefADf24sf. $( _time) .tmp "
return 0
2016-11-09 19:30:39 +08:00
elif [ " $LE_TEMP_DIR " ] && mkdir -p " $LE_TEMP_DIR " ; then
2016-11-01 20:29:58 +08:00
echo " / $LE_TEMP_DIR /wefADf24sf. $( _time) .tmp "
return 0
2016-08-25 21:46:31 +08:00
fi
_err "Can not create temp file."
2016-08-14 22:37:21 +08:00
}
_inithttp( ) {
2016-11-09 19:30:39 +08:00
if [ -z " $HTTP_HEADER " ] || ! touch " $HTTP_HEADER " ; then
2016-08-14 22:37:21 +08:00
HTTP_HEADER = " $( _mktemp) "
_debug2 HTTP_HEADER " $HTTP_HEADER "
fi
2016-11-09 19:30:39 +08:00
if [ " $__HTTP_INITIALIZED " ] ; then
if [ " $_ACME_CURL $_ACME_WGET " ] ; then
2016-10-28 20:56:18 +08:00
_debug2 "Http already initialized."
return 0
fi
fi
2016-11-09 19:30:39 +08:00
if [ -z " $_ACME_CURL " ] && _exists "curl" ; then
2016-10-28 20:56:18 +08:00
_ACME_CURL = " curl -L --silent --dump-header $HTTP_HEADER "
2016-11-09 19:30:39 +08:00
if [ " $DEBUG " ] && [ " $DEBUG " -ge "2" ] ; then
2016-08-14 22:37:21 +08:00
_CURL_DUMP = " $( _mktemp) "
2016-10-28 20:56:18 +08:00
_ACME_CURL = " $_ACME_CURL --trace-ascii $_CURL_DUMP "
2016-08-14 22:37:21 +08:00
fi
2017-03-19 16:10:09 +01:00
if [ " $CA_PATH " ] ; then
_ACME_CURL = " $_ACME_CURL --capath $CA_PATH "
elif [ " $CA_BUNDLE " ] ; then
2016-10-28 20:56:18 +08:00
_ACME_CURL = " $_ACME_CURL --cacert $CA_BUNDLE "
2016-08-25 01:14:56 -04:00
fi
2018-02-10 23:23:31 +08:00
if _contains " $( curl --help 2>& 1) " "--globoff" ; then
_ACME_CURL = " $_ACME_CURL -g "
fi
2016-08-14 22:37:21 +08:00
fi
2016-11-09 19:30:39 +08:00
2016-10-28 20:56:18 +08:00
if [ -z " $_ACME_WGET " ] && _exists "wget" ; then
_ACME_WGET = "wget -q"
2016-11-09 19:30:39 +08:00
if [ " $DEBUG " ] && [ " $DEBUG " -ge "2" ] ; then
2016-10-28 20:56:18 +08:00
_ACME_WGET = " $_ACME_WGET -d "
2016-08-14 22:37:21 +08:00
fi
2017-03-19 16:10:09 +01:00
if [ " $CA_PATH " ] ; then
_ACME_WGET = " $_ACME_WGET --ca-directory= $CA_PATH "
elif [ " $CA_BUNDLE " ] ; then
_ACME_WGET = " $_ACME_WGET --ca-certificate= $CA_BUNDLE "
2016-08-25 01:14:56 -04:00
fi
2016-08-14 22:37:21 +08:00
fi
2017-02-28 21:35:20 +08:00
#from wget 1.14: do not skip body on 404 error
2017-03-01 13:12:29 +08:00
if [ " $_ACME_WGET " ] && _contains " $( $_ACME_WGET --help 2>& 1) " "--content-on-error" ; then
2017-02-28 21:35:20 +08:00
_ACME_WGET = " $_ACME_WGET --content-on-error "
fi
2016-10-28 20:56:18 +08:00
__HTTP_INITIALIZED = 1
2016-08-14 22:37:21 +08:00
}
2016-05-09 22:36:48 +08:00
# body url [needbase64] [POST|PUT]
2016-03-19 18:18:34 +08:00
_post( ) {
body = " $1 "
2018-01-06 12:45:24 +08:00
_post_url = " $2 "
2016-03-19 18:18:34 +08:00
needbase64 = " $3 "
2016-05-07 23:33:42 +08:00
httpmethod = " $4 "
2016-03-19 18:18:34 +08:00
2016-11-09 19:30:39 +08:00
if [ -z " $httpmethod " ] ; then
2016-05-07 23:33:42 +08:00
httpmethod = "POST"
fi
_debug $httpmethod
2018-01-06 12:45:24 +08:00
_debug "_post_url" " $_post_url "
2016-07-29 18:07:16 +08:00
_debug2 "body" " $body "
2016-11-09 19:30:39 +08:00
2016-08-14 22:37:21 +08:00
_inithttp
2016-11-09 19:30:39 +08:00
2017-02-27 20:48:48 +08:00
if [ " $_ACME_CURL " ] && [ " ${ ACME_USE_WGET :- 0 } " = "0" ] ; then
2016-10-28 20:56:18 +08:00
_CURL = " $_ACME_CURL "
2016-11-21 20:56:50 +08:00
if [ " $HTTPS_INSECURE " ] ; then
_CURL = " $_CURL --insecure "
fi
2016-05-31 21:38:41 +08:00
_debug "_CURL" " $_CURL "
2016-11-09 19:30:39 +08:00
if [ " $needbase64 " ] ; then
2018-01-06 12:45:24 +08:00
response = " $( $_CURL --user-agent " $USER_AGENT " -X $httpmethod -H " $_H1 " -H " $_H2 " -H " $_H3 " -H " $_H4 " -H " $_H5 " --data " $body " " $_post_url " | _base64) "
2016-03-19 18:18:34 +08:00
else
2018-01-06 12:45:24 +08:00
response = " $( $_CURL --user-agent " $USER_AGENT " -X $httpmethod -H " $_H1 " -H " $_H2 " -H " $_H3 " -H " $_H4 " -H " $_H5 " --data " $body " " $_post_url " ) "
2016-03-19 18:18:34 +08:00
fi
2016-05-31 12:12:30 +08:00
_ret = " $? "
2016-11-09 19:30:39 +08:00
if [ " $_ret " != "0" ] ; then
2016-06-25 09:40:00 +08:00
_err " Please refer to https://curl.haxx.se/libcurl/c/libcurl-errors.html for error code: $_ret "
2016-11-09 19:30:39 +08:00
if [ " $DEBUG " ] && [ " $DEBUG " -ge "2" ] ; then
2016-06-25 09:40:00 +08:00
_err "Here is the curl dump log:"
_err " $( cat " $_CURL_DUMP " ) "
fi
2016-06-25 09:29:23 +08:00
fi
2016-11-09 19:30:39 +08:00
elif [ " $_ACME_WGET " ] ; then
2016-11-21 20:56:50 +08:00
_WGET = " $_ACME_WGET "
if [ " $HTTPS_INSECURE " ] ; then
_WGET = " $_WGET --no-check-certificate "
fi
_debug "_WGET" " $_WGET "
2016-11-09 19:30:39 +08:00
if [ " $needbase64 " ] ; then
if [ " $httpmethod " = "POST" ] ; then
2018-01-06 12:45:24 +08:00
response = " $( $_WGET -S -O - --user-agent= " $USER_AGENT " --header " $_H5 " --header " $_H4 " --header " $_H3 " --header " $_H2 " --header " $_H1 " --post-data= " $body " " $_post_url " 2>" $HTTP_HEADER " | _base64) "
2016-05-13 21:58:29 +08:00
else
2018-01-06 12:45:24 +08:00
response = " $( $_WGET -S -O - --user-agent= " $USER_AGENT " --header " $_H5 " --header " $_H4 " --header " $_H3 " --header " $_H2 " --header " $_H1 " --method $httpmethod --body-data= " $body " " $_post_url " 2>" $HTTP_HEADER " | _base64) "
2016-05-13 21:58:29 +08:00
fi
2016-03-19 18:18:34 +08:00
else
2016-11-09 19:30:39 +08:00
if [ " $httpmethod " = "POST" ] ; then
2018-01-06 12:45:24 +08:00
response = " $( $_WGET -S -O - --user-agent= " $USER_AGENT " --header " $_H5 " --header " $_H4 " --header " $_H3 " --header " $_H2 " --header " $_H1 " --post-data= " $body " " $_post_url " 2>" $HTTP_HEADER " ) "
2016-05-13 21:58:29 +08:00
else
2018-01-06 12:45:24 +08:00
response = " $( $_WGET -S -O - --user-agent= " $USER_AGENT " --header " $_H5 " --header " $_H4 " --header " $_H3 " --header " $_H2 " --header " $_H1 " --method $httpmethod --body-data= " $body " " $_post_url " 2>" $HTTP_HEADER " ) "
2016-05-13 21:58:29 +08:00
fi
2016-03-19 18:18:34 +08:00
fi
2016-05-31 12:12:30 +08:00
_ret = " $? "
2016-11-09 19:30:39 +08:00
if [ " $_ret " = "8" ] ; then
2016-10-03 22:08:40 +08:00
_ret = 0
2017-02-28 21:08:20 +08:00
_debug "wget returns 8, the server returns a 'Bad request' response, lets process the response later."
2016-10-03 22:08:40 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $_ret " != "0" ] ; then
_err " Please refer to https://www.gnu.org/software/wget/manual/html_node/Exit-Status.html for error code: $_ret "
2016-06-25 09:29:23 +08:00
fi
2016-03-19 18:18:34 +08:00
_sed_i "s/^ *//g" " $HTTP_HEADER "
2016-07-02 13:46:35 +08:00
else
_ret = " $? "
_err " Neither curl nor wget is found, can not do $httpmethod . "
2016-03-19 18:18:34 +08:00
fi
2016-05-31 12:12:30 +08:00
_debug "_ret" " $_ret "
2016-05-13 21:14:00 +08:00
printf "%s" " $response "
2016-05-31 12:12:30 +08:00
return $_ret
2016-03-19 18:18:34 +08:00
}
2016-08-07 14:25:55 +08:00
# url getheader timeout
2016-03-19 18:18:34 +08:00
_get( ) {
2016-05-07 23:33:42 +08:00
_debug GET
2016-03-19 18:18:34 +08:00
url = " $1 "
onlyheader = " $2 "
2016-08-07 14:25:55 +08:00
t = " $3 "
2016-11-09 21:18:47 +08:00
_debug url " $url "
2018-01-06 17:39:15 +08:00
_debug " timeout= $t "
2016-08-14 22:37:21 +08:00
_inithttp
2017-02-27 20:48:48 +08:00
if [ " $_ACME_CURL " ] && [ " ${ ACME_USE_WGET :- 0 } " = "0" ] ; then
2016-10-28 20:56:18 +08:00
_CURL = " $_ACME_CURL "
2016-11-21 20:56:50 +08:00
if [ " $HTTPS_INSECURE " ] ; then
_CURL = " $_CURL --insecure "
fi
2016-11-09 19:30:39 +08:00
if [ " $t " ] ; then
2016-08-07 14:25:55 +08:00
_CURL = " $_CURL --connect-timeout $t "
fi
_debug "_CURL" " $_CURL "
2016-11-09 19:30:39 +08:00
if [ " $onlyheader " ] ; then
2016-11-09 21:06:22 +08:00
$_CURL -I --user-agent " $USER_AGENT " -H " $_H1 " -H " $_H2 " -H " $_H3 " -H " $_H4 " -H " $_H5 " " $url "
2016-03-19 18:18:34 +08:00
else
2016-11-09 21:06:22 +08:00
$_CURL --user-agent " $USER_AGENT " -H " $_H1 " -H " $_H2 " -H " $_H3 " -H " $_H4 " -H " $_H5 " " $url "
2016-03-19 18:18:34 +08:00
fi
2016-05-31 21:20:10 +08:00
ret = $?
2016-11-09 19:30:39 +08:00
if [ " $ret " != "0" ] ; then
2016-08-14 23:20:53 +08:00
_err " Please refer to https://curl.haxx.se/libcurl/c/libcurl-errors.html for error code: $ret "
2016-11-09 19:30:39 +08:00
if [ " $DEBUG " ] && [ " $DEBUG " -ge "2" ] ; then
2016-08-14 22:37:21 +08:00
_err "Here is the curl dump log:"
_err " $( cat " $_CURL_DUMP " ) "
fi
fi
2016-11-09 19:30:39 +08:00
elif [ " $_ACME_WGET " ] ; then
2016-10-28 20:56:18 +08:00
_WGET = " $_ACME_WGET "
2016-11-21 20:56:50 +08:00
if [ " $HTTPS_INSECURE " ] ; then
_WGET = " $_WGET --no-check-certificate "
fi
2016-11-09 19:30:39 +08:00
if [ " $t " ] ; then
2016-08-07 14:25:55 +08:00
_WGET = " $_WGET --timeout= $t "
fi
_debug "_WGET" " $_WGET "
2016-11-09 19:30:39 +08:00
if [ " $onlyheader " ] ; then
2016-11-09 21:06:22 +08:00
$_WGET --user-agent= " $USER_AGENT " --header " $_H5 " --header " $_H4 " --header " $_H3 " --header " $_H2 " --header " $_H1 " -S -O /dev/null " $url " 2>& 1 | sed 's/^[ ]*//g'
2016-03-19 18:18:34 +08:00
else
2016-11-09 21:06:22 +08:00
$_WGET --user-agent= " $USER_AGENT " --header " $_H5 " --header " $_H4 " --header " $_H3 " --header " $_H2 " --header " $_H1 " -O - " $url "
2016-03-19 18:18:34 +08:00
fi
2016-05-31 21:20:10 +08:00
ret = $?
2017-02-28 21:06:02 +08:00
if [ " $ret " = "8" ] ; then
2017-02-28 21:04:33 +08:00
ret = 0
2017-02-28 21:08:20 +08:00
_debug "wget returns 8, the server returns a 'Bad request' response, lets process the response later."
2016-10-03 22:08:40 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $ret " != "0" ] ; then
_err " Please refer to https://www.gnu.org/software/wget/manual/html_node/Exit-Status.html for error code: $ret "
2016-08-14 22:37:21 +08:00
fi
2016-07-02 13:46:35 +08:00
else
ret = $?
_err "Neither curl nor wget is found, can not do GET."
2016-05-31 21:20:10 +08:00
fi
2016-05-31 21:38:41 +08:00
_debug "ret" " $ret "
2016-03-19 18:18:34 +08:00
return $ret
}
2016-03-15 21:27:47 +08:00
2016-10-03 22:29:48 +08:00
_head_n( ) {
2016-11-09 21:18:47 +08:00
head -n " $1 "
2016-10-03 22:29:48 +08:00
}
_tail_n( ) {
2016-11-09 21:06:22 +08:00
if ! tail -n " $1 " 2>/dev/null; then
2016-10-05 13:03:45 +08:00
#fix for solaris
2016-11-09 21:06:22 +08:00
tail -" $1 "
2016-10-05 13:03:45 +08:00
fi
2016-10-03 22:29:48 +08:00
}
2016-08-14 22:37:21 +08:00
2016-03-15 21:27:47 +08:00
# url payload needbase64 keyfile
2016-03-08 20:44:12 +08:00
_send_signed_request( ) {
url = $1
payload = $2
needbase64 = $3
2016-03-15 21:27:47 +08:00
keyfile = $4
2016-11-09 19:30:39 +08:00
if [ -z " $keyfile " ] ; then
2016-03-15 21:27:47 +08:00
keyfile = " $ACCOUNT_KEY_PATH "
fi
2016-11-09 21:06:22 +08:00
_debug url " $url "
2016-03-08 20:44:12 +08:00
_debug payload " $payload "
2016-11-09 19:30:39 +08:00
if ! _calcjwk " $keyfile " ; then
2016-03-15 21:27:47 +08:00
return 1
fi
2016-03-19 18:18:34 +08:00
2017-01-29 11:47:04 +08:00
payload64 = $( printf "%s" " $payload " | _base64 | _url_replace)
2016-11-09 21:06:22 +08:00
_debug3 payload64 " $payload64 "
2016-11-09 19:30:39 +08:00
2017-02-17 13:51:17 +08:00
MAX_REQUEST_RETRY_TIMES = 5
_request_retry_times = 0
while [ " ${ _request_retry_times } " -lt " $MAX_REQUEST_RETRY_TIMES " ] ; do
2017-02-17 14:40:58 +08:00
_debug3 _request_retry_times " $_request_retry_times "
2017-02-17 13:51:17 +08:00
if [ -z " $_CACHED_NONCE " ] ; then
2017-06-19 20:24:31 +08:00
_headers = ""
2017-06-19 20:05:43 +08:00
if [ " $ACME_NEW_NONCE " ] ; then
_debug2 "Get nonce. ACME_NEW_NONCE" " $ACME_NEW_NONCE "
nonceurl = " $ACME_NEW_NONCE "
if _post "" " $nonceurl " "" "HEAD" ; then
_headers = " $( cat " $HTTP_HEADER " ) "
fi
fi
if [ -z " $_headers " ] ; then
_debug2 "Get nonce. ACME_DIRECTORY" " $ACME_DIRECTORY "
nonceurl = " $ACME_DIRECTORY "
_headers = " $( _get " $nonceurl " "onlyheader" ) "
fi
2017-02-17 13:51:17 +08:00
if [ " $? " != "0" ] ; then
_err " Can not connect to $nonceurl to get nonce. "
return 1
fi
2016-11-09 19:30:39 +08:00
2017-02-17 13:51:17 +08:00
_debug2 _headers " $_headers "
2016-11-09 19:30:39 +08:00
2017-02-17 13:51:17 +08:00
_CACHED_NONCE = " $( echo " $_headers " | grep "Replay-Nonce:" | _head_n 1 | tr -d "\r\n " | cut -d ':' -f 2) "
_debug2 _CACHED_NONCE " $_CACHED_NONCE "
else
_debug2 "Use _CACHED_NONCE" " $_CACHED_NONCE "
fi
nonce = " $_CACHED_NONCE "
_debug2 nonce " $nonce "
2016-11-09 19:30:39 +08:00
2018-01-06 12:45:24 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
2018-01-06 21:33:27 +08:00
if [ " $url " = " $ACME_NEW_ACCOUNT " ] || [ " $url " = " $ACME_REVOKE_CERT " ] ; then
2018-01-06 12:45:24 +08:00
protected = " $JWK_HEADERPLACE_PART1 $nonce \", \"url\": \" ${ url } $JWK_HEADERPLACE_PART2 , \"jwk\": $jwk " '}'
else
2018-02-05 16:38:42 -05:00
protected = " $JWK_HEADERPLACE_PART1 $nonce \", \"url\": \" ${ url } $JWK_HEADERPLACE_PART2 , \"kid\": \" ${ ACCOUNT_URL } \" " '}'
2018-01-06 12:45:24 +08:00
fi
else
protected = " $JWK_HEADERPLACE_PART1 $nonce \", \"url\": \" ${ url } $JWK_HEADERPLACE_PART2 , \"jwk\": $jwk " '}'
fi
2017-02-17 13:51:17 +08:00
_debug3 protected " $protected "
2016-05-31 20:16:57 +08:00
2017-02-17 13:51:17 +08:00
protected64 = " $( printf "%s" " $protected " | _base64 | _url_replace) "
_debug3 protected64 " $protected64 "
2016-11-09 19:30:39 +08:00
2017-02-17 13:51:17 +08:00
if ! _sig_t = " $( printf "%s" " $protected64 . $payload64 " | _sign " $keyfile " "sha256" ) " ; then
_err "Sign request failed."
return 1
fi
_debug3 _sig_t " $_sig_t "
2016-03-15 21:27:47 +08:00
2017-02-17 13:51:17 +08:00
sig = " $( printf "%s" " $_sig_t " | _url_replace) "
_debug3 sig " $sig "
2016-11-09 19:30:39 +08:00
2018-01-06 12:45:24 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
body = " {\"protected\": \" $protected64 \", \"payload\": \" $payload64 \", \"signature\": \" $sig \"} "
else
body = " {\"header\": $JWK_HEADER , \"protected\": \" $protected64 \", \"payload\": \" $payload64 \", \"signature\": \" $sig \"} "
fi
2017-02-17 13:51:17 +08:00
_debug3 body " $body "
2016-11-09 19:30:39 +08:00
2017-02-17 13:51:17 +08:00
response = " $( _post " $body " " $url " " $needbase64 " ) "
_CACHED_NONCE = ""
2016-03-19 22:04:03 +08:00
2017-02-17 13:51:17 +08:00
if [ " $? " != "0" ] ; then
_err " Can not post to $url "
return 1
fi
_debug2 original " $response "
response = " $( echo " $response " | _normalizeJson) "
2016-03-08 20:44:12 +08:00
2017-02-18 10:31:18 +08:00
responseHeaders = " $( cat " $HTTP_HEADER " ) "
2016-03-08 20:44:12 +08:00
2017-02-17 13:51:17 +08:00
_debug2 responseHeaders " $responseHeaders "
_debug2 response " $response "
code = " $( grep "^HTTP" " $HTTP_HEADER " | _tail_n 1 | cut -d " " -f 2 | tr -d "\r\n" ) "
_debug code " $code "
2016-11-09 19:30:39 +08:00
2017-02-17 13:51:17 +08:00
_CACHED_NONCE = " $( echo " $responseHeaders " | grep "Replay-Nonce:" | _head_n 1 | tr -d "\r\n " | cut -d ':' -f 2) "
2016-03-08 20:44:12 +08:00
2017-09-05 20:32:14 +08:00
_body = " $response "
if [ " $needbase64 " ] ; then
_body = " $( echo " $_body " | _dbase64) "
2017-09-11 21:28:37 +08:00
_debug2 _body " $_body "
2017-09-05 20:32:14 +08:00
fi
2017-09-11 21:28:37 +08:00
2017-09-05 20:32:14 +08:00
if _contains " $_body " "JWS has invalid anti-replay nonce" ; then
2017-02-17 13:51:17 +08:00
_info "It seems the CA server is busy now, let's wait and retry."
_request_retry_times = $( _math " $_request_retry_times " + 1)
_sleep 5
continue
fi
2017-02-17 14:40:58 +08:00
break
2017-02-17 13:51:17 +08:00
done
2016-03-08 20:44:12 +08:00
}
#setopt "file" "opt" "=" "value" [";"]
_setopt( ) {
__conf = " $1 "
__opt = " $2 "
__sep = " $3 "
__val = " $4 "
__end = " $5 "
2016-11-09 19:30:39 +08:00
if [ -z " $__opt " ] ; then
_usage usage: _setopt '"file" "opt" "=" "value" [";"]'
2016-03-08 20:44:12 +08:00
return
fi
2016-11-09 19:30:39 +08:00
if [ ! -f " $__conf " ] ; then
2016-03-08 20:44:12 +08:00
touch " $__conf "
fi
2016-11-09 19:30:39 +08:00
if grep -n " ^ $__opt $__sep " " $__conf " >/dev/null; then
2016-08-10 21:54:08 +08:00
_debug3 OK
2016-11-09 19:30:39 +08:00
if _contains " $__val " "&" ; then
2016-11-09 21:18:47 +08:00
__val = " $( echo " $__val " | sed 's/&/\\&/g' ) "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 21:18:47 +08:00
text = " $( cat " $__conf " ) "
2017-02-16 22:37:32 +08:00
printf -- "%s\n" " $text " | sed " s|^ $__opt $__sep .* $| $__opt $__sep $__val $__end | " >" $__conf "
2016-03-08 20:44:12 +08:00
2016-11-09 19:30:39 +08:00
elif grep -n " ^# $__opt $__sep " " $__conf " >/dev/null; then
if _contains " $__val " "&" ; then
2016-11-09 21:18:47 +08:00
__val = " $( echo " $__val " | sed 's/&/\\&/g' ) "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 21:18:47 +08:00
text = " $( cat " $__conf " ) "
2017-02-16 22:37:32 +08:00
printf -- "%s\n" " $text " | sed " s|^# $__opt $__sep .* $| $__opt $__sep $__val $__end | " >" $__conf "
2016-03-08 20:44:12 +08:00
else
2016-08-10 21:54:08 +08:00
_debug3 APP
2016-11-09 19:30:39 +08:00
echo " $__opt $__sep $__val $__end " >>" $__conf "
2016-03-08 20:44:12 +08:00
fi
2017-02-20 20:18:58 +08:00
_debug3 " $( grep -n " ^ $__opt $__sep " " $__conf " ) "
2016-03-08 20:44:12 +08:00
}
2016-10-28 22:45:19 +08:00
#_save_conf file key value
#save to conf
_save_conf( ) {
_s_c_f = " $1 "
_sdkey = " $2 "
_sdvalue = " $3 "
2016-11-09 19:30:39 +08:00
if [ " $_s_c_f " ] ; then
2016-10-28 22:45:19 +08:00
_setopt " $_s_c_f " " $_sdkey " "=" " ' $_sdvalue ' "
2016-04-27 22:14:15 +08:00
else
2016-10-28 22:45:19 +08:00
_err " config file is empty, can not save $_sdkey = $_sdvalue "
2016-04-27 22:14:15 +08:00
fi
}
2016-10-28 22:45:19 +08:00
#_clear_conf file key
_clear_conf( ) {
_c_c_f = " $1 "
_sdkey = " $2 "
2016-11-09 19:30:39 +08:00
if [ " $_c_c_f " ] ; then
2016-11-14 17:47:22 +08:00
_conf_data = " $( cat " $_c_c_f " ) "
2016-11-16 22:44:39 +08:00
echo " $_conf_data " | sed " s/^ $_sdkey *=.* $// " >" $_c_c_f "
2016-03-08 20:44:12 +08:00
else
2016-10-28 22:45:19 +08:00
_err "config file is empty, can not clear"
2016-03-08 20:44:12 +08:00
fi
}
2016-10-28 22:45:19 +08:00
#_read_conf file key
_read_conf( ) {
_r_c_f = " $1 "
_sdkey = " $2 "
2016-11-09 19:30:39 +08:00
if [ -f " $_r_c_f " ] ; then
(
2016-11-09 21:18:47 +08:00
eval " $( grep " ^ $_sdkey *= " " $_r_c_f " ) "
2016-11-09 19:30:39 +08:00
eval " printf \"%s\" \"\$ $_sdkey \" "
)
2016-07-02 13:03:59 +08:00
else
2016-11-06 23:08:45 +08:00
_debug " config file is empty, can not read $_sdkey "
2016-03-08 20:44:12 +08:00
fi
}
#_savedomainconf key value
#save to domain.conf
_savedomainconf( ) {
2016-10-28 22:45:19 +08:00
_save_conf " $DOMAIN_CONF " " $1 " " $2 "
2016-04-27 22:14:15 +08:00
}
#_cleardomainconf key
_cleardomainconf( ) {
2016-10-28 22:45:19 +08:00
_clear_conf " $DOMAIN_CONF " " $1 "
2016-03-08 20:44:12 +08:00
}
2016-07-02 13:03:59 +08:00
#_readdomainconf key
_readdomainconf( ) {
2016-10-28 22:45:19 +08:00
_read_conf " $DOMAIN_CONF " " $1 "
2016-07-02 13:03:59 +08:00
}
2016-03-08 20:44:12 +08:00
#_saveaccountconf key value
_saveaccountconf( ) {
2016-10-28 22:45:19 +08:00
_save_conf " $ACCOUNT_CONF_PATH " " $1 " " $2 "
2016-03-08 20:44:12 +08:00
}
2017-04-11 21:37:56 +08:00
#key value
_saveaccountconf_mutable( ) {
_save_conf " $ACCOUNT_CONF_PATH " " SAVED_ $1 " " $2 "
#remove later
_clearaccountconf " $1 "
}
#key
_readaccountconf( ) {
_read_conf " $ACCOUNT_CONF_PATH " " $1 "
}
#key
_readaccountconf_mutable( ) {
_rac_key = " $1 "
_readaccountconf " SAVED_ $_rac_key "
}
2016-08-14 22:37:21 +08:00
#_clearaccountconf key
_clearaccountconf( ) {
2016-10-28 22:45:19 +08:00
_clear_conf " $ACCOUNT_CONF_PATH " " $1 "
}
#_savecaconf key value
_savecaconf( ) {
_save_conf " $CA_CONF " " $1 " " $2 "
}
#_readcaconf key
_readcaconf( ) {
_read_conf " $CA_CONF " " $1 "
}
#_clearaccountconf key
_clearcaconf( ) {
_clear_conf " $CA_CONF " " $1 "
2016-08-14 22:37:21 +08:00
}
2016-09-23 23:14:03 +08:00
# content localaddress
2016-03-08 20:44:12 +08:00
_startserver( ) {
content = " $1 "
2016-09-23 23:14:03 +08:00
ncaddr = " $2 "
_debug "ncaddr" " $ncaddr "
2016-04-12 23:18:22 +08:00
_debug " startserver: $$ "
2016-11-09 19:30:39 +08:00
2016-05-29 14:08:39 +08:00
_debug Le_HTTPPort " $Le_HTTPPort "
2016-10-02 23:37:37 +08:00
_debug Le_Listen_V4 " $Le_Listen_V4 "
_debug Le_Listen_V6 " $Le_Listen_V6 "
2016-11-09 19:30:39 +08:00
2017-09-01 23:01:37 +08:00
_NC = "socat"
2016-11-09 19:30:39 +08:00
if [ " $Le_Listen_V4 " ] ; then
2016-10-02 23:37:37 +08:00
_NC = " $_NC -4 "
2016-11-09 19:30:39 +08:00
elif [ " $Le_Listen_V6 " ] ; then
2016-10-02 23:37:37 +08:00
_NC = " $_NC -6 "
fi
2016-11-09 19:30:39 +08:00
2016-10-02 23:37:37 +08:00
_debug "_NC" " $_NC "
2017-09-01 23:01:37 +08:00
#todo listen address
2017-09-26 19:43:06 +04:00
$_NC TCP-LISTEN:$Le_HTTPPort ,crlf,reuseaddr,fork SYSTEM:" sleep 0.5; echo HTTP/1.1 200 OK; echo ; echo $content ; echo; " &
2017-09-01 23:01:37 +08:00
serverproc = " $! "
2016-03-08 20:44:12 +08:00
}
2016-11-09 19:30:39 +08:00
_stopserver( ) {
2016-03-08 20:44:12 +08:00
pid = " $1 "
2016-04-12 23:18:22 +08:00
_debug "pid" " $pid "
2016-11-09 19:30:39 +08:00
if [ -z " $pid " ] ; then
2016-04-12 23:18:22 +08:00
return
fi
2016-06-17 13:23:44 +08:00
2017-09-01 23:01:37 +08:00
kill $pid
2016-03-08 20:44:12 +08:00
}
2016-09-30 22:13:27 +08:00
# sleep sec
_sleep( ) {
_sleep_sec = " $1 "
2016-11-09 19:30:39 +08:00
if [ " $__INTERACTIVE " ] ; then
2016-09-30 22:13:27 +08:00
_sleep_c = " $_sleep_sec "
2016-11-09 19:30:39 +08:00
while [ " $_sleep_c " -ge "0" ] ; do
2016-09-30 22:43:24 +08:00
printf "\r \r"
2016-09-30 22:13:27 +08:00
__green " $_sleep_c "
2016-11-09 21:18:47 +08:00
_sleep_c = " $( _math " $_sleep_c " - 1) "
2016-09-30 22:13:27 +08:00
sleep 1
done
2016-09-30 22:43:24 +08:00
printf "\r"
2016-09-30 22:13:27 +08:00
else
sleep " $_sleep_sec "
fi
}
2016-06-17 13:23:44 +08:00
2016-10-02 23:37:37 +08:00
# _starttlsserver san_a san_b port content _ncaddr
2016-06-17 13:23:44 +08:00
_starttlsserver( ) {
_info "Starting tls server."
san_a = " $1 "
san_b = " $2 "
port = " $3 "
content = " $4 "
2016-10-02 23:37:37 +08:00
opaddr = " $5 "
2016-11-09 19:30:39 +08:00
2016-06-17 13:23:44 +08:00
_debug san_a " $san_a "
_debug san_b " $san_b "
_debug port " $port "
2016-11-09 19:30:39 +08:00
2016-06-17 13:23:44 +08:00
#create key TLS_KEY
2016-11-09 19:30:39 +08:00
if ! _createkey "2048" " $TLS_KEY " ; then
2016-06-17 13:23:44 +08:00
_err "Create tls validation key error."
return 1
fi
2016-11-09 19:30:39 +08:00
2016-06-17 13:23:44 +08:00
#create csr
alt = " $san_a "
2016-11-09 19:30:39 +08:00
if [ " $san_b " ] ; then
2016-06-17 13:23:44 +08:00
alt = " $alt , $san_b "
fi
2016-11-09 19:30:39 +08:00
if ! _createcsr "tls.acme.sh" " $alt " " $TLS_KEY " " $TLS_CSR " " $TLS_CONF " ; then
2016-06-17 13:23:44 +08:00
_err "Create tls validation csr error."
return 1
fi
2016-11-09 19:30:39 +08:00
2016-06-17 13:23:44 +08:00
#self signed
2016-11-09 19:30:39 +08:00
if ! _signcsr " $TLS_KEY " " $TLS_CSR " " $TLS_CONF " " $TLS_CERT " ; then
2016-06-17 13:23:44 +08:00
_err "Create tls validation cert error."
return 1
fi
2016-11-09 19:30:39 +08:00
2017-10-08 19:45:50 +08:00
__S_OPENSSL = " ${ ACME_OPENSSL_BIN :- openssl } s_server -www -cert $TLS_CERT -key $TLS_KEY "
if [ " $opaddr " ] ; then
__S_OPENSSL = " $__S_OPENSSL -accept $opaddr : $port "
else
__S_OPENSSL = " $__S_OPENSSL -accept $port "
fi
2016-10-02 23:37:37 +08:00
_debug Le_Listen_V4 " $Le_Listen_V4 "
_debug Le_Listen_V6 " $Le_Listen_V6 "
2016-11-09 19:30:39 +08:00
if [ " $Le_Listen_V4 " ] ; then
2016-10-02 23:37:37 +08:00
__S_OPENSSL = " $__S_OPENSSL -4 "
2016-11-09 19:30:39 +08:00
elif [ " $Le_Listen_V6 " ] ; then
2016-10-02 23:37:37 +08:00
__S_OPENSSL = " $__S_OPENSSL -6 "
fi
2016-11-09 19:30:39 +08:00
2016-10-02 23:37:37 +08:00
_debug " $__S_OPENSSL "
2017-10-08 19:45:50 +08:00
if [ " $DEBUG " ] && [ " $DEBUG " -ge "2" ] ; then
$__S_OPENSSL -tlsextdebug &
else
$__S_OPENSSL >/dev/null 2>& 1 &
fi
2016-06-17 20:54:22 +08:00
2016-06-17 13:23:44 +08:00
serverproc = " $! "
2016-10-29 10:53:45 +08:00
sleep 1
2016-11-09 21:44:46 +08:00
_debug serverproc " $serverproc "
2016-06-17 13:23:44 +08:00
}
2016-09-22 13:15:25 +08:00
#file
_readlink( ) {
_rf = " $1 "
if ! readlink -f " $_rf " 2>/dev/null; then
2017-02-03 11:13:38 +08:00
if _startswith " $_rf " "/" ; then
echo " $_rf "
2016-09-22 21:38:11 +08:00
return 0
fi
2017-02-03 11:13:38 +08:00
echo " $( pwd ) / $_rf " | _conapath
2016-09-22 13:15:25 +08:00
fi
}
2017-02-03 11:13:38 +08:00
_conapath( ) {
sed "s#/\./#/#g"
}
2016-09-19 23:07:43 +08:00
__initHome( ) {
2016-11-09 19:30:39 +08:00
if [ -z " $_SCRIPT_HOME " ] ; then
if _exists readlink && _exists dirname; then
2016-10-09 22:27:25 +08:00
_debug "Lets find script dir."
