mirror of
https://github.com/serghey-rodin/vesta.git
synced 2026-09-08 18:38:40 +02:00
154 lines
4.2 KiB
Bash
Executable File
154 lines
4.2 KiB
Bash
Executable File
#!/bin/bash
|
|
# info: adding ssl for domain
|
|
# options: user domain ssl_dir [ssl_home]
|
|
#
|
|
# The function turns on SSL support for a domain. Parameter ssl_dir is a path
|
|
# to directory where 2 or 3 ssl files can be found. Certificate file
|
|
# domain.tld.crt and its key domain.tld.key are mandatory. Certificate
|
|
# authority domain.tld.ca file is optional. If home directory parameter
|
|
# (ssl_home) is not set, https domain uses public_shtml as separate
|
|
# documentroot directory.
|
|
|
|
|
|
#----------------------------------------------------------#
|
|
# Variable&Function #
|
|
#----------------------------------------------------------#
|
|
|
|
# Argument defenition
|
|
user=$1
|
|
domain=$(idn -t --quiet -u "$2" )
|
|
domain_idn=$(idn -t --quiet -a "$domain")
|
|
ssl_dir=$3
|
|
ssl_home=${4-single}
|
|
|
|
# Importing variables
|
|
source $VESTA/conf/vars.conf
|
|
source $V_CONF/vesta.conf
|
|
source $V_FUNC/shared.func
|
|
source $V_FUNC/domain.func
|
|
source $V_FUNC/ip.func
|
|
|
|
|
|
#----------------------------------------------------------#
|
|
# Verifications #
|
|
#----------------------------------------------------------#
|
|
|
|
# Checking arg number
|
|
check_args '3' "$#" 'user domain ssl_dir [ssl_home]'
|
|
|
|
# Checking argument format
|
|
format_validation 'user' 'domain' 'ssl_dir'
|
|
|
|
# Checking web system is enabled
|
|
is_system_enabled 'web'
|
|
|
|
# Checking user
|
|
is_user_valid
|
|
|
|
# Checking user is active
|
|
is_user_suspended
|
|
|
|
# Checking domain exist
|
|
is_web_domain_valid
|
|
|
|
# Checking domain is not suspened
|
|
is_domain_suspended 'web'
|
|
|
|
# Checking package
|
|
is_package_full 'web_ssl'
|
|
|
|
# Check ssl is not added
|
|
is_web_domain_key_empty '$SSL'
|
|
|
|
# Checking ssl certificate
|
|
is_web_domain_cert_valid
|
|
|
|
|
|
#----------------------------------------------------------#
|
|
# Action #
|
|
#----------------------------------------------------------#
|
|
|
|
# Adding certificate to user data directory
|
|
cp -f $ssl_dir/$domain.crt $V_USERS/$user/ssl/$domain.crt
|
|
cp -f $ssl_dir/$domain.key $V_USERS/$user/ssl/$domain.key
|
|
cp -f $ssl_dir/$domain.crt $V_USERS/$user/ssl/$domain.pem
|
|
if [ -e "$ssl_dir/$domain.ca" ]; then
|
|
cp -f $ssl_dir/$domain.ca $V_USERS/$user/ssl/$domain.ca
|
|
cat $V_USERS/$user/ssl/$domain.ca >> $V_USERS/$user/ssl/$domain.pem
|
|
fi
|
|
chmod 660 $V_USERS/$user/ssl/$domain.*
|
|
|
|
# Parsing domain values
|
|
get_web_domain_values
|
|
conf="$V_HOME/$user/conf/web/shttpd.conf"
|
|
tpl_file="$V_WEBTPL/apache_$TPL.stpl"
|
|
SSL_HOME="$ssl_home"
|
|
|
|
# Checking ip ownership
|
|
is_sys_ip_owner
|
|
|
|
# Preparing domain values for the template substitution
|
|
upd_web_domain_values
|
|
|
|
# Adding domain to the shttpd.conf
|
|
add_web_config
|
|
|
|
chown root:apache $conf
|
|
chmod 640 $conf
|
|
|
|
# Adding certificate to user dir
|
|
cp -f $V_USERS/$user/ssl/$domain.crt $V_HOME/$user/conf/web/ssl.$domain.crt
|
|
cp -f $V_USERS/$user/ssl/$domain.key $V_HOME/$user/conf/web/ssl.$domain.key
|
|
cp -f $V_USERS/$user/ssl/$domain.pem $V_HOME/$user/conf/web/ssl.$domain.pem
|
|
if [ -e "$V_USERS/$user/ssl/$domain.ca" ]; then
|
|
cp -f $V_USERS/$user/ssl/$domain.ca $V_HOME/$user/conf/web/ssl.$domain.ca
|
|
fi
|
|
|
|
# Running template trigger
|
|
if [ -x $V_WEBTPL/apache_$template.sh ]; then
|
|
$V_WEBTPL/apache_$template.sh $user $domain $ip $V_HOME $docroot
|
|
fi
|
|
|
|
# Checking main vesta httpd config
|
|
main_conf='/etc/httpd/conf.d/vesta.conf'
|
|
main_conf_check=$(grep "$conf" $main_conf )
|
|
if [ -z "$main_conf_check" ]; then
|
|
echo "Include $conf" >> $main_conf
|
|
fi
|
|
|
|
# Checking nginx
|
|
if [ ! -z "$NGINX" ]; then
|
|
# Adding domain to the snginx.conf
|
|
conf="$V_HOME/$user/conf/web/snginx.conf"
|
|
tpl_file="$V_WEBTPL/ngingx_vhost_$NGINX.stpl"
|
|
add_web_config
|
|
|
|
chown root:nginx $conf
|
|
chmod 640 $conf
|
|
|
|
# Checking vesta nginx config
|
|
main_conf='/etc/nginx/conf.d/vesta_users.conf'
|
|
main_conf_check=$(grep "$conf" $main_conf )
|
|
if [ -z "$main_conf_check" ]; then
|
|
echo "include $conf;" >>$main_conf
|
|
fi
|
|
fi
|
|
|
|
|
|
#----------------------------------------------------------#
|
|
# Vesta #
|
|
#----------------------------------------------------------#
|
|
|
|
# Increasing domain value
|
|
increase_user_value "$user" '$U_WEB_SSL'
|
|
|
|
# Adding ssl values
|
|
update_web_domain_value '$SSL_HOME' "$SSL_HOME"
|
|
update_web_domain_value '$SSL' 'yes'
|
|
|
|
# Logging
|
|
log_history "$V_EVENT" "v_delete_web_domain_ssl $user $domain"
|
|
log_event 'system' "$V_EVENT"
|
|
|
|
exit
|