|
@@ -170,10 +170,6 @@ if ! which openssl > /dev/null ;then
|
170
|
170
|
exit 5689
|
171
|
171
|
fi
|
172
|
172
|
|
173
|
|
-if [ ! -d /etc/ssl/mycerts ]; then
|
174
|
|
- mkdir /etc/ssl/mycerts
|
175
|
|
-fi
|
176
|
|
-
|
177
|
173
|
CERTFILE=$HOSTNAME
|
178
|
174
|
|
179
|
175
|
function remove_cert_letsencrypt {
|
|
@@ -317,7 +313,6 @@ function add_cert_selfsigned {
|
317
|
313
|
-out "/etc/ssl/certs/${CERTFILE}.crt"
|
318
|
314
|
chmod 400 "/etc/ssl/private/${CERTFILE}.key"
|
319
|
315
|
chmod 640 "/etc/ssl/certs/${CERTFILE}.crt"
|
320
|
|
- cp "/etc/ssl/certs/${CERTFILE}.crt" "/etc/ssl/mycerts"
|
321
|
316
|
|
322
|
317
|
if [ "$PIN_CERTS" ]; then
|
323
|
318
|
if ! "${PROJECT_NAME}-pin-cert" "$CERTFILE"; then
|
|
@@ -341,12 +336,6 @@ function restart_web_server {
|
341
|
336
|
fi
|
342
|
337
|
}
|
343
|
338
|
|
344
|
|
-function make_cert_bundle {
|
345
|
|
- # Create a bundle of your certificates
|
346
|
|
- cat /etc/ssl/mycerts/*.crt /etc/ssl/mycerts/*.pem > /etc/ssl/${PROJECT_NAME}-bundle.crt
|
347
|
|
- tar -czvf /etc/ssl/${PROJECT_NAME}-certs.tar.gz /etc/ssl/mycerts/*.crt /etc/ssl/mycerts/*.pem
|
348
|
|
-}
|
349
|
|
-
|
350
|
339
|
function create_cert {
|
351
|
340
|
if [ "$remove_cert" ]; then
|
352
|
341
|
remove_cert_letsencrypt
|
|
@@ -363,6 +352,5 @@ function create_cert {
|
363
|
352
|
create_cert
|
364
|
353
|
generate_dh_params
|
365
|
354
|
restart_web_server
|
366
|
|
-make_cert_bundle
|
367
|
355
|
|
368
|
356
|
exit 0
|