2016-09-02 22:37:49 +08:00
_debug "_SCRIPT_" " $_SCRIPT_ "
2016-09-22 13:15:25 +08:00
_script = " $( _readlink " $_SCRIPT_ " ) "
2016-09-02 22:37:49 +08:00
_debug "_script" " $_script "
_script_home = " $( dirname " $_script " ) "
_debug "_script_home" " $_script_home "
2016-11-09 19:30:39 +08:00
if [ -d " $_script_home " ] ; then
2016-09-02 22:37:49 +08:00
_SCRIPT_HOME = " $_script_home "
else
_err " It seems the script home is not correct: $_script_home "
fi
fi
fi
2016-12-02 20:30:52 +08:00
# if [ -z "$LE_WORKING_DIR" ]; then
# if [ -f "$DEFAULT_INSTALL_HOME/account.conf" ]; then
# _debug "It seems that $PROJECT_NAME is already installed in $DEFAULT_INSTALL_HOME"
# LE_WORKING_DIR="$DEFAULT_INSTALL_HOME"
# else
# LE_WORKING_DIR="$_SCRIPT_HOME"
# fi
# fi
2016-11-09 19:30:39 +08:00
if [ -z " $LE_WORKING_DIR " ] ; then
2016-09-02 22:37:49 +08:00
_debug " Using default home: $DEFAULT_INSTALL_HOME "
LE_WORKING_DIR = " $DEFAULT_INSTALL_HOME "
fi
2016-09-22 21:38:11 +08:00
export LE_WORKING_DIR
2016-09-02 22:37:49 +08:00
2017-01-21 11:28:10 +08:00
if [ -z " $LE_CONFIG_HOME " ] ; then
LE_CONFIG_HOME = " $LE_WORKING_DIR "
2017-01-16 22:31:24 +08:00
fi
2017-01-21 11:28:10 +08:00
_debug " Using config home: $LE_CONFIG_HOME "
export LE_CONFIG_HOME
2017-01-16 22:31:24 +08:00
2017-01-21 11:28:10 +08:00
_DEFAULT_ACCOUNT_CONF_PATH = " $LE_CONFIG_HOME /account.conf "
2016-04-11 22:33:57 +08:00
2016-11-09 19:30:39 +08:00
if [ -z " $ACCOUNT_CONF_PATH " ] ; then
if [ -f " $_DEFAULT_ACCOUNT_CONF_PATH " ] ; then
2016-04-17 07:38:43 +08:00
. " $_DEFAULT_ACCOUNT_CONF_PATH "
2016-04-16 17:25:26 +08:00
fi
2016-04-11 22:33:57 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $ACCOUNT_CONF_PATH " ] ; then
2016-04-11 22:33:57 +08:00
ACCOUNT_CONF_PATH = " $_DEFAULT_ACCOUNT_CONF_PATH "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-01-21 11:28:10 +08:00
DEFAULT_LOG_FILE = " $LE_CONFIG_HOME / $PROJECT_NAME .log "
2016-11-09 19:30:39 +08:00
2017-01-21 11:28:10 +08:00
DEFAULT_CA_HOME = " $LE_CONFIG_HOME /ca "
2016-11-09 19:30:39 +08:00
if [ -z " $LE_TEMP_DIR " ] ; then
2017-01-21 11:28:10 +08:00
LE_TEMP_DIR = " $LE_CONFIG_HOME /tmp "
2016-11-01 20:29:58 +08:00
fi
2016-09-19 23:07:43 +08:00
}
2017-06-17 15:49:45 +08:00
#server
_initAPI( ) {
_api_server = " ${ 1 :- $ACME_DIRECTORY } "
_debug " _init api for server: $_api_server "
2017-06-17 15:59:27 +08:00
2017-06-19 20:05:43 +08:00
if [ -z " $ACME_NEW_ACCOUNT " ] ; then
2017-06-17 15:49:45 +08:00
response = $( _get " $_api_server " )
if [ " $? " != "0" ] ; then
_debug2 "response" " $response "
_err "Can not init api."
return 1
fi
_debug2 "response" " $response "
ACME_KEY_CHANGE = $( echo " $response " | _egrep_o 'key-change" *: *"[^"]*"' | cut -d '"' -f 3)
2018-01-06 12:45:24 +08:00
if [ -z " $ACME_KEY_CHANGE " ] ; then
ACME_KEY_CHANGE = $( echo " $response " | _egrep_o 'keyChange" *: *"[^"]*"' | cut -d '"' -f 3)
fi
2017-06-17 15:49:45 +08:00
export ACME_KEY_CHANGE
ACME_NEW_AUTHZ = $( echo " $response " | _egrep_o 'new-authz" *: *"[^"]*"' | cut -d '"' -f 3)
2018-01-06 12:45:24 +08:00
if [ -z " $ACME_NEW_AUTHZ " ] ; then
ACME_NEW_AUTHZ = $( echo " $response " | _egrep_o 'newAuthz" *: *"[^"]*"' | cut -d '"' -f 3)
fi
2017-06-17 15:49:45 +08:00
export ACME_NEW_AUTHZ
2017-06-19 20:05:43 +08:00
ACME_NEW_ORDER = $( echo " $response " | _egrep_o 'new-cert" *: *"[^"]*"' | cut -d '"' -f 3)
2017-07-02 18:05:55 +08:00
ACME_NEW_ORDER_RES = "new-cert"
2017-06-19 20:05:43 +08:00
if [ -z " $ACME_NEW_ORDER " ] ; then
ACME_NEW_ORDER = $( echo " $response " | _egrep_o 'new-order" *: *"[^"]*"' | cut -d '"' -f 3)
2017-07-02 18:05:55 +08:00
ACME_NEW_ORDER_RES = "new-order"
2018-01-06 12:45:24 +08:00
if [ -z " $ACME_NEW_ORDER " ] ; then
ACME_NEW_ORDER = $( echo " $response " | _egrep_o 'newOrder" *: *"[^"]*"' | cut -d '"' -f 3)
fi
2017-06-19 20:05:43 +08:00
fi
export ACME_NEW_ORDER
2017-07-02 18:05:55 +08:00
export ACME_NEW_ORDER_RES
2017-06-17 15:49:45 +08:00
2017-06-19 20:05:43 +08:00
ACME_NEW_ACCOUNT = $( echo " $response " | _egrep_o 'new-reg" *: *"[^"]*"' | cut -d '"' -f 3)
2017-07-02 18:05:55 +08:00
ACME_NEW_ACCOUNT_RES = "new-reg"
2017-06-19 20:05:43 +08:00
if [ -z " $ACME_NEW_ACCOUNT " ] ; then
ACME_NEW_ACCOUNT = $( echo " $response " | _egrep_o 'new-account" *: *"[^"]*"' | cut -d '"' -f 3)
2017-07-02 18:05:55 +08:00
ACME_NEW_ACCOUNT_RES = "new-account"
2018-01-06 12:45:24 +08:00
if [ -z " $ACME_NEW_ACCOUNT " ] ; then
ACME_NEW_ACCOUNT = $( echo " $response " | _egrep_o 'newAccount" *: *"[^"]*"' | cut -d '"' -f 3)
if [ " $ACME_NEW_ACCOUNT " ] ; then
export ACME_VERSION = 2
fi
fi
2017-06-19 20:05:43 +08:00
fi
export ACME_NEW_ACCOUNT
2017-07-02 18:05:55 +08:00
export ACME_NEW_ACCOUNT_RES
2017-06-17 15:49:45 +08:00
ACME_REVOKE_CERT = $( echo " $response " | _egrep_o 'revoke-cert" *: *"[^"]*"' | cut -d '"' -f 3)
2018-01-06 12:45:24 +08:00
if [ -z " $ACME_REVOKE_CERT " ] ; then
ACME_REVOKE_CERT = $( echo " $response " | _egrep_o 'revokeCert" *: *"[^"]*"' | cut -d '"' -f 3)
fi
2017-06-17 15:49:45 +08:00
export ACME_REVOKE_CERT
2017-06-19 20:05:43 +08:00
ACME_NEW_NONCE = $( echo " $response " | _egrep_o 'new-nonce" *: *"[^"]*"' | cut -d '"' -f 3)
2018-01-06 12:45:24 +08:00
if [ -z " $ACME_NEW_NONCE " ] ; then
ACME_NEW_NONCE = $( echo " $response " | _egrep_o 'newNonce" *: *"[^"]*"' | cut -d '"' -f 3)
fi
2017-06-19 20:05:43 +08:00
export ACME_NEW_NONCE
2017-12-08 19:54:25 +08:00
2017-12-07 21:32:17 +08:00
ACME_AGREEMENT = $( echo " $response " | _egrep_o 'terms-of-service" *: *"[^"]*"' | cut -d '"' -f 3)
2018-01-06 12:45:24 +08:00
if [ -z " $ACME_AGREEMENT " ] ; then
ACME_AGREEMENT = $( echo " $response " | _egrep_o 'termsOfService" *: *"[^"]*"' | cut -d '"' -f 3)
fi
2017-12-07 21:32:17 +08:00
export ACME_AGREEMENT
2017-06-19 20:05:43 +08:00
2017-12-07 21:32:17 +08:00
_debug "ACME_KEY_CHANGE" " $ACME_KEY_CHANGE "
_debug "ACME_NEW_AUTHZ" " $ACME_NEW_AUTHZ "
_debug "ACME_NEW_ORDER" " $ACME_NEW_ORDER "
_debug "ACME_NEW_ACCOUNT" " $ACME_NEW_ACCOUNT "
_debug "ACME_REVOKE_CERT" " $ACME_REVOKE_CERT "
_debug "ACME_AGREEMENT" " $ACME_AGREEMENT "
2018-01-06 12:45:24 +08:00
_debug "ACME_NEW_NONCE" " $ACME_NEW_NONCE "
_debug "ACME_VERSION" " $ACME_VERSION "
2017-06-17 15:49:45 +08:00
2017-12-07 21:32:17 +08:00
fi
2017-06-17 15:49:45 +08:00
}
2017-07-25 09:39:15 +01:00
#[domain] [keylength or isEcc flag]
2016-09-19 23:07:43 +08:00
_initpath( ) {
2018-01-16 20:55:07 +08:00
domain = " $1 "
_ilength = " $2 "
2016-09-19 23:07:43 +08:00
__initHome
2016-11-09 19:30:39 +08:00
if [ -f " $ACCOUNT_CONF_PATH " ] ; then
2016-04-17 07:38:43 +08:00
. " $ACCOUNT_CONF_PATH "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $IN_CRON " ] ; then
if [ ! " $_USER_PATH_EXPORTED " ] ; then
2016-04-05 21:08:19 +08:00
_USER_PATH_EXPORTED = 1
export PATH = " $USER_PATH : $PATH "
fi
fi
2016-11-09 19:30:39 +08:00
if [ -z " $CA_HOME " ] ; then
2016-09-27 23:43:18 +08:00
CA_HOME = " $DEFAULT_CA_HOME "
fi
2016-04-05 21:08:19 +08:00
2018-01-06 17:39:15 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
DEFAULT_CA = " $LETSENCRYPT_CA_V2 "
DEFAULT_STAGING_CA = " $LETSENCRYPT_STAGING_CA_V2 "
fi
2017-06-17 15:49:45 +08:00
if [ -z " $ACME_DIRECTORY " ] ; then
2016-11-09 19:30:39 +08:00
if [ -z " $STAGE " ] ; then
2017-06-17 15:49:45 +08:00
ACME_DIRECTORY = " $DEFAULT_CA "
2016-03-08 20:44:12 +08:00
else
2018-01-06 12:45:24 +08:00
ACME_DIRECTORY = " $DEFAULT_STAGING_CA "
2017-06-17 15:49:45 +08:00
_info " Using stage ACME_DIRECTORY: $ACME_DIRECTORY "
2016-11-09 19:30:39 +08:00
fi
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-09-23 22:12:17 +08:00
_debug2 ACME_DIRECTORY " $ACME_DIRECTORY "
2017-06-19 20:19:30 +08:00
_ACME_SERVER_HOST = " $( echo " $ACME_DIRECTORY " | cut -d : -f 2 | tr -s / | cut -d / -f 2) "
2017-06-17 15:49:45 +08:00
_debug2 "_ACME_SERVER_HOST" " $_ACME_SERVER_HOST "
CA_DIR = " $CA_HOME / $_ACME_SERVER_HOST "
2016-11-09 19:30:39 +08:00
2016-09-27 23:43:18 +08:00
_DEFAULT_CA_CONF = " $CA_DIR /ca.conf "
2016-11-09 19:30:39 +08:00
if [ -z " $CA_CONF " ] ; then
2016-09-27 23:43:18 +08:00
CA_CONF = " $_DEFAULT_CA_CONF "
fi
2016-12-10 21:32:47 +08:00
_debug3 CA_CONF " $CA_CONF "
2016-11-09 19:30:39 +08:00
if [ -f " $CA_CONF " ] ; then
2016-09-27 23:43:18 +08:00
. " $CA_CONF "
fi
2016-11-09 19:30:39 +08:00
if [ -z " $ACME_DIR " ] ; then
2016-03-08 20:44:12 +08:00
ACME_DIR = "/home/.acme"
fi
2016-11-09 19:30:39 +08:00
if [ -z " $APACHE_CONF_BACKUP_DIR " ] ; then
2017-01-21 11:28:10 +08:00
APACHE_CONF_BACKUP_DIR = " $LE_CONFIG_HOME "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $USER_AGENT " ] ; then
2016-03-19 22:04:03 +08:00
USER_AGENT = " $DEFAULT_USER_AGENT "
fi
2016-11-09 19:30:39 +08:00
if [ -z " $HTTP_HEADER " ] ; then
2017-01-21 11:28:10 +08:00
HTTP_HEADER = " $LE_CONFIG_HOME /http.header "
2016-08-17 13:17:06 +08:00
fi
2016-04-16 19:05:53 +08:00
2016-09-27 23:43:18 +08:00
_OLD_ACCOUNT_KEY = " $LE_WORKING_DIR /account.key "
_OLD_ACCOUNT_JSON = " $LE_WORKING_DIR /account.json "
2016-11-09 19:30:39 +08:00
2016-09-27 23:43:18 +08:00
_DEFAULT_ACCOUNT_KEY_PATH = " $CA_DIR /account.key "
_DEFAULT_ACCOUNT_JSON_PATH = " $CA_DIR /account.json "
2016-11-09 19:30:39 +08:00
if [ -z " $ACCOUNT_KEY_PATH " ] ; then
2016-04-16 19:05:53 +08:00
ACCOUNT_KEY_PATH = " $_DEFAULT_ACCOUNT_KEY_PATH "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $ACCOUNT_JSON_PATH " ] ; then
2016-09-27 23:43:18 +08:00
ACCOUNT_JSON_PATH = " $_DEFAULT_ACCOUNT_JSON_PATH "
fi
2016-11-09 19:30:39 +08:00
2017-01-21 11:28:10 +08:00
_DEFAULT_CERT_HOME = " $LE_CONFIG_HOME "
2016-11-09 19:30:39 +08:00
if [ -z " $CERT_HOME " ] ; then
2016-04-18 02:37:35 +02:00
CERT_HOME = " $_DEFAULT_CERT_HOME "
fi
2017-02-25 19:12:20 +08:00
if [ -z " $ACME_OPENSSL_BIN " ] || [ ! -f " $ACME_OPENSSL_BIN " ] || [ ! -x " $ACME_OPENSSL_BIN " ] ; then
2017-02-25 19:08:00 +08:00
ACME_OPENSSL_BIN = " $DEFAULT_OPENSSL_BIN "
2016-11-22 21:43:42 +08:00
fi
2018-01-16 20:55:07 +08:00
if [ -z " $domain " ] ; then
2016-03-08 20:44:12 +08:00
return 0
fi
2016-11-09 19:30:39 +08:00
if [ -z " $DOMAIN_PATH " ] ; then
2016-08-13 19:22:25 +08:00
domainhome = " $CERT_HOME / $domain "
domainhomeecc = " $CERT_HOME / $domain $ECC_SUFFIX "
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
DOMAIN_PATH = " $domainhome "
2016-11-09 19:30:39 +08:00
if _isEccKey " $_ilength " ; then
2016-08-13 19:22:25 +08:00
DOMAIN_PATH = " $domainhomeecc "
else
2016-11-09 19:30:39 +08:00
if [ ! -d " $domainhome " ] && [ -d " $domainhomeecc " ] ; then
2016-08-23 10:03:50 +08:00
_info " The domain ' $domain ' seems to have a ECC cert already, please add ' $( __red "--ecc" ) ' parameter if you want to use that cert. "
2016-08-13 19:22:25 +08:00
fi
fi
_debug DOMAIN_PATH " $DOMAIN_PATH "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-02-12 10:10:53 +08:00
if [ -z " $DOMAIN_BACKUP_PATH " ] ; then
2017-02-12 10:20:50 +08:00
DOMAIN_BACKUP_PATH = " $DOMAIN_PATH /backup "
2017-02-12 10:10:53 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $DOMAIN_CONF " ] ; then
2016-08-13 19:22:25 +08:00
DOMAIN_CONF = " $DOMAIN_PATH / $domain .conf "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $DOMAIN_SSL_CONF " ] ; then
2016-09-15 10:41:47 +08:00
DOMAIN_SSL_CONF = " $DOMAIN_PATH / $domain .csr.conf "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $CSR_PATH " ] ; then
2016-08-13 19:22:25 +08:00
CSR_PATH = " $DOMAIN_PATH / $domain .csr "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $CERT_KEY_PATH " ] ; then
2016-08-13 19:22:25 +08:00
CERT_KEY_PATH = " $DOMAIN_PATH / $domain .key "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $CERT_PATH " ] ; then
2016-08-13 19:22:25 +08:00
CERT_PATH = " $DOMAIN_PATH / $domain .cer "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $CA_CERT_PATH " ] ; then
2016-08-13 19:22:25 +08:00
CA_CERT_PATH = " $DOMAIN_PATH /ca.cer "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $CERT_FULLCHAIN_PATH " ] ; then
2016-08-13 19:22:25 +08:00
CERT_FULLCHAIN_PATH = " $DOMAIN_PATH /fullchain.cer "
2016-03-13 11:37:14 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $CERT_PFX_PATH " ] ; then
2016-08-13 19:22:25 +08:00
CERT_PFX_PATH = " $DOMAIN_PATH / $domain .pfx "
2016-04-05 22:39:34 +08:00
fi
2017-02-25 19:31:52 +08:00
if [ -z " $CERT_PKCS8_PATH " ] ; then
CERT_PKCS8_PATH = " $DOMAIN_PATH / $domain .pkcs8 "
fi
2016-11-09 19:30:39 +08:00
if [ -z " $TLS_CONF " ] ; then
2017-03-26 05:32:29 +00:00
TLS_CONF = " $DOMAIN_PATH /tls.validation.conf "
2016-06-17 13:23:44 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $TLS_CERT " ] ; then
2017-03-26 05:32:29 +00:00
TLS_CERT = " $DOMAIN_PATH /tls.validation.cert "
2016-06-17 13:23:44 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $TLS_KEY " ] ; then
2017-03-26 05:32:29 +00:00
TLS_KEY = " $DOMAIN_PATH /tls.validation.key "
2016-06-17 13:23:44 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $TLS_CSR " ] ; then
2017-03-26 05:32:29 +00:00
TLS_CSR = " $DOMAIN_PATH /tls.validation.csr "
2016-06-17 13:23:44 +08:00
fi
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
}
2016-11-01 20:29:58 +08:00
_exec( ) {
2016-11-09 19:30:39 +08:00
if [ -z " $_EXEC_TEMP_ERR " ] ; then
2016-11-01 20:29:58 +08:00
_EXEC_TEMP_ERR = " $( _mktemp) "
fi
2016-11-09 19:30:39 +08:00
if [ " $_EXEC_TEMP_ERR " ] ; then
2016-11-16 22:20:47 +08:00
eval " $@ 2>> $_EXEC_TEMP_ERR "
2016-11-01 20:29:58 +08:00
else
2016-11-16 22:20:47 +08:00
eval " $@ "
2016-11-01 20:29:58 +08:00
fi
}
_exec_err( ) {
2016-11-16 22:20:47 +08:00
[ " $_EXEC_TEMP_ERR " ] && _err " $( cat " $_EXEC_TEMP_ERR " ) " && echo "" >" $_EXEC_TEMP_ERR "
2016-11-01 20:29:58 +08:00
}
2016-03-08 20:44:12 +08:00
_apachePath( ) {
2016-07-20 22:18:07 +08:00
_APACHECTL = "apachectl"
2016-11-09 19:30:39 +08:00
if ! _exists apachectl; then
if _exists apache2ctl; then
_APACHECTL = "apache2ctl"
2016-06-26 11:49:41 +08:00
else
2016-06-27 10:32:51 +08:00
_err "'apachectl not found. It seems that apache is not installed, or you are not root user.'"
2016-06-26 11:49:41 +08:00
_err "Please use webroot mode to try again."
return 1
fi
2016-04-19 18:36:15 +08:00
fi
2016-11-09 19:30:39 +08:00
if ! _exec $_APACHECTL -V >/dev/null; then
2016-11-01 20:29:58 +08:00
_exec_err
return 1
fi
2016-11-09 19:30:39 +08:00
if [ " $APACHE_HTTPD_CONF " ] ; then
2016-11-06 23:26:38 +08:00
_saveaccountconf APACHE_HTTPD_CONF " $APACHE_HTTPD_CONF "
httpdconf = " $APACHE_HTTPD_CONF "
2016-11-09 21:18:47 +08:00
httpdconfname = " $( basename " $httpdconfname " ) "
2016-04-04 22:37:58 +08:00
else
2016-11-09 19:30:39 +08:00
httpdconfname = " $( $_APACHECTL -V | grep SERVER_CONFIG_FILE = | cut -d = -f 2 | tr -d '"' ) "
2016-11-06 23:26:38 +08:00
_debug httpdconfname " $httpdconfname "
2016-11-09 19:30:39 +08:00
if [ -z " $httpdconfname " ] ; then
2016-11-06 23:26:38 +08:00
_err "Can not read apache config file."
return 1
fi
2016-11-09 19:30:39 +08:00
if _startswith " $httpdconfname " '/' ; then
2016-11-06 23:26:38 +08:00
httpdconf = " $httpdconfname "
2016-11-09 21:18:47 +08:00
httpdconfname = " $( basename " $httpdconfname " ) "
2016-11-06 23:26:38 +08:00
else
2016-11-09 19:30:39 +08:00
httpdroot = " $( $_APACHECTL -V | grep HTTPD_ROOT = | cut -d = -f 2 | tr -d '"' ) "
2016-11-06 23:26:38 +08:00
_debug httpdroot " $httpdroot "
httpdconf = " $httpdroot / $httpdconfname "
2016-11-09 21:18:47 +08:00
httpdconfname = " $( basename " $httpdconfname " ) "
2016-11-06 23:26:38 +08:00
fi
2016-04-04 22:37:58 +08:00
fi
2016-05-21 14:47:23 +08:00
_debug httpdconf " $httpdconf "
2016-05-21 15:33:10 +08:00
_debug httpdconfname " $httpdconfname "
2016-11-09 19:30:39 +08:00
if [ ! -f " $httpdconf " ] ; then
2016-05-21 14:47:23 +08:00
_err "Apache Config file not found" " $httpdconf "
2016-03-08 20:44:12 +08:00
return 1
fi
return 0
}
_restoreApache( ) {
2016-11-09 19:30:39 +08:00
if [ -z " $usingApache " ] ; then
2016-03-08 20:44:12 +08:00
return 0
fi
_initpath
2016-11-09 19:30:39 +08:00
if ! _apachePath; then
2016-03-08 20:44:12 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
if [ ! -f " $APACHE_CONF_BACKUP_DIR / $httpdconfname " ] ; then
2016-03-08 20:44:12 +08:00
_debug "No config file to restore."
return 0
fi
2016-11-09 19:30:39 +08:00
cat " $APACHE_CONF_BACKUP_DIR / $httpdconfname " >" $httpdconf "
2016-04-16 18:31:00 +08:00
_debug " Restored: $httpdconf . "
2016-11-09 19:30:39 +08:00
if ! _exec $_APACHECTL -t; then
2016-11-01 20:29:58 +08:00
_exec_err
2016-03-08 20:44:12 +08:00
_err "Sorry, restore apache config error, please contact me."
2016-11-09 19:30:39 +08:00
return 1
2016-03-08 20:44:12 +08:00
fi
2016-04-16 18:31:00 +08:00
_debug "Restored successfully."
2016-03-08 20:44:12 +08:00
rm -f " $APACHE_CONF_BACKUP_DIR / $httpdconfname "
2016-11-09 19:30:39 +08:00
return 0
2016-03-08 20:44:12 +08:00
}
_setApache( ) {
_initpath
2016-11-09 19:30:39 +08:00
if ! _apachePath; then
2016-03-08 20:44:12 +08:00
return 1
fi
2016-06-15 13:46:45 +08:00
#test the conf first
2016-06-15 13:57:27 +08:00
_info "Checking if there is an error in the apache config file before starting."
2016-11-09 19:30:39 +08:00
2016-11-09 22:35:30 +08:00
if ! _exec " $_APACHECTL " -t >/dev/null; then
2016-11-01 20:29:58 +08:00
_exec_err
_err "The apache config file has error, please fix it first, then try again."
2016-06-15 13:57:27 +08:00
_err "Don't worry, there is nothing changed to your system."
2016-11-09 19:30:39 +08:00
return 1
2016-06-15 13:46:45 +08:00
else
_info "OK"
fi
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
#backup the conf
2016-05-16 22:42:32 +08:00
_debug "Backup apache config file" " $httpdconf "
2016-11-09 19:30:39 +08:00
if ! cp " $httpdconf " " $APACHE_CONF_BACKUP_DIR / " ; then
2016-06-15 13:57:27 +08:00
_err "Can not backup apache config file, so abort. Don't worry, the apache config is not changed."
2017-03-26 05:29:30 +00:00
_err " This might be a bug of $PROJECT_NAME , please report issue: $PROJECT "
2016-05-21 15:33:10 +08:00
return 1
fi
2016-03-08 20:44:12 +08:00
_info " JFYI, Config file $httpdconf is backuped to $APACHE_CONF_BACKUP_DIR / $httpdconfname "
_info "In case there is an error that can not be restored automatically, you may try restore it yourself."
2016-12-14 21:32:24 +01:00
_info "The backup file will be deleted on success, just forget it."
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
#add alias
2016-11-09 19:30:39 +08:00
apacheVer = " $( $_APACHECTL -V | grep "Server version:" | cut -d : -f 2 | cut -d " " -f 2 | cut -d '/' -f 2) "
2016-04-05 21:40:48 +08:00
_debug "apacheVer" " $apacheVer "
apacheMajer = " $( echo " $apacheVer " | cut -d . -f 1) "
apacheMinor = " $( echo " $apacheVer " | cut -d . -f 2) "
2016-11-09 19:30:39 +08:00
if [ " $apacheVer " ] && [ " $apacheMajer $apacheMinor " -ge "24" ] ; then
2016-04-05 21:40:48 +08:00
echo "
2016-03-08 20:44:12 +08:00
Alias /.well-known/acme-challenge $ACME_DIR
<Directory $ACME_DIR >
Require all granted
2016-04-05 21:40:48 +08:00
</Directory>
2016-11-09 19:30:39 +08:00
" >>" $httpdconf "
2016-04-05 21:40:48 +08:00
else
echo "
Alias /.well-known/acme-challenge $ACME_DIR
<Directory $ACME_DIR >
Order allow,deny
Allow from all
2016-03-08 20:44:12 +08:00
</Directory>
2016-11-09 19:30:39 +08:00
" >>" $httpdconf "
2016-04-05 21:40:48 +08:00
fi
2016-11-09 19:30:39 +08:00
_msg = " $( $_APACHECTL -t 2>& 1) "
if [ " $? " != "0" ] ; then
2016-06-15 13:46:45 +08:00
_err "Sorry, apache config error"
2016-11-09 19:30:39 +08:00
if _restoreApache; then
2016-06-15 13:57:27 +08:00
_err "The apache config file is restored."
2016-06-15 13:46:45 +08:00
else
2016-06-15 13:57:27 +08:00
_err "Sorry, The apache config file can not be restored, please report bug."
