update scripts for self signed
This commit is contained in:
parent
bac60d9bd4
commit
2849d8f45d
|
@ -101,6 +101,11 @@ if grep -q CERT_FILE "$local_settings"; then
|
||||||
KEY_FILE=$(grep "^KEY_FILE" "$local_settings" | awk -F'[= "]' '{print $5}')
|
KEY_FILE=$(grep "^KEY_FILE" "$local_settings" | awk -F'[= "]' '{print $5}')
|
||||||
cp -p $CERT_FILE ${tmp_dir}/certs/custom/cert
|
cp -p $CERT_FILE ${tmp_dir}/certs/custom/cert
|
||||||
cp -p $KEY_FILE ${tmp_dir}/certs/custom/key
|
cp -p $KEY_FILE ${tmp_dir}/certs/custom/key
|
||||||
|
elif grep -q TRMM_INSECURE "$local_settings"; then
|
||||||
|
mkdir -p ${tmp_dir}/certs/selfsigned
|
||||||
|
certdir='/etc/ssl/tactical'
|
||||||
|
cp -p ${certdir}/key.pem ${tmp_dir}/certs/selfsigned/
|
||||||
|
cp -p ${certdir}/cert.pem ${tmp_dir}/certs/selfsigned/
|
||||||
fi
|
fi
|
||||||
|
|
||||||
for i in rmm frontend meshcentral; do
|
for i in rmm frontend meshcentral; do
|
||||||
|
|
|
@ -177,8 +177,8 @@ if [[ "$insecure" = true ]]; then
|
||||||
sudo mkdir -p $certdir
|
sudo mkdir -p $certdir
|
||||||
sudo chown ${USER}:${USER} $certdir
|
sudo chown ${USER}:${USER} $certdir
|
||||||
sudo chmod 770 $certdir
|
sudo chmod 770 $certdir
|
||||||
CERT_PRIV_KEY=${certdir}/privkey.pem
|
CERT_PRIV_KEY=${certdir}/key.pem
|
||||||
CERT_PUB_KEY=${certdir}/fullchain.pem
|
CERT_PUB_KEY=${certdir}/cert.pem
|
||||||
openssl req -x509 -newkey rsa:4096 -sha256 -days 3650 \
|
openssl req -x509 -newkey rsa:4096 -sha256 -days 3650 \
|
||||||
-nodes -keyout ${CERT_PRIV_KEY} -out ${CERT_PUB_KEY} -subj "/CN=${rootdomain}" \
|
-nodes -keyout ${CERT_PRIV_KEY} -out ${CERT_PUB_KEY} -subj "/CN=${rootdomain}" \
|
||||||
-addext "subjectAltName=DNS:${rootdomain},DNS:*.${rootdomain}"
|
-addext "subjectAltName=DNS:${rootdomain},DNS:*.${rootdomain}"
|
||||||
|
|
|
@ -209,7 +209,13 @@ if [ -d "${tmp_dir}/certs/custom" ]; then
|
||||||
|
|
||||||
cp -p ${tmp_dir}/certs/custom/cert $CERT_FILE
|
cp -p ${tmp_dir}/certs/custom/cert $CERT_FILE
|
||||||
cp -p ${tmp_dir}/certs/custom/key $KEY_FILE
|
cp -p ${tmp_dir}/certs/custom/key $KEY_FILE
|
||||||
|
elif [ -d "${tmp_dir}/certs/selfsigned" ]; then
|
||||||
|
certdir='/etc/ssl/tactical'
|
||||||
|
sudo mkdir -p $certdir
|
||||||
|
sudo chown ${USER}:${USER} $certdir
|
||||||
|
sudo chmod 770 $certdir
|
||||||
|
cp -p ${tmp_dir}/certs/selfsigned/key.pem $certdir
|
||||||
|
cp -p ${tmp_dir}/certs/selfsigned/cert.pem $certdir
|
||||||
fi
|
fi
|
||||||
|
|
||||||
print_green 'Restoring celery configs'
|
print_green 'Restoring celery configs'
|
||||||
|
|
Loading…
Reference in New Issue