X-Git-Url: https://git.hcoop.net/hcoop/domtool2.git/blobdiff_plain/385c3534feda76934476fd3a058574fc84e302da..9a8de13739d797ae324dcf0387f24eda3cdcb4a9:/scripts/domtool-addcert diff --git a/scripts/domtool-addcert b/scripts/domtool-addcert index 535d825..8d9e295 100755 --- a/scripts/domtool-addcert +++ b/scripts/domtool-addcert @@ -1,23 +1,29 @@ #!/bin/sh -e - KEYDIR=/afs/hcoop.net/common/etc/domtool/keys/$1 +USER="$1" +if test -z "$USER"; then + echo Usage: domtool-addcert USERNAME + exit 1 +fi + + KEYDIR=/afs/hcoop.net/common/etc/domtool/keys/$USER KEYFILE=$KEYDIR/key.pem -CERTFILE=/afs/hcoop.net/common/etc/domtool/certs/$1.pem +CERTFILE=/afs/hcoop.net/common/etc/domtool/certs/$USER.pem NEWREQ=~/.newreq.pem NEW=~/.new.pem KEYIN=~/.keyin -mkdir $KEYDIR || echo Already exists +mkdir $KEYDIR || echo Key directory already exists. openssl genrsa -out $KEYFILE chown -R domtool.domtool $KEYDIR -fs sa $KEYDIR $1 read +fs sa $KEYDIR $USER read || echo This must be a server principal. echo "." >$KEYIN echo "." >>$KEYIN echo "." >>$KEYIN echo "." >>$KEYIN echo "." >>$KEYIN -echo "$1" >>$KEYIN -echo "$1@hcoop.net" >>$KEYIN +echo "$USER" >>$KEYIN +echo "$USER@hcoop.net" >>$KEYIN echo "" >>$KEYIN echo "" >>$KEYIN openssl req -new -key $KEYFILE -out $NEWREQ -days 365 <$KEYIN