2016-06-15 13:46:45 +08:00
fi
2016-11-09 19:30:39 +08:00
return 1
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ ! -d " $ACME_DIR " ] ; then
2016-03-08 20:44:12 +08:00
mkdir -p " $ACME_DIR "
chmod 755 " $ACME_DIR "
fi
2016-11-09 19:30:39 +08:00
2016-11-09 22:35:30 +08:00
if ! _exec " $_APACHECTL " graceful; then
2016-11-09 19:30:39 +08:00
_exec_err
2016-11-01 20:29:58 +08:00
_err " $_APACHECTL graceful error, please contact me. "
2016-03-08 20:44:12 +08:00
_restoreApache
2016-11-09 19:30:39 +08:00
return 1
2016-03-08 20:44:12 +08:00
fi
usingApache = "1"
return 0
}
2017-02-13 23:29:37 +08:00
#find the real nginx conf file
#backup
#set the nginx conf
#returns the real nginx conf file
_setNginx( ) {
_d = " $1 "
_croot = " $2 "
_thumbpt = " $3 "
2018-01-19 22:41:42 +08:00
2017-02-13 23:29:37 +08:00
FOUND_REAL_NGINX_CONF = ""
2017-02-14 23:57:00 +08:00
FOUND_REAL_NGINX_CONF_LN = ""
2017-02-13 23:29:37 +08:00
BACKUP_NGINX_CONF = ""
_debug _croot " $_croot "
_start_f = " $( echo " $_croot " | cut -d : -f 2) "
_debug _start_f " $_start_f "
if [ -z " $_start_f " ] ; then
_debug "find start conf from nginx command"
if [ -z " $NGINX_CONF " ] ; then
2018-01-19 22:41:42 +08:00
if ! _exists "nginx" ; then
_err "nginx command is not found."
return 1
fi
2017-02-13 23:29:37 +08:00
NGINX_CONF = " $( nginx -V 2>& 1 | _egrep_o "--conf-path=[^ ]* " | tr -d " " ) "
_debug NGINX_CONF " $NGINX_CONF "
NGINX_CONF = " $( echo " $NGINX_CONF " | cut -d = -f 2) "
_debug NGINX_CONF " $NGINX_CONF "
if [ ! -f " $NGINX_CONF " ] ; then
_err " ' $NGINX_CONF ' doesn't exist. "
NGINX_CONF = ""
return 1
fi
_debug " Found nginx conf file: $NGINX_CONF "
fi
_start_f = " $NGINX_CONF "
fi
2017-02-14 22:03:48 +08:00
_debug " Start detect nginx conf for $_d from: $_start_f "
2017-02-13 23:29:37 +08:00
if ! _checkConf " $_d " " $_start_f " ; then
2017-03-08 13:55:01 +08:00
_err " Can not find conf file for domain $d "
2017-02-13 23:29:37 +08:00
return 1
fi
_info " Found conf file: $FOUND_REAL_NGINX_CONF "
2017-02-14 23:57:00 +08:00
_ln = $FOUND_REAL_NGINX_CONF_LN
2017-02-14 22:03:48 +08:00
_debug "_ln" " $_ln "
_lnn = $( _math $_ln + 1)
_debug _lnn " $_lnn "
_start_tag = " $( sed -n " $_lnn , ${ _lnn } p " " $FOUND_REAL_NGINX_CONF " ) "
_debug "_start_tag" " $_start_tag "
if [ " $_start_tag " = " $NGINX_START " ] ; then
_info " The domain $_d is already configured, skip "
FOUND_REAL_NGINX_CONF = ""
return 0
fi
2017-02-13 23:29:37 +08:00
mkdir -p " $DOMAIN_BACKUP_PATH "
_backup_conf = " $DOMAIN_BACKUP_PATH / $_d .nginx.conf "
_debug _backup_conf " $_backup_conf "
BACKUP_NGINX_CONF = " $_backup_conf "
_info " Backup $FOUND_REAL_NGINX_CONF to $_backup_conf "
if ! cp " $FOUND_REAL_NGINX_CONF " " $_backup_conf " ; then
_err "backup error."
FOUND_REAL_NGINX_CONF = ""
return 1
fi
2018-01-19 22:41:42 +08:00
if ! _exists "nginx" ; then
_err "nginx command is not found."
return 1
fi
2017-02-13 23:29:37 +08:00
_info "Check the nginx conf before setting up."
if ! _exec "nginx -t" >/dev/null; then
_exec_err
return 1
fi
_info "OK, Set up nginx config file"
2017-02-14 22:41:34 +08:00
if ! sed -n " 1, ${ _ln } p " " $_backup_conf " >" $FOUND_REAL_NGINX_CONF " ; then
2017-02-14 22:03:48 +08:00
cat " $_backup_conf " >" $FOUND_REAL_NGINX_CONF "
2017-02-13 23:29:37 +08:00
_err "write nginx conf error, but don't worry, the file is restored to the original version."
return 1
fi
2017-02-14 22:03:48 +08:00
echo " $NGINX_START
2017-02-13 23:29:37 +08:00
location ~ \" ^/\. well-known/acme-challenge/( [ -_a-zA-Z0-9] +) \$ \" {
default_type text/plain;
return 200 \" \$ 1.$_thumbpt \" ;
2017-04-17 19:08:34 +08:00
}
2017-02-14 22:03:48 +08:00
#NGINX_START
" >>" $FOUND_REAL_NGINX_CONF "
2017-02-13 23:29:37 +08:00
2017-02-14 22:03:48 +08:00
if ! sed -n " ${ _lnn } ,99999p " " $_backup_conf " >>" $FOUND_REAL_NGINX_CONF " ; then
cat " $_backup_conf " >" $FOUND_REAL_NGINX_CONF "
2017-02-13 23:29:37 +08:00
_err "write nginx conf error, but don't worry, the file is restored."
return 1
fi
2017-06-04 22:04:43 +08:00
_debug3 " Modified config: $( cat $FOUND_REAL_NGINX_CONF ) "
2017-02-13 23:29:37 +08:00
_info "nginx conf is done, let's check it again."
if ! _exec "nginx -t" >/dev/null; then
_exec_err
_err "It seems that nginx conf was broken, let's restore."
2017-02-14 22:41:34 +08:00
cat " $_backup_conf " >" $FOUND_REAL_NGINX_CONF "
2017-02-13 23:29:37 +08:00
return 1
fi
_info "Reload nginx"
if ! _exec "nginx -s reload" >/dev/null; then
_exec_err
_err "It seems that nginx reload error, let's restore."
2017-02-14 22:41:34 +08:00
cat " $_backup_conf " >" $FOUND_REAL_NGINX_CONF "
2017-02-13 23:29:37 +08:00
return 1
fi
return 0
}
#d , conf
_checkConf( ) {
_d = " $1 "
_c_file = " $2 "
_debug " Start _checkConf from: $_c_file "
if [ ! -f " $2 " ] && ! echo " $2 " | grep '*$' >/dev/null && echo " $2 " | grep '*' >/dev/null; then
_debug "wildcard"
for _w_f in $2 ; do
2017-04-08 14:50:39 +08:00
if [ -f " $_w_f " ] && _checkConf " $1 " " $_w_f " ; then
2017-02-13 23:29:37 +08:00
return 0
fi
done
#not found
return 1
elif [ -f " $2 " ] ; then
_debug "single"
if _isRealNginxConf " $1 " " $2 " ; then
_debug " $2 is found. "
FOUND_REAL_NGINX_CONF = " $2 "
return 0
fi
2017-03-08 16:01:14 +08:00
if cat " $2 " | tr "\t" " " | grep "^ *include *.*;" >/dev/null; then
2017-02-13 23:29:37 +08:00
_debug "Try include files"
2017-03-08 16:01:14 +08:00
for included in $( cat " $2 " | tr "\t" " " | grep "^ *include *.*;" | sed "s/include //" | tr -d " ;" ) ; do
2017-02-13 23:29:37 +08:00
_debug " check included $included "
if _checkConf " $1 " " $included " ; then
return 0
fi
done
fi
return 1
else
_debug " $2 not found. "
return 1
fi
return 1
}
#d , conf
_isRealNginxConf( ) {
_debug " _isRealNginxConf $1 $2 "
2017-02-14 22:41:34 +08:00
if [ -f " $2 " ] ; then
2017-04-27 18:29:29 +08:00
for _fln in $( tr "\t" ' ' <" $2 " | grep -n " ^ *server_name.* $1 " | cut -d : -f 1) ; do
2017-02-14 22:41:34 +08:00
_debug _fln " $_fln "
if [ " $_fln " ] ; then
2018-01-21 20:20:54 +08:00
_start = $( tr "\t" ' ' <" $2 " | _head_n " $_fln " | grep -n "^ *server *" | grep -v server_name | _tail_n 1)
2017-02-14 23:57:00 +08:00
_debug "_start" " $_start "
_start_n = $( echo " $_start " | cut -d : -f 1)
_start_nn = $( _math $_start_n + 1)
_debug "_start_n" " $_start_n "
_debug "_start_nn" " $_start_nn "
_left = " $( sed -n " ${ _start_nn } ,99999p " " $2 " ) "
_debug2 _left " $_left "
2018-02-12 20:01:40 +08:00
_end = " $( echo " $_left " | tr "\t" ' ' | grep -n "^ *server *" | grep -v server_name | _head_n 1) "
_debug "_end" " $_end "
if [ " $_end " ] ; then
2017-02-14 23:57:00 +08:00
_end_n = $( echo " $_end " | cut -d : -f 1)
_debug "_end_n" " $_end_n "
_seg_n = $( echo " $_left " | sed -n " 1, ${ _end_n } p " )
else
_seg_n = " $_left "
fi
_debug "_seg_n" " $_seg_n "
2018-01-21 20:20:54 +08:00
_skip_ssl = 1
2018-01-25 21:08:20 +08:00
for _listen_i in $( echo " $_seg_n " | tr "\t" ' ' | grep "^ *listen" | tr -d " " ) ; do
2018-01-21 20:20:54 +08:00
if [ " $_listen_i " ] ; then
if [ " $( echo " $_listen_i " | _egrep_o "listen.*ssl[ |;]" ) " ] ; then
_debug2 " $_listen_i is ssl "
else
_debug2 " $_listen_i is plain text "
_skip_ssl = ""
2018-01-23 19:42:57 +08:00
break
fi
2018-01-21 20:20:54 +08:00
fi
done
if [ " $_skip_ssl " = "1" ] ; then
2017-02-14 23:57:00 +08:00
_debug "ssl on, skip"
2017-06-05 22:29:21 +08:00
else
FOUND_REAL_NGINX_CONF_LN = $_fln
_debug3 "found FOUND_REAL_NGINX_CONF_LN" " $FOUND_REAL_NGINX_CONF_LN "
return 0
2017-06-05 22:55:16 +08:00
fi
2017-02-14 22:41:34 +08:00
fi
done
2017-02-13 23:29:37 +08:00
fi
2017-02-14 22:41:34 +08:00
return 1
2017-02-13 23:29:37 +08:00
}
#restore all the nginx conf
_restoreNginx( ) {
2017-02-14 22:12:58 +08:00
if [ -z " $NGINX_RESTORE_VLIST " ] ; then
2017-02-13 23:29:37 +08:00
_debug "No need to restore nginx, skip."
return
fi
_debug "_restoreNginx"
2017-02-14 22:12:58 +08:00
_debug "NGINX_RESTORE_VLIST" " $NGINX_RESTORE_VLIST "
2017-02-13 23:29:37 +08:00
2017-02-14 22:12:58 +08:00
for ng_entry in $( echo " $NGINX_RESTORE_VLIST " | tr " $dvsep " ' ' ) ; do
2017-02-13 23:29:37 +08:00
_debug "ng_entry" " $ng_entry "
_nd = $( echo " $ng_entry " | cut -d " $sep " -f 1)
_ngconf = $( echo " $ng_entry " | cut -d " $sep " -f 2)
_ngbackupconf = $( echo " $ng_entry " | cut -d " $sep " -f 3)
_info " Restoring from $_ngbackupconf to $_ngconf "
2017-02-14 22:41:34 +08:00
cat " $_ngbackupconf " >" $_ngconf "
2017-02-13 23:29:37 +08:00
done
_info "Reload nginx"
if ! _exec "nginx -s reload" >/dev/null; then
_exec_err
_err "It seems that nginx reload error, please report bug."
return 1
fi
return 0
}
2016-04-16 18:31:00 +08:00
_clearup( ) {
2016-11-09 22:35:30 +08:00
_stopserver " $serverproc "
2016-03-08 20:44:12 +08:00
serverproc = ""
_restoreApache
2017-02-13 23:29:37 +08:00
_restoreNginx
2016-10-25 23:02:49 +08:00
_clearupdns
2016-11-09 19:30:39 +08:00
if [ -z " $DEBUG " ] ; then
2016-06-17 13:23:44 +08:00
rm -f " $TLS_CONF "
rm -f " $TLS_CERT "
rm -f " $TLS_KEY "
rm -f " $TLS_CSR "
fi
2016-03-08 20:44:12 +08:00
}
2016-10-25 23:02:49 +08:00
_clearupdns( ) {
_debug "_clearupdns"
2016-11-09 19:30:39 +08:00
if [ " $dnsadded " != 1 ] || [ -z " $vlist " ] ; then
2017-06-15 21:26:14 +08:00
_debug "skip dns."
2016-10-25 23:02:49 +08:00
return
fi
2016-11-09 19:30:39 +08:00
ventries = $( echo " $vlist " | tr ',' ' ' )
for ventry in $ventries ; do
2016-11-09 22:07:32 +08:00
d = $( echo " $ventry " | cut -d " $sep " -f 1)
keyauthorization = $( echo " $ventry " | cut -d " $sep " -f 2)
vtype = $( echo " $ventry " | cut -d " $sep " -f 4)
_currentRoot = $( echo " $ventry " | cut -d " $sep " -f 5)
2017-01-29 11:47:04 +08:00
txt = " $( printf "%s" " $keyauthorization " | _digest "sha256" | _url_replace) "
2016-12-06 14:58:36 +08:00
_debug txt " $txt "
2016-11-09 19:30:39 +08:00
if [ " $keyauthorization " = " $STATE_VERIFIED " ] ; then
2017-02-15 20:24:24 +08:00
_debug " $d is already verified, skip $vtype . "
2016-10-25 23:02:49 +08:00
continue
fi
2016-11-09 19:30:39 +08:00
if [ " $vtype " != " $VTYPE_DNS " ] ; then
2016-10-25 23:02:49 +08:00
_info " Skip $d for $vtype "
continue
fi
2016-11-09 19:30:39 +08:00
2016-11-09 22:07:32 +08:00
d_api = " $( _findHook " $d " dnsapi " $_currentRoot " ) "
2016-10-25 23:02:49 +08:00
_debug d_api " $d_api "
2016-11-09 19:30:39 +08:00
if [ -z " $d_api " ] ; then
2016-10-25 23:02:49 +08:00
_info " Not Found domain api file: $d_api "
continue
fi
2016-11-09 19:30:39 +08:00
2016-10-25 23:02:49 +08:00
(
2016-11-09 21:44:46 +08:00
if ! . " $d_api " ; then
2016-10-25 23:02:49 +08:00
_err " Load file $d_api error. Please check your api file and try again. "
return 1
fi
2016-11-09 19:30:39 +08:00
2016-10-25 23:02:49 +08:00
rmcommand = " ${ _currentRoot } _rm "
2016-11-09 21:44:46 +08:00
if ! _exists " $rmcommand " ; then
2016-10-25 23:02:49 +08:00
_err " It seems that your api file doesn't define $rmcommand "
return 1
fi
2016-11-09 19:30:39 +08:00
2018-01-06 17:39:15 +08:00
_dns_root_d = " $d "
if _startswith " $_dns_root_d " "*." ; then
_dns_root_d = " $( echo " $_dns_root_d " | sed 's/*.//' ) "
fi
txtdomain = " _acme-challenge. $_dns_root_d "
2016-11-09 19:30:39 +08:00
2016-12-06 14:58:36 +08:00
if ! $rmcommand " $txtdomain " " $txt " ; then
2016-10-25 23:02:49 +08:00
_err " Error removing txt for domain: $txtdomain "
return 1
fi
)
2016-11-09 19:30:39 +08:00
2016-10-25 23:02:49 +08:00
done
}
2016-03-08 20:44:12 +08:00
# webroot removelevel tokenfile
_clearupwebbroot( ) {
__webroot = " $1 "
2016-11-09 19:30:39 +08:00
if [ -z " $__webroot " ] ; then
2016-03-08 20:44:12 +08:00
_debug "no webroot specified, skip"
return 0
fi
2016-11-09 19:30:39 +08:00
2016-07-15 16:40:03 +08:00
_rmpath = ""
2016-11-09 19:30:39 +08:00
if [ " $2 " = '1' ] ; then
2016-07-15 16:40:03 +08:00
_rmpath = " $__webroot /.well-known "
2016-11-09 19:30:39 +08:00
elif [ " $2 " = '2' ] ; then
2016-07-15 16:40:03 +08:00
_rmpath = " $__webroot /.well-known/acme-challenge "
2016-11-09 19:30:39 +08:00
elif [ " $2 " = '3' ] ; then
2016-07-15 16:40:03 +08:00
_rmpath = " $__webroot /.well-known/acme-challenge/ $3 "
2016-03-08 20:44:12 +08:00
else
2016-06-18 11:29:28 +08:00
_debug " Skip for removelevel: $2 "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $_rmpath " ] ; then
if [ " $DEBUG " ] ; then
2016-07-15 16:40:03 +08:00
_debug " Debugging, skip removing: $_rmpath "
else
rm -rf " $_rmpath "
fi
fi
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
return 0
}
2016-09-06 23:26:22 +08:00
_on_before_issue( ) {
2017-02-19 21:13:00 +08:00
_chk_web_roots = " $1 "
2017-02-19 21:18:00 +08:00
_chk_main_domain = " $2 "
_chk_alt_domains = " $3 "
2017-02-19 22:09:22 +08:00
_chk_pre_hook = " $4 "
_chk_local_addr = " $5 "
2016-09-26 13:33:09 +08:00
_debug _on_before_issue
2017-01-03 19:31:11 +08:00
#run pre hook
2017-02-19 22:09:22 +08:00
if [ " $_chk_pre_hook " ] ; then
_info " Run pre hook:' $_chk_pre_hook ' "
2017-01-03 19:31:11 +08:00
if ! (
2017-02-19 22:09:22 +08:00
cd " $DOMAIN_PATH " && eval " $_chk_pre_hook "
2017-01-03 19:31:11 +08:00
) ; then
_err "Error when run pre hook."
return 1
fi
fi
2017-02-19 21:13:00 +08:00
if _hasfield " $_chk_web_roots " " $NO_VALUE " ; then
2017-09-01 23:01:37 +08:00
if ! _exists "socat" ; then
_err "Please install socat tools first."
2016-09-23 23:14:03 +08:00
return 1
fi
fi
2017-02-19 22:09:22 +08:00
_debug Le_LocalAddress " $_chk_local_addr "
2016-11-09 19:30:39 +08:00
2017-02-19 21:18:00 +08:00
alldomains = $( echo " $_chk_main_domain , $_chk_alt_domains " | tr ',' ' ' )
2016-09-23 23:14:03 +08:00
_index = 1
_currentRoot = ""
_addrIndex = 1
2016-11-09 19:30:39 +08:00
for d in $alldomains ; do
2016-11-09 21:44:46 +08:00
_debug "Check for domain" " $d "
2017-02-19 21:13:00 +08:00
_currentRoot = " $( _getfield " $_chk_web_roots " $_index ) "
2016-09-23 23:14:03 +08:00
_debug "_currentRoot" " $_currentRoot "
_index = $( _math $_index + 1)
_checkport = ""
2016-11-09 19:30:39 +08:00
if [ " $_currentRoot " = " $NO_VALUE " ] ; then
2016-09-23 23:14:03 +08:00
_info "Standalone mode."
2016-11-09 19:30:39 +08:00
if [ -z " $Le_HTTPPort " ] ; then
2016-09-23 23:14:03 +08:00
Le_HTTPPort = 80
else
2016-11-09 19:30:39 +08:00
_savedomainconf "Le_HTTPPort" " $Le_HTTPPort "
2016-09-23 23:14:03 +08:00
fi
_checkport = " $Le_HTTPPort "
2016-11-09 19:30:39 +08:00
elif [ " $_currentRoot " = " $W_TLS " ] ; then
2016-09-23 23:14:03 +08:00
_info "Standalone tls mode."
2016-11-09 19:30:39 +08:00
if [ -z " $Le_TLSPort " ] ; then
2016-09-23 23:14:03 +08:00
Le_TLSPort = 443
else
2016-11-09 19:30:39 +08:00
_savedomainconf "Le_TLSPort" " $Le_TLSPort "
2016-09-23 23:14:03 +08:00
fi
_checkport = " $Le_TLSPort "
fi
2016-11-09 19:30:39 +08:00
if [ " $_checkport " ] ; then
2016-09-23 23:14:03 +08:00
_debug _checkport " $_checkport "
2017-02-19 22:09:22 +08:00
_checkaddr = " $( _getfield " $_chk_local_addr " $_addrIndex ) "
2016-09-23 23:14:03 +08:00
_debug _checkaddr " $_checkaddr "
2016-11-09 19:30:39 +08:00
2016-09-23 23:14:03 +08:00
_addrIndex = " $( _math $_addrIndex + 1) "
2016-11-09 19:30:39 +08:00
2016-09-23 23:14:03 +08:00
_netprc = " $( _ss " $_checkport " | grep " $_checkport " ) "
netprc = " $( echo " $_netprc " | grep " $_checkaddr " ) "
2016-11-09 19:30:39 +08:00
if [ -z " $netprc " ] ; then
2016-09-23 23:14:03 +08:00
netprc = " $( echo " $_netprc " | grep " $LOCAL_ANY_ADDRESS " ) "
fi
2016-11-09 19:30:39 +08:00
if [ " $netprc " ] ; then
2016-09-23 23:14:03 +08:00
_err " $netprc "
2016-11-09 19:30:39 +08:00
_err " tcp port $_checkport is already used by $( echo " $netprc " | cut -d : -f 4) "
2016-09-23 23:14:03 +08:00
_err "Please stop it first"
return 1
fi
fi
done
2017-02-19 21:13:00 +08:00
if _hasfield " $_chk_web_roots " "apache" ; then
2016-11-09 19:30:39 +08:00
if ! _setApache; then
2016-09-23 23:14:03 +08:00
_err "set up apache error. Report error to me."
return 1
fi
else
usingApache = ""
fi
2016-09-06 23:26:22 +08:00
}
_on_issue_err( ) {
2017-02-19 22:09:22 +08:00
_chk_post_hook = " $1 "
2017-02-26 12:07:06 +08:00
_chk_vlist = " $2 "
2016-09-26 13:33:09 +08:00
_debug _on_issue_err
2018-01-06 21:50:57 +08:00
2016-11-09 19:30:39 +08:00
if [ " $LOG_FILE " ] ; then
2016-09-25 21:58:59 +08:00
_err " Please check log file for more details: $LOG_FILE "
else
2016-11-16 19:45:00 +08:00
_err "Please add '--debug' or '--log' to check more details."
2016-09-25 21:58:59 +08:00
_err " See: $_DEBUG_WIKI "
fi
2016-11-09 19:30:39 +08:00
2016-09-06 23:26:22 +08:00
#run the post hook
2017-02-19 22:09:22 +08:00
if [ " $_chk_post_hook " ] ; then
_info " Run post hook:' $_chk_post_hook ' "
2016-09-06 23:26:22 +08:00
if ! (
2017-02-19 22:09:22 +08:00
cd " $DOMAIN_PATH " && eval " $_chk_post_hook "
2016-11-09 19:30:39 +08:00
) ; then
2016-09-06 23:26:22 +08:00
_err "Error when run post hook."
return 1
fi
fi
2017-02-26 12:07:06 +08:00
#trigger the validation to flush the pending authz
2017-07-01 20:31:42 +08:00
_debug2 "_chk_vlist" " $_chk_vlist "
2017-02-26 12:07:06 +08:00
if [ " $_chk_vlist " ] ; then
(
2017-02-26 12:15:39 +08:00
_debug2 "start to deactivate authz"
ventries = $( echo " $_chk_vlist " | tr " $dvsep " ' ' )
for ventry in $ventries ; do
d = $( echo " $ventry " | cut -d " $sep " -f 1)
keyauthorization = $( echo " $ventry " | cut -d " $sep " -f 2)
uri = $( echo " $ventry " | cut -d " $sep " -f 3)
vtype = $( echo " $ventry " | cut -d " $sep " -f 4)
_currentRoot = $( echo " $ventry " | cut -d " $sep " -f 5)
2017-03-26 05:32:29 +00:00
__trigger_validation " $uri " " $keyauthorization "
2017-02-26 12:15:39 +08:00
done
2017-02-26 12:07:06 +08:00
)
fi
2017-08-22 20:27:13 +08:00
if [ " $IS_RENEW " = "1" ] && _hasfield " $Le_Webroot " "dns" ; then
_err " $_DNS_MANUAL_ERR "
fi
2017-02-26 12:07:06 +08:00
if [ " $DEBUG " ] && [ " $DEBUG " -gt "0" ] ; then
_debug " $( _dlg_versions) "
fi
2016-09-06 23:26:22 +08:00
}
_on_issue_success( ) {
2017-02-19 22:09:22 +08:00
_chk_post_hook = " $1 "
_chk_renew_hook = " $2 "
2016-09-26 13:33:09 +08:00
_debug _on_issue_success
2016-09-06 23:26:22 +08:00
#run the post hook
2017-02-19 22:09:22 +08:00
if [ " $_chk_post_hook " ] ; then
_info " Run post hook:' $_chk_post_hook ' "
2016-09-06 23:26:22 +08:00
if ! (
2017-02-19 22:09:22 +08:00
cd " $DOMAIN_PATH " && eval " $_chk_post_hook "
2016-11-09 19:30:39 +08:00
) ; then
2016-09-06 23:26:22 +08:00
_err "Error when run post hook."
return 1
fi
fi
2016-11-09 19:30:39 +08:00
2016-09-06 23:26:22 +08:00
#run renew hook
2017-02-19 22:09:22 +08:00
if [ " $IS_RENEW " ] && [ " $_chk_renew_hook " ] ; then
_info " Run renew hook:' $_chk_renew_hook ' "
2016-09-06 23:26:22 +08:00
if ! (
2017-02-19 22:09:22 +08:00
cd " $DOMAIN_PATH " && eval " $_chk_renew_hook "
2016-11-09 19:30:39 +08:00
) ; then
2016-09-06 23:26:22 +08:00
_err "Error when run renew hook."
return 1
fi
2016-11-09 19:30:39 +08:00
fi
2017-08-22 20:27:13 +08:00
if _hasfield " $Le_Webroot " "dns" ; then
_err " $_DNS_MANUAL_WARN "
fi
2016-09-06 23:26:22 +08:00
}
2016-09-25 10:56:06 +08:00
updateaccount( ) {
_initpath
_regAccount
}
2016-09-06 23:26:22 +08:00
2016-09-25 10:56:06 +08:00
registeraccount( ) {
2016-11-06 23:08:45 +08:00
_reg_length = " $1 "
2016-09-25 10:56:06 +08:00
_initpath
2016-11-06 23:08:45 +08:00
_regAccount " $_reg_length "
2016-09-25 10:56:06 +08:00
}
2016-09-24 23:53:53 +08:00
2016-10-28 22:45:19 +08:00
__calcAccountKeyHash( ) {
2016-11-09 21:56:50 +08:00
[ -f " $ACCOUNT_KEY_PATH " ] && _digest sha256 <" $ACCOUNT_KEY_PATH "
2016-10-28 22:45:19 +08:00
}
2017-02-06 19:53:12 +08:00
__calc_account_thumbprint( ) {
printf "%s" " $jwk " | tr -d ' ' | _digest "sha256" | _url_replace
}
2016-11-06 23:08:45 +08:00
#keylength
2016-09-24 23:53:53 +08:00
_regAccount( ) {
_initpath
2016-11-06 23:08:45 +08:00
_reg_length = " $1 "
2017-12-07 21:32:17 +08:00
_debug3 _regAccount " $_regAccount "
2018-01-06 12:45:24 +08:00
_initAPI
2017-07-02 18:24:55 +08:00
mkdir -p " $CA_DIR "
2016-09-27 23:43:18 +08:00
if [ ! -f " $ACCOUNT_KEY_PATH " ] && [ -f " $_OLD_ACCOUNT_KEY " ] ; then
_info " mv $_OLD_ACCOUNT_KEY to $ACCOUNT_KEY_PATH "
mv " $_OLD_ACCOUNT_KEY " " $ACCOUNT_KEY_PATH "
fi
2016-11-09 19:30:39 +08:00
2016-09-27 23:43:18 +08:00
if [ ! -f " $ACCOUNT_JSON_PATH " ] && [ -f " $_OLD_ACCOUNT_JSON " ] ; then
_info " mv $_OLD_ACCOUNT_JSON to $ACCOUNT_JSON_PATH "
mv " $_OLD_ACCOUNT_JSON " " $ACCOUNT_JSON_PATH "
fi
2016-11-09 19:30:39 +08:00
if [ ! -f " $ACCOUNT_KEY_PATH " ] ; then
if ! _create_account_key " $_reg_length " ; then
2016-09-24 23:53:53 +08:00
_err "Create account key error."
return 1
fi
fi
2016-11-09 19:30:39 +08:00
if ! _calcjwk " $ACCOUNT_KEY_PATH " ; then
2016-09-24 23:53:53 +08:00
return 1
fi
2018-01-06 13:57:35 +08:00
2018-01-06 12:45:24 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
regjson = '{"termsOfServiceAgreed": true}'
if [ " $ACCOUNT_EMAIL " ] ; then
regjson = '{"contact": ["mailto: ' $ACCOUNT_EMAIL '"], "termsOfServiceAgreed": true}'
fi
else
_reg_res = " $ACME_NEW_ACCOUNT_RES "
regjson = '{"resource": "' $_reg_res '", "terms-of-service-agreed": true, "agreement": "' $ACME_AGREEMENT '"}'
if [ " $ACCOUNT_EMAIL " ] ; then
regjson = '{"resource": "' $_reg_res '", "contact": ["mailto: ' $ACCOUNT_EMAIL '"], "terms-of-service-agreed": true, "agreement": "' $ACME_AGREEMENT '"}'
fi
2017-12-07 21:32:17 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-12-08 19:49:18 +08:00
_info "Registering account"
2016-09-24 23:53:53 +08:00
2017-12-07 21:32:17 +08:00
if ! _send_signed_request " ${ ACME_NEW_ACCOUNT } " " $regjson " ; then
_err " Register account Error: $response "
return 1
fi
2016-09-24 23:53:53 +08:00
2017-12-07 21:32:17 +08:00
if [ " $code " = "" ] || [ " $code " = '201' ] ; then
echo " $response " >" $ACCOUNT_JSON_PATH "
_info "Registered"
2018-02-05 16:37:57 -05:00
elif [ " $code " = '409' ] || [ " $code " = '200' ] ; then
2017-12-07 21:32:17 +08:00
_info "Already registered"
else
_err " Register account Error: $response "
return 1
fi
2016-09-24 23:53:53 +08:00
2017-12-07 21:32:17 +08:00
_accUri = " $( echo " $responseHeaders " | grep "^Location:" | _head_n 1 | cut -d ' ' -f 2 | tr -d "\r\n" ) "
_debug "_accUri" " $_accUri "
_savecaconf "ACCOUNT_URL" " $_accUri "
2018-01-06 12:45:24 +08:00
export ACCOUNT_URL = " $ACCOUNT_URL "
2016-09-24 23:53:53 +08:00
2017-12-07 21:32:17 +08:00
CA_KEY_HASH = " $( __calcAccountKeyHash) "
_debug "Calc CA_KEY_HASH" " $CA_KEY_HASH "
_savecaconf CA_KEY_HASH " $CA_KEY_HASH "
2016-09-24 23:53:53 +08:00
2017-12-07 21:32:17 +08:00
if [ " $code " = '403' ] ; then
_err "It seems that the account key is already deactivated, please use a new account key."
return 1
fi
2016-11-09 19:30:39 +08:00
2017-12-07 21:32:17 +08:00
ACCOUNT_THUMBPRINT = " $( __calc_account_thumbprint) "
_info "ACCOUNT_THUMBPRINT" " $ACCOUNT_THUMBPRINT "
2016-09-24 23:53:53 +08:00
}
2017-07-02 17:02:54 +08:00
#Implement deactivate account
deactivateaccount( ) {
_initpath
if [ ! -f " $ACCOUNT_KEY_PATH " ] && [ -f " $_OLD_ACCOUNT_KEY " ] ; then
_info " mv $_OLD_ACCOUNT_KEY to $ACCOUNT_KEY_PATH "
mv " $_OLD_ACCOUNT_KEY " " $ACCOUNT_KEY_PATH "
fi
if [ ! -f " $ACCOUNT_JSON_PATH " ] && [ -f " $_OLD_ACCOUNT_JSON " ] ; then
_info " mv $_OLD_ACCOUNT_JSON to $ACCOUNT_JSON_PATH "
mv " $_OLD_ACCOUNT_JSON " " $ACCOUNT_JSON_PATH "
fi
if [ ! -f " $ACCOUNT_KEY_PATH " ] ; then
_err " Account key is not found at: $ACCOUNT_KEY_PATH "
return 1
fi
_accUri = $( _readcaconf "ACCOUNT_URL" )
_debug _accUri " $_accUri "
if [ -z " $_accUri " ] ; then
_err "The account url is empty, please run '--update-account' first to update the account info first,"
_err "Then try again."
return 1
fi
if ! _calcjwk " $ACCOUNT_KEY_PATH " ; then
return 1
fi
_initAPI
2018-01-06 21:33:27 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
_djson = "{\"status\":\"deactivated\"}"
else
_djson = "{\"resource\": \"reg\", \"status\":\"deactivated\"}"
fi
if _send_signed_request " $_accUri " " $_djson " && _contains " $response " '"deactivated"' ; then
2017-07-02 17:02:54 +08:00
_info " Deactivate account success for $_accUri . "
_accid = $( echo " $response " | _egrep_o "\"id\" *: *[^,]*," | cut -d : -f 2 | tr -d ' ,' )
elif [ " $code " = "403" ] ; then
_info "The account is already deactivated."
