Files
LetsencryptCertUpdater/usr/local/bin/update-letsencrypt-certs

49 lines
1.5 KiB
Bash

#!/bin/bash
# update-letsencrypt-certs
# Pull SSL certificates form a certificate host and restart
# servers as necessary.
# 7/21/2026 Rod Wright
# Set the host from which certificates will be pulled
cert_host="portal.thermionic.net"
# Set which http server to restart
http_server="nginx"
#http_server="apache2"
#http_server="pveproxy"
#http_server="unifi"
# Pull certs from the certifiate host
if rsync -aL --info=stats2 root@$cert_host:/etc/letsencrypt/live/thermionic.net/ /etc/ssl/thermionic.net/ |grep -q "Number of regular files transferred: 0"; then http_server_restart=false; else http_server_restart=true; fi
#Certs go in a non-standard place for a proxmox server
if [[ "$http_server" = "pveproxy" ]]
then
cp -f /etc/ssl/thermionic.net/fullchain.pem /etc/pve/local/pveproxy-ssl.pem
cp -f /etc/ssl/thermionic.net/privkey.pem /etc/pve/local/pveproxy-ssl.key
fi
# Populate additional TLS cers for iRedMail server
if [[ -e "/etc/ssl/private/iRedMail.key" ]]
then
cp -f /etc/ssl/thermionic.net/fullchain.pem /etc/ssl/certs/iRedMail.crt
cp -f /etc/ssl/thermionic.net/privkey.pem /etc/ssl/private/iRedMail.key
fi
# Restart if required
if $http_server_restart
then
if [[ $http_server == "unifi" ]]
then
# Stop unifi, recreate keystore, start unifi
unifi_ssl_import.sh
else
# Restart normal http servers
echo "New certs downloaded. Restarting $http_server."
systemctl restart $http_server
fi
else
echo "Certs are up to date. $http_server restart not required."
fi