2017-03-05 13:43:01 +01:00
|
|
|
#!/usr/bin/env bash
|
|
|
|
|
|
|
|
#Here is a script to deploy cert to routeros router.
|
|
|
|
|
|
|
|
#returns 0 means success, otherwise error.
|
|
|
|
|
|
|
|
######## Public functions #####################
|
|
|
|
|
|
|
|
#domain keyfile certfile cafile fullchain
|
|
|
|
routeros_deploy() {
|
|
|
|
_cdomain="$1"
|
|
|
|
_ckey="$2"
|
|
|
|
_ccert="$3"
|
|
|
|
_cca="$4"
|
|
|
|
_cfullchain="$5"
|
|
|
|
|
|
|
|
_debug _cdomain "$_cdomain"
|
|
|
|
_debug _ckey "$_ckey"
|
|
|
|
_debug _ccert "$_ccert"
|
|
|
|
_debug _cca "$_cca"
|
|
|
|
_debug _cfullchain "$_cfullchain"
|
|
|
|
|
|
|
|
if [ -z "$ROUTER_OS_HOST" ]; then
|
2018-03-26 07:41:56 +02:00
|
|
|
_debug "Using _cdomain as ROUTER_OS_HOST, please set if not correct."
|
2018-03-26 08:24:04 +02:00
|
|
|
ROUTER_OS_HOST="$_cdomain"
|
2017-03-05 13:43:01 +01:00
|
|
|
fi
|
|
|
|
|
|
|
|
if [ -z "$ROUTER_OS_USERNAME" ]; then
|
|
|
|
_err "Need to set the env variable ROUTER_OS_USERNAME"
|
|
|
|
return 1
|
|
|
|
fi
|
|
|
|
|
|
|
|
_info "Trying to push key '$_ckey' to router"
|
2017-03-06 19:39:55 +01:00
|
|
|
scp "$_ckey" "$ROUTER_OS_USERNAME@$ROUTER_OS_HOST:$_cdomain.key"
|
2017-03-05 13:43:01 +01:00
|
|
|
_info "Trying to push cert '$_ccert' to router"
|
2017-03-06 19:39:55 +01:00
|
|
|
scp "$_ccert" "$ROUTER_OS_USERNAME@$ROUTER_OS_HOST:$_cdomain.cer"
|
2017-03-05 13:43:01 +01:00
|
|
|
_info "Trying to push ca cert '$_cca' to router"
|
2017-03-06 19:39:55 +01:00
|
|
|
scp "$_cca" "$ROUTER_OS_USERNAME@$ROUTER_OS_HOST:$_cdomain.ca"
|
|
|
|
# shellcheck disable=SC2029
|
|
|
|
ssh "$ROUTER_OS_USERNAME@$ROUTER_OS_HOST" bash -c "'
|
2017-03-05 13:43:01 +01:00
|
|
|
|
|
|
|
/certificate remove $_cdomain.cer_0
|
|
|
|
|
2017-03-06 19:39:55 +01:00
|
|
|
/certificate remove $_cdomain.cer_1
|
|
|
|
|
2017-03-05 13:43:01 +01:00
|
|
|
/certificate remove $_cdomain.ca_0
|
|
|
|
|
|
|
|
delay 1
|
|
|
|
|
|
|
|
/certificate import file-name=$_cdomain.cer passphrase=\"\"
|
|
|
|
|
|
|
|
/certificate import file-name=$_cdomain.key passphrase=\"\"
|
|
|
|
|
2017-03-06 19:39:55 +01:00
|
|
|
/certificate import file-name=$_cdomain.ca passphrase=\"\"
|
|
|
|
|
2017-03-05 13:43:01 +01:00
|
|
|
delay 1
|
|
|
|
|
|
|
|
/file remove $_cdomain.cer
|
|
|
|
|
|
|
|
/file remove $_cdomain.key
|
|
|
|
|
2017-03-06 19:39:55 +01:00
|
|
|
/file remove $_cdomain.ca
|
|
|
|
|
2017-03-05 13:43:01 +01:00
|
|
|
delay 2
|
|
|
|
|
|
|
|
/ip service set www-ssl certificate=$_cdomain.cer_0
|
|
|
|
|
|
|
|
'"
|
|
|
|
return 0
|
|
|
|
}
|