_accid = $( _getfield " $_accUri " "999" "/" )
else
_err " Deactivate: account failed for $_accUri . "
return 1
fi
_debug " Account id: $_accid "
if [ " $_accid " ] ; then
_deactivated_account_path = " $CA_DIR /deactivated/ $_accid "
_debug _deactivated_account_path " $_deactivated_account_path "
if mkdir -p " $_deactivated_account_path " ; then
_info " Moving deactivated account info to $_deactivated_account_path / "
mv " $CA_CONF " " $_deactivated_account_path / "
mv " $ACCOUNT_JSON_PATH " " $_deactivated_account_path / "
mv " $ACCOUNT_KEY_PATH " " $_deactivated_account_path / "
else
_err " Can not create dir: $_deactivated_account_path , try to remove the deactivated account key. "
rm -f " $CA_CONF "
rm -f " $ACCOUNT_JSON_PATH "
rm -f " $ACCOUNT_KEY_PATH "
fi
fi
}
2016-10-11 20:56:59 +08:00
# domain folder file
_findHook( ) {
_hookdomain = " $1 "
_hookcat = " $2 "
_hookname = " $3 "
2016-11-11 23:30:14 +08:00
if [ -f " $_SCRIPT_HOME / $_hookcat / $_hookname " ] ; then
d_api = " $_SCRIPT_HOME / $_hookcat / $_hookname "
elif [ -f " $_SCRIPT_HOME / $_hookcat / $_hookname .sh " ] ; then
d_api = " $_SCRIPT_HOME / $_hookcat / $_hookname .sh "
2016-11-09 19:30:39 +08:00
elif [ -f " $LE_WORKING_DIR / $_hookdomain / $_hookname " ] ; then
2016-10-11 20:56:59 +08:00
d_api = " $LE_WORKING_DIR / $_hookdomain / $_hookname "
2016-11-09 19:30:39 +08:00
elif [ -f " $LE_WORKING_DIR / $_hookdomain / $_hookname .sh " ] ; then
2016-10-11 20:56:59 +08:00
d_api = " $LE_WORKING_DIR / $_hookdomain / $_hookname .sh "
2016-11-09 19:30:39 +08:00
elif [ -f " $LE_WORKING_DIR / $_hookname " ] ; then
2016-10-11 20:56:59 +08:00
d_api = " $LE_WORKING_DIR / $_hookname "
2016-11-09 19:30:39 +08:00
elif [ -f " $LE_WORKING_DIR / $_hookname .sh " ] ; then
2016-10-11 20:56:59 +08:00
d_api = " $LE_WORKING_DIR / $_hookname .sh "
2016-11-09 19:30:39 +08:00
elif [ -f " $LE_WORKING_DIR / $_hookcat / $_hookname " ] ; then
2016-10-11 20:56:59 +08:00
d_api = " $LE_WORKING_DIR / $_hookcat / $_hookname "
2016-11-09 19:30:39 +08:00
elif [ -f " $LE_WORKING_DIR / $_hookcat / $_hookname .sh " ] ; then
2016-10-11 20:56:59 +08:00
d_api = " $LE_WORKING_DIR / $_hookcat / $_hookname .sh "
fi
printf "%s" " $d_api "
}
2016-10-27 22:10:58 +08:00
#domain
__get_domain_new_authz( ) {
_gdnd = " $1 "
_info "Getting new-authz for domain" " $_gdnd "
2017-06-17 16:20:32 +08:00
_initAPI
2016-10-27 22:10:58 +08:00
_Max_new_authz_retry_times = 5
_authz_i = 0
2016-11-09 19:30:39 +08:00
while [ " $_authz_i " -lt " $_Max_new_authz_retry_times " ] ; do
2016-11-11 23:52:02 +08:00
_debug " Try new-authz for the $_authz_i time. "
2017-06-17 15:49:45 +08:00
if ! _send_signed_request " ${ ACME_NEW_AUTHZ } " " {\"resource\": \"new-authz\", \"identifier\": {\"type\": \"dns\", \"value\": \" $( _idn " $_gdnd " ) \"}} " ; then
2016-10-27 22:10:58 +08:00
_err "Can not get domain new authz."
return 1
fi
2017-01-10 10:36:47 +08:00
if _contains " $response " "No registration exists matching provided key" ; then
_err "It seems there is an error, but it's recovered now, please try again."
_err " If you see this message for a second time, please report bug: $( __green " $PROJECT " ) "
_clearcaconf "CA_KEY_HASH"
break
fi
2016-11-09 19:30:39 +08:00
if ! _contains " $response " "An error occurred while processing your request" ; then
2016-10-27 22:10:58 +08:00
_info "The new-authz request is ok."
break
fi
_authz_i = " $( _math " $_authz_i " + 1) "
2016-10-27 22:47:19 +08:00
_info " The server is busy, Sleep $_authz_i to retry. "
2016-10-27 22:10:58 +08:00
_sleep " $_authz_i "
2016-11-09 19:30:39 +08:00
done
2016-10-27 22:10:58 +08:00
2016-11-09 19:30:39 +08:00
if [ " $_authz_i " = " $_Max_new_authz_retry_times " ] ; then
2016-11-11 23:52:02 +08:00
_err " new-authz retry reach the max $_Max_new_authz_retry_times times. "
2016-10-27 22:10:58 +08:00
fi
2016-11-09 19:30:39 +08:00
2018-02-07 23:49:08 +08:00
if [ " $code " ] && [ " $code " != '201' ] ; then
2016-10-27 22:10:58 +08:00
_err " new-authz error: $response "
return 1
fi
}
2017-02-26 12:07:06 +08:00
#uri keyAuthorization
2017-03-26 05:32:29 +00:00
__trigger_validation( ) {
2017-02-26 12:07:06 +08:00
_debug2 "tigger domain validation."
_t_url = " $1 "
_debug2 _t_url " $_t_url "
_t_key_authz = " $2 "
_debug2 _t_key_authz " $_t_key_authz "
2018-01-06 12:45:24 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
_send_signed_request " $_t_url " " {\"keyAuthorization\": \" $_t_key_authz \"} "
else
_send_signed_request " $_t_url " " {\"resource\": \"challenge\", \"keyAuthorization\": \" $_t_key_authz \"} "
fi
2017-02-26 12:07:06 +08:00
}
2017-04-17 19:08:34 +08:00
#webroot, domain domainlist keylength
2016-03-08 20:44:12 +08:00
issue( ) {
2016-11-09 19:30:39 +08:00
if [ -z " $2 " ] ; then
2016-08-13 19:22:25 +08:00
_usage " Usage: $PROJECT_ENTRY --issue -d a.com -w /path/to/webroot/a.com/ "
2016-03-08 20:44:12 +08:00
return 1
fi
2017-04-05 20:46:17 +08:00
if [ -z " $1 " ] ; then
_usage "Please specify at least one validation method: '--webroot', '--standalone', '--apache', '--nginx' or '--dns' etc."
return 1
fi
2017-02-19 21:13:00 +08:00
_web_roots = " $1 "
_main_domain = " $2 "
2017-02-19 21:18:00 +08:00
_alt_domains = " $3 "
2018-01-06 21:33:27 +08:00
2017-02-19 21:13:00 +08:00
if _contains " $_main_domain " "," ; then
_main_domain = $( echo " $2 , $3 " | cut -d , -f 1)
2017-02-19 21:18:00 +08:00
_alt_domains = $( echo " $2 , $3 " | cut -d , -f 2- | sed " s/, ${ NO_VALUE } $// " )
2017-01-17 20:13:15 +08:00
fi
2017-02-19 21:21:11 +08:00
_key_length = " $4 "
2017-02-19 22:09:22 +08:00
_real_cert = " $5 "
_real_key = " $6 "
_real_ca = " $7 "
_reload_cmd = " $8 "
_real_fullchain = " $9 "
_pre_hook = " ${ 10 } "
_post_hook = " ${ 11 } "
_renew_hook = " ${ 12 } "
_local_addr = " ${ 13 } "
2016-11-09 19:30:39 +08:00
2016-04-16 22:19:29 +08:00
#remove these later.
2017-02-19 21:13:00 +08:00
if [ " $_web_roots " = "dns-cf" ] ; then
_web_roots = "dns_cf"
2016-04-16 22:19:29 +08:00
fi
2017-02-19 21:13:00 +08:00
if [ " $_web_roots " = "dns-dp" ] ; then
_web_roots = "dns_dp"
2016-04-16 22:19:29 +08:00
fi
2017-02-19 21:13:00 +08:00
if [ " $_web_roots " = "dns-cx" ] ; then
_web_roots = "dns_cx"
2016-04-16 22:19:29 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ ! " $IS_RENEW " ] ; then
2017-02-19 21:21:11 +08:00
_initpath " $_main_domain " " $_key_length "
2016-08-13 19:22:25 +08:00
mkdir -p " $DOMAIN_PATH "
fi
2016-04-16 22:19:29 +08:00
2017-06-17 15:49:45 +08:00
_debug " Using ACME_DIRECTORY: $ACME_DIRECTORY "
_initAPI
2016-11-09 19:30:39 +08:00
if [ -f " $DOMAIN_CONF " ] ; then
2016-07-02 13:03:59 +08:00
Le_NextRenewTime = $( _readdomainconf Le_NextRenewTime)
2016-05-07 23:33:42 +08:00
_debug Le_NextRenewTime " $Le_NextRenewTime "
2016-11-09 20:45:57 +08:00
if [ -z " $FORCE " ] && [ " $Le_NextRenewTime " ] && [ " $( _time) " -lt " $Le_NextRenewTime " ] ; then
2016-10-05 22:09:15 +08:00
_saved_domain = $( _readdomainconf Le_Domain)
_debug _saved_domain " $_saved_domain "
_saved_alt = $( _readdomainconf Le_Alt)
_debug _saved_alt " $_saved_alt "
2017-02-19 21:18:00 +08:00
if [ " $_saved_domain , $_saved_alt " = " $_main_domain , $_alt_domains " ] ; then
2016-10-05 22:09:15 +08:00
_info "Domains not changed."
_info " Skip, Next renewal time is: $( __green " $( _readdomainconf Le_NextRenewTimeStr) " ) "
2016-11-09 19:30:39 +08:00
_info " Add ' $( __red '--force' ) ' to force to renew. "
2016-10-05 22:09:15 +08:00
return $RENEW_SKIP
else
_info "Domains have changed."
fi
2016-03-08 20:44:12 +08:00
fi
fi
2016-04-02 10:10:05 +08:00
2017-02-19 21:13:00 +08:00
_savedomainconf "Le_Domain" " $_main_domain "
2017-02-19 21:18:00 +08:00
_savedomainconf "Le_Alt" " $_alt_domains "
2017-02-19 21:13:00 +08:00
_savedomainconf "Le_Webroot" " $_web_roots "
2016-11-09 19:30:39 +08:00
2017-02-19 22:09:22 +08:00
_savedomainconf "Le_PreHook" " $_pre_hook "
_savedomainconf "Le_PostHook" " $_post_hook "
_savedomainconf "Le_RenewHook" " $_renew_hook "
2016-11-09 19:30:39 +08:00
2017-02-19 22:09:22 +08:00
if [ " $_local_addr " ] ; then
_savedomainconf "Le_LocalAddress" " $_local_addr "
2016-10-29 17:43:38 +08:00
else
_cleardomainconf "Le_LocalAddress"
fi
2016-10-02 23:37:37 +08:00
2017-06-17 15:49:45 +08:00
Le_API = " $ACME_DIRECTORY "
2016-09-28 13:07:51 +08:00
_savedomainconf "Le_API" " $Le_API "
2016-11-09 19:30:39 +08:00
2017-02-19 21:18:00 +08:00
if [ " $_alt_domains " = " $NO_VALUE " ] ; then
_alt_domains = ""
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-02-19 21:21:11 +08:00
if [ " $_key_length " = " $NO_VALUE " ] ; then
_key_length = ""
2016-09-24 23:53:53 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-02-19 22:09:22 +08:00
if ! _on_before_issue " $_web_roots " " $_main_domain " " $_alt_domains " " $_pre_hook " " $_local_addr " ; then
2016-09-23 23:14:03 +08:00
_err "_on_before_issue."
return 1
2016-03-08 20:44:12 +08:00
fi
2016-09-23 23:14:03 +08:00
2016-10-28 22:45:19 +08:00
_saved_account_key_hash = " $( _readcaconf "CA_KEY_HASH" ) "
_debug2 _saved_account_key_hash " $_saved_account_key_hash "
2016-11-09 19:30:39 +08:00
if [ -z " $_saved_account_key_hash " ] || [ " $_saved_account_key_hash " != " $( __calcAccountKeyHash) " ] ; then
2016-11-06 23:08:45 +08:00
if ! _regAccount " $_accountkeylength " ; then
2017-02-19 22:09:22 +08:00
_on_issue_err " $_post_hook "
2016-10-28 22:45:19 +08:00
return 1
fi
2016-11-06 23:08:45 +08:00
else
_debug "_saved_account_key_hash is not changed, skip register account."
2016-03-15 21:27:47 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -f " $CSR_PATH " ] && [ ! -f " $CERT_KEY_PATH " ] ; then
2016-08-27 13:52:13 +08:00
_info "Signing from existing CSR."
else
_key = $( _readdomainconf Le_Keylength)
_debug " Read key length: $_key "
2017-07-02 15:25:35 +08:00
if [ ! -f " $CERT_KEY_PATH " ] || [ " $_key_length " != " $_key " ] || [ " $Le_ForceNewDomainKey " = "1" ] ; then
2017-02-19 21:21:11 +08:00
if ! createDomainKey " $_main_domain " " $_key_length " ; then
2016-08-27 13:52:13 +08:00
_err "Create domain key error."
_clearup
2017-02-19 22:09:22 +08:00
_on_issue_err " $_post_hook "
2016-08-27 13:52:13 +08:00
return 1
fi
fi
2017-02-19 21:18:00 +08:00
if ! _createcsr " $_main_domain " " $_alt_domains " " $CERT_KEY_PATH " " $CSR_PATH " " $DOMAIN_SSL_CONF " ; then
2016-08-27 13:52:13 +08:00
_err "Create CSR error."
2016-04-16 18:31:00 +08:00
_clearup
2017-02-19 22:09:22 +08:00
_on_issue_err " $_post_hook "
2016-04-15 21:27:32 +08:00
return 1
fi
2016-03-08 20:44:12 +08:00
fi
2016-08-27 13:52:13 +08:00
2017-02-19 21:21:11 +08:00
_savedomainconf "Le_Keylength" " $_key_length "
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
vlist = " $Le_Vlist "
2016-10-28 23:30:32 +08:00
_info "Getting domain auth token for each domain"
2016-03-08 20:44:12 +08:00
sep = '#'
2017-02-13 23:29:37 +08:00
dvsep = ','
2016-11-09 19:30:39 +08:00
if [ -z " $vlist " ] ; then
2018-01-06 21:33:27 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
2018-01-06 12:45:24 +08:00
#make new order request
_identifiers = " {\"type\":\"dns\",\"value\":\" $_main_domain \"} "
for d in $( echo " $_alt_domains " | tr ',' ' ' ) ; do
if [ " $d " ] ; then
_identifiers = " $_identifiers ,{\"type\":\"dns\",\"value\":\" $d \"} "
fi
done
_debug2 _identifiers " $_identifiers "
if ! _send_signed_request " $ACME_NEW_ORDER " " {\"identifiers\": [ $_identifiers ]} " ; then
_err "Create new order error."
_clearup
_on_issue_err " $_post_hook "
return 1
fi
2018-01-06 21:33:27 +08:00
Le_OrderFinalize = " $( echo " $response " | tr -d '\r\n' | _egrep_o '"finalize" *: *"[^"]*"' | cut -d '"' -f 4) "
_debug Le_OrderFinalize " $Le_OrderFinalize "
if [ -z " $Le_OrderFinalize " ] ; then
2018-02-07 23:49:08 +08:00
_err " Create new order error. Le_OrderFinalize not found. $response "
2018-01-06 12:45:24 +08:00
_clearup
_on_issue_err " $_post_hook "
return 1
fi
#for dns manual mode
2018-01-06 21:33:27 +08:00
_savedomainconf "Le_OrderFinalize" " $Le_OrderFinalize "
2018-01-06 12:45:24 +08:00
2018-01-06 13:57:35 +08:00
_authorizations_seg = " $( echo " $response " | tr -d '\r\n' | _egrep_o '"authorizations" *: *\[[^\]*\]' | cut -d '[' -f 2 | tr -d ']' | tr -d '"' ) "
2018-01-06 12:45:24 +08:00
_debug2 _authorizations_seg " $_authorizations_seg "
if [ -z " $_authorizations_seg " ] ; then
_err "_authorizations_seg not found."
_clearup
_on_issue_err " $_post_hook "
return 1
fi
#domain and authz map
_authorizations_map = ""
2018-01-06 13:57:35 +08:00
for _authz_url in $( echo " $_authorizations_seg " | tr ',' ' ' ) ; do
2018-01-06 12:45:24 +08:00
_debug2 "_authz_url" " $_authz_url "
if ! response = " $( _get " $_authz_url " ) " ; then
_err "get to authz error."
_clearup
_on_issue_err " $_post_hook "
return 1
fi
response = " $( echo " $response " | _normalizeJson) "
_debug2 response " $response "
_d = " $( echo " $response " | _egrep_o '"value" *: *"[^"]*"' | cut -d : -f 2 | tr -d ' "' ) "
2018-01-06 17:39:15 +08:00
if _contains " $response " "\"wildcard\" *: *true" ; then
_d = " *. $_d "
fi
2018-01-06 12:45:24 +08:00
_debug2 _d " $_d "
_authorizations_map = " $_d , $response
$_authorizations_map "
done
_debug2 _authorizations_map " $_authorizations_map "
fi
2017-02-19 21:18:00 +08:00
alldomains = $( echo " $_main_domain , $_alt_domains " | tr ',' ' ' )
2018-01-06 12:45:24 +08:00
_index = 0
2016-04-09 23:40:59 +08:00
_currentRoot = ""
2016-11-09 19:30:39 +08:00
for d in $alldomains ; do
2016-11-09 21:56:50 +08:00
_info "Getting webroot for domain" " $d "
2018-01-06 12:45:24 +08:00
_index = $( _math $_index + 1)
2017-02-19 21:13:00 +08:00
_w = " $( echo $_web_roots | cut -d , -f $_index ) "
2017-02-13 23:29:37 +08:00
_debug _w " $_w "
2016-11-09 19:30:39 +08:00
if [ " $_w " ] ; then
2016-04-09 23:40:59 +08:00
_currentRoot = " $_w "
fi
_debug "_currentRoot" " $_currentRoot "
2016-11-09 19:30:39 +08:00
2016-04-09 23:40:59 +08:00
vtype = " $VTYPE_HTTP "
2018-01-06 12:45:24 +08:00
#todo, v2 wildcard force to use dns
2016-11-09 19:30:39 +08:00
if _startswith " $_currentRoot " "dns" ; then
2016-04-09 23:40:59 +08:00
vtype = " $VTYPE_DNS "
fi
2016-11-09 19:30:39 +08:00
if [ " $_currentRoot " = " $W_TLS " ] ; then
2018-01-06 12:45:24 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
vtype = " $VTYPE_TLS2 "
else
vtype = " $VTYPE_TLS "
fi
2016-06-17 13:23:44 +08:00
fi
2016-05-31 20:32:58 +08:00
2018-01-06 12:45:24 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
response = " $( echo " $_authorizations_map " | grep " ^ $d , " | sed " s/ $d ,// " ) "
_debug2 "response" " $response "
if [ -z " $response " ] ; then
_err "get to authz error."
_clearup
_on_issue_err " $_post_hook "
return 1
fi
else
if ! __get_domain_new_authz " $d " ; then
_clearup
_on_issue_err " $_post_hook "
return 1
fi
2016-05-31 20:32:58 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $thumbprint " ] ; then
2017-02-06 19:53:12 +08:00
thumbprint = " $( __calc_account_thumbprint) "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
entry = " $( printf "%s\n" " $response " | _egrep_o '[^\{]*"type":"' $vtype '"[^\}]*' ) "
2016-03-08 20:44:12 +08:00
_debug entry " $entry "
2016-11-09 19:30:39 +08:00
if [ -z " $entry " ] ; then
2018-02-06 21:23:08 +08:00
_err " Error, can not get domain token entry $d "
2018-02-15 21:04:53 +08:00
_supported_vtypes = " $( echo " $response " | _egrep_o "\"challenges\":\[[^]]*]" | tr '{' "\n" | grep type | cut -d '"' -f 4 | tr "\n" ' ' ) "
2018-02-15 10:29:03 +08:00
if [ " $_supported_vtypes " ] ; then
_err " The supported validation types are: $_supported_vtypes , but you specified: $vtype "
fi
2016-05-13 21:14:00 +08:00
_clearup
2017-02-19 22:09:22 +08:00
_on_issue_err " $_post_hook "
2016-05-13 21:14:00 +08:00
return 1
fi
2016-08-10 21:54:08 +08:00
token = " $( printf "%s\n" " $entry " | _egrep_o '"token":"[^"]*' | cut -d : -f 2 | tr -d '"' ) "
2016-11-09 21:56:50 +08:00
_debug token " $token "
2016-11-09 19:30:39 +08:00
2018-02-06 21:23:08 +08:00
if [ -z " $token " ] ; then
_err " Error, can not get domain token $entry "
_clearup
_on_issue_err " $_post_hook "
return 1
fi
2018-01-06 12:45:24 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
uri = " $( printf "%s\n" " $entry " | _egrep_o '"url":"[^"]*' | cut -d '"' -f 4 | _head_n 1) "
else
uri = " $( printf "%s\n" " $entry " | _egrep_o '"uri":"[^"]*' | cut -d '"' -f 4) "
fi
2016-11-09 21:56:50 +08:00
_debug uri " $uri "
2016-10-28 23:30:32 +08:00
2018-02-06 21:23:08 +08:00
if [ -z " $uri " ] ; then
_err " Error, can not get domain uri. $entry "
_clearup
_on_issue_err " $_post_hook "
return 1
fi
2016-03-08 20:44:12 +08:00
keyauthorization = " $token . $thumbprint "
_debug keyauthorization " $keyauthorization "
2016-11-09 20:45:57 +08:00
if printf "%s" " $response " | grep '"status":"valid"' >/dev/null 2>& 1; then
2018-01-06 12:45:24 +08:00
_debug " $d is already verified. "
2016-11-09 21:56:50 +08:00
keyauthorization = " $STATE_VERIFIED "
2016-08-07 10:23:52 +08:00
_debug keyauthorization " $keyauthorization "
2016-08-07 10:21:27 +08:00
fi
2016-04-09 23:40:59 +08:00
dvlist = " $d $sep $keyauthorization $sep $uri $sep $vtype $sep $_currentRoot "
2016-03-08 20:44:12 +08:00
_debug dvlist " $dvlist "
2016-11-09 19:30:39 +08:00
2017-02-13 23:29:37 +08:00
vlist = " $vlist $dvlist $dvsep "
2016-03-08 20:44:12 +08:00
done
2017-02-13 23:29:37 +08:00
_debug vlist " $vlist "
2016-03-08 20:44:12 +08:00
#add entry
dnsadded = ""
2017-02-13 23:29:37 +08:00
ventries = $( echo " $vlist " | tr " $dvsep " ' ' )
2016-11-09 19:30:39 +08:00
for ventry in $ventries ; do
2016-11-09 21:56:50 +08:00
d = $( echo " $ventry " | cut -d " $sep " -f 1)
keyauthorization = $( echo " $ventry " | cut -d " $sep " -f 2)
vtype = $( echo " $ventry " | cut -d " $sep " -f 4)
_currentRoot = $( echo " $ventry " | cut -d " $sep " -f 5)
2018-01-06 17:39:15 +08:00
_debug d " $d "
2016-11-09 19:30:39 +08:00
if [ " $keyauthorization " = " $STATE_VERIFIED " ] ; then
2017-02-15 20:24:24 +08:00
_debug " $d is already verified, skip $vtype . "
2016-08-07 10:21:27 +08:00
continue
fi
2016-11-09 19:30:39 +08:00
if [ " $vtype " = " $VTYPE_DNS " ] ; then
2016-03-08 20:44:12 +08:00
dnsadded = '0'
2018-01-06 17:39:15 +08:00
_dns_root_d = " $d "
if _startswith " $_dns_root_d " "*." ; then
_dns_root_d = " $( echo " $_dns_root_d " | sed 's/*.//' ) "
fi
txtdomain = " _acme-challenge. $_dns_root_d "
2016-03-08 20:44:12 +08:00
_debug txtdomain " $txtdomain "
2017-01-29 11:47:04 +08:00
txt = " $( printf "%s" " $keyauthorization " | _digest "sha256" | _url_replace) "
2016-03-08 20:44:12 +08:00
_debug txt " $txt "
2016-10-11 20:56:59 +08:00
2018-01-06 17:39:15 +08:00
d_api = " $( _findHook " $_dns_root_d " dnsapi " $_currentRoot " ) "
2016-10-11 20:56:59 +08:00
2016-03-08 20:44:12 +08:00
_debug d_api " $d_api "
2016-11-09 19:30:39 +08:00
if [ " $d_api " ] ; then
2016-03-08 20:44:12 +08:00
_info " Found domain api file: $d_api "
else
2017-07-04 08:23:09 +08:00
_info " $( __red "Add the following TXT record:" ) "
2017-07-04 09:08:54 +08:00
_info " $( __red " Domain: ' $( __green " $txtdomain " ) ' " ) "
_info " $( __red " TXT value: ' $( __green " $txt " ) ' " ) "
_info " $( __red "Please be aware that you prepend _acme-challenge. before your domain" ) "
_info " $( __red " so the resulting subdomain will be: $txtdomain " ) "
2016-03-08 20:44:12 +08:00
continue
fi
2016-11-09 19:30:39 +08:00
2016-03-31 21:28:54 +08:00
(
2016-11-09 21:56:50 +08:00
if ! . " $d_api " ; then
2016-03-31 21:28:54 +08:00
_err " Load file $d_api error. Please check your api file and try again. "
return 1
fi
2016-11-09 19:30:39 +08:00
2016-04-16 22:31:17 +08:00
addcommand = " ${ _currentRoot } _add "
2016-11-09 21:56:50 +08:00
if ! _exists " $addcommand " ; then
2016-03-31 21:28:54 +08:00
_err " It seems that your api file is not correct, it must have a function named: $addcommand "
return 1
fi
2016-11-09 19:30:39 +08:00
2016-11-09 21:56:50 +08:00
if ! $addcommand " $txtdomain " " $txt " ; then
2016-03-31 21:28:54 +08:00
_err " Error add txt for domain: $txtdomain "
return 1
fi
)
2016-11-09 19:30:39 +08:00
if [ " $? " != "0" ] ; then
2016-04-16 18:31:00 +08:00
_clearup
2017-07-01 20:31:42 +08:00
_on_issue_err " $_post_hook " " $vlist "
2016-03-08 20:44:12 +08:00
return 1
fi
dnsadded = '1'
fi
done
2016-11-09 19:30:39 +08:00
if [ " $dnsadded " = '0' ] ; then
_savedomainconf "Le_Vlist" " $vlist "
2016-03-08 20:44:12 +08:00
_debug " Dns record not added yet, so, save to $DOMAIN_CONF and exit. "
_err "Please add the TXT records to the domains, and retry again."
