diff options
author | Silvio Rhatto <rhatto@riseup.net> | 2016-10-18 12:57:19 -0200 |
---|---|---|
committer | Silvio Rhatto <rhatto@riseup.net> | 2016-10-18 12:57:19 -0200 |
commit | 3e1ce7f00628bed99c630b5eb5f4c6761b24de6d (patch) | |
tree | 82f65d63c3137d9998796ef7186277de9f063c2a /share | |
parent | d294c31dde207c9670631ccc8070f8cf6926c4a8 (diff) | |
download | hydra-3e1ce7f00628bed99c630b5eb5f4c6761b24de6d.tar.gz hydra-3e1ce7f00628bed99c630b5eb5f4c6761b24de6d.tar.bz2 |
Import-certs: concat.pem; cert.pem and cert.crt symlinks; restart services
Diffstat (limited to 'share')
-rwxr-xr-x | share/hydra/import-certs | 28 |
1 files changed, 28 insertions, 0 deletions
diff --git a/share/hydra/import-certs b/share/hydra/import-certs index 63cb935..74f8d21 100755 --- a/share/hydra/import-certs +++ b/share/hydra/import-certs @@ -55,6 +55,8 @@ EOF keyringer $HYDRA ls -1 ssl/ | grep crt | while read cert; do cert="`basename $cert .asc`" priv="`basename $cert .crt`.pem" + prefix="`basename $cert .crt`" + domain="`facter domain`" $HYDRA_CONNECT $hostname <<EOF sudo touch /etc/ssl/certs/$cert @@ -72,5 +74,31 @@ EOF echo "Importing $priv from keyringer to $hostname:/etc/ssl/private..." keyringer $HYDRA decrypt ssl/$priv | \ $HYDRA_CONNECT $hostname "cat - | sudo tee /etc/ssl/private/$priv > /dev/null" + + # Post-processing + $HYDRA_CONNECT $hostname <<EOF + # Symlinks for the main cert and key + if [ "$prefix" == "$domain" ] && [ -e "" ]; then + cd /etc/ssl/certs && sudo ln -s $cert cert.crt + cd /etc/ssl/private && sudo ln -s $priv cert.pem + fi + + # Concatenated cert + cd /etc/ssl/private + sudo touch $prefix-concat.pem + sudo chown root.ssl-cert $prefix-concat.pem + sudo chmod 640 $prefix-concat.pem + sudo cp /etc/ssl/certs/$cert $prefix-concat.pem + sudo cat $priv | sudo tee -a $prefix-concat.pem > /dev/null + + # Restart services + services="apache2 postfix nginx lighttpd mumble" + for service in \$services; do + if systemctl list-units | grep active | grep -q $service'.service'; then + sudo service $service restart + fi + done +EOF + done done |