blob: 9674bc18859d343a5d273e4ee6516a798a2b450e (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
|
# This source code is released into the public domain.
_PROGNAME="$0"
_fatal() {
local _fmt=$1; shift
local _msg="$(printf "$_fmt" "$@")"
printf >&2 '%s: FATAL: %s\n' "$_PROGNAME" "$_msg"
exit 1
}
_error() {
local _fmt=$1; shift
local _msg="$(printf "$_fmt" "$@")"
printf >&2 '%s: ERROR: %s\n' "$_PROGNAME" "$_msg"
}
_warn() {
local _fmt=$1; shift
local _msg="$(printf "$_fmt" "$@")"
printf >&2 '%s: WARNING: %s\n' "$_PROGNAME" "$_msg"
}
# The prefix we're installed in.
_BASEDIR="/usr/local"
# Where the internal scripts are.
_SHARE="${_BASEDIR}/share/lfacme"
_CHALLENGE="${_SHARE}/challenge"
# Our configuration directory. This might be overridden by command-line
# arguments.
if [ -z "$_CONFDIR" ]; then
_CONFDIR="${_BASEDIR}/etc/lfacme"
fi
# Our configuration file.
_CONFIG="${_CONFDIR}/acme.conf"
# Read and validate the configuration file.
if ! [ -f "$_CONFIG" ]; then
_fatal "missing %s" "$_CONFIG"
fi
. "$_CONFIG"
if [ -z "$ACME_URL" ]; then
_fatal "ACME_URL must be set in %s" "$_CONFIG"
fi
if [ -z "$ACME_DATADIR" ]; then
ACME_DATADIR="/var/db/lfacme"
fi
if [ -z "$ACME_KERBEROS_PRINCIPAL" ]; then
ACME_KERBEROS_PRINCIPAL="host/$(hostname)"
fi
if [ -z "$ACME_HOOKDIR" ]; then
ACME_HOOKDIR="${ACME_CONFDIR}/hooks"
fi
# The domains.conf file.
_DOMAINS="${_CONFDIR}/domains.conf"
# uacme's base directory; this is where it puts certificates.
_UACME_DIR="${ACME_DATADIR}/certs"
# The uacme executable.
_UACME=/usr/local/bin/uacme
_uacme() {
"$_UACME" -a "$ACME_URL" -c "$_UACME_DIR" "$@"
}
# Find a challenge script and make sure it's valid. If the challenge name
# begins with a '/' it's a full path, otherwise we search $_CHALLENGE and
# $_CONFDIR/challenge.
_findchallenge() {
local identifier="$1"
local challenge="$2"
local path=""
if [ "${challenge#/*}" != "$challenge" ]; then
path="${challenge}"
elif [ -f "${_CHALLENGE}/${challenge}" ]; then
path="${_CHALLENGE}/${challenge}"
elif [ -f "${_CONFDIR}/challenge/${challenge}" ]; then
path="${_CONFDIR}/challenge/${challenge}"
else
_error "%s: could not find challenge script '%s'" \
"$identifier" "$challenge"
return 1
fi
if ! [ -x "$path" ]; then
_error "%s: challenge is not executable: %s" \
"$identifier" "$path"
return 1
fi
echo "$path"
}
# Find a hook script and make sure it's valid. If the hook name begins with a
# '/' it's a full path, otherwise it's relative to ACME_HOOKDIR.
_findhook() {
hook="$1"
if [ "${hook#/*}" = "$hook" ]; then
hook="${ACME_HOOKDIR}/$hook"
fi
if ! [ -f "$hook" ]; then
_error "%s: hook does not exist: %s" \
"$identifier" "$hook"
return 1
fi
if ! [ -x "$hook" ]; then
_error "%s: hook is not executable: %s" \
"$identifier" "$hook"
return 1
fi
echo "$hook"
}
|