2016-04-16 18:31:00 +08:00
_clearup
2017-07-04 08:23:09 +08:00
_on_issue_err " $_post_hook "
2016-03-08 20:44:12 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $dnsadded " = '1' ] ; then
if [ -z " $Le_DNSSleep " ] ; then
2016-11-09 21:56:50 +08:00
Le_DNSSleep = " $DEFAULT_DNS_SLEEP "
2016-06-13 10:13:20 +08:00
else
2016-11-09 19:30:39 +08:00
_savedomainconf "Le_DNSSleep" " $Le_DNSSleep "
2016-06-13 10:13:20 +08:00
fi
2016-08-23 22:53:43 +08:00
_info " Sleep $( __green $Le_DNSSleep ) seconds for the txt records to take effect "
2016-11-09 21:56:50 +08:00
_sleep " $Le_DNSSleep "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-02-14 22:12:58 +08:00
NGINX_RESTORE_VLIST = ""
2016-03-08 20:44:12 +08:00
_debug "ok, let's start to verify"
2016-04-09 23:40:59 +08:00
2016-09-23 23:14:03 +08:00
_ncIndex = 1
2017-02-13 23:29:37 +08:00
ventries = $( echo " $vlist " | tr " $dvsep " ' ' )
2016-11-09 19:30:39 +08:00
for ventry in $ventries ; do
2016-11-09 21:56:50 +08:00
d = $( echo " $ventry " | cut -d " $sep " -f 1)
keyauthorization = $( echo " $ventry " | cut -d " $sep " -f 2)
uri = $( echo " $ventry " | cut -d " $sep " -f 3)
vtype = $( echo " $ventry " | cut -d " $sep " -f 4)
_currentRoot = $( echo " $ventry " | cut -d " $sep " -f 5)
2016-08-07 10:21:27 +08:00
2016-11-09 19:30:39 +08:00
if [ " $keyauthorization " = " $STATE_VERIFIED " ] ; then
2016-08-07 10:21:27 +08:00
_info " $d is already verified, skip $vtype . "
continue
fi
2016-03-08 20:44:12 +08:00
_info " Verifying: $d "
_debug "d" " $d "
_debug "keyauthorization" " $keyauthorization "
_debug "uri" " $uri "
removelevel = ""
2016-06-17 13:23:44 +08:00
token = " $( printf "%s" " $keyauthorization " | cut -d '.' -f 1) "
2016-04-09 23:40:59 +08:00
_debug "_currentRoot" " $_currentRoot "
2016-11-09 19:30:39 +08:00
if [ " $vtype " = " $VTYPE_HTTP " ] ; then
if [ " $_currentRoot " = " $NO_VALUE " ] ; then
2016-03-08 20:44:12 +08:00
_info "Standalone mode server"
2017-02-19 22:09:22 +08:00
_ncaddr = " $( _getfield " $_local_addr " " $_ncIndex " ) "
2016-09-23 23:14:03 +08:00
_ncIndex = " $( _math $_ncIndex + 1) "
2017-09-01 23:01:37 +08:00
_startserver " $keyauthorization " " $_ncaddr "
2016-11-09 19:30:39 +08:00
if [ " $? " != "0" ] ; then
2016-04-16 18:31:00 +08:00
_clearup
2017-02-26 12:07:06 +08:00
_on_issue_err " $_post_hook " " $vlist "
2016-04-12 23:18:22 +08:00
return 1
fi
2016-10-29 10:53:45 +08:00
sleep 1
2016-11-09 21:56:50 +08:00
_debug serverproc " $serverproc "
2017-02-06 20:42:54 +08:00
elif [ " $_currentRoot " = " $MODE_STATELESS " ] ; then
_info " Stateless mode for domain: $d "
_sleep 1
2017-02-13 23:29:37 +08:00
elif _startswith " $_currentRoot " " $NGINX " ; then
_info " Nginx mode for domain: $d "
#set up nginx server
FOUND_REAL_NGINX_CONF = ""
BACKUP_NGINX_CONF = ""
if ! _setNginx " $d " " $_currentRoot " " $thumbprint " ; then
_clearup
2017-02-26 12:07:06 +08:00
_on_issue_err " $_post_hook " " $vlist "
2017-02-13 23:29:37 +08:00
return 1
2017-02-14 22:03:48 +08:00
fi
2017-02-14 22:41:34 +08:00
2017-02-14 22:03:48 +08:00
if [ " $FOUND_REAL_NGINX_CONF " ] ; then
2017-02-13 23:29:37 +08:00
_realConf = " $FOUND_REAL_NGINX_CONF "
_backup = " $BACKUP_NGINX_CONF "
_debug _realConf " $_realConf "
2017-02-14 22:12:58 +08:00
NGINX_RESTORE_VLIST = " $d $sep $_realConf $sep $_backup $dvsep $NGINX_RESTORE_VLIST "
2017-02-13 23:29:37 +08:00
fi
_sleep 1
2016-03-08 20:44:12 +08:00
else
2016-11-09 19:30:39 +08:00
if [ " $_currentRoot " = "apache" ] ; then
2016-04-16 19:23:44 +08:00
wellknown_path = " $ACME_DIR "
else
2016-04-09 23:40:59 +08:00
wellknown_path = " $_currentRoot /.well-known/acme-challenge "
2016-11-09 19:30:39 +08:00
if [ ! -d " $_currentRoot /.well-known " ] ; then
2016-04-16 19:23:44 +08:00
removelevel = '1'
2016-11-09 19:30:39 +08:00
elif [ ! -d " $_currentRoot /.well-known/acme-challenge " ] ; then
2016-04-16 19:23:44 +08:00
removelevel = '2'
else
removelevel = '3'
fi
2016-03-08 20:44:12 +08:00
fi
2016-04-16 19:23:44 +08:00
2016-03-08 20:44:12 +08:00
_debug wellknown_path " $wellknown_path "
2016-04-16 19:23:44 +08:00
2016-03-08 20:44:12 +08:00
_debug " writing token: $token to $wellknown_path / $token "
mkdir -p " $wellknown_path "
2016-11-01 19:14:33 +08:00
2016-11-09 19:30:39 +08:00
if ! printf "%s" " $keyauthorization " >" $wellknown_path / $token " ; then
2016-11-01 19:14:33 +08:00
_err " $d :Can not write token to file : $wellknown_path / $token "
_clearupwebbroot " $_currentRoot " " $removelevel " " $token "
_clearup
2017-02-26 12:07:06 +08:00
_on_issue_err " $_post_hook " " $vlist "
2016-11-01 19:14:33 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
if [ ! " $usingApache " ] ; then
2016-11-09 22:35:30 +08:00
if webroot_owner = $( _stat " $_currentRoot " ) ; then
2016-07-22 14:17:33 -07:00
_debug " Changing owner/group of .well-known to $webroot_owner "
2017-03-16 18:02:36 +08:00
if ! _exec " chown -R \" $webroot_owner \" \" $_currentRoot /.well-known\" " ; then
_debug " $( cat " $_EXEC_TEMP_ERR " ) "
_exec_err >/dev/null 2>& 1
fi
2016-07-22 14:17:33 -07:00
else
2017-03-26 05:25:23 +00:00
_debug "not changing owner/group of webroot"
2016-07-22 14:17:33 -07:00
fi
2016-04-05 19:18:19 +08:00
fi
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
elif [ " $vtype " = " $VTYPE_TLS " ] ; then
2016-06-17 13:23:44 +08:00
#create A
#_hash_A="$(printf "%s" $token | _digest "sha256" "hex" )"
#_debug2 _hash_A "$_hash_A"
#_x="$(echo $_hash_A | cut -c 1-32)"
#_debug2 _x "$_x"
#_y="$(echo $_hash_A | cut -c 33-64)"
#_debug2 _y "$_y"
#_SAN_A="$_x.$_y.token.acme.invalid"
#_debug2 _SAN_A "$_SAN_A"
2016-11-09 19:30:39 +08:00
2016-06-17 13:23:44 +08:00
#create B
2016-11-09 22:07:32 +08:00
_hash_B = " $( printf "%s" " $keyauthorization " | _digest "sha256" "hex" ) "
2016-06-17 13:23:44 +08:00
_debug2 _hash_B " $_hash_B "
2016-11-09 22:07:32 +08:00
_x = " $( echo " $_hash_B " | cut -c 1-32) "
2016-06-17 13:23:44 +08:00
_debug2 _x " $_x "
2016-11-09 22:07:32 +08:00
_y = " $( echo " $_hash_B " | cut -c 33-64) "
2016-06-17 13:23:44 +08:00
_debug2 _y " $_y "
2016-11-09 19:30:39 +08:00
2016-06-17 13:23:44 +08:00
#_SAN_B="$_x.$_y.ka.acme.invalid"
2016-11-09 19:30:39 +08:00
2016-06-17 13:23:44 +08:00
_SAN_B = " $_x . $_y .acme.invalid "
_debug2 _SAN_B " $_SAN_B "
2016-11-09 19:30:39 +08:00
2017-02-19 22:09:22 +08:00
_ncaddr = " $( _getfield " $_local_addr " " $_ncIndex " ) "
2016-11-09 22:07:32 +08:00
_ncIndex = " $( _math " $_ncIndex " + 1) "
2016-09-23 23:14:03 +08:00
if ! _starttlsserver " $_SAN_B " " $_SAN_A " " $Le_TLSPort " " $keyauthorization " " $_ncaddr " ; then
2016-06-17 13:23:44 +08:00
_err "Start tls server error."
_clearupwebbroot " $_currentRoot " " $removelevel " " $token "
_clearup
2017-02-26 12:07:06 +08:00
_on_issue_err " $_post_hook " " $vlist "
2016-06-17 13:23:44 +08:00
return 1
fi
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-03-26 05:32:29 +00:00
if ! __trigger_validation " $uri " " $keyauthorization " ; then
2016-05-31 20:32:58 +08:00
_err " $d :Can not get challenge: $response "
_clearupwebbroot " $_currentRoot " " $removelevel " " $token "
_clearup
2017-02-26 12:07:06 +08:00
_on_issue_err " $_post_hook " " $vlist "
2016-05-31 20:32:58 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
2018-01-06 12:45:24 +08:00
if [ " $code " ] && [ " $code " != '202' ] ; then
if [ " $ACME_VERSION " = "2" ] && [ " $code " = '200' ] ; then
_debug " trigger validation code: $code "
else
_err " $d :Challenge error: $response "
_clearupwebbroot " $_currentRoot " " $removelevel " " $token "
_clearup
_on_issue_err " $_post_hook " " $vlist "
return 1
fi
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
2016-04-12 23:18:22 +08:00
waittimes = 0
2016-11-09 19:30:39 +08:00
if [ -z " $MAX_RETRY_TIMES " ] ; then
2016-04-12 23:18:22 +08:00
MAX_RETRY_TIMES = 30
fi
2016-11-09 19:30:39 +08:00
while true; do
2016-11-09 22:07:32 +08:00
waittimes = $( _math " $waittimes " + 1)
2016-11-09 19:30:39 +08:00
if [ " $waittimes " -ge " $MAX_RETRY_TIMES " ] ; then
2016-04-12 23:18:22 +08:00
_err " $d :Timeout "
_clearupwebbroot " $_currentRoot " " $removelevel " " $token "
_clearup
2017-02-26 12:07:06 +08:00
_on_issue_err " $_post_hook " " $vlist "
2016-04-12 23:18:22 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
2016-10-29 10:53:45 +08:00
_debug "sleep 2 secs to verify"
sleep 2
2016-03-08 20:44:12 +08:00
_debug "checking"
2016-11-09 22:35:30 +08:00
response = " $( _get " $uri " ) "
2016-11-09 19:30:39 +08:00
if [ " $? " != "0" ] ; then
2016-03-19 18:18:34 +08:00
_err " $d :Verify error: $response "
2016-04-09 23:40:59 +08:00
_clearupwebbroot " $_currentRoot " " $removelevel " " $token "
2016-03-08 20:44:12 +08:00
_clearup
2017-02-26 12:07:06 +08:00
_on_issue_err " $_post_hook " " $vlist "
2016-03-08 20:44:12 +08:00
return 1
fi
2016-05-31 21:20:10 +08:00
_debug2 original " $response "
2016-11-09 19:30:39 +08:00
response = " $( echo " $response " | _normalizeJson) "
2016-05-31 12:28:43 +08:00
_debug2 response " $response "
2016-11-09 19:30:39 +08:00
status = $( echo " $response " | _egrep_o '"status":"[^"]*' | cut -d : -f 2 | tr -d '"' )
if [ " $status " = "valid" ] ; then
2016-11-24 22:36:21 +08:00
_info " $( __green Success) "
2016-11-09 21:56:50 +08:00
_stopserver " $serverproc "
2016-03-08 20:44:12 +08:00
serverproc = ""
2016-04-09 23:40:59 +08:00
_clearupwebbroot " $_currentRoot " " $removelevel " " $token "
2016-11-09 19:30:39 +08:00
break
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $status " = "invalid" ] ; then
error = " $( echo " $response " | tr -d "\r\n" | _egrep_o '"error":\{[^\}]*' ) "
_debug2 error " $error "
errordetail = " $( echo " $error " | _egrep_o '"detail": *"[^"]*' | cut -d '"' -f 4) "
_debug2 errordetail " $errordetail "
if [ " $errordetail " ] ; then
_err " $d :Verify error: $errordetail "
else
_err " $d :Verify error: $error "
fi
if [ " $DEBUG " ] ; then
if [ " $vtype " = " $VTYPE_HTTP " ] ; then
_debug "Debug: get token url."
_get " http:// $d /.well-known/acme-challenge/ $token " "" 1
fi
fi
2016-04-09 23:40:59 +08:00
_clearupwebbroot " $_currentRoot " " $removelevel " " $token "
2016-03-08 20:44:12 +08:00
_clearup
2017-02-26 12:07:06 +08:00
_on_issue_err " $_post_hook " " $vlist "
2016-11-09 19:30:39 +08:00
return 1
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $status " = "pending" ] ; then
2016-03-08 20:44:12 +08:00
_info "Pending"
else
2016-11-09 19:30:39 +08:00
_err " $d :Verify error: $response "
2016-04-09 23:40:59 +08:00
_clearupwebbroot " $_currentRoot " " $removelevel " " $token "
2016-03-08 20:44:12 +08:00
_clearup
2017-02-26 12:07:06 +08:00
_on_issue_err " $_post_hook " " $vlist "
2016-03-08 20:44:12 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
done
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
done
_clearup
_info "Verify finished, start to sign."
2017-01-29 11:47:04 +08:00
der = " $( _getfile " ${ CSR_PATH } " " ${ BEGIN_CSR } " " ${ END_CSR } " | tr -d "\r\n" | _url_replace) "
2016-11-09 19:30:39 +08:00
2018-01-06 12:45:24 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
2018-01-06 21:33:27 +08:00
if ! _send_signed_request " ${ Le_OrderFinalize } " " {\"csr\": \" $der \"} " ; then
2018-01-06 12:45:24 +08:00
_err "Sign failed."
_on_issue_err " $_post_hook "
return 1
fi
if [ " $code " != "200" ] ; then
_err "Sign failed, code is not 200."
_on_issue_err " $_post_hook "
return 1
fi
2018-01-06 13:57:35 +08:00
Le_LinkCert = " $( echo " $response " | tr -d '\r\n' | _egrep_o '"certificate" *: *"[^"]*"' | cut -d '"' -f 4) "
2016-11-09 19:30:39 +08:00
2018-01-06 13:57:35 +08:00
if ! _get " $Le_LinkCert " >" $CERT_PATH " ; then
2018-01-06 12:45:24 +08:00
_err "Sign failed, code is not 200."
_on_issue_err " $_post_hook "
return 1
fi
2016-03-08 20:44:12 +08:00
2018-01-26 21:37:30 +08:00
if [ " $( grep -- " $BEGIN_CERT " " $CERT_PATH " | wc -l) " -gt "1" ] ; then
_debug "Found cert chain"
2018-01-27 17:20:38 +08:00
cat " $CERT_PATH " >" $CERT_FULLCHAIN_PATH "
2018-01-26 21:37:30 +08:00
_end_n = " $( grep -n -- " $END_CERT " " $CERT_FULLCHAIN_PATH " | _head_n 1 | cut -d : -f 1) "
_debug _end_n " $_end_n "
2018-01-27 17:20:38 +08:00
sed -n " 1, ${ _end_n } p " " $CERT_FULLCHAIN_PATH " >" $CERT_PATH "
2018-01-26 21:37:30 +08:00
_end_n = " $( _math $_end_n + 1) "
2018-01-27 17:20:38 +08:00
sed -n " ${ _end_n } ,9999p " " $CERT_FULLCHAIN_PATH " >" $CA_CERT_PATH "
2018-01-26 21:37:30 +08:00
fi
2018-01-06 12:45:24 +08:00
else
if ! _send_signed_request " ${ ACME_NEW_ORDER } " " {\"resource\": \" $ACME_NEW_ORDER_RES \", \"csr\": \" $der \"} " "needbase64" ; then
_err "Sign failed."
_on_issue_err " $_post_hook "
return 1
fi
_rcert = " $response "
Le_LinkCert = " $( grep -i '^Location.*$' " $HTTP_HEADER " | _head_n 1 | tr -d "\r\n" | cut -d " " -f 2) "
2016-11-09 19:30:39 +08:00
echo " $BEGIN_CERT " >" $CERT_PATH "
2016-03-08 20:44:12 +08:00
2016-10-29 17:43:38 +08:00
#if ! _get "$Le_LinkCert" | _base64 "multiline" >> "$CERT_PATH" ; then
# _debug "Get cert failed. Let's try last response."
2017-04-17 19:08:34 +08:00
# printf -- "%s" "$_rcert" | _dbase64 "multiline" | _base64 "multiline" >> "$CERT_PATH"
2016-10-29 17:43:38 +08:00
#fi
2016-11-09 19:30:39 +08:00
if ! printf -- "%s" " $_rcert " | _dbase64 "multiline" | _base64 "multiline" >>" $CERT_PATH " ; then
2016-10-29 17:43:38 +08:00
_debug "Try cert link."
2016-11-09 19:30:39 +08:00
_get " $Le_LinkCert " | _base64 "multiline" >>" $CERT_PATH "
2016-09-24 23:53:53 +08:00
fi
2016-11-09 19:30:39 +08:00
echo " $END_CERT " >>" $CERT_PATH "
2018-01-06 12:45:24 +08:00
fi
_debug "Le_LinkCert" " $Le_LinkCert "
_savedomainconf "Le_LinkCert" " $Le_LinkCert "
if [ " $Le_LinkCert " ] ; then
2016-08-13 19:22:25 +08:00
_info " $( __green "Cert success." ) "
2016-03-08 20:44:12 +08:00
cat " $CERT_PATH "
2016-08-27 15:44:03 +08:00
2016-11-09 19:30:39 +08:00
_info " Your cert is in $( __green " $CERT_PATH " ) "
if [ -f " $CERT_KEY_PATH " ] ; then
_info " Your cert key is in $( __green " $CERT_KEY_PATH " ) "
2016-08-27 15:44:03 +08:00
fi
2016-03-13 11:37:14 +08:00
cp " $CERT_PATH " " $CERT_FULLCHAIN_PATH "
2016-04-05 21:08:19 +08:00
2016-11-09 19:30:39 +08:00
if [ ! " $USER_PATH " ] || [ ! " $IN_CRON " ] ; then
2016-04-05 21:08:19 +08:00
USER_PATH = " $PATH "
_saveaccountconf "USER_PATH" " $USER_PATH "
fi
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $Le_LinkCert " ] ; then
2016-11-09 22:07:32 +08:00
response = " $( echo " $response " | _dbase64 "multiline" | _normalizeJson) "
2016-11-09 19:30:39 +08:00
_err " Sign failed: $( echo " $response " | _egrep_o '"detail":"[^"]*"' ) "
2017-02-19 22:09:22 +08:00
_on_issue_err " $_post_hook "
2016-03-08 20:44:12 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
_cleardomainconf "Le_Vlist"
2018-01-26 21:37:30 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
_debug "v2 chain."
else
Le_LinkIssuer = $( grep -i '^Link' " $HTTP_HEADER " | _head_n 1 | cut -d " " -f 2 | cut -d ';' -f 1 | tr -d '<>' )
2017-03-30 21:16:25 +08:00
2018-01-26 21:37:30 +08:00
if [ " $Le_LinkIssuer " ] ; then
if ! _contains " $Le_LinkIssuer " ":" ; then
_info " $( __red "Relative issuer link found." ) "
Le_LinkIssuer = " $_ACME_SERVER_HOST $Le_LinkIssuer "
2017-03-30 21:16:25 +08:00
fi
2018-01-26 21:37:30 +08:00
_debug Le_LinkIssuer " $Le_LinkIssuer "
_savedomainconf "Le_LinkIssuer" " $Le_LinkIssuer "
2017-03-30 21:16:25 +08:00
2018-01-26 21:37:30 +08:00
_link_issuer_retry = 0
_MAX_ISSUER_RETRY = 5
while [ " $_link_issuer_retry " -lt " $_MAX_ISSUER_RETRY " ] ; do
_debug _link_issuer_retry " $_link_issuer_retry "
if [ " $ACME_VERSION " = "2" ] ; then
if _get " $Le_LinkIssuer " >" $CA_CERT_PATH " ; then
break
fi
else
if _get " $Le_LinkIssuer " >" $CA_CERT_PATH .der " ; then
echo " $BEGIN_CERT " >" $CA_CERT_PATH "
_base64 "multiline" <" $CA_CERT_PATH .der " >>" $CA_CERT_PATH "
echo " $END_CERT " >>" $CA_CERT_PATH "
cat " $CA_CERT_PATH " >>" $CERT_FULLCHAIN_PATH "
rm -f " $CA_CERT_PATH .der "
break
fi
2018-01-06 12:45:24 +08:00
fi
2018-01-26 21:37:30 +08:00
_link_issuer_retry = $( _math $_link_issuer_retry + 1)
_sleep " $_link_issuer_retry "
done
if [ " $_link_issuer_retry " = " $_MAX_ISSUER_RETRY " ] ; then
_err "Max retry for issuer ca cert is reached."
2017-03-30 21:16:25 +08:00
fi
2018-01-26 21:37:30 +08:00
else
_debug "No Le_LinkIssuer header found."
2017-03-30 21:16:25 +08:00
fi
2016-03-08 20:44:12 +08:00
fi
2018-01-26 21:37:30 +08:00
[ -f " $CA_CERT_PATH " ] && _info " The intermediate CA cert is in $( __green " $CA_CERT_PATH " ) "
[ -f " $CERT_FULLCHAIN_PATH " ] && _info " And the full chain certs is there: $( __green " $CERT_FULLCHAIN_PATH " ) "
2016-11-09 19:30:39 +08:00
2016-08-25 21:46:31 +08:00
Le_CertCreateTime = $( _time)
2016-11-09 19:30:39 +08:00
_savedomainconf "Le_CertCreateTime" " $Le_CertCreateTime "
Le_CertCreateTimeStr = $( date -u)
_savedomainconf "Le_CertCreateTimeStr" " $Le_CertCreateTimeStr "
if [ -z " $Le_RenewalDays " ] || [ " $Le_RenewalDays " -lt "0" ] || [ " $Le_RenewalDays " -gt " $MAX_RENEW " ] ; then
2016-11-09 21:56:50 +08:00
Le_RenewalDays = " $MAX_RENEW "
2016-06-13 14:49:00 +08:00
else
2016-11-09 19:30:39 +08:00
_savedomainconf "Le_RenewalDays" " $Le_RenewalDays "
2016-06-20 18:35:40 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $CA_BUNDLE " ] ; then
2016-08-25 01:14:56 -04:00
_saveaccountconf CA_BUNDLE " $CA_BUNDLE "
else
_clearaccountconf "CA_BUNDLE"
fi
2017-03-19 16:10:09 +01:00
if [ " $CA_PATH " ] ; then
_saveaccountconf CA_PATH " $CA_PATH "
else
_clearaccountconf "CA_PATH"
fi
2016-08-25 01:14:56 -04:00
2016-11-09 19:30:39 +08:00
if [ " $HTTPS_INSECURE " ] ; then
2016-08-14 22:37:21 +08:00
_saveaccountconf HTTPS_INSECURE " $HTTPS_INSECURE "
else
2016-11-09 19:30:39 +08:00
_clearaccountconf "HTTPS_INSECURE"
2016-06-20 18:35:40 +08:00
fi
2016-04-17 17:33:08 +08:00
2016-11-09 19:30:39 +08:00
if [ " $Le_Listen_V4 " ] ; then
_savedomainconf "Le_Listen_V4" " $Le_Listen_V4 "
2016-10-02 23:54:21 +08:00
_cleardomainconf Le_Listen_V6
2016-11-09 19:30:39 +08:00
elif [ " $Le_Listen_V6 " ] ; then
_savedomainconf "Le_Listen_V6" " $Le_Listen_V6 "
2016-10-02 23:54:21 +08:00
_cleardomainconf Le_Listen_V4
fi
2016-09-28 13:07:51 +08:00
2017-07-02 15:25:35 +08:00
if [ " $Le_ForceNewDomainKey " = "1" ] ; then
_savedomainconf "Le_ForceNewDomainKey" " $Le_ForceNewDomainKey "
else
_cleardomainconf Le_ForceNewDomainKey
fi
2016-11-09 21:56:50 +08:00
Le_NextRenewTime = $( _math " $Le_CertCreateTime " + " $Le_RenewalDays " \* 24 \* 60 \* 60)
2016-11-09 19:30:39 +08:00
2016-11-09 21:56:50 +08:00
Le_NextRenewTimeStr = $( _time2str " $Le_NextRenewTime " )
2016-11-09 19:30:39 +08:00
_savedomainconf "Le_NextRenewTimeStr" " $Le_NextRenewTimeStr "
2016-11-09 21:56:50 +08:00
Le_NextRenewTime = $( _math " $Le_NextRenewTime " - 86400)
2016-11-09 19:30:39 +08:00
_savedomainconf "Le_NextRenewTime" " $Le_NextRenewTime "
2016-09-28 13:07:51 +08:00
2017-09-02 20:46:04 +08:00
if ! _on_issue_success " $_post_hook " " $_renew_hook " ; then
_err "Call hook error."
return 1
fi
2016-03-08 20:44:12 +08:00
2017-02-19 22:09:22 +08:00
if [ " $_real_cert $_real_key $_real_ca $_reload_cmd $_real_fullchain " ] ; then
_savedomainconf "Le_RealCertPath" " $_real_cert "
_savedomainconf "Le_RealCACertPath" " $_real_ca "
_savedomainconf "Le_RealKeyPath" " $_real_key "
_savedomainconf "Le_ReloadCmd" " $_reload_cmd "
_savedomainconf "Le_RealFullChainPath" " $_real_fullchain "
2017-02-21 21:34:43 +08:00
_installcert " $_main_domain " " $_real_cert " " $_real_key " " $_real_ca " " $_real_fullchain " " $_reload_cmd "
2016-04-27 23:34:29 +08:00
fi
2016-07-08 11:50:47 +08:00
2016-03-08 20:44:12 +08:00
}
2016-08-13 19:22:25 +08:00
#domain [isEcc]
2016-03-08 20:44:12 +08:00
renew( ) {
Le_Domain = " $1 "
2016-11-09 19:30:39 +08:00
if [ -z " $Le_Domain " ] ; then
2016-08-13 19:22:25 +08:00
_usage " Usage: $PROJECT_ENTRY --renew -d domain.com [--ecc] "
2016-03-08 20:44:12 +08:00
return 1
fi
2016-08-13 19:22:25 +08:00
_isEcc = " $2 "
2016-11-09 22:09:30 +08:00
_initpath " $Le_Domain " " $_isEcc "
2016-08-13 19:22:25 +08:00
2016-08-25 13:06:04 +08:00
_info " $( __green " Renew: ' $Le_Domain ' " ) "
2016-11-09 19:30:39 +08:00
if [ ! -f " $DOMAIN_CONF " ] ; then
2016-08-13 19:22:25 +08:00
_info " ' $Le_Domain ' is not a issued domain, skip. "
2016-11-09 19:30:39 +08:00
return 0
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $Le_RenewalDays " ] ; then
2016-08-02 21:47:35 +08:00
_savedomainconf Le_RenewalDays " $Le_RenewalDays "
fi
2016-04-17 07:38:43 +08:00
. " $DOMAIN_CONF "
2016-11-09 19:30:39 +08:00
if [ " $Le_API " ] ; then
2017-06-17 15:49:45 +08:00
if [ " $_OLD_CA_HOST " = " $Le_API " ] ; then
export Le_API = " $DEFAULT_CA "
_savedomainconf Le_API " $Le_API "
fi
2017-06-17 17:15:37 +08:00
if [ " $_OLD_STAGE_CA_HOST " = " $Le_API " ] ; then
2018-01-06 12:45:24 +08:00
export Le_API = " $DEFAULT_STAGING_CA "
2017-06-17 17:15:37 +08:00
_savedomainconf Le_API " $Le_API "
fi
2017-06-17 15:49:45 +08:00
export ACME_DIRECTORY = " $Le_API "
2016-12-10 21:32:47 +08:00
#reload ca configs
ACCOUNT_KEY_PATH = ""
ACCOUNT_JSON_PATH = ""
CA_CONF = ""
_debug3 "initpath again."
_initpath " $Le_Domain " " $_isEcc "
2016-09-27 23:43:18 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ -z " $FORCE " ] && [ " $Le_NextRenewTime " ] && [ " $( _time) " -lt " $Le_NextRenewTime " ] ; then
2016-08-25 13:06:04 +08:00
_info " Skip, Next renewal time is: $( __green " $Le_NextRenewTimeStr " ) "
_info " Add ' $( __red '--force' ) ' to force to renew. "
2016-11-09 22:09:30 +08:00
return " $RENEW_SKIP "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-07-10 19:51:55 +08:00
if [ " $IN_CRON " = "1" ] && [ -z " $Le_CertCreateTime " ] ; then
_info " Skip invalid cert for: $Le_Domain "
return 0
fi
2016-03-08 20:44:12 +08:00
IS_RENEW = "1"
2016-09-23 23:14:03 +08:00
issue " $Le_Webroot " " $Le_Domain " " $Le_Alt " " $Le_Keylength " " $Le_RealCertPath " " $Le_RealKeyPath " " $Le_RealCACertPath " " $Le_ReloadCmd " " $Le_RealFullChainPath " " $Le_PreHook " " $Le_PostHook " " $Le_RenewHook " " $Le_LocalAddress "
2016-11-09 22:09:30 +08:00
res = " $? "
2016-11-09 19:30:39 +08:00
if [ " $res " != "0" ] ; then
2016-11-09 22:09:30 +08:00
return " $res "
2016-10-11 20:56:59 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $Le_DeployHook " ] ; then
2017-02-19 20:15:00 +08:00
_deploy " $Le_Domain " " $Le_DeployHook "
2016-11-09 22:09:30 +08:00
res = " $? "
2016-10-11 20:56:59 +08:00
fi
2016-11-09 19:30:39 +08:00
2016-03-08 20:44:12 +08:00
IS_RENEW = ""
2016-11-09 22:09:30 +08:00
return " $res "
2016-03-08 20:44:12 +08:00
}
2016-06-18 11:29:28 +08:00
#renewAll [stopRenewOnError]
2016-03-08 20:44:12 +08:00
renewAll( ) {
_initpath
2016-06-18 11:29:28 +08:00
_stopRenewOnError = " $1 "
_debug "_stopRenewOnError" " $_stopRenewOnError "
_ret = "0"
2016-08-13 19:22:25 +08:00
2016-11-11 21:13:33 +08:00
for di in " ${ CERT_HOME } " /*.*/; do
_debug di " $di "
2016-11-18 19:44:43 +08:00
if ! [ -d " $di " ] ; then
2016-11-18 19:40:41 +08:00
_debug " Not directory, skip: $di "
continue
fi
2016-11-11 21:13:33 +08:00
d = $( basename " $di " )
2016-11-09 22:28:12 +08:00
_debug d " $d "
2016-08-13 19:22:25 +08:00
(
2016-11-09 22:28:12 +08:00
if _endswith " $d " " $ECC_SUFFIX " ; then
_isEcc = $( echo " $d " | cut -d " $ECC_SEP " -f 2)
d = $( echo " $d " | cut -d " $ECC_SEP " -f 1)
2016-08-13 19:22:25 +08:00
fi
renew " $d " " $_isEcc "
2016-04-27 22:14:15 +08:00
)
2016-06-18 11:29:28 +08:00
rc = " $? "
_debug " Return code: $rc "
2016-11-09 19:30:39 +08:00
if [ " $rc " != "0" ] ; then
if [ " $rc " = " $RENEW_SKIP " ] ; then
2016-06-18 11:29:28 +08:00
_info " Skipped $d "
2016-11-09 19:30:39 +08:00
elif [ " $_stopRenewOnError " ] ; then
2016-06-18 11:29:28 +08:00
_err " Error renew $d , stop now. "
2016-11-09 22:28:12 +08:00
return " $rc "
2016-06-18 11:29:28 +08:00
else
_ret = " $rc "
2017-04-06 19:29:09 +08:00
_err " Error renew $d . "
2016-06-18 11:29:28 +08:00
fi
fi
2016-03-08 20:44:12 +08:00
done
2016-11-09 22:28:12 +08:00
return " $_ret "
2016-03-08 20:44:12 +08:00
}
2016-08-27 13:52:13 +08:00
#csr webroot
2016-11-09 19:30:39 +08:00
signcsr( ) {
2016-08-27 13:52:13 +08:00
_csrfile = " $1 "
_csrW = " $2 "
if [ -z " $_csrfile " ] || [ -z " $_csrW " ] ; then
_usage " Usage: $PROJECT_ENTRY --signcsr --csr mycsr.csr -w /path/to/webroot/a.com/ "
return 1
fi
_csrsubj = $( _readSubjectFromCSR " $_csrfile " )
2016-11-09 19:30:39 +08:00
if [ " $? " != "0" ] ; then
2016-08-27 13:52:13 +08:00
_err " Can not read subject from csr: $_csrfile "
return 1
fi
2016-09-29 22:19:03 +08:00
_debug _csrsubj " $_csrsubj "
2017-06-18 10:18:20 +08:00
if _contains " $_csrsubj " ' ' || ! _contains " $_csrsubj " '.' ; then
_info " It seems that the subject: $_csrsubj is not a valid domain name. Drop it. "
_csrsubj = ""
fi
2016-08-27 13:52:13 +08:00
_csrdomainlist = $( _readSubjectAltNamesFromCSR " $_csrfile " )
2016-11-09 19:30:39 +08:00
if [ " $? " != "0" ] ; then
2016-08-27 13:52:13 +08:00
_err " Can not read domain list from csr: $_csrfile "
return 1
fi
_debug "_csrdomainlist" " $_csrdomainlist "
2016-11-09 19:30:39 +08:00
if [ -z " $_csrsubj " ] ; then
2016-09-29 22:19:03 +08:00
_csrsubj = " $( _getfield " $_csrdomainlist " 1) "
_debug _csrsubj " $_csrsubj "
_csrdomainlist = " $( echo " $_csrdomainlist " | cut -d , -f 2-) "
_debug "_csrdomainlist" " $_csrdomainlist "
fi
2016-11-09 19:30:39 +08:00
if [ -z " $_csrsubj " ] ; then
2016-09-29 22:19:03 +08:00
_err " Can not read subject from csr: $_csrfile "
return 1
fi
2016-11-09 19:30:39 +08:00
2016-08-27 13:52:13 +08:00
_csrkeylength = $( _readKeyLengthFromCSR " $_csrfile " )
2016-11-09 19:30:39 +08:00
if [ " $? " != "0" ] || [ -z " $_csrkeylength " ] ; then
2016-08-27 13:52:13 +08:00
_err " Can not read key length from csr: $_csrfile "
return 1
fi
2016-11-09 19:30:39 +08:00
2018-01-16 20:55:07 +08:00
if [ -z " $ACME_VERSION " ] && _contains " $_csrsubj , $_csrdomainlist " "*." ; then
export ACME_VERSION = 2
fi
2016-08-27 13:52:13 +08:00
_initpath " $_csrsubj " " $_csrkeylength "
mkdir -p " $DOMAIN_PATH "
2016-11-09 19:30:39 +08:00
2016-08-27 13:52:13 +08:00
_info " Copy csr to: $CSR_PATH "
cp " $_csrfile " " $CSR_PATH "
2016-11-09 19:30:39 +08:00
2016-08-27 13:52:13 +08:00
issue " $_csrW " " $_csrsubj " " $_csrdomainlist " " $_csrkeylength "
2016-11-09 19:30:39 +08:00
2016-08-27 13:52:13 +08:00
}
showcsr( ) {
2016-11-09 19:30:39 +08:00
_csrfile = " $1 "
2016-08-27 13:52:13 +08:00
_csrd = " $2 "
if [ -z " $_csrfile " ] && [ -z " $_csrd " ] ; then
_usage " Usage: $PROJECT_ENTRY --showcsr --csr mycsr.csr "
return 1
fi
_initpath
2016-11-09 19:30:39 +08:00
2016-08-27 13:52:13 +08:00
_csrsubj = $( _readSubjectFromCSR " $_csrfile " )
2016-11-09 19:30:39 +08:00
if [ " $? " != "0" ] || [ -z " $_csrsubj " ] ; then
2016-08-27 13:52:13 +08:00
_err " Can not read subject from csr: $_csrfile "
return 1
fi
2016-11-09 19:30:39 +08:00
2016-08-27 13:52:13 +08:00
_info " Subject= $_csrsubj "
_csrdomainlist = $( _readSubjectAltNamesFromCSR " $_csrfile " )
2016-11-09 19:30:39 +08:00
if [ " $? " != "0" ] ; then
2016-08-27 13:52:13 +08:00
_err " Can not read domain list from csr: $_csrfile "
return 1
fi
_debug "_csrdomainlist" " $_csrdomainlist "
_info " SubjectAltNames= $_csrdomainlist "
_csrkeylength = $( _readKeyLengthFromCSR " $_csrfile " )
2016-11-09 19:30:39 +08:00
if [ " $? " != "0" ] || [ -z " $_csrkeylength " ] ; then
2016-08-27 13:52:13 +08:00
_err " Can not read key length from csr: $_csrfile "
return 1
fi
_info " KeyLength= $_csrkeylength "
}
2016-06-09 14:18:54 +08:00
list( ) {
2016-08-10 21:54:08 +08:00
_raw = " $1 "
2016-06-09 14:18:54 +08:00
_initpath
2016-11-09 19:30:39 +08:00
2016-06-14 13:07:33 +08:00
_sep = "|"
2016-11-09 19:30:39 +08:00
if [ " $_raw " ] ; then
2016-11-09 21:44:46 +08:00
printf "%s\n" " Main_Domain ${ _sep } KeyLength ${ _sep } SAN_Domains ${ _sep } Created ${ _sep } Renew "
2016-11-11 21:13:33 +08:00
for di in " ${ CERT_HOME } " /*.*/; do
2016-11-18 19:44:43 +08:00
if ! [ -d " $di " ] ; then
2016-11-18 19:40:41 +08:00
_debug " Not directory, skip: $di "
continue
fi
2016-11-11 21:13:33 +08:00
d = $( basename " $di " )
2016-11-09 22:28:12 +08:00
_debug d " $d "
2016-06-14 13:07:33 +08:00
(
2016-11-09 22:28:12 +08:00
if _endswith " $d " " $ECC_SUFFIX " ; then
_isEcc = $( echo " $d " | cut -d " $ECC_SEP " -f 2)
d = $( echo " $d " | cut -d " $ECC_SEP " -f 1)
2016-08-13 19:22:25 +08:00
fi
2016-11-11 21:13:33 +08:00
_initpath " $d " " $_isEcc "
2016-11-09 19:30:39 +08:00
if [ -f " $DOMAIN_CONF " ] ; then
2016-06-14 13:07:33 +08:00
. " $DOMAIN_CONF "
2016-11-09 21:44:46 +08:00
printf "%s\n" " $Le_Domain ${ _sep } \" $Le_Keylength \" ${ _sep } $Le_Alt ${ _sep } $Le_CertCreateTimeStr ${ _sep } $Le_NextRenewTimeStr "
2016-06-14 13:07:33 +08:00
fi
)
done
else
2016-11-09 19:30:39 +08:00
if _exists column; then
2016-08-10 21:54:08 +08:00
list "raw" | column -t -s " $_sep "
else
2016-08-13 19:22:25 +08:00
list "raw" | tr " $_sep " '\t'
2016-08-10 21:54:08 +08:00
fi
2016-06-14 13:07:33 +08:00
fi
2016-06-09 14:18:54 +08:00
}
2017-02-19 20:15:00 +08:00
_deploy( ) {
_d = " $1 "
_hooks = " $2 "
for _d_api in $( echo " $_hooks " | tr ',' " " ) ; do
_deployApi = " $( _findHook " $_d " deploy " $_d_api " ) "
if [ -z " $_deployApi " ] ; then
_err " The deploy hook $_d_api is not found. "
return 1
fi
_debug _deployApi " $_deployApi "
if ! (
if ! . " $_deployApi " ; then
_err " Load file $_deployApi error. Please check your api file and try again. "
return 1
fi
d_command = " ${ _d_api } _deploy "
if ! _exists " $d_command " ; then
_err " It seems that your api file is not correct, it must have a function named: $d_command "
return 1
fi
if ! $d_command " $_d " " $CERT_KEY_PATH " " $CERT_PATH " " $CA_CERT_PATH " " $CERT_FULLCHAIN_PATH " ; then
_err " Error deploy for domain: $_d "
return 1
fi
) ; then
_err "Deploy error."
