acme.sh/dnsapi/dns_nsupdate.sh

62 lines
1.7 KiB
Bash
Raw Normal View History

#!/usr/bin/env sh
2016-10-26 11:52:26 +02:00
######## Public functions #####################
#Usage: dns_nsupdate_add _acme-challenge.www.domain.com "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
dns_nsupdate_add() {
fulldomain=$1
txtvalue=$2
_checkKeyFile || return 1
[ -n "${NSUPDATE_SERVER}" ] || NSUPDATE_SERVER="localhost"
[ -n "${NSUPDATE_SERVER_PORT}" ] || NSUPDATE_SERVER_PORT=53
2016-10-26 11:52:26 +02:00
# save the dns server and key to the account conf file.
2018-04-05 11:50:55 +02:00
_saveaccountconf NSUPDATE_SERVER "${NSUPDATE_SERVER}"
_saveaccountconf NSUPDATE_SERVER_PORT "${NSUPDATE_SERVER_PORT}"
2016-10-26 11:52:26 +02:00
_saveaccountconf NSUPDATE_KEY "${NSUPDATE_KEY}"
_info "adding ${fulldomain}. 60 in txt \"${txtvalue}\""
nsupdate -k "${NSUPDATE_KEY}" <<EOF
2018-04-05 11:45:15 +02:00
server ${NSUPDATE_SERVER} ${NSUPDATE_SERVER_PORT}
2016-10-26 11:52:26 +02:00
update add ${fulldomain}. 60 in txt "${txtvalue}"
send
EOF
if [ $? -ne 0 ]; then
_err "error updating domain"
2016-10-26 11:52:26 +02:00
return 1
fi
2016-11-16 15:44:39 +01:00
2016-10-26 11:52:26 +02:00
return 0
}
#Usage: dns_nsupdate_rm _acme-challenge.www.domain.com
dns_nsupdate_rm() {
fulldomain=$1
_checkKeyFile || return 1
[ -n "${NSUPDATE_SERVER}" ] || NSUPDATE_SERVER="localhost"
[ -n "${NSUPDATE_SERVER_PORT}" ] || NSUPDATE_SERVER_PORT=53
_info "removing ${fulldomain}. txt"
nsupdate -k "${NSUPDATE_KEY}" <<EOF
2018-04-05 11:45:15 +02:00
server ${NSUPDATE_SERVER} ${NSUPDATE_SERVER_PORT}
2016-10-26 11:52:26 +02:00
update delete ${fulldomain}. txt
send
EOF
if [ $? -ne 0 ]; then
_err "error updating domain"
2016-10-26 11:52:26 +02:00
return 1
fi
return 0
}
2016-12-14 21:32:24 +01:00
#################### Private functions below ##################################
2016-10-26 11:52:26 +02:00
_checkKeyFile() {
if [ -z "${NSUPDATE_KEY}" ]; then
_err "you must specify a path to the nsupdate key file"
return 1
fi
if [ ! -r "${NSUPDATE_KEY}" ]; then
_err "key ${NSUPDATE_KEY} is unreadable"
return 1
fi
}