aboutsummaryrefslogtreecommitdiffstats
path: root/init.sh
blob: 9674bc18859d343a5d273e4ee6516a798a2b450e (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
# This source code is released into the public domain.

_PROGNAME="$0"

_fatal() {
	local _fmt=$1; shift
	local _msg="$(printf "$_fmt" "$@")"
	printf >&2 '%s: FATAL: %s\n' "$_PROGNAME" "$_msg"
	exit 1
}

_error() {
	local _fmt=$1; shift
	local _msg="$(printf "$_fmt" "$@")"
	printf >&2 '%s: ERROR: %s\n' "$_PROGNAME" "$_msg"
}

_warn() {
	local _fmt=$1; shift
	local _msg="$(printf "$_fmt" "$@")"
	printf >&2 '%s: WARNING: %s\n' "$_PROGNAME" "$_msg"
}

# The prefix we're installed in.
_BASEDIR="/usr/local"
# Where the internal scripts are.
_SHARE="${_BASEDIR}/share/lfacme"
_CHALLENGE="${_SHARE}/challenge"

# Our configuration directory.  This might be overridden by command-line
# arguments.
if [ -z "$_CONFDIR" ]; then
	_CONFDIR="${_BASEDIR}/etc/lfacme"
fi

# Our configuration file.
_CONFIG="${_CONFDIR}/acme.conf"

# Read and validate the configuration file.

if ! [ -f "$_CONFIG" ]; then
	_fatal "missing %s" "$_CONFIG"
fi

. "$_CONFIG"

if [ -z "$ACME_URL" ]; then
	_fatal "ACME_URL must be set in %s" "$_CONFIG"
fi

if [ -z "$ACME_DATADIR" ]; then
	ACME_DATADIR="/var/db/lfacme"
fi

if [ -z "$ACME_KERBEROS_PRINCIPAL" ]; then
	ACME_KERBEROS_PRINCIPAL="host/$(hostname)"
fi

if [ -z "$ACME_HOOKDIR" ]; then
	ACME_HOOKDIR="${ACME_CONFDIR}/hooks"
fi

# The domains.conf file.
_DOMAINS="${_CONFDIR}/domains.conf"

# uacme's base directory; this is where it puts certificates.
_UACME_DIR="${ACME_DATADIR}/certs"

# The uacme executable.
_UACME=/usr/local/bin/uacme

_uacme() {
	"$_UACME" -a "$ACME_URL" -c "$_UACME_DIR" "$@"
}

# Find a challenge script and make sure it's valid.  If the challenge name
# begins with a '/' it's a full path, otherwise we search $_CHALLENGE and
# $_CONFDIR/challenge.
_findchallenge() {
	local identifier="$1"
	local challenge="$2"
	local path=""

	if [ "${challenge#/*}" != "$challenge" ]; then
		path="${challenge}"
	elif [ -f "${_CHALLENGE}/${challenge}" ]; then
		path="${_CHALLENGE}/${challenge}"
	elif [ -f "${_CONFDIR}/challenge/${challenge}" ]; then
		path="${_CONFDIR}/challenge/${challenge}"
	else
		_error "%s: could not find challenge script '%s'" \
			"$identifier" "$challenge"
		return 1
	fi

	if ! [ -x "$path" ]; then
		_error "%s: challenge is not executable: %s" \
			"$identifier" "$path"
		return 1
	fi

	echo "$path"
}

# Find a hook script and make sure it's valid.  If the hook name begins with a
# '/' it's a full path, otherwise it's relative to ACME_HOOKDIR.
_findhook() {
	hook="$1"

	if [ "${hook#/*}" = "$hook" ]; then
		hook="${ACME_HOOKDIR}/$hook"
	fi

	if ! [ -f "$hook" ]; then
		_error "%s: hook does not exist: %s" \
			"$identifier" "$hook"
		return 1
	fi

	if ! [ -x "$hook" ]; then
		_error "%s: hook is not executable: %s" \
			"$identifier" "$hook"
		return 1
	fi

	echo "$hook"
}