return 1
else
_info " $( __green Success) "
fi
done
}
#domain hooks
2016-10-11 20:56:59 +08:00
deploy( ) {
2017-02-19 20:15:00 +08:00
_d = " $1 "
_hooks = " $2 "
2016-10-11 20:56:59 +08:00
_isEcc = " $3 "
2017-02-19 20:15:00 +08:00
if [ -z " $_hooks " ] ; then
2016-10-11 20:56:59 +08:00
_usage " Usage: $PROJECT_ENTRY --deploy -d domain.com --deploy-hook cpanel [--ecc] "
return 1
fi
2017-02-19 20:15:00 +08:00
_initpath " $_d " " $_isEcc "
2016-11-09 19:30:39 +08:00
if [ ! -d " $DOMAIN_PATH " ] ; then
2017-02-19 20:15:00 +08:00
_err " Domain is not valid:' $_d ' "
2016-10-11 20:56:59 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
2017-02-19 20:15:00 +08:00
. " $DOMAIN_CONF "
2016-11-09 19:30:39 +08:00
2017-02-19 20:15:00 +08:00
_savedomainconf Le_DeployHook " $_hooks "
2016-11-09 19:30:39 +08:00
2017-02-19 20:15:00 +08:00
_deploy " $_d " " $_hooks "
2016-10-11 20:56:59 +08:00
}
2016-03-08 20:44:12 +08:00
installcert( ) {
2017-02-19 22:09:22 +08:00
_main_domain = " $1 "
if [ -z " $_main_domain " ] ; then
2017-03-22 21:20:35 +08:00
_usage " Usage: $PROJECT_ENTRY --installcert -d domain.com [--ecc] [--cert-file cert-file-path] [--key-file key-file-path] [--ca-file ca-cert-file-path] [ --reloadCmd reloadCmd] [--fullchain-file fullchain-path] "
2016-03-08 20:44:12 +08:00
return 1
fi
2017-02-19 22:09:22 +08:00
_real_cert = " $2 "
_real_key = " $3 "
_real_ca = " $4 "
_reload_cmd = " $5 "
_real_fullchain = " $6 "
2016-08-13 19:22:25 +08:00
_isEcc = " $7 "
2017-02-19 22:09:22 +08:00
_initpath " $_main_domain " " $_isEcc "
2016-11-09 19:30:39 +08:00
if [ ! -d " $DOMAIN_PATH " ] ; then
2017-02-19 22:09:22 +08:00
_err " Domain is not valid:' $_main_domain ' "
2016-08-13 19:22:25 +08:00
return 1
fi
2017-02-19 22:09:22 +08:00
_savedomainconf "Le_RealCertPath" " $_real_cert "
_savedomainconf "Le_RealCACertPath" " $_real_ca "
_savedomainconf "Le_RealKeyPath" " $_real_key "
_savedomainconf "Le_ReloadCmd" " $_reload_cmd "
_savedomainconf "Le_RealFullChainPath" " $_real_fullchain "
2017-02-21 21:34:43 +08:00
_installcert " $_main_domain " " $_real_cert " " $_real_key " " $_real_ca " " $_real_fullchain " " $_reload_cmd "
2016-08-13 19:22:25 +08:00
}
2016-03-08 20:44:12 +08:00
2017-02-21 21:34:43 +08:00
#domain cert key ca fullchain reloadcmd backup-prefix
2016-08-13 19:22:25 +08:00
_installcert( ) {
2017-02-19 22:09:22 +08:00
_main_domain = " $1 "
_real_cert = " $2 "
_real_key = " $3 "
_real_ca = " $4 "
2017-02-21 21:34:43 +08:00
_real_fullchain = " $5 "
_reload_cmd = " $6 "
_backup_prefix = " $7 "
2016-03-08 20:44:12 +08:00
2017-02-19 22:09:22 +08:00
if [ " $_real_cert " = " $NO_VALUE " ] ; then
_real_cert = ""
2016-04-27 22:14:15 +08:00
fi
2017-02-19 22:09:22 +08:00
if [ " $_real_key " = " $NO_VALUE " ] ; then
_real_key = ""
2016-04-27 22:14:15 +08:00
fi
2017-02-19 22:09:22 +08:00
if [ " $_real_ca " = " $NO_VALUE " ] ; then
_real_ca = ""
2016-04-27 22:14:15 +08:00
fi
2017-02-19 22:09:22 +08:00
if [ " $_reload_cmd " = " $NO_VALUE " ] ; then
_reload_cmd = ""
2016-04-27 22:14:15 +08:00
fi
2017-02-19 22:09:22 +08:00
if [ " $_real_fullchain " = " $NO_VALUE " ] ; then
_real_fullchain = ""
2016-04-27 22:14:15 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-02-21 21:34:43 +08:00
_backup_path = " $DOMAIN_BACKUP_PATH / $_backup_prefix "
mkdir -p " $_backup_path "
2017-02-19 22:09:22 +08:00
if [ " $_real_cert " ] ; then
_info " Installing cert to: $_real_cert "
if [ -f " $_real_cert " ] && [ ! " $IS_RENEW " ] ; then
2017-02-21 21:34:43 +08:00
cp " $_real_cert " " $_backup_path /cert.bak "
2016-03-08 20:44:12 +08:00
fi
2017-02-19 22:09:22 +08:00
cat " $CERT_PATH " >" $_real_cert "
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-02-19 22:09:22 +08:00
if [ " $_real_ca " ] ; then
_info " Installing CA to: $_real_ca "
if [ " $_real_ca " = " $_real_cert " ] ; then
echo "" >>" $_real_ca "
cat " $CA_CERT_PATH " >>" $_real_ca "
2016-03-08 20:44:12 +08:00
else
2017-02-19 22:09:22 +08:00
if [ -f " $_real_ca " ] && [ ! " $IS_RENEW " ] ; then
2017-02-21 21:34:43 +08:00
cp " $_real_ca " " $_backup_path /ca.bak "
2016-03-03 14:51:07 +01:00
fi
2017-02-19 22:09:22 +08:00
cat " $CA_CERT_PATH " >" $_real_ca "
2016-03-08 20:44:12 +08:00
fi
fi
2017-02-19 22:09:22 +08:00
if [ " $_real_key " ] ; then
_info " Installing key to: $_real_key "
if [ -f " $_real_key " ] && [ ! " $IS_RENEW " ] ; then
2017-02-21 21:34:43 +08:00
cp " $_real_key " " $_backup_path /key.bak "
2016-03-08 20:44:12 +08:00
fi
2017-12-09 21:50:45 +08:00
if [ -f " $_real_key " ] ; then
cat " $CERT_KEY_PATH " >" $_real_key "
else
cat " $CERT_KEY_PATH " >" $_real_key "
2018-02-14 06:44:06 -02:00
chmod 600 " $_real_key "
2017-12-09 21:50:45 +08:00
fi
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-02-19 22:09:22 +08:00
if [ " $_real_fullchain " ] ; then
_info " Installing full chain to: $_real_fullchain "
if [ -f " $_real_fullchain " ] && [ ! " $IS_RENEW " ] ; then
2017-02-21 21:34:43 +08:00
cp " $_real_fullchain " " $_backup_path /fullchain.bak "
2016-04-09 23:40:59 +08:00
fi
2017-02-19 22:09:22 +08:00
cat " $CERT_FULLCHAIN_PATH " >" $_real_fullchain "
2016-11-09 19:30:39 +08:00
fi
2016-03-08 20:44:12 +08:00
2017-02-19 22:09:22 +08:00
if [ " $_reload_cmd " ] ; then
_info " Run reload cmd: $_reload_cmd "
2017-01-22 18:11:32 +08:00
if (
2017-01-22 18:48:21 +08:00
export CERT_PATH
export CERT_KEY_PATH
export CA_CERT_PATH
export CERT_FULLCHAIN_PATH
2017-03-29 09:10:42 +08:00
export Le_Domain
2017-02-19 22:09:22 +08:00
cd " $DOMAIN_PATH " && eval " $_reload_cmd "
2017-01-22 18:48:21 +08:00
) ; then
2016-08-13 19:22:25 +08:00
_info " $( __green "Reload success" ) "
2016-04-27 22:14:15 +08:00
else
_err " Reload error for : $Le_Domain "
fi
fi
2016-03-08 20:44:12 +08:00
}
2017-01-16 22:31:24 +08:00
#confighome
2016-03-08 20:44:12 +08:00
installcronjob( ) {
2017-01-16 22:31:24 +08:00
_c_home = " $1 "
2016-03-08 20:44:12 +08:00
_initpath
2017-08-10 21:31:28 +08:00
_CRONTAB = "crontab"
if ! _exists " $_CRONTAB " && _exists "fcrontab" ; then
_CRONTAB = "fcrontab"
fi
if ! _exists " $_CRONTAB " ; then
_err "crontab/fcrontab doesn't exist, so, we can not install cron jobs."
2016-03-29 21:49:18 +08:00
_err "All your certs will not be renewed automatically."
2016-04-13 20:37:18 +08:00
_err " You must add your own cron job to call ' $PROJECT_ENTRY --cron' everyday. "
2016-03-29 21:49:18 +08:00
return 1
fi
2016-03-08 20:44:12 +08:00
_info "Installing cron job"
2017-08-10 21:31:28 +08:00
if ! $_CRONTAB -l | grep " $PROJECT_ENTRY --cron " ; then
2016-11-09 19:30:39 +08:00
if [ -f " $LE_WORKING_DIR / $PROJECT_ENTRY " ] ; then
2016-04-13 20:37:18 +08:00
lesh = " \" $LE_WORKING_DIR \"/ $PROJECT_ENTRY "
2016-03-08 20:44:12 +08:00
else
2016-04-13 20:37:18 +08:00
_err " Can not install cronjob, $PROJECT_ENTRY not found. "
2016-03-08 20:44:12 +08:00
return 1
fi
2017-01-16 22:31:24 +08:00
if [ " $_c_home " ] ; then
2017-01-16 22:36:13 +08:00
_c_entry = " --config-home \" $_c_home \" "
2017-01-16 22:31:24 +08:00
fi
2017-01-17 21:49:02 +08:00
_t = $( _time)
random_minute = $( _math $_t % 60)
2016-12-21 20:19:57 +08:00
if _exists uname && uname -a | grep SunOS >/dev/null; then
2017-08-10 21:31:28 +08:00
$_CRONTAB -l | {
2016-11-09 19:30:39 +08:00
cat
2017-01-17 21:57:12 +08:00
echo " $random_minute 0 * * * $lesh --cron --home \" $LE_WORKING_DIR \" $_c_entry > /dev/null "
2017-08-10 21:31:28 +08:00
} | $_CRONTAB --
2016-08-10 21:54:08 +08:00
else
2017-08-10 21:31:28 +08:00
$_CRONTAB -l | {
2016-11-09 19:30:39 +08:00
cat
2017-01-17 21:57:12 +08:00
echo " $random_minute 0 * * * $lesh --cron --home \" $LE_WORKING_DIR \" $_c_entry > /dev/null "
2017-08-10 21:31:28 +08:00
} | $_CRONTAB -
2016-08-10 21:54:08 +08:00
fi
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $? " != "0" ] ; then
2016-03-08 20:44:12 +08:00
_err "Install cron job failed. You need to manually renew your certs."
_err "Or you can add cronjob by yourself:"
2016-04-13 20:37:18 +08:00
_err " $lesh --cron --home \" $LE_WORKING_DIR \" > /dev/null "
2016-03-08 20:44:12 +08:00
return 1
fi
}
uninstallcronjob( ) {
2017-08-10 21:31:28 +08:00
_CRONTAB = "crontab"
if ! _exists " $_CRONTAB " && _exists "fcrontab" ; then
_CRONTAB = "fcrontab"
fi
if ! _exists " $_CRONTAB " ; then
2016-03-29 21:57:56 +08:00
return
fi
2016-03-08 20:44:12 +08:00
_info "Removing cron job"
2017-08-10 21:31:28 +08:00
cr = " $( $_CRONTAB -l | grep " $PROJECT_ENTRY --cron " ) "
2016-11-09 19:30:39 +08:00
if [ " $cr " ] ; then
if _exists uname && uname -a | grep solaris >/dev/null; then
2017-08-10 21:31:28 +08:00
$_CRONTAB -l | sed " / $PROJECT_ENTRY --cron/d " | $_CRONTAB --
2016-08-10 21:54:08 +08:00
else
2017-08-10 21:31:28 +08:00
$_CRONTAB -l | sed " / $PROJECT_ENTRY --cron/d " | $_CRONTAB -
2016-08-10 21:54:08 +08:00
fi
2016-04-13 20:37:18 +08:00
LE_WORKING_DIR = " $( echo " $cr " | cut -d ' ' -f 9 | tr -d '"' ) "
2016-03-08 20:44:12 +08:00
_info LE_WORKING_DIR " $LE_WORKING_DIR "
2017-01-16 22:31:24 +08:00
if _contains " $cr " "--config-home" ; then
2017-01-21 11:28:10 +08:00
LE_CONFIG_HOME = " $( echo " $cr " | cut -d ' ' -f 11 | tr -d '"' ) "
_debug LE_CONFIG_HOME " $LE_CONFIG_HOME "
2017-01-16 22:31:24 +08:00
fi
2016-11-09 19:30:39 +08:00
fi
2016-03-08 20:44:12 +08:00
_initpath
2016-04-13 20:37:18 +08:00
2016-03-08 20:44:12 +08:00
}
2016-04-06 22:16:09 +08:00
revoke( ) {
Le_Domain = " $1 "
2016-11-09 19:30:39 +08:00
if [ -z " $Le_Domain " ] ; then
2017-01-21 13:32:12 +08:00
_usage " Usage: $PROJECT_ENTRY --revoke -d domain.com [--ecc] "
2016-04-06 22:16:09 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
2016-08-13 19:22:25 +08:00
_isEcc = " $2 "
2016-11-11 21:22:48 +08:00
_initpath " $Le_Domain " " $_isEcc "
2016-11-09 19:30:39 +08:00
if [ ! -f " $DOMAIN_CONF " ] ; then
2016-04-06 22:16:09 +08:00
_err " $Le_Domain is not a issued domain, skip. "
2016-11-09 19:30:39 +08:00
return 1
2016-04-06 22:16:09 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ ! -f " $CERT_PATH " ] ; then
2016-04-06 22:16:09 +08:00
_err " Cert for $Le_Domain $CERT_PATH is not found, skip. "
return 1
fi
2017-01-29 11:47:04 +08:00
cert = " $( _getfile " ${ CERT_PATH } " " ${ BEGIN_CERT } " " ${ END_CERT } " | tr -d "\r\n" | _url_replace) "
2016-11-09 19:30:39 +08:00
if [ -z " $cert " ] ; then
2016-04-06 22:16:09 +08:00
_err " Cert for $Le_Domain is empty found, skip. "
return 1
fi
2016-11-09 19:30:39 +08:00
2017-06-17 15:49:45 +08:00
_initAPI
2018-01-06 21:33:27 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
data = " {\"certificate\": \" $cert \"} "
else
data = " {\"resource\": \"revoke-cert\", \"certificate\": \" $cert \"} "
fi
2017-06-17 15:49:45 +08:00
uri = " ${ ACME_REVOKE_CERT } "
2016-04-06 22:16:09 +08:00
2016-11-09 19:30:39 +08:00
if [ -f " $CERT_KEY_PATH " ] ; then
2016-10-28 20:56:18 +08:00
_info "Try domain key first."
2016-11-11 21:22:48 +08:00
if _send_signed_request " $uri " " $data " "" " $CERT_KEY_PATH " ; then
2016-11-09 19:30:39 +08:00
if [ -z " $response " ] ; then
2016-10-28 20:56:18 +08:00
_info "Revoke success."
2016-11-11 21:22:48 +08:00
rm -f " $CERT_PATH "
2016-10-28 20:56:18 +08:00
return 0
2016-11-09 19:30:39 +08:00
else
2016-10-28 20:56:18 +08:00
_err "Revoke error by domain key."
_err " $response "
fi
2016-04-06 22:16:09 +08:00
fi
2016-11-09 19:30:39 +08:00
else
2016-10-28 20:56:18 +08:00
_info "Domain key file doesn't exists."
2016-04-06 22:16:09 +08:00
fi
2016-10-28 20:56:18 +08:00
_info "Try account key."
2016-04-06 22:16:09 +08:00
2016-11-11 21:22:48 +08:00
if _send_signed_request " $uri " " $data " "" " $ACCOUNT_KEY_PATH " ; then
2016-11-09 19:30:39 +08:00
if [ -z " $response " ] ; then
2016-04-06 22:16:09 +08:00
_info "Revoke success."
2016-11-11 21:22:48 +08:00
rm -f " $CERT_PATH "
2016-04-06 22:16:09 +08:00
return 0
2016-11-09 19:30:39 +08:00
else
2016-04-06 22:16:09 +08:00
_err "Revoke error."
2016-07-21 10:48:37 +08:00
_debug " $response "
2016-04-06 22:16:09 +08:00
fi
fi
return 1
}
2016-03-08 20:44:12 +08:00
2017-01-21 13:32:12 +08:00
#domain ecc
remove( ) {
Le_Domain = " $1 "
if [ -z " $Le_Domain " ] ; then
_usage " Usage: $PROJECT_ENTRY --remove -d domain.com [--ecc] "
return 1
fi
_isEcc = " $2 "
_initpath " $Le_Domain " " $_isEcc "
_removed_conf = " $DOMAIN_CONF .removed "
if [ ! -f " $DOMAIN_CONF " ] ; then
if [ -f " $_removed_conf " ] ; then
_err " $Le_Domain is already removed, You can remove the folder by yourself: $DOMAIN_PATH "
else
_err " $Le_Domain is not a issued domain, skip. "
fi
return 1
fi
if mv " $DOMAIN_CONF " " $_removed_conf " ; then
2017-01-21 14:19:01 +08:00
_info " $Le_Domain is removed, the key and cert files are in $( __green $DOMAIN_PATH ) "
2017-01-21 13:32:12 +08:00
_info "You can remove them by yourself."
return 0
else
_err " Remove $Le_Domain failed. "
return 1
fi
}
2016-09-22 23:17:50 +08:00
#domain vtype
_deactivate( ) {
_d_domain = " $1 "
_d_type = " $2 "
_initpath
2016-11-09 19:30:39 +08:00
2018-01-06 21:33:27 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
_identifiers = " {\"type\":\"dns\",\"value\":\" $_d_domain \"} "
if ! _send_signed_request " $ACME_NEW_ORDER " " {\"identifiers\": [ $_identifiers ]} " ; then
_err "Can not get domain new order."
return 1
fi
_authorizations_seg = " $( echo " $response " | tr -d '\r\n' | _egrep_o '"authorizations" *: *\[[^\]*\]' | cut -d '[' -f 2 | tr -d ']' | tr -d '"' ) "
_debug2 _authorizations_seg " $_authorizations_seg "
if [ -z " $_authorizations_seg " ] ; then
_err "_authorizations_seg not found."
_clearup
_on_issue_err " $_post_hook "
return 1
fi
2016-11-09 19:30:39 +08:00
2018-01-06 21:33:27 +08:00
authzUri = " $_authorizations_seg "
_debug2 "authzUri" " $authzUri "
if ! response = " $( _get " $authzUri " ) " ; then
_err "get to authz error."
_clearup
_on_issue_err " $_post_hook "
return 1
fi
2016-11-09 19:30:39 +08:00
2018-01-06 21:33:27 +08:00
response = " $( echo " $response " | _normalizeJson) "
_debug2 response " $response "
_URL_NAME = "url"
else
if ! __get_domain_new_authz " $_d_domain " ; then
_err "Can not get domain new authz token."
return 1
fi
authzUri = " $( echo " $responseHeaders " | grep "^Location:" | _head_n 1 | cut -d ' ' -f 2 | tr -d "\r\n" ) "
_debug "authzUri" " $authzUri "
if [ " $code " ] && [ ! " $code " = '201' ] ; then
_err " new-authz error: $response "
return 1
fi
_URL_NAME = "uri"
2017-07-01 21:47:30 +08:00
fi
2016-09-22 23:17:50 +08:00
2018-01-06 21:33:27 +08:00
entries = " $( echo " $response " | _egrep_o " { *\"type\":\"[^\"]*\", *\"status\": *\"valid\", *\" $_URL_NAME \"[^}]* " ) "
2017-07-01 21:47:30 +08:00
if [ -z " $entries " ] ; then
_info "No valid entries found."
if [ -z " $thumbprint " ] ; then
thumbprint = " $( __calc_account_thumbprint) "
fi
_debug "Trigger validation."
2018-01-06 21:33:27 +08:00
vtype = " $VTYPE_DNS "
2017-07-01 21:47:30 +08:00
entry = " $( printf "%s\n" " $response " | _egrep_o '[^\{]*"type":"' $vtype '"[^\}]*' ) "
_debug entry " $entry "
if [ -z " $entry " ] ; then
_err " Error, can not get domain token $d "
2016-09-22 23:17:50 +08:00
return 1
fi
2017-07-01 21:47:30 +08:00
token = " $( printf "%s\n" " $entry " | _egrep_o '"token":"[^"]*' | cut -d : -f 2 | tr -d '"' ) "
_debug token " $token "
2016-11-09 19:30:39 +08:00
2018-01-06 21:33:27 +08:00
uri = " $( printf "%s\n" " $entry " | _egrep_o " \" $_URL_NAME \":\"[^\"]* " | cut -d : -f 2,3 | tr -d '"' ) "
2017-07-01 21:47:30 +08:00
_debug uri " $uri "
keyauthorization = " $token . $thumbprint "
_debug keyauthorization " $keyauthorization "
__trigger_validation " $uri " " $keyauthorization "
fi
_d_i = 0
_d_max_retry = $( echo " $entries " | wc -l)
while [ " $_d_i " -lt " $_d_max_retry " ] ; do
_info " Deactivate: $_d_domain "
_d_i = " $( _math $_d_i + 1) "
entry = " $( echo " $entries " | sed -n " ${ _d_i } p " ) "
2016-09-22 23:17:50 +08:00
_debug entry " $entry "
2016-11-09 19:30:39 +08:00
if [ -z " $entry " ] ; then
2016-09-22 23:25:32 +08:00
_info "No more valid entry found."
2016-09-22 23:17:50 +08:00
break
fi
2016-11-09 19:30:39 +08:00
2016-09-22 23:17:50 +08:00
_vtype = " $( printf "%s\n" " $entry " | _egrep_o '"type": *"[^"]*"' | cut -d : -f 2 | tr -d '"' ) "
2016-11-11 21:22:48 +08:00
_debug _vtype " $_vtype "
2016-09-22 23:17:50 +08:00
_info " Found $_vtype "
2018-01-06 21:33:27 +08:00
uri = " $( printf "%s\n" " $entry " | _egrep_o " \" $_URL_NAME \":\"[^\"]* " | cut -d : -f 2,3 | tr -d '"' ) "
2016-11-11 21:22:48 +08:00
_debug uri " $uri "
2016-11-09 19:30:39 +08:00
if [ " $_d_type " ] && [ " $_d_type " != " $_vtype " ] ; then
2016-09-22 23:17:50 +08:00
_info " Skip $_vtype "
continue
fi
2016-11-09 19:30:39 +08:00
2016-09-22 23:17:50 +08:00
_info " Deactivate: $_vtype "
2016-11-09 19:30:39 +08:00
2018-01-06 21:33:27 +08:00
if [ " $ACME_VERSION " = "2" ] ; then
_djson = "{\"status\":\"deactivated\"}"
else
_djson = "{\"resource\": \"authz\", \"status\":\"deactivated\"}"
fi
if _send_signed_request " $authzUri " " $_djson " && _contains " $response " '"deactivated"' ; then
2017-07-01 21:47:30 +08:00
_info " Deactivate: $_vtype success. "
else
2016-09-22 23:17:50 +08:00
_err " Can not deactivate $_vtype . "
2017-07-01 21:47:30 +08:00
break
2016-09-22 23:17:50 +08:00
fi
2016-11-09 19:30:39 +08:00
2016-09-22 23:17:50 +08:00
done
_debug " $_d_i "
2017-07-01 21:47:30 +08:00
if [ " $_d_i " -eq " $_d_max_retry " ] ; then
2016-09-22 23:17:50 +08:00
_info "Deactivated success!"
else
_err "Deactivate failed."
fi
}
deactivate( ) {
2016-09-23 22:35:13 +08:00
_d_domain_list = " $1 "
2016-09-22 23:17:50 +08:00
_d_type = " $2 "
_initpath
2017-06-17 16:30:04 +08:00
_initAPI
2016-09-23 22:35:13 +08:00
_debug _d_domain_list " $_d_domain_list "
2016-11-09 19:30:39 +08:00
if [ -z " $( echo $_d_domain_list | cut -d , -f 1) " ] ; then
2016-09-23 22:35:13 +08:00
_usage " Usage: $PROJECT_ENTRY --deactivate -d domain.com [-d domain.com] "
2016-09-22 23:17:50 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
for _d_dm in $( echo " $_d_domain_list " | tr ',' ' ' ) ; do
if [ -z " $_d_dm " ] || [ " $_d_dm " = " $NO_VALUE " ] ; then
2016-09-23 22:35:13 +08:00
continue
fi
2016-11-11 21:22:48 +08:00
if ! _deactivate " $_d_dm " " $_d_type " ; then
2016-09-24 14:17:04 +08:00
return 1
fi
2016-09-23 22:35:13 +08:00
done
2016-09-22 23:17:50 +08:00
}
2016-03-08 20:44:12 +08:00
# Detect profile file if not specified as environment variable
_detect_profile( ) {
2016-11-09 19:30:39 +08:00
if [ -n " $PROFILE " -a -f " $PROFILE " ] ; then
2016-03-08 20:44:12 +08:00
echo " $PROFILE "
return
fi
DETECTED_PROFILE = ''
SHELLTYPE = " $( basename " / $SHELL " ) "
2016-11-09 19:30:39 +08:00
if [ " $SHELLTYPE " = "bash" ] ; then
if [ -f " $HOME /.bashrc " ] ; then
2016-03-08 20:44:12 +08:00
DETECTED_PROFILE = " $HOME /.bashrc "
2016-11-09 19:30:39 +08:00
elif [ -f " $HOME /.bash_profile " ] ; then
2016-03-08 20:44:12 +08:00
DETECTED_PROFILE = " $HOME /.bash_profile "
fi
2016-11-09 19:30:39 +08:00
elif [ " $SHELLTYPE " = "zsh" ] ; then
2016-03-08 20:44:12 +08:00
DETECTED_PROFILE = " $HOME /.zshrc "
fi
2016-11-09 19:30:39 +08:00
if [ -z " $DETECTED_PROFILE " ] ; then
if [ -f " $HOME /.profile " ] ; then
2016-03-08 20:44:12 +08:00
DETECTED_PROFILE = " $HOME /.profile "
2016-11-09 19:30:39 +08:00
elif [ -f " $HOME /.bashrc " ] ; then
2016-03-08 20:44:12 +08:00
DETECTED_PROFILE = " $HOME /.bashrc "
2016-11-09 19:30:39 +08:00
elif [ -f " $HOME /.bash_profile " ] ; then
2016-03-08 20:44:12 +08:00
DETECTED_PROFILE = " $HOME /.bash_profile "
2016-11-09 19:30:39 +08:00
elif [ -f " $HOME /.zshrc " ] ; then
2016-03-08 20:44:12 +08:00
DETECTED_PROFILE = " $HOME /.zshrc "
fi
fi
2017-07-02 13:38:44 +08:00
echo " $DETECTED_PROFILE "
2016-03-08 20:44:12 +08:00
}
_initconf( ) {
_initpath
2016-11-09 19:30:39 +08:00
if [ ! -f " $ACCOUNT_CONF_PATH " ] ; then
2017-02-06 09:28:30 +08:00
echo "
2016-09-24 23:53:53 +08:00
2016-09-20 19:08:02 +08:00
#LOG_FILE=\"$DEFAULT_LOG_FILE\"
2016-09-25 22:26:41 +08:00
#LOG_LEVEL=1
2016-09-19 23:07:43 +08:00
2016-09-20 22:23:49 +08:00
#AUTO_UPGRADE=\"1\"
2016-09-20 20:22:25 +08:00
2016-11-29 00:11:02 +08:00
#NO_TIMESTAMP=1
2016-11-20 23:21:07 +08:00
2016-11-09 21:44:46 +08:00
" >" $ACCOUNT_CONF_PATH "
2016-03-08 20:44:12 +08:00
fi
}
2016-06-24 22:27:22 +08:00
# nocron
2016-03-19 18:18:34 +08:00
_precheck( ) {
2016-06-24 22:27:22 +08:00
_nocron = " $1 "
2016-11-09 19:30:39 +08:00
if ! _exists "curl" && ! _exists "wget" ; then
2016-03-19 18:18:34 +08:00
_err "Please install curl or wget first, we need to access http resources."
