bunkerized-nginx/scripts/certbot-renew.sh

36 lines
836 B
Bash
Raw Normal View History

2019-08-20 23:25:16 +02:00
#!/bin/sh
2020-03-28 23:05:05 +01:00
function replace_in_file() {
# escape slashes
pattern=$(echo "$2" | sed "s/\//\\\\\//g")
replace=$(echo "$3" | sed "s/\//\\\\\//g")
sed -i "s/$pattern/$replace/g" "$1"
}
2020-03-30 22:10:53 +02:00
# check if HTTP enabled
# and disable it temporarily if needed
2020-11-06 17:11:27 +01:00
if grep -q "listen" "/etc/nginx/server.conf" ; then
replace_in_file "/etc/nginx/server.conf" "listen" "#listen"
if [ -f /tmp/nginx.pid ] ; then
2020-03-28 23:05:05 +01:00
/usr/sbin/nginx -s reload
2020-03-30 22:10:53 +02:00
sleep 10
2020-03-28 23:05:05 +01:00
fi
fi
# ask a new certificate if needed
2019-08-20 23:25:16 +02:00
certbot renew
2020-03-30 22:10:53 +02:00
# enable HTTP again if needed
2020-11-06 17:11:27 +01:00
if grep -q "#listen" "/etc/nginx/server.conf" ; then
replace_in_file "/etc/nginx/server.conf" "#listen" "listen"
2020-03-28 23:05:05 +01:00
fi
chown -R root:nginx /etc/letsencrypt
chmod -R 740 /etc/letsencrypt
find /etc/letsencrypt -type d -exec chmod 750 {} \;
2020-03-28 23:05:05 +01:00
# reload nginx
if [ -f /tmp/nginx.pid ] ; then
2019-08-20 23:25:16 +02:00
/usr/sbin/nginx -s reload
fi