2021-02-12 01:16:37 +00:00
|
|
|
#!/bin/bash
|
|
|
|
|
2024-10-14 01:13:21 +00:00
|
|
|
TMPDIR=/tmp/nginx
|
2023-06-20 05:29:44 +00:00
|
|
|
|
2021-02-12 01:16:37 +00:00
|
|
|
if [ "$1" == "certbot" ]; then
|
2024-10-14 01:13:21 +00:00
|
|
|
certbot renew -q --config-dir /etc/nginx/ssl/letsencrypt/ --renew-hook "/usr/sbin/nginx -s reload"
|
2021-02-12 01:16:37 +00:00
|
|
|
|
|
|
|
elif [ "$1" == "lego" ]; then
|
2024-10-14 01:13:21 +00:00
|
|
|
CERTDIR=/etc/nginx/ssl
|
|
|
|
LEGODIR=${CERTDIR}/lego
|
|
|
|
CERTFILE=${LEGODIR}/lego-cert.ssl
|
2021-02-12 01:16:37 +00:00
|
|
|
RELOAD="/tmp/nginx.reload"
|
|
|
|
TLS_PORT=444
|
|
|
|
|
|
|
|
[ -r ${CERTFILE} ] || exit 1
|
|
|
|
|
|
|
|
cat ${CERTFILE} | while read line; do
|
2021-02-25 02:49:03 +00:00
|
|
|
#echo " - line is [${line}]"
|
2021-02-12 01:16:37 +00:00
|
|
|
LEGO_ACCOUNT_EMAIL=$(echo ${line} | cut -d':' -f 1)
|
|
|
|
DOMAINS=$(echo ${line} | cut -d':' -f 2)
|
|
|
|
LEGO_CERT_DOMAIN=(${DOMAINS//,/ })
|
|
|
|
|
2021-02-25 02:49:03 +00:00
|
|
|
if [ -n "$3" ]; then
|
|
|
|
if [[ ! " ${DOMAINS[@]} " =~ " ${3} " ]]; then
|
2021-02-12 01:16:37 +00:00
|
|
|
continue;
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
METHOD=$(echo ${line} | cut -d':' -f 3)
|
|
|
|
|
|
|
|
LEGO_ACCOUNT_EMAIL=${LEGO_ACCOUNT_EMAIL:? LEGO_ACCOUNT_EMAIL not set}
|
|
|
|
LEGO_CERT_DOMAIN=${LEGO_CERT_DOMAIN:? LEGO_CERT_DOMAIN not set}
|
|
|
|
|
|
|
|
LEGO_CERT_DOMAIN=(${LEGO_CERT_DOMAIN[@]/#/-d })
|
|
|
|
|
|
|
|
if [ ${METHOD} == 'dns' ]; then
|
|
|
|
DNS=$(echo ${line} | cut -d':' -f 4)
|
|
|
|
if [ ${DNS} == 'cloudflare' ]; then
|
|
|
|
export CLOUDFLARE_EMAIL=$(echo ${line} | cut -d':' -f 5)
|
|
|
|
export CF_DNS_API_TOKEN=$(echo ${line} | cut -d':' -f 6)
|
|
|
|
LEGO_METHOD="--dns cloudflare"
|
|
|
|
else
|
|
|
|
echo "! ERROR: Unknown DNS [${DNS}]" && continue
|
|
|
|
fi
|
|
|
|
|
|
|
|
elif [ ${METHOD} == 'tls' ]; then
|
|
|
|
LEGO_METHOD="--tls --tls.port :${TLS_PORT}"
|
|
|
|
else
|
|
|
|
echo "! ERROR: Unknown METHOD [${METHOD}]" && continue
|
|
|
|
fi
|
|
|
|
|
|
|
|
if [ "$2" == "renew" ]; then
|
2023-06-20 05:29:44 +00:00
|
|
|
lego ${LEGO_METHOD} --email="${LEGO_ACCOUNT_EMAIL}" ${LEGO_CERT_DOMAIN[@]} --path ${CERTDIR}/ssl/lego renew --renew-hook="touch ${RELOAD}"
|
|
|
|
elif [ "$2" == "run" ]; then
|
|
|
|
lego ${LEGO_METHOD} --email="${LEGO_ACCOUNT_EMAIL}" ${LEGO_CERT_DOMAIN[@]} --path ${CERTDIR}/ssl/lego run --run-hook="touch ${RELOAD}"
|
2021-02-12 01:16:37 +00:00
|
|
|
else
|
2023-06-20 05:29:44 +00:00
|
|
|
echo "! ERROR: Not doing anything?" && exit 1
|
|
|
|
fi
|
|
|
|
done
|
|
|
|
|
|
|
|
# Checkour MD5s and reload if required
|
|
|
|
for cert in $(lego --path ${LEGODIR} list |grep Certificate\ Path|awk '{print $3}'); do
|
|
|
|
OUTPUT=$(basename ${cert})
|
|
|
|
SRC=$(cat ${TMPDIR}/${OUTPUT}.md5)
|
|
|
|
TGT=$(cat ${cert} | md5sum)
|
|
|
|
|
|
|
|
echo "- Comparing MD5 of SRC [${SRC}] with [${TGT}]"
|
|
|
|
if [ "${SRC}" != "${TGT}" ]; then
|
|
|
|
touch ${RELOAD}
|
|
|
|
echo ${TGT} > ${TMPDIR}/${OUTPUT}.md5
|
2021-02-12 01:16:37 +00:00
|
|
|
fi
|
|
|
|
done
|
|
|
|
|
|
|
|
if [ -r ${RELOAD} ]; then
|
2023-06-20 05:29:44 +00:00
|
|
|
echo "* Reloading NGINX"
|
2021-02-12 01:16:37 +00:00
|
|
|
/usr/sbin/nginx -s reload
|
|
|
|
rm -f ${RELOAD}
|
|
|
|
fi
|
|
|
|
|
|
|
|
else
|
|
|
|
echo "! ERROR: Unknown certbot method [$1]"
|
|
|
|
fi
|