2016-03-08 20:44:12 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
if [ -z " $_nocron " ] ; then
2017-08-10 21:31:28 +08:00
if ! _exists "crontab" && ! _exists "fcrontab" ; then
2016-06-24 22:27:22 +08:00
_err "It is recommended to install crontab first. try to install 'cron, crontab, crontabs or vixie-cron'."
_err "We need to set cron job to renew the certs automatically."
_err "Otherwise, your certs will not be able to be renewed automatically."
2016-11-09 19:30:39 +08:00
if [ -z " $FORCE " ] ; then
2016-06-24 22:27:22 +08:00
_err "Please add '--force' and try install again to go without crontab."
_err " ./ $PROJECT_ENTRY --install --force "
return 1
fi
2016-03-29 21:49:18 +08:00
fi
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-03-30 21:16:25 +08:00
if ! _exists " ${ ACME_OPENSSL_BIN :- openssl } " ; then
2017-02-25 19:08:00 +08:00
_err " Please install openssl first. ACME_OPENSSL_BIN= $ACME_OPENSSL_BIN "
2016-03-19 18:18:34 +08:00
_err "We need openssl to generate keys."
2016-03-08 20:44:12 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
2017-09-01 23:01:37 +08:00
if ! _exists "socat" ; then
_err "It is recommended to install socat first."
_err "We use socat for standalone server if you use standalone mode."
2016-03-19 18:18:34 +08:00
_err "If you don't use standalone mode, just ignore this warning."
fi
2016-11-09 19:30:39 +08:00
2016-03-19 18:18:34 +08:00
return 0
}
2016-04-17 19:47:22 +08:00
_setShebang( ) {
_file = " $1 "
_shebang = " $2 "
2016-11-09 19:30:39 +08:00
if [ -z " $_shebang " ] ; then
2016-08-13 19:22:25 +08:00
_usage "Usage: file shebang"
2016-04-17 19:47:22 +08:00
return 1
fi
cp " $_file " " $_file .tmp "
2016-11-09 19:30:39 +08:00
echo " $_shebang " >" $_file "
sed -n 2,99999p " $_file .tmp " >>" $_file "
rm -f " $_file .tmp "
2016-04-17 19:47:22 +08:00
}
2017-01-16 22:31:24 +08:00
#confighome
2016-05-07 17:11:01 +08:00
_installalias( ) {
2017-01-16 22:31:24 +08:00
_c_home = " $1 "
2016-05-07 17:11:01 +08:00
_initpath
_envfile = " $LE_WORKING_DIR / $PROJECT_ENTRY .env "
2016-11-09 19:30:39 +08:00
if [ " $_upgrading " ] && [ " $_upgrading " = "1" ] ; then
2016-11-09 22:35:30 +08:00
echo " $( cat " $_envfile " ) " | sed " s|^LE_WORKING_DIR.* $|| " >" $_envfile "
echo " $( cat " $_envfile " ) " | sed " s|^alias le.* $|| " >" $_envfile "
echo " $( cat " $_envfile " ) " | sed " s|^alias le.sh.* $|| " >" $_envfile "
2016-05-07 17:11:01 +08:00
fi
2017-01-16 22:31:24 +08:00
if [ " $_c_home " ] ; then
2017-01-21 12:40:43 +08:00
_c_entry = " --config-home ' $_c_home ' "
2017-01-16 22:31:24 +08:00
fi
2016-05-08 21:21:07 +08:00
_setopt " $_envfile " "export LE_WORKING_DIR" "=" " \" $LE_WORKING_DIR \" "
2017-01-21 11:28:10 +08:00
if [ " $_c_home " ] ; then
_setopt " $_envfile " "export LE_CONFIG_HOME" "=" " \" $LE_CONFIG_HOME \" "
2017-07-01 10:54:14 +08:00
else
_sed_i "/^export LE_CONFIG_HOME/d" " $_envfile "
2017-01-21 11:28:10 +08:00
fi
2017-01-21 12:40:43 +08:00
_setopt " $_envfile " " alias $PROJECT_ENTRY " "=" " \" $LE_WORKING_DIR / $PROJECT_ENTRY $_c_entry \" "
2016-05-07 17:11:01 +08:00
_profile = " $( _detect_profile) "
2016-11-09 19:30:39 +08:00
if [ " $_profile " ] ; then
2016-05-07 17:11:01 +08:00
_debug " Found profile: $_profile "
2016-10-23 15:04:52 +08:00
_info " Installing alias to ' $_profile ' "
2016-05-07 17:11:01 +08:00
_setopt " $_profile " " . \" $_envfile \" "
_info " OK, Close and reopen your terminal to start using $PROJECT_NAME "
else
_info " No profile is found, you will need to go into $LE_WORKING_DIR to use $PROJECT_NAME "
fi
#for csh
_cshfile = " $LE_WORKING_DIR / $PROJECT_ENTRY .csh "
_csh_profile = " $HOME /.cshrc "
2016-11-09 19:30:39 +08:00
if [ -f " $_csh_profile " ] ; then
2016-10-23 15:04:52 +08:00
_info " Installing alias to ' $_csh_profile ' "
2016-05-08 00:44:03 +08:00
_setopt " $_cshfile " "setenv LE_WORKING_DIR" " " " \" $LE_WORKING_DIR \" "
2017-01-21 11:28:10 +08:00
if [ " $_c_home " ] ; then
_setopt " $_cshfile " "setenv LE_CONFIG_HOME" " " " \" $LE_CONFIG_HOME \" "
2017-07-01 10:54:14 +08:00
else
_sed_i "/^setenv LE_CONFIG_HOME/d" " $_cshfile "
2017-01-21 11:28:10 +08:00
fi
2017-01-21 12:40:43 +08:00
_setopt " $_cshfile " " alias $PROJECT_ENTRY " " " " \" $LE_WORKING_DIR / $PROJECT_ENTRY $_c_entry \" "
2016-11-09 19:30:39 +08:00
_setopt " $_csh_profile " " source \" $_cshfile \" "
2016-05-07 17:11:01 +08:00
fi
2016-11-09 19:30:39 +08:00
2016-05-09 22:28:45 +08:00
#for tcsh
_tcsh_profile = " $HOME /.tcshrc "
2016-11-09 19:30:39 +08:00
if [ -f " $_tcsh_profile " ] ; then
2016-10-23 15:04:52 +08:00
_info " Installing alias to ' $_tcsh_profile ' "
2016-05-09 22:28:45 +08:00
_setopt " $_cshfile " "setenv LE_WORKING_DIR" " " " \" $LE_WORKING_DIR \" "
2017-01-21 11:28:10 +08:00
if [ " $_c_home " ] ; then
_setopt " $_cshfile " "setenv LE_CONFIG_HOME" " " " \" $LE_CONFIG_HOME \" "
fi
2017-01-21 12:40:43 +08:00
_setopt " $_cshfile " " alias $PROJECT_ENTRY " " " " \" $LE_WORKING_DIR / $PROJECT_ENTRY $_c_entry \" "
2016-11-09 19:30:39 +08:00
_setopt " $_tcsh_profile " " source \" $_cshfile \" "
2016-05-09 22:28:45 +08:00
fi
2016-05-07 17:11:01 +08:00
}
2017-01-16 22:31:24 +08:00
# nocron confighome
2016-03-19 18:18:34 +08:00
install( ) {
2016-09-02 22:37:49 +08:00
2016-11-09 19:30:39 +08:00
if [ -z " $LE_WORKING_DIR " ] ; then
2016-09-02 22:37:49 +08:00
LE_WORKING_DIR = " $DEFAULT_INSTALL_HOME "
fi
2016-11-09 19:30:39 +08:00
2016-06-24 22:27:22 +08:00
_nocron = " $1 "
2017-01-16 22:31:24 +08:00
_c_home = " $2 "
2016-11-09 19:30:39 +08:00
if ! _initpath; then
2016-03-19 18:18:34 +08:00
_err "Install failed."
2016-03-08 20:44:12 +08:00
return 1
fi
2016-11-09 19:30:39 +08:00
if [ " $_nocron " ] ; then
2016-06-26 13:30:47 +08:00
_debug "Skip install cron job"
fi
2016-11-09 19:30:39 +08:00
2017-09-03 08:42:44 +08:00
if [ " $IN_CRON " != "1" ] ; then
if ! _precheck " $_nocron " ; then
_err "Pre-check failed, can not install."
return 1
fi
2016-03-08 20:44:12 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-06-06 10:08:09 +08:00
if [ -z " $_c_home " ] && [ " $LE_CONFIG_HOME " != " $LE_WORKING_DIR " ] ; then
_info " Using config home: $LE_CONFIG_HOME "
_c_home = " $LE_CONFIG_HOME "
fi
2016-04-14 21:44:26 +08:00
#convert from le
2016-11-09 19:30:39 +08:00
if [ -d " $HOME /.le " ] ; then
for envfile in "le.env" "le.sh.env" ; do
if [ -f " $HOME /.le/ $envfile " ] ; then
if grep "le.sh" " $HOME /.le/ $envfile " >/dev/null; then
_upgrading = "1"
_info "You are upgrading from le.sh"
_info " Renaming \" $HOME /.le\" to $LE_WORKING_DIR "
mv " $HOME /.le " " $LE_WORKING_DIR "
mv " $LE_WORKING_DIR / $envfile " " $LE_WORKING_DIR / $PROJECT_ENTRY .env "
break
2016-04-14 21:44:26 +08:00
fi
fi
done
fi
2016-03-08 20:44:12 +08:00
_info " Installing to $LE_WORKING_DIR "
2016-04-16 17:25:26 +08:00
2017-07-01 10:54:14 +08:00
if [ ! -d " $LE_WORKING_DIR " ] ; then
if ! mkdir -p " $LE_WORKING_DIR " ; then
_err " Can not create working dir: $LE_WORKING_DIR "
return 1
fi
chmod 700 " $LE_WORKING_DIR "
2016-03-27 20:31:22 +08:00
fi
2016-11-09 19:30:39 +08:00
2017-07-01 10:54:14 +08:00
if [ ! -d " $LE_CONFIG_HOME " ] ; then
if ! mkdir -p " $LE_CONFIG_HOME " ; then
_err " Can not create config dir: $LE_CONFIG_HOME "
return 1
fi
2016-04-26 08:11:40 +08:00
2017-07-01 10:54:14 +08:00
chmod 700 " $LE_CONFIG_HOME "
2017-01-16 22:31:24 +08:00
fi
2016-11-09 21:44:46 +08:00
cp " $PROJECT_ENTRY " " $LE_WORKING_DIR / " && chmod +x " $LE_WORKING_DIR / $PROJECT_ENTRY "
2016-03-08 20:44:12 +08:00
2016-11-09 19:30:39 +08:00
if [ " $? " != "0" ] ; then
2016-04-13 20:37:18 +08:00
_err " Install failed, can not copy $PROJECT_ENTRY "
2016-03-08 20:44:12 +08:00
return 1
fi
2016-04-13 20:37:18 +08:00
_info " Installed to $LE_WORKING_DIR / $PROJECT_ENTRY "
2016-03-08 20:44:12 +08:00
2017-09-03 08:42:44 +08:00
if [ " $IN_CRON " != "1" ] ; then
_installalias " $_c_home "
fi
2016-03-08 20:44:12 +08:00
2016-11-09 19:30:39 +08:00
for subf in $_SUB_FOLDERS ; do
if [ -d " $subf " ] ; then
2016-11-09 21:44:46 +08:00
mkdir -p " $LE_WORKING_DIR / $subf "
cp " $subf " /* " $LE_WORKING_DIR " /" $subf " /
2016-10-11 20:56:59 +08:00
fi
done
2016-11-09 19:30:39 +08:00
if [ ! -f " $ACCOUNT_CONF_PATH " ] ; then
2016-03-08 20:44:12 +08:00
_initconf
fi
2016-04-14 21:44:26 +08:00
2016-11-09 19:30:39 +08:00
if [ " $_DEFAULT_ACCOUNT_CONF_PATH " != " $ACCOUNT_CONF_PATH " ] ; then
2016-04-16 17:25:26 +08:00
_setopt " $_DEFAULT_ACCOUNT_CONF_PATH " "ACCOUNT_CONF_PATH" "=" " \" $ACCOUNT_CONF_PATH \" "
2016-04-14 21:44:26 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $_DEFAULT_CERT_HOME " != " $CERT_HOME " ] ; then
2016-04-16 19:05:53 +08:00
_saveaccountconf "CERT_HOME" " $CERT_HOME "
fi
2016-11-09 19:30:39 +08:00
if [ " $_DEFAULT_ACCOUNT_KEY_PATH " != " $ACCOUNT_KEY_PATH " ] ; then
2016-04-16 19:05:53 +08:00
_saveaccountconf "ACCOUNT_KEY_PATH" " $ACCOUNT_KEY_PATH "
fi
2016-11-09 19:30:39 +08:00
if [ -z " $_nocron " ] ; then
2017-01-16 22:31:24 +08:00
installcronjob " $_c_home "
2016-06-24 22:27:22 +08:00
fi
2016-04-17 19:47:22 +08:00
2016-11-09 19:30:39 +08:00
if [ -z " $NO_DETECT_SH " ] ; then
2016-04-18 22:43:33 +08:00
#Modify shebang
2016-11-09 19:30:39 +08:00
if _exists bash; then
2018-02-07 21:12:49 +08:00
_bash_path = " $( bash -c "command -v bash 2>/dev/null" ) "
if [ -z " $_bash_path " ] ; then
_bash_path = " $( bash -c 'echo $SHELL' ) "
fi
fi
if [ " $_bash_path " ] ; then
2016-12-14 21:32:24 +01:00
_info "Good, bash is found, so change the shebang to use bash as preferred."
2018-02-07 21:12:49 +08:00
_shebang = '#!' " $_bash_path "
2016-04-18 22:43:33 +08:00
_setShebang " $LE_WORKING_DIR / $PROJECT_ENTRY " " $_shebang "
2016-11-09 19:30:39 +08:00
for subf in $_SUB_FOLDERS ; do
if [ -d " $LE_WORKING_DIR / $subf " ] ; then
for _apifile in " $LE_WORKING_DIR / $subf / " *.sh; do
2016-10-11 20:56:59 +08:00
_setShebang " $_apifile " " $_shebang "
done
fi
done
2016-04-17 19:47:22 +08:00
fi
fi
2016-03-08 20:44:12 +08:00
_info OK
}
2016-06-26 13:30:47 +08:00
# nocron
2016-03-08 20:44:12 +08:00
uninstall( ) {
2016-06-26 13:30:47 +08:00
_nocron = " $1 "
2016-11-09 19:30:39 +08:00
if [ -z " $_nocron " ] ; then
2016-06-26 13:30:47 +08:00
uninstallcronjob
fi
2016-03-08 20:44:12 +08:00
_initpath
2016-10-23 15:10:09 +08:00
_uninstallalias
2016-11-09 19:30:39 +08:00
2016-11-09 21:44:46 +08:00
rm -f " $LE_WORKING_DIR / $PROJECT_ENTRY "
2017-01-21 11:28:10 +08:00
_info " The keys and certs are in \" $( __green " $LE_CONFIG_HOME " ) \", you can remove them by yourself. "
2016-10-23 15:10:09 +08:00
}
_uninstallalias( ) {
_initpath
2016-03-08 20:44:12 +08:00
_profile = " $( _detect_profile) "
2016-11-09 19:30:39 +08:00
if [ " $_profile " ] ; then
2016-10-23 15:10:09 +08:00
_info " Uninstalling alias from: ' $_profile ' "
2016-11-09 21:44:46 +08:00
text = " $( cat " $_profile " ) "
2016-11-09 19:30:39 +08:00
echo " $text " | sed " s|^.*\" $LE_WORKING_DIR / $PROJECT_NAME .env\" $|| " >" $_profile "
2016-03-08 20:44:12 +08:00
fi
2016-05-07 17:11:01 +08:00
_csh_profile = " $HOME /.cshrc "
2016-11-09 19:30:39 +08:00
if [ -f " $_csh_profile " ] ; then
2016-10-23 15:10:09 +08:00
_info " Uninstalling alias from: ' $_csh_profile ' "
2016-11-09 21:44:46 +08:00
text = " $( cat " $_csh_profile " ) "
2016-11-09 19:30:39 +08:00
echo " $text " | sed " s|^.*\" $LE_WORKING_DIR / $PROJECT_NAME .csh\" $|| " >" $_csh_profile "
2016-05-07 17:11:01 +08:00
fi
2016-11-09 19:30:39 +08:00
2016-05-09 22:28:45 +08:00
_tcsh_profile = " $HOME /.tcshrc "
2016-11-09 19:30:39 +08:00
if [ -f " $_tcsh_profile " ] ; then
2016-10-23 15:10:09 +08:00
_info " Uninstalling alias from: ' $_csh_profile ' "
2016-11-09 21:44:46 +08:00
text = " $( cat " $_tcsh_profile " ) "
2016-11-09 19:30:39 +08:00
echo " $text " | sed " s|^.*\" $LE_WORKING_DIR / $PROJECT_NAME .csh\" $|| " >" $_tcsh_profile "
2016-05-09 22:28:45 +08:00
fi
2016-03-08 20:44:12 +08:00
}
cron( ) {
2017-09-03 08:45:58 +08:00
export IN_CRON = 1
2016-09-20 20:22:25 +08:00
_initpath
2017-03-30 21:16:25 +08:00
_info " $( __green "===Starting cron===" ) "
2016-11-09 19:30:39 +08:00
if [ " $AUTO_UPGRADE " = "1" ] ; then
2016-09-20 20:22:25 +08:00
export LE_WORKING_DIR
(
2016-11-09 19:30:39 +08:00
if ! upgrade; then
_err "Cron:Upgrade failed!"
return 1
fi
2016-09-20 20:22:25 +08:00
)
2016-11-09 21:44:46 +08:00
. " $LE_WORKING_DIR / $PROJECT_ENTRY " >/dev/null
2016-09-20 20:34:33 +08:00
2016-11-09 19:30:39 +08:00
if [ -t 1 ] ; then
2016-09-20 20:34:33 +08:00
__INTERACTIVE = "1"
fi
2016-11-09 19:30:39 +08:00
2016-09-20 20:22:25 +08:00
_info " Auto upgraded to: $VER "
fi
2016-03-08 20:44:12 +08:00
renewAll
2016-06-18 11:29:28 +08:00
_ret = " $? "
2016-04-05 21:08:19 +08:00
IN_CRON = ""
2017-03-30 21:16:25 +08:00
_info " $( __green "===End cron===" ) "
2016-09-24 13:43:08 +08:00
exit $_ret
2016-03-08 20:44:12 +08:00
}
version( ) {
2016-04-09 23:40:59 +08:00
echo " $PROJECT "
echo " v $VER "
2016-03-08 20:44:12 +08:00
}
showhelp( ) {
2016-09-20 19:08:02 +08:00
_initpath
2016-03-08 20:44:12 +08:00
version
2016-04-13 20:37:18 +08:00
echo " Usage: $PROJECT_ENTRY command ...[parameters]....
2016-04-09 23:40:59 +08:00
Commands:
--help, -h Show this help message.
--version, -v Show version info.
2016-04-13 20:37:18 +08:00
--install Install $PROJECT_NAME to your system.
--uninstall Uninstall $PROJECT_NAME , and uninstall the cron job.
2017-02-10 13:26:17 +01:00
--upgrade Upgrade $PROJECT_NAME to the latest code from $PROJECT .
2016-04-09 23:40:59 +08:00
--issue Issue a cert.
2016-08-27 13:52:13 +08:00
--signcsr Issue a cert from an existing csr.
2016-10-11 20:56:59 +08:00
--deploy Deploy the cert to your server.
2017-01-16 22:31:24 +08:00
--install-cert Install the issued cert to apache/nginx or any other server.
2016-04-09 23:40:59 +08:00
--renew, -r Renew a cert.
2017-01-16 22:31:24 +08:00
--renew-all Renew all the certs.
2016-04-09 23:40:59 +08:00
--revoke Revoke a cert.
2018-02-01 18:07:29 +01:00
--remove Remove the cert from list of certs known to $PROJECT_NAME .
2016-08-27 13:52:13 +08:00
--list List all the certs.
--showcsr Show the content of a csr.
2017-01-16 22:31:24 +08:00
--install-cronjob Install the cron job to renew certs, you don't need to call this. The ' install' command can automatically install the cron job.
--uninstall-cronjob Uninstall the cron job. The 'uninstall' command can do this automatically.
2016-04-09 23:40:59 +08:00
--cron Run cron job to renew all the certs.
--toPkcs Export the certificate and key to a pfx file.
2017-02-25 19:31:52 +08:00
--toPkcs8 Convert to pkcs8 format.
2017-01-16 22:31:24 +08:00
--update-account Update account info.
--register-account Register account key.
2017-07-02 17:02:54 +08:00
--deactivate-account Deactivate the account.
2017-02-11 13:36:52 +08:00
--create-account-key Create an account private key, professional use.
--create-domain-key Create an domain private key, professional use.
2016-04-09 23:40:59 +08:00
--createCSR, -ccsr Create CSR , professional use.
2016-09-22 23:17:50 +08:00
--deactivate Deactivate the domain authz, professional use.
2017-04-17 19:08:34 +08:00
2016-04-09 23:40:59 +08:00
Parameters:
--domain, -d domain.tld Specifies a domain, used to issue, renew or revoke etc.
--force, -f Used to force to install or force to renew a cert immediately.
--staging, --test Use staging server, just for test.
--debug Output debug info.
2017-02-19 13:24:00 +08:00
--output-insecure Output all the sensitive messages. By default all the credentials/sensitive messages are hidden from the output/debug/log for secure.
2016-04-09 23:40:59 +08:00
--webroot, -w /path/to/webroot Specifies the web root folder for web root mode.
--standalone Use standalone mode.
2017-02-06 20:42:54 +08:00
--stateless Use stateless mode, see: $_STATELESS_WIKI
2016-06-17 13:23:44 +08:00
--tls Use standalone tls mode.
2016-04-09 23:40:59 +08:00
--apache Use apache mode.
2016-04-16 22:19:29 +08:00
--dns [ dns_cf| dns_dp| dns_cx| /path/to/api/file] Use dns mode or dns api.
2016-07-15 22:56:16 +08:00
--dnssleep [ $DEFAULT_DNS_SLEEP ] The time in seconds to wait for all the txt records to take effect in dns api mode. Default $DEFAULT_DNS_SLEEP seconds.
2017-04-17 19:08:34 +08:00
2016-04-09 23:40:59 +08:00
--keylength, -k [ 2048] Specifies the domain key length: 2048, 3072, 4096, 8192 or ec-256, ec-384.
--accountkeylength, -ak [ 2048] Specifies the account key length.
2016-09-20 19:08:02 +08:00
--log [ /path/to/logfile] Specifies the log file. The default is: \" $DEFAULT_LOG_FILE \" if you don' t give a file path here.
2016-09-25 21:58:59 +08:00
--log-level 1| 2 Specifies the log level, default is 1.
2017-02-19 12:55:05 +08:00
--syslog [ 0| 3| 6| 7] Syslog level, 0: disable syslog, 3: error, 6: info, 7: debug.
2017-04-17 19:08:34 +08:00
2016-04-09 23:40:59 +08:00
These parameters are to install the cert to nginx/apache or anyother server after issue/renew a cert:
2017-04-17 19:08:34 +08:00
2017-03-22 22:58:03 +08:00
--cert-file After issue/renew, the cert will be copied to this path.
--key-file After issue/renew, the key will be copied to this path.
--ca-file After issue/renew, the intermediate cert will be copied to this path.
--fullchain-file After issue/renew, the fullchain cert will be copied to this path.
2017-04-17 19:08:34 +08:00
2016-04-09 23:40:59 +08:00
--reloadcmd \" service nginx reload\" After issue/renew, it' s used to reload the server.
2017-06-17 15:49:45 +08:00
--server SERVER ACME Directory Resource URI. ( default: https://acme-v01.api.letsencrypt.org/directory)
2016-04-09 23:40:59 +08:00
--accountconf Specifies a customized account config file.
2016-04-16 17:25:26 +08:00
--home Specifies the home dir for $PROJECT_NAME .
2017-01-16 22:31:24 +08:00
--cert-home Specifies the home dir to save all the certs, only valid for '--install' command.
--config-home Specifies the home dir to save all the configurations.
2016-04-16 17:25:26 +08:00
--useragent Specifies the user agent string. it will be saved for future use too.
2016-04-16 17:56:45 +08:00
--accountemail Specifies the account email for registering, Only valid for the '--install' command.
2016-04-16 18:15:36 +08:00
--accountkey Specifies the account key path, Only valid for the '--install' command.
2016-06-26 10:09:51 +08:00
--days Specifies the days to renew the cert when using '--issue' command. The max value is $MAX_RENEW days.
2016-05-29 14:08:39 +08:00
--httpport Specifies the standalone listening port. Only valid if the server is behind a reverse proxy or load balancer.
2016-06-17 13:23:44 +08:00
--tlsport Specifies the standalone tls listening port. Only valid if the server is behind a reverse proxy or load balancer.
2016-10-02 23:37:37 +08:00
--local-address Specifies the standalone/tls server listening address, in case you have multiple ip addresses.
2016-06-14 13:07:33 +08:00
--listraw Only used for '--list' command, list the certs in raw format.
2017-01-16 22:31:24 +08:00
--stopRenewOnError, -se Only valid for '--renew-all' command. Stop if one cert has error in renewal.
2016-06-20 18:35:40 +08:00
--insecure Do not check the server certificate, in some devices, the api server' s certificate may not be trusted.
2017-03-26 05:31:12 +00:00
--ca-bundle Specifies the path to the CA certificate bundle to verify api server' s certificate.
2017-03-22 22:58:03 +08:00
--ca-path Specifies directory containing CA certificates in PEM format, used by wget or curl.
2016-06-27 10:32:51 +08:00
--nocron Only valid for '--install' command, which means: do not install the default cron job. In this case , the certs will not be renewed automatically.
2017-06-18 22:13:33 +08:00
--no-color Do not output color text.
2017-01-16 22:31:24 +08:00
--ecc Specifies to use the ECC cert. Valid for '--install-cert' , '--renew' , '--revoke' , '--toPkcs' and '--createCSR'
2016-08-27 13:52:13 +08:00
--csr Specifies the input csr.
2016-09-06 23:26:22 +08:00
--pre-hook Command to be run before obtaining any certificates.
2017-03-26 05:28:37 +00:00
--post-hook Command to be run after attempting to obtain/renew certificates. No matter the obtain/renew is success or failed.
2016-09-06 23:26:22 +08:00
--renew-hook Command to be run once for each successfully renewed certificate.
2016-10-11 20:56:59 +08:00
--deploy-hook The hook file to deploy cert
2016-09-15 10:41:47 +08:00
--ocsp-must-staple, --ocsp Generate ocsp must Staple extension.
2017-07-02 15:25:35 +08:00
--always-force-new-domain-key Generate new domain key when renewal. Otherwise, the domain key is not changed by default.
2016-09-28 22:05:43 +08:00
--auto-upgrade [ 0| 1] Valid for '--upgrade' command, indicating whether to upgrade automatically in future.
2016-10-02 23:37:37 +08:00
--listen-v4 Force standalone/tls server to listen at ipv4.
--listen-v6 Force standalone/tls server to listen at ipv6.
2016-11-22 21:43:42 +08:00
--openssl-bin Specifies a custom openssl bin location.
2017-02-27 20:48:48 +08:00
--use-wget Force to use wget, if you have both curl and wget installed.
2016-03-08 20:44:12 +08:00
"
}
2016-06-26 13:30:47 +08:00
# nocron
2016-03-27 20:31:22 +08:00
_installOnline( ) {
_info "Installing from online archive."
2016-06-26 13:30:47 +08:00
_nocron = " $1 "
2016-11-09 19:30:39 +08:00
if [ ! " $BRANCH " ] ; then
2016-03-27 20:31:22 +08:00
BRANCH = "master"
fi
2016-08-15 21:14:36 +08:00
2016-03-27 20:31:22 +08:00
target = " $PROJECT /archive/ $BRANCH .tar.gz "
_info " Downloading $target "
localname = " $BRANCH .tar.gz "
2016-11-09 19:30:39 +08:00
if ! _get " $target " >$localname ; then
2016-08-15 19:15:19 +08:00
_err "Download error."
2016-03-27 20:31:22 +08:00
return 1
fi
2016-07-03 12:46:18 +08:00
(
2016-11-09 19:30:39 +08:00
_info " Extracting $localname "
2016-12-21 20:38:14 +08:00
if ! ( tar xzf $localname || gtar xzf $localname ) ; then
_err "Extraction error."
exit 1
fi
2016-11-09 19:30:39 +08:00
cd " $PROJECT_NAME - $BRANCH "
chmod +x $PROJECT_ENTRY
if ./$PROJECT_ENTRY install " $_nocron " ; then
_info "Install success!"
fi
cd ..
rm -rf " $PROJECT_NAME - $BRANCH "
rm -f " $localname "
2016-07-03 12:46:18 +08:00
)
2016-03-27 20:31:22 +08:00
}
2016-06-26 13:30:47 +08:00
upgrade( ) {
if (
2016-09-18 13:06:15 +08:00
_initpath
export LE_WORKING_DIR
2016-07-02 13:46:35 +08:00
cd " $LE_WORKING_DIR "
2016-06-26 13:30:47 +08:00
_installOnline "nocron"
2016-11-09 19:30:39 +08:00
) ; then
2016-06-26 13:30:47 +08:00
_info "Upgrade success!"
2016-07-04 20:40:29 +08:00
exit 0
2016-06-26 13:30:47 +08:00
else
_err "Upgrade failed!"
