Parcourir la source

Don't pin certs

Bob Mottram il y a 8 ans
Parent
révision
e9949e8861
Aucun compte lié à l'adresse email de l'auteur
1 fichiers modifiés avec 3 ajouts et 5 suppressions
  1. 3
    5
      src/freedombone-pin-cert

+ 3
- 5
src/freedombone-pin-cert Voir le fichier

53
                     if [ ${#BACKUP_KEY_HASH} -gt 5 ]; then
53
                     if [ ${#BACKUP_KEY_HASH} -gt 5 ]; then
54
 
54
 
55
                         PIN_HEADER="Public-Key-Pins 'pin-sha256=\"${KEY_HASH}\"; pin-sha256=\"${BACKUP_KEY_HASH}\"; max-age=5184000; includeSubDomains';"
55
                         PIN_HEADER="Public-Key-Pins 'pin-sha256=\"${KEY_HASH}\"; pin-sha256=\"${BACKUP_KEY_HASH}\"; max-age=5184000; includeSubDomains';"
56
-                        sed -i "s|Public-Key-Pins.*|${PIN_HEADER}|g" $file
56
+                        # sed -i "s|Public-Key-Pins.*|${PIN_HEADER}|g" $file
57
                         echo $"Pinned $DOMAIN_NAME with keys $KEY_HASH $BACKUP_KEY_HASH"
57
                         echo $"Pinned $DOMAIN_NAME with keys $KEY_HASH $BACKUP_KEY_HASH"
58
                     fi
58
                     fi
59
                 fi
59
                 fi
115
 fi
115
 fi
116
 
116
 
117
 PIN_HEADER="Public-Key-Pins 'pin-sha256=\"${KEY_HASH}\"; pin-sha256=\"${BACKUP_KEY_HASH}\"; max-age=5184000; includeSubDomains';"
117
 PIN_HEADER="Public-Key-Pins 'pin-sha256=\"${KEY_HASH}\"; pin-sha256=\"${BACKUP_KEY_HASH}\"; max-age=5184000; includeSubDomains';"
118
-if ! grep -q "Public-Key-Pins" $SITE_FILENAME; then
119
-    sed -i "/ssl_ciphers.*/a     add_header ${PIN_HEADER}" $SITE_FILENAME
120
-else
121
-    sed -i "s|Public-Key-Pins.*|${PIN_HEADER}|g" $SITE_FILENAME
118
+if grep -q "Public-Key-Pins" $SITE_FILENAME; then
119
+    sed -i "s|Public-Key-Pins.*||g" $SITE_FILENAME
122
 fi
120
 fi
123
 
121
 
124
 systemctl restart nginx
122
 systemctl restart nginx