X-Git-Url: https://git.hcoop.net/hcoop/domtool2.git/blobdiff_plain/906a79a6b13c8e20cfd8fd38e937f0c4e79318ff..ea459e3e5eea2a0015649fb987abda7d7e925c78:/scripts/domtool-addcert diff --git a/scripts/domtool-addcert b/scripts/domtool-addcert index 3fb6b82..6e58197 100755 --- a/scripts/domtool-addcert +++ b/scripts/domtool-addcert @@ -6,17 +6,17 @@ if test -z "$USER"; then exit 1 fi - KEYDIR=/afs/hcoop.net/common/etc/domtool/keys/$1 + KEYDIR=/afs/hcoop.net/common/etc/domtool/keys/$USER KEYFILE=$KEYDIR/key.pem -CERTFILE=/afs/hcoop.net/common/etc/domtool/certs/$1.pem +CERTFILE=/afs/hcoop.net/common/etc/domtool/certs/$USER.pem NEWREQ=~/.newreq.pem NEW=~/.new.pem KEYIN=~/.keyin -mkdir -p $KEYDIR +mkdir $KEYDIR || echo Key directory already exists. openssl genrsa -out $KEYFILE -chown -R domtool.domtool $KEYDIR -fs sa $KEYDIR $USER read +chown -R domtool.nogroup $KEYDIR +fs sa $KEYDIR $USER read || echo This must be a server principal. echo "." >$KEYIN echo "." >>$KEYIN echo "." >>$KEYIN @@ -32,4 +32,4 @@ cat $NEWREQ $KEYFILE >$NEW rm $NEWREQ openssl ca -batch -config /etc/domtool/openssl.cnf -policy policy_anything -out $CERTFILE -infiles $NEW rm $NEW -chown domtool.domtool $CERTFILE +chown domtool.nogroup $CERTFILE