From 36c07a46bc76a720534b9a5a64bc5ef3cb88e33d Mon Sep 17 00:00:00 2001 From: Rod Wright Date: Sun, 19 Jul 2026 16:32:31 -0400 Subject: [PATCH] Added code to populate the TLS certs on iRedMail servers --- usr/local/bin/update-letsencrypt-certs | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/usr/local/bin/update-letsencrypt-certs b/usr/local/bin/update-letsencrypt-certs index 30abad9..e4ef308 100644 --- a/usr/local/bin/update-letsencrypt-certs +++ b/usr/local/bin/update-letsencrypt-certs @@ -9,18 +9,28 @@ cert_host="portal.thermionic.net" # Set which http server to restart -#http_server="nginx" +http_server="nginx" #http_server="apache2" -http_server="pveproxy" +#http_server="pveproxy" +# Pull certs from the certifiate host if rsync -aL --info=stats2 root@$cert_host:/etc/letsencrypt/live/thermionic.net/ /etc/ssl/thermionic.net/ |grep -q "Number of regular files transferred: 0"; then http_server_restart=false; else http_server_restart=true; fi +#Certs go in a non-standard place for a proxmox server if [ "$http_server" = "pveproxy" ] then cp -f /etc/ssl/thermionic.net/fullchain.pem /etc/pve/local/pveproxy-ssl.pem cp -f /etc/ssl/thermionic.net/privkey.pem /etc/pve/local/pveproxy-ssl.key fi +# Populate additional TLS cers for iRedMail server +if [ -e "/etc/ssl/private/iRedMail.key" ] +then + cp -f /etc/ssl/thermionic.net/fullchain.pem /etc/ssl/certs/iRedMail.crt + cp -f /etc/ssl/thermionic.net/privkey.pem /etc/ssl/private/iRedMail.key +fi + +# Restart if required if $http_server_restart; then echo "New certs downloaded. Restarting $http_server." systemctl restart $http_server