exit 1
fi
- KEYDIR=/afs/hcoop.net/common/etc/domtool/keys/$1
+ KEYDIR=/afs/hcoop.net/common/etc/domtool/keys/$USER
KEYFILE=$KEYDIR/key.pem
-CERTFILE=/afs/hcoop.net/common/etc/domtool/certs/$1.pem
+CERTFILE=/afs/hcoop.net/common/etc/domtool/certs/$USER.pem
NEWREQ=~/.newreq.pem
NEW=~/.new.pem
KEYIN=~/.keyin
-mkdir -p $KEYDIR
+mkdir $KEYDIR || echo Key directory already exists.
openssl genrsa -out $KEYFILE
-chown -R domtool.domtool $KEYDIR
-fs sa $KEYDIR $USER read
+chown -R domtool.nogroup $KEYDIR
+fs sa $KEYDIR $USER read || echo This must be a server principal.
echo "." >$KEYIN
echo "." >>$KEYIN
echo "." >>$KEYIN
rm $NEWREQ
openssl ca -batch -config /etc/domtool/openssl.cnf -policy policy_anything -out $CERTFILE -infiles $NEW
rm $NEW
-chown domtool.domtool $CERTFILE
+chown domtool.nogroup $CERTFILE