Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
E
etersoft-admin-essentials
Project
Project
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
etersoft
etersoft-admin-essentials
Commits
932c9e2b
Commit
932c9e2b
authored
Oct 23, 2014
by
Vitaly Lipatov
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
update certs scripts
parent
5daecf82
Hide whitespace changes
Inline
Side-by-side
Showing
5 changed files
with
101 additions
and
52 deletions
+101
-52
copy_cacert_to_hosts.sh
certs/copy_cacert_to_hosts.sh
+11
-52
copy_cacert_to_nginx_host.sh
certs/copy_cacert_to_nginx_host.sh
+21
-0
copy_certs_to_hosts-common.sh
certs/copy_certs_to_hosts-common.sh
+40
-0
copy_startssl_to_hosts.sh
certs/copy_startssl_to_hosts.sh
+22
-0
gencsr.sh
certs/gencsr.sh
+7
-0
No files found.
certs/copy_c
erts
_to_hosts.sh
→
certs/copy_c
acert
_to_hosts.sh
View file @
932c9e2b
...
...
@@ -2,62 +2,12 @@
# Размещает сертификаты на нужных местах нужных серверов
fatal
()
{
echo
"Fatal Error"
exit
1
}
.
$(
dirname
$(
realpath
$0
))
/copy_certs_to_hosts-common.sh
.
cert.conf
cd
sites
copy_to_nginx
()
{
ALTPEM
=
"
$(
dirname
"
$PRIVATEPEM
"
)
/
$1
"
if
[
-r
"
$ALTPEM
"
]
;
then
PEM
=
"
$ALTPEM
"
shift
else
PEM
=
"
$PRIVATEPEM
"
fi
echo
"Copying
$1
cert..."
CERT
=
$1
if
[
-r
"
$INTERMEDCERT
"
]
;
then
cat
"
$CERT
"
"
$INTERMEDCERT
"
>
tempcert.crt
||
fatal
CERT
=
tempcert.crt
fi
scp
$CERT
$2
:/etc/nginx/ssl/
$1
||
fatal
scp
"
$PEM
"
$2
:/etc/nginx/ssl/
||
fatal
[
-n
"
$3
"
]
||
ssh
$2
service nginx reload
}
do_pem
()
{
test
-f
"
$1
"
||
return
cat
"
$1
"
"
$PRIVATEPEM
"
\
>
"
$2
"
}
# TODO: use two script with common part
# StartSSL
if
false
;
then
#copy_to_nginx pravtor.pem pravtor.ru.crt pravtor
#exit
copy_to_nginx bugs.etersoft.ru.crt bugs
copy_to_nginx mysql.eterhost.ru.crt host03
copy_to_nginx stog.etersoft.ru.crt stog
for
crt
in
roundcube.eterhost.ru.crt
;
do
copy_to_nginx
$crt
priv noreload
||
fatal
done
ssh priv service nginx reload
fi
copy_to_priv
()
{
for
crt
in
sales.etersoft.ru.crt rt.etersoft.ru.crt cyradm.eterhost.ru.crt
\
...
...
@@ -68,7 +18,7 @@ copy_to_priv()
ssh priv service nginx reload
}
#
copy_to_priv
copy_to_priv
copy_to_im
()
{
...
...
@@ -99,3 +49,12 @@ ssh mail service cyrus-imapd restart
}
copy_to_mail
copy_to_host
()
{
copy_to_nginx
$1
.crt
$1
reload
}
for
host
in
research.devel.etersoft.ru
;
do
copy_to_host
$host
done
certs/copy_cacert_to_nginx_host.sh
0 → 100755
View file @
932c9e2b
#!/bin/sh
# Размещает сертификаты на нужных местах нужных серверов
.
$(
dirname
$(
realpath
$0
))
/copy_certs_to_hosts-common.sh
.
cert.conf
cd
sites
HOST
=
$1
crt
=
$HOST
.crt
[
-n
"
$HOST
"
]
||
fatal
"Need run with hostname"
[
-s
"
$crt
"
]
||
fatal
"No cert file
$crt
"
ssh
$HOST
true
||
fatal
"No ssh access to
$HOST
server"
copy_to_nginx
$crt
$HOST
certs/copy_certs_to_hosts-common.sh
0 → 100755
View file @
932c9e2b
#!/bin/sh
# Размещает сертификаты на нужных местах нужных серверов
fatal
()
{
echo
"Fatal Error:
$@
"
exit
1
}
copy_to_nginx
()
{
ALTPEM
=
"
$(
dirname
"
$PRIVATEPEM
"
)
/
$1
"
if
[
-r
"
$ALTPEM
"
]
;
then
PEM
=
"
$ALTPEM
"
shift
else
PEM
=
"
$PRIVATEPEM
"
fi
echo
"Copying
$1
cert..."
CERT
=
$1
if
[
-r
"
$INTERMEDCERT
"
]
;
then
cat
"
$CERT
"
"
$INTERMEDCERT
"
>
tempcert.crt
||
fatal
CERT
=
tempcert.crt
fi
scp
$CERT
$2
:/etc/nginx/ssl/
$1
||
fatal
scp
"
$PEM
"
$2
:/etc/nginx/ssl/
||
fatal
[
-n
"
$3
"
]
||
ssh
$2
service nginx condreload
}
do_pem
()
{
test
-f
"
$1
"
||
return
cat
"
$1
"
"
$PRIVATEPEM
"
\
>
"
$2
"
}
certs/copy_startssl_to_hosts.sh
0 → 100755
View file @
932c9e2b
#!/bin/sh
# Размещает сертификаты на нужных местах нужных серверов
.
$(
dirname
$(
realpath
$0
))
/copy_certs_to_hosts-common.sh
.
cert.conf
cd
sites
#copy_to_nginx eterfund.pem gitlab.eterfund.ru.crt devel
#copy_to_nginx search.office.etersoft.ru.crt priv
#copy_to_nginx stog.etersoft.ru.crt stog
copy_to_nginx pravtor.pem pravtor.ru.crt pravtor
copy_to_nginx bugs.etersoft.ru.crt bugs
copy_to_nginx mysql.eterhost.ru.crt priv
copy_to_nginx winehq.org.ru.crt host03
copy_to_nginx stog.etersoft.ru.crt stog
copy_to_nginx roundcube.eterhost.ru.crt priv
certs/gencsr.sh
View file @
932c9e2b
#!/bin/bash
create_request
()
{
DOMAIN
=
$1
PRIVATE_KEY
=
private/etersoft-cacert.pem
SUFFIX_OUT_FILE
=
"request.csr"
mkdir
-p
csr/
openssl req
-new
-subj
"/C=RU/ST=Saint-Petersburg/L=Saint-Petersburg/O=Etersoft/OU=/CN=
$DOMAIN
/emailAddress=admin@
$DOMAIN
"
-key
$PRIVATE_KEY
-out
csr/
$DOMAIN
-
$SUFFIX_OUT_FILE
}
for
i
in
$@
;
do
create_request
$i
done
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment