Deprecate cert bundle
This commit is contained in:
parent
f1f789415e
commit
eb6103f19a
|
@ -170,10 +170,6 @@ if ! which openssl > /dev/null ;then
|
||||||
exit 5689
|
exit 5689
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [ ! -d /etc/ssl/mycerts ]; then
|
|
||||||
mkdir /etc/ssl/mycerts
|
|
||||||
fi
|
|
||||||
|
|
||||||
CERTFILE=$HOSTNAME
|
CERTFILE=$HOSTNAME
|
||||||
|
|
||||||
function remove_cert_letsencrypt {
|
function remove_cert_letsencrypt {
|
||||||
|
@ -317,7 +313,6 @@ function add_cert_selfsigned {
|
||||||
-out "/etc/ssl/certs/${CERTFILE}.crt"
|
-out "/etc/ssl/certs/${CERTFILE}.crt"
|
||||||
chmod 400 "/etc/ssl/private/${CERTFILE}.key"
|
chmod 400 "/etc/ssl/private/${CERTFILE}.key"
|
||||||
chmod 640 "/etc/ssl/certs/${CERTFILE}.crt"
|
chmod 640 "/etc/ssl/certs/${CERTFILE}.crt"
|
||||||
cp "/etc/ssl/certs/${CERTFILE}.crt" "/etc/ssl/mycerts"
|
|
||||||
|
|
||||||
if [ "$PIN_CERTS" ]; then
|
if [ "$PIN_CERTS" ]; then
|
||||||
if ! "${PROJECT_NAME}-pin-cert" "$CERTFILE"; then
|
if ! "${PROJECT_NAME}-pin-cert" "$CERTFILE"; then
|
||||||
|
@ -341,12 +336,6 @@ function restart_web_server {
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
function make_cert_bundle {
|
|
||||||
# Create a bundle of your certificates
|
|
||||||
cat /etc/ssl/mycerts/*.crt /etc/ssl/mycerts/*.pem > /etc/ssl/${PROJECT_NAME}-bundle.crt
|
|
||||||
tar -czvf /etc/ssl/${PROJECT_NAME}-certs.tar.gz /etc/ssl/mycerts/*.crt /etc/ssl/mycerts/*.pem
|
|
||||||
}
|
|
||||||
|
|
||||||
function create_cert {
|
function create_cert {
|
||||||
if [ "$remove_cert" ]; then
|
if [ "$remove_cert" ]; then
|
||||||
remove_cert_letsencrypt
|
remove_cert_letsencrypt
|
||||||
|
@ -363,6 +352,5 @@ function create_cert {
|
||||||
create_cert
|
create_cert
|
||||||
generate_dh_params
|
generate_dh_params
|
||||||
restart_web_server
|
restart_web_server
|
||||||
make_cert_bundle
|
|
||||||
|
|
||||||
exit 0
|
exit 0
|
||||||
|
|
Loading…
Reference in New Issue