2016-07-04 20:40:29 +08:00
exit 1
2016-06-26 13:30:47 +08:00
fi
}
2016-04-09 23:40:59 +08:00
2016-09-19 23:07:43 +08:00
_processAccountConf( ) {
2016-11-09 19:30:39 +08:00
if [ " $_useragent " ] ; then
2016-09-19 23:07:43 +08:00
_saveaccountconf "USER_AGENT" " $_useragent "
2016-11-09 19:30:39 +08:00
elif [ " $USER_AGENT " ] && [ " $USER_AGENT " != " $DEFAULT_USER_AGENT " ] ; then
2016-09-20 19:08:02 +08:00
_saveaccountconf "USER_AGENT" " $USER_AGENT "
2016-09-19 23:07:43 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $_accountemail " ] ; then
2016-09-19 23:07:43 +08:00
_saveaccountconf "ACCOUNT_EMAIL" " $_accountemail "
2016-11-09 19:30:39 +08:00
elif [ " $ACCOUNT_EMAIL " ] && [ " $ACCOUNT_EMAIL " != " $DEFAULT_ACCOUNT_EMAIL " ] ; then
2016-09-20 19:08:02 +08:00
_saveaccountconf "ACCOUNT_EMAIL" " $ACCOUNT_EMAIL "
2016-09-19 23:07:43 +08:00
fi
2016-11-09 19:30:39 +08:00
2016-11-22 21:43:42 +08:00
if [ " $_openssl_bin " ] ; then
2017-02-25 19:08:00 +08:00
_saveaccountconf "ACME_OPENSSL_BIN" " $_openssl_bin "
elif [ " $ACME_OPENSSL_BIN " ] && [ " $ACME_OPENSSL_BIN " != " $DEFAULT_OPENSSL_BIN " ] ; then
_saveaccountconf "ACME_OPENSSL_BIN" " $ACME_OPENSSL_BIN "
2016-11-22 21:43:42 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $_auto_upgrade " ] ; then
2016-09-28 22:05:43 +08:00
_saveaccountconf "AUTO_UPGRADE" " $_auto_upgrade "
2016-11-09 19:30:39 +08:00
elif [ " $AUTO_UPGRADE " ] ; then
2016-09-28 22:05:43 +08:00
_saveaccountconf "AUTO_UPGRADE" " $AUTO_UPGRADE "
fi
2016-11-09 19:30:39 +08:00
2017-02-27 20:48:48 +08:00
if [ " $_use_wget " ] ; then
_saveaccountconf "ACME_USE_WGET" " $_use_wget "
elif [ " $ACME_USE_WGET " ] ; then
_saveaccountconf "ACME_USE_WGET" " $ACME_USE_WGET "
fi
2016-09-19 23:07:43 +08:00
}
2016-04-09 23:40:59 +08:00
_process( ) {
_CMD = ""
_domain = ""
2016-09-23 22:35:13 +08:00
_altdomains = " $NO_VALUE "
2016-04-09 23:40:59 +08:00
_webroot = ""
2016-07-09 17:25:27 +08:00
_keylength = ""
_accountkeylength = ""
2017-03-22 21:20:35 +08:00
_cert_file = ""
_key_file = ""
_ca_file = ""
_fullchain_file = ""
2016-04-27 22:14:15 +08:00
_reloadcmd = ""
2016-04-09 23:40:59 +08:00
_password = ""
2016-04-16 17:25:26 +08:00
_accountconf = ""
_useragent = ""
2016-04-16 17:56:45 +08:00
_accountemail = ""
_accountkey = ""
2016-04-16 19:05:53 +08:00
_certhome = ""
2017-01-16 22:31:24 +08:00
_confighome = ""
2016-05-29 14:08:39 +08:00
_httpport = ""
2016-06-17 13:23:44 +08:00
_tlsport = ""
2016-06-13 10:13:20 +08:00
_dnssleep = ""
2016-06-14 13:07:33 +08:00
_listraw = ""
2016-06-18 11:29:28 +08:00
_stopRenewOnError = ""
2016-11-11 21:15:48 +08:00
#_insecure=""
2016-08-25 01:14:56 -04:00
_ca_bundle = ""
2017-03-19 16:10:09 +01:00
_ca_path = ""
2016-06-24 22:27:22 +08:00
_nocron = ""
2016-08-13 19:22:25 +08:00
_ecc = ""
2016-08-27 13:52:13 +08:00
_csr = ""
2016-09-06 23:26:22 +08:00
_pre_hook = ""
_post_hook = ""
_renew_hook = ""
2016-10-11 20:56:59 +08:00
_deploy_hook = ""
2016-09-19 23:07:43 +08:00
_logfile = ""
2016-09-20 19:08:02 +08:00
_log = ""
2016-09-23 23:14:03 +08:00
_local_address = ""
2016-09-25 21:58:59 +08:00
_log_level = ""
2016-09-28 22:05:43 +08:00
_auto_upgrade = ""
2016-10-02 23:37:37 +08:00
_listen_v4 = ""
_listen_v6 = ""
2016-11-22 21:43:42 +08:00
_openssl_bin = ""
2017-02-11 21:15:36 +08:00
_syslog = ""
2017-02-27 20:48:48 +08:00
_use_wget = ""
2017-06-19 20:19:30 +08:00
_server = ""
2016-11-09 19:30:39 +08:00
while [ ${# } -gt 0 ] ; do
2016-04-09 23:40:59 +08:00
case " ${ 1 } " in
2016-11-09 19:30:39 +08:00
--help | -h)
2016-04-09 23:40:59 +08:00
showhelp
return
; ;
2016-11-09 19:30:39 +08:00
--version | -v)
2016-04-09 23:40:59 +08:00
version
return
; ;
2016-11-09 19:30:39 +08:00
--install)
2016-04-09 23:40:59 +08:00
_CMD = "install"
; ;
2016-11-09 19:30:39 +08:00
--uninstall)
2016-04-09 23:40:59 +08:00
_CMD = "uninstall"
; ;
2016-11-09 19:30:39 +08:00
--upgrade)
2016-06-26 13:30:47 +08:00
_CMD = "upgrade"
; ;
2016-11-09 19:30:39 +08:00
--issue)
2016-04-09 23:40:59 +08:00
_CMD = "issue"
; ;
2016-11-09 19:30:39 +08:00
--deploy)
2016-10-11 20:56:59 +08:00
_CMD = "deploy"
; ;
2016-11-09 19:30:39 +08:00
--signcsr)
2016-08-27 13:52:13 +08:00
_CMD = "signcsr"
; ;
2016-11-09 19:30:39 +08:00
--showcsr)
2016-08-27 13:52:13 +08:00
_CMD = "showcsr"
; ;
2017-01-17 13:06:44 +08:00
--installcert | -i | --install-cert)
2016-04-09 23:40:59 +08:00
_CMD = "installcert"
; ;
2016-11-09 19:30:39 +08:00
--renew | -r)
2016-04-09 23:40:59 +08:00
_CMD = "renew"
; ;
2017-01-17 13:06:44 +08:00
--renewAll | --renewall | --renew-all)
2016-04-09 23:40:59 +08:00
_CMD = "renewAll"
; ;
2016-11-09 19:30:39 +08:00
--revoke)
2016-04-09 23:40:59 +08:00
_CMD = "revoke"
; ;
2017-01-21 13:32:12 +08:00
--remove)
_CMD = "remove"
; ;
2016-11-09 19:30:39 +08:00
--list)
2016-06-09 14:18:54 +08:00
_CMD = "list"
; ;
2017-01-17 13:04:02 +08:00
--installcronjob | --install-cronjob)
2016-04-09 23:40:59 +08:00
_CMD = "installcronjob"
; ;
2017-01-17 13:06:44 +08:00
--uninstallcronjob | --uninstall-cronjob)
2016-04-09 23:40:59 +08:00
_CMD = "uninstallcronjob"
; ;
2016-11-09 19:30:39 +08:00
--cron)
2016-04-09 23:40:59 +08:00
_CMD = "cron"
; ;
2016-11-09 19:30:39 +08:00
--toPkcs)
2016-04-09 23:40:59 +08:00
_CMD = "toPkcs"
2016-11-09 19:30:39 +08:00
; ;
2017-02-25 19:31:52 +08:00
--toPkcs8)
_CMD = "toPkcs8"
2017-02-25 21:09:06 +08:00
; ;
2017-02-11 13:36:52 +08:00
--createAccountKey | --createaccountkey | -cak | --create-account-key)
2016-04-09 23:40:59 +08:00
_CMD = "createAccountKey"
; ;
2017-02-11 13:36:52 +08:00
--createDomainKey | --createdomainkey | -cdk | --create-domain-key)
2016-04-09 23:40:59 +08:00
_CMD = "createDomainKey"
; ;
2016-11-09 19:30:39 +08:00
--createCSR | --createcsr | -ccr)
2016-04-09 23:40:59 +08:00
_CMD = "createCSR"
; ;
2016-11-09 19:30:39 +08:00
--deactivate)
2016-09-22 23:17:50 +08:00
_CMD = "deactivate"
; ;
2017-01-17 13:04:02 +08:00
--updateaccount | --update-account)
2016-09-25 10:56:06 +08:00
_CMD = "updateaccount"
; ;
2017-01-17 13:04:02 +08:00
--registeraccount | --register-account)
2016-09-25 10:56:06 +08:00
_CMD = "registeraccount"
; ;
2017-07-02 17:02:54 +08:00
--deactivate-account)
_CMD = "deactivateaccount"
; ;
2016-11-09 19:30:39 +08:00
--domain | -d)
2016-04-09 23:40:59 +08:00
_dvalue = " $2 "
2016-11-09 19:30:39 +08:00
if [ " $_dvalue " ] ; then
if _startswith " $_dvalue " "-" ; then
2016-06-09 12:45:30 +08:00
_err " ' $_dvalue ' is not a valid domain for parameter ' $1 ' "
return 1
fi
2016-11-09 19:30:39 +08:00
if _is_idn " $_dvalue " && ! _exists idn; then
2016-10-23 14:56:52 +08:00
_err " It seems that $_dvalue is an IDN( Internationalized Domain Names), please install 'idn' command first. "
return 1
fi
2016-11-09 19:30:39 +08:00
2018-01-15 21:55:40 +08:00
if _startswith " $_dvalue " "*." ; then
_debug "Wildcard domain"
export ACME_VERSION = 2
fi
2016-11-09 19:30:39 +08:00
if [ -z " $_domain " ] ; then
2016-06-09 12:45:30 +08:00
_domain = " $_dvalue "
2016-04-09 23:40:59 +08:00
else
2016-11-09 19:30:39 +08:00
if [ " $_altdomains " = " $NO_VALUE " ] ; then
2016-06-09 12:45:30 +08:00
_altdomains = " $_dvalue "
else
_altdomains = " $_altdomains , $_dvalue "
fi
2016-04-09 23:40:59 +08:00
fi
fi
2016-11-09 19:30:39 +08:00
2016-04-09 23:40:59 +08:00
shift
; ;
2016-11-09 19:30:39 +08:00
--force | -f)
2016-04-09 23:40:59 +08:00
FORCE = "1"
; ;
2016-11-09 19:30:39 +08:00
--staging | --test)
2016-04-09 23:40:59 +08:00
STAGE = "1"
; ;
2017-06-17 15:49:45 +08:00
--server)
ACME_DIRECTORY = " $2 "
2017-06-19 20:19:30 +08:00
_server = " $ACME_DIRECTORY "
2017-06-17 15:49:45 +08:00
export ACME_DIRECTORY
shift
; ;
2016-11-09 19:30:39 +08:00
--debug)
if [ -z " $2 " ] || _startswith " $2 " "-" ; then
2017-02-19 12:13:18 +08:00
DEBUG = " $DEBUG_LEVEL_DEFAULT "
2016-04-09 23:40:59 +08:00
else
DEBUG = " $2 "
shift
2016-11-09 19:30:39 +08:00
fi
2016-04-09 23:40:59 +08:00
; ;
2017-02-19 13:24:00 +08:00
--output-insecure)
export OUTPUT_INSECURE = 1
; ;
2016-11-09 19:30:39 +08:00
--webroot | -w)
2016-04-09 23:40:59 +08:00
wvalue = " $2 "
2016-11-09 19:30:39 +08:00
if [ -z " $_webroot " ] ; then
2016-04-09 23:40:59 +08:00
_webroot = " $wvalue "
else
_webroot = " $_webroot , $wvalue "
fi
shift
2016-11-09 19:30:39 +08:00
; ;
--standalone)
2016-09-23 22:35:13 +08:00
wvalue = " $NO_VALUE "
2016-11-09 19:30:39 +08:00
if [ -z " $_webroot " ] ; then
2016-04-09 23:40:59 +08:00
_webroot = " $wvalue "
else
_webroot = " $_webroot , $wvalue "
fi
; ;
2017-02-06 20:42:54 +08:00
--stateless)
wvalue = " $MODE_STATELESS "
if [ -z " $_webroot " ] ; then
_webroot = " $wvalue "
else
_webroot = " $_webroot , $wvalue "
fi
; ;
2016-11-09 19:30:39 +08:00
--local-address)
2016-09-23 23:14:03 +08:00
lvalue = " $2 "
_local_address = " $_local_address $lvalue , "
shift
; ;
2016-11-09 19:30:39 +08:00
--apache)
2016-04-09 23:40:59 +08:00
wvalue = "apache"
2016-11-09 19:30:39 +08:00
if [ -z " $_webroot " ] ; then
2016-04-09 23:40:59 +08:00
_webroot = " $wvalue "
else
_webroot = " $_webroot , $wvalue "
fi
; ;
2017-02-13 23:29:37 +08:00
--nginx)
wvalue = " $NGINX "
if [ -z " $_webroot " ] ; then
_webroot = " $wvalue "
else
_webroot = " $_webroot , $wvalue "
fi
; ;
2016-11-09 19:30:39 +08:00
--tls)
2016-06-17 13:23:44 +08:00
wvalue = " $W_TLS "
2016-11-09 19:30:39 +08:00
if [ -z " $_webroot " ] ; then
2016-06-17 13:23:44 +08:00
_webroot = " $wvalue "
else
_webroot = " $_webroot , $wvalue "
fi
; ;
2016-11-09 19:30:39 +08:00
--dns)
2016-04-09 23:40:59 +08:00
wvalue = "dns"
2017-07-29 15:23:31 +08:00
if [ " $2 " ] && ! _startswith " $2 " "-" ; then
2016-04-09 23:40:59 +08:00
wvalue = " $2 "
shift
fi
2016-11-09 19:30:39 +08:00
if [ -z " $_webroot " ] ; then
2016-04-09 23:40:59 +08:00
_webroot = " $wvalue "
else
_webroot = " $_webroot , $wvalue "
fi
; ;
2016-11-09 19:30:39 +08:00
--dnssleep)
2016-06-13 10:13:20 +08:00
_dnssleep = " $2 "
Le_DNSSleep = " $_dnssleep "
shift
; ;
2016-11-09 19:30:39 +08:00
--keylength | -k)
2016-04-09 23:40:59 +08:00
_keylength = " $2 "
shift
; ;
2016-11-09 19:30:39 +08:00
--accountkeylength | -ak)
2016-06-23 14:11:43 +02:00
_accountkeylength = " $2 "
2016-04-09 23:40:59 +08:00
shift
; ;
2017-03-22 21:20:35 +08:00
--cert-file | --certpath)
_cert_file = " $2 "
2016-04-09 23:40:59 +08:00
shift
; ;
2017-03-22 21:20:35 +08:00
--key-file | --keypath)
_key_file = " $2 "
2016-04-09 23:40:59 +08:00
shift
; ;
2017-03-22 21:20:35 +08:00
--ca-file | --capath)
_ca_file = " $2 "
2016-04-09 23:40:59 +08:00
shift
; ;
2017-03-22 21:20:35 +08:00
--fullchain-file | --fullchainpath)
_fullchain_file = " $2 "
2016-04-09 23:40:59 +08:00
shift
; ;
2016-11-09 19:30:39 +08:00
--reloadcmd | --reloadCmd)
2016-04-09 23:40:59 +08:00
_reloadcmd = " $2 "
shift
; ;
2016-11-09 19:30:39 +08:00
--password)
2016-04-09 23:40:59 +08:00
_password = " $2 "
shift
; ;
2016-11-09 19:30:39 +08:00
--accountconf)
2016-04-16 17:25:26 +08:00
_accountconf = " $2 "
ACCOUNT_CONF_PATH = " $_accountconf "
2016-04-13 20:37:18 +08:00
shift
2016-04-09 23:40:59 +08:00
; ;
2016-11-09 19:30:39 +08:00
--home)
2016-04-09 23:40:59 +08:00
LE_WORKING_DIR = " $2 "
2016-04-13 20:37:18 +08:00
shift
2016-04-09 23:40:59 +08:00
; ;
2017-01-17 13:04:02 +08:00
--certhome | --cert-home)
2016-04-16 19:05:53 +08:00
_certhome = " $2 "
CERT_HOME = " $_certhome "
shift
2016-11-09 19:30:39 +08:00
; ;
2017-01-16 22:31:24 +08:00
--config-home)
_confighome = " $2 "
2017-01-21 11:28:10 +08:00
LE_CONFIG_HOME = " $_confighome "
2017-01-16 22:31:24 +08:00
shift
; ;
2016-11-09 19:30:39 +08:00
--useragent)
2016-04-16 17:25:26 +08:00
_useragent = " $2 "
USER_AGENT = " $_useragent "
shift
; ;
2016-11-09 19:30:39 +08:00
--accountemail)
2016-04-16 17:56:45 +08:00
_accountemail = " $2 "
ACCOUNT_EMAIL = " $_accountemail "
shift
; ;
2016-11-09 19:30:39 +08:00
--accountkey)
2016-04-16 17:56:45 +08:00
_accountkey = " $2 "
ACCOUNT_KEY_PATH = " $_accountkey "
shift
; ;
2016-11-09 19:30:39 +08:00
--days)
2016-04-16 18:15:36 +08:00
_days = " $2 "
Le_RenewalDays = " $_days "
shift
; ;
2016-11-09 19:30:39 +08:00
--httpport)
2016-05-29 14:08:39 +08:00
_httpport = " $2 "
Le_HTTPPort = " $_httpport "
shift
; ;
2016-11-09 19:30:39 +08:00
--tlsport)
2016-06-17 13:23:44 +08:00
_tlsport = " $2 "
Le_TLSPort = " $_tlsport "
shift
; ;
2016-11-09 19:30:39 +08:00
--listraw)
2016-06-14 13:07:33 +08:00
_listraw = "raw"
2016-11-09 19:30:39 +08:00
; ;
--stopRenewOnError | --stoprenewonerror | -se)
2016-06-18 11:29:28 +08:00
_stopRenewOnError = "1"
; ;
2016-11-09 19:30:39 +08:00
--insecure)
2016-11-11 21:15:48 +08:00
#_insecure="1"
2016-08-14 22:37:21 +08:00
HTTPS_INSECURE = "1"
2016-06-20 18:35:40 +08:00
; ;
2016-11-09 19:30:39 +08:00
--ca-bundle)
2018-01-17 19:21:14 +01:00
_ca_bundle = " $( _readlink " $2 " ) "
2016-08-25 01:14:56 -04:00
CA_BUNDLE = " $_ca_bundle "
shift
; ;
2017-03-19 16:10:09 +01:00
--ca-path)
_ca_path = " $2 "
CA_PATH = " $_ca_path "
shift
; ;
2016-11-09 19:30:39 +08:00
--nocron)
2016-06-24 22:27:22 +08:00
_nocron = "1"
; ;
2017-06-18 22:13:33 +08:00
--no-color)
export ACME_NO_COLOR = 1
; ;
2016-11-09 19:30:39 +08:00
--ecc)
2016-08-13 19:22:25 +08:00
_ecc = "isEcc"
; ;
2016-11-09 19:30:39 +08:00
--csr)
2016-08-27 13:52:13 +08:00
_csr = " $2 "
shift
; ;
2016-11-09 19:30:39 +08:00
--pre-hook)
2016-09-06 23:26:22 +08:00
_pre_hook = " $2 "
shift
; ;
2016-11-09 19:30:39 +08:00
--post-hook)
2016-09-06 23:26:22 +08:00
_post_hook = " $2 "
shift
; ;
2016-11-09 19:30:39 +08:00
--renew-hook)
2016-09-06 23:26:22 +08:00
_renew_hook = " $2 "
shift
; ;
2016-11-09 19:30:39 +08:00
--deploy-hook)
2017-02-19 20:15:00 +08:00
if [ -z " $2 " ] || _startswith " $2 " "-" ; then
_usage "Please specify a value for '--deploy-hook'"
return 1
fi
_deploy_hook = " $_deploy_hook $2 , "
2016-10-11 20:56:59 +08:00
shift
; ;
2016-11-09 19:30:39 +08:00
--ocsp-must-staple | --ocsp)
2016-12-18 03:17:35 +01:00
Le_OCSP_Staple = "1"
2016-09-15 10:41:47 +08:00
; ;
2017-07-02 15:25:35 +08:00
--always-force-new-domain-key)
if [ -z " $2 " ] || _startswith " $2 " "-" ; then
Le_ForceNewDomainKey = 1
else
Le_ForceNewDomainKey = " $2 "
shift
fi
; ;
2016-11-09 19:30:39 +08:00
--log | --logfile)
2016-09-20 19:08:02 +08:00
_log = "1"
2016-09-19 23:07:43 +08:00
_logfile = " $2 "
2016-11-09 19:30:39 +08:00
if _startswith " $_logfile " '-' ; then
2016-09-20 19:08:02 +08:00
_logfile = ""
else
shift
fi
2016-09-19 23:07:43 +08:00
LOG_FILE = " $_logfile "
2016-11-09 19:30:39 +08:00
if [ -z " $LOG_LEVEL " ] ; then
2016-09-25 21:58:59 +08:00
LOG_LEVEL = " $DEFAULT_LOG_LEVEL "
fi
; ;
2016-11-09 19:30:39 +08:00
--log-level)
2016-09-27 13:11:08 +08:00
_log_level = " $2 "
2016-09-25 21:58:59 +08:00
LOG_LEVEL = " $_log_level "
shift
2016-09-19 23:07:43 +08:00
; ;
2017-02-11 21:15:36 +08:00
--syslog)
if ! _startswith " $2 " '-' ; then
_syslog = " $2 "
shift
fi
if [ -z " $_syslog " ] ; then
2017-02-19 12:13:18 +08:00
_syslog = " $SYSLOG_LEVEL_DEFAULT "
2017-02-11 21:15:36 +08:00
fi
; ;
2016-11-09 19:30:39 +08:00
--auto-upgrade)
2016-09-28 22:05:43 +08:00
_auto_upgrade = " $2 "
2016-11-09 19:30:39 +08:00
if [ -z " $_auto_upgrade " ] || _startswith " $_auto_upgrade " '-' ; then
2016-09-28 22:05:43 +08:00
_auto_upgrade = "1"
else
shift
fi
AUTO_UPGRADE = " $_auto_upgrade "
; ;
2016-11-09 19:30:39 +08:00
--listen-v4)
2016-10-02 23:37:37 +08:00
_listen_v4 = "1"
Le_Listen_V4 = " $_listen_v4 "
; ;
2016-11-09 19:30:39 +08:00
--listen-v6)
2016-10-02 23:37:37 +08:00
_listen_v6 = "1"
Le_Listen_V6 = " $_listen_v6 "
; ;
2016-11-22 21:43:42 +08:00
--openssl-bin)
_openssl_bin = " $2 "
2017-02-25 19:08:00 +08:00
ACME_OPENSSL_BIN = " $_openssl_bin "
2017-02-26 22:20:08 +08:00
shift
2016-11-22 21:43:42 +08:00
; ;
2017-02-27 20:48:48 +08:00
--use-wget)
_use_wget = "1"
ACME_USE_WGET = "1"
; ;
2016-11-09 19:30:39 +08:00
*)
2016-04-09 23:40:59 +08:00
_err " Unknown parameter : $1 "
return 1
; ;
esac
shift 1
done
2016-11-09 19:30:39 +08:00
if [ " ${ _CMD } " != "install" ] ; then
2016-09-19 23:07:43 +08:00
__initHome
2016-10-12 21:48:18 +08:00
if [ " $_log " ] ; then
2016-11-09 19:30:39 +08:00
if [ -z " $_logfile " ] ; then
2016-10-12 21:48:18 +08:00
_logfile = " $DEFAULT_LOG_FILE "
fi
2016-09-20 19:08:02 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $_logfile " ] ; then
2016-09-19 23:07:43 +08:00
_saveaccountconf "LOG_FILE" " $_logfile "
2016-10-12 21:48:18 +08:00
LOG_FILE = " $_logfile "
2016-09-19 23:07:43 +08:00
fi
2016-09-25 21:58:59 +08:00
2016-11-09 19:30:39 +08:00
if [ " $_log_level " ] ; then
2016-09-25 21:58:59 +08:00
_saveaccountconf "LOG_LEVEL" " $_log_level "
LOG_LEVEL = " $_log_level "
fi
2016-11-09 19:30:39 +08:00
2017-02-11 21:15:36 +08:00
if [ " $_syslog " ] ; then
if _exists logger; then
if [ " $_syslog " = "0" ] ; then
_clearaccountconf "SYS_LOG"
else
_saveaccountconf "SYS_LOG" " $_syslog "
fi
SYS_LOG = " $_syslog "
else
_err "The 'logger' command is not found, can not enable syslog."
_clearaccountconf "SYS_LOG"
SYS_LOG = ""
fi
fi
2016-09-19 23:07:43 +08:00
_processAccountConf
fi
2016-11-09 19:30:39 +08:00
2016-11-04 22:03:41 +08:00
_debug2 LE_WORKING_DIR " $LE_WORKING_DIR "
2016-11-09 19:30:39 +08:00
if [ " $DEBUG " ] ; then
2016-07-15 16:40:03 +08:00
version
2017-06-19 20:19:30 +08:00
if [ " $_server " ] ; then
_debug " Using server: $_server "
fi
2016-07-15 16:40:03 +08:00
fi
2016-04-09 23:40:59 +08:00
case " ${ _CMD } " in
2017-01-16 22:31:24 +08:00
install) install " $_nocron " " $_confighome " ; ;
2016-06-27 10:32:51 +08:00
uninstall) uninstall " $_nocron " ; ;
2016-06-26 13:30:47 +08:00
upgrade) upgrade ; ;
2016-04-09 23:40:59 +08:00
issue)
2017-03-22 21:20:35 +08:00
issue " $_webroot " " $_domain " " $_altdomains " " $_keylength " " $_cert_file " " $_key_file " " $_ca_file " " $_reloadcmd " " $_fullchain_file " " $_pre_hook " " $_post_hook " " $_renew_hook " " $_local_address "
2016-04-09 23:40:59 +08:00
; ;
2016-10-11 20:56:59 +08:00
deploy)
deploy " $_domain " " $_deploy_hook " " $_ecc "
; ;
2016-08-27 13:52:13 +08:00
signcsr)
signcsr " $_csr " " $_webroot "
; ;
showcsr)
showcsr " $_csr " " $_domain "
; ;
2016-04-09 23:40:59 +08:00
installcert)
2017-03-22 21:20:35 +08:00
installcert " $_domain " " $_cert_file " " $_key_file " " $_ca_file " " $_reloadcmd " " $_fullchain_file " " $_ecc "
2016-04-09 23:40:59 +08:00
; ;
2016-11-09 19:30:39 +08:00
renew)
2016-08-13 19:22:25 +08:00
renew " $_domain " " $_ecc "
2016-04-09 23:40:59 +08:00
; ;
2016-11-09 19:30:39 +08:00
renewAll)
2016-06-18 11:29:28 +08:00
renewAll " $_stopRenewOnError "
2016-04-09 23:40:59 +08:00
; ;
2016-11-09 19:30:39 +08:00
revoke)
2016-08-13 19:22:25 +08:00
revoke " $_domain " " $_ecc "
2016-04-09 23:40:59 +08:00
; ;
2017-01-21 13:32:12 +08:00
remove)
remove " $_domain " " $_ecc "
; ;
2016-11-09 19:30:39 +08:00
deactivate)
2016-09-23 22:35:13 +08:00
deactivate " $_domain , $_altdomains "
2016-09-25 10:56:06 +08:00
; ;
2016-11-09 19:30:39 +08:00
registeraccount)
2016-11-06 23:08:45 +08:00
registeraccount " $_accountkeylength "
2016-09-25 10:56:06 +08:00
; ;
2016-11-09 19:30:39 +08:00
updateaccount)
2016-09-25 10:56:06 +08:00
updateaccount
; ;
2017-07-02 17:02:54 +08:00
deactivateaccount)
deactivateaccount
; ;
2016-11-09 19:30:39 +08:00
list)
2016-06-14 13:07:33 +08:00
list " $_listraw "
2016-06-09 14:18:54 +08:00
; ;
2017-01-16 22:31:24 +08:00
installcronjob) installcronjob " $_confighome " ; ;
2016-04-09 23:40:59 +08:00
uninstallcronjob) uninstallcronjob ; ;
cron) cron ; ;
2016-11-09 19:30:39 +08:00
toPkcs)
2016-08-13 19:22:25 +08:00
toPkcs " $_domain " " $_password " " $_ecc "
2016-04-09 23:40:59 +08:00
; ;
2017-02-25 19:31:52 +08:00
toPkcs8)
toPkcs8 " $_domain " " $_ecc "
; ;
2016-11-09 19:30:39 +08:00
createAccountKey)
2016-08-23 22:53:43 +08:00
createAccountKey " $_accountkeylength "
2016-04-09 23:40:59 +08:00
; ;
2016-11-09 19:30:39 +08:00
createDomainKey)
2016-04-09 23:40:59 +08:00
createDomainKey " $_domain " " $_keylength "
; ;
2016-11-09 19:30:39 +08:00
createCSR)
2016-08-13 19:22:25 +08:00
createCSR " $_domain " " $_altdomains " " $_ecc "
2016-04-09 23:40:59 +08:00
; ;
*)
2017-01-16 22:31:24 +08:00
if [ " $_CMD " ] ; then
_err " Invalid command: $_CMD "
fi
2016-11-09 19:30:39 +08:00
showhelp
2016-04-09 23:40:59 +08:00
return 1
2016-11-09 19:30:39 +08:00
; ;
2016-04-09 23:40:59 +08:00
esac
2016-05-09 22:56:19 +08:00
_ret = " $? "
2016-11-09 19:30:39 +08:00
if [ " $_ret " != "0" ] ; then
2016-05-09 22:56:19 +08:00
return $_ret
fi
2016-11-09 19:30:39 +08:00
if [ " ${ _CMD } " = "install" ] ; then
if [ " $_log " ] ; then
if [ -z " $LOG_FILE " ] ; then
2016-09-20 19:08:02 +08:00
LOG_FILE = " $DEFAULT_LOG_FILE "
fi
_saveaccountconf "LOG_FILE" " $LOG_FILE "
2016-09-19 23:07:43 +08:00
fi
2016-11-09 19:30:39 +08:00
if [ " $_log_level " ] ; then
2016-09-25 21:58:59 +08:00
_saveaccountconf "LOG_LEVEL" " $_log_level "
fi
2017-02-11 21:15:36 +08:00
if [ " $_syslog " ] ; then
if _exists logger; then
if [ " $_syslog " = "0" ] ; then
_clearaccountconf "SYS_LOG"
else
_saveaccountconf "SYS_LOG" " $_syslog "
fi
else
_err "The 'logger' command is not found, can not enable syslog."
_clearaccountconf "SYS_LOG"
SYS_LOG = ""
fi
fi
2016-09-19 23:07:43 +08:00
_processAccountConf
2016-04-16 17:56:45 +08:00
fi
2016-04-16 17:25:26 +08:00
2016-04-09 23:40:59 +08:00
}
2016-11-09 19:30:39 +08:00
if [ " $INSTALLONLINE " ] ; then
2016-03-27 20:37:26 +08:00
INSTALLONLINE = ""
2017-01-13 20:49:58 +08:00
_installOnline
2016-03-27 20:31:22 +08:00
exit
fi
2016-03-08 20:44:12 +08:00
2016-09-21 13:39:39 +08:00
main( ) {
[ -z " $1 " ] && showhelp && return
2016-11-09 19:30:39 +08:00
if _startswith " $1 " '-' ; then _process " $@ " ; else " $@ " ; fi
2016-09-21 13:39:39 +08:00
}
2016-09-21 13:27:05 +08:00
2016-10-05 12:15:06 +08:00
main " $@ "