2020-02-13 03:59:09 +01:00
|
|
|
#!/bin/sh
|
|
|
|
usage()
|
|
|
|
{
|
2020-02-14 04:02:52 +01:00
|
|
|
printf "Usage: %s [-c curve] [-d days] domain\n" "${0##*/}" >&2
|
2020-02-13 03:59:09 +01:00
|
|
|
exit 1
|
|
|
|
}
|
|
|
|
|
|
|
|
tonumber()
|
|
|
|
{
|
|
|
|
printf "%u\n" "$*"
|
|
|
|
}
|
|
|
|
|
|
|
|
curve=secp384r1
|
|
|
|
days=3650
|
2020-02-14 04:02:52 +01:00
|
|
|
while getopts c:d: flag; do
|
2020-02-13 03:59:09 +01:00
|
|
|
case $flag in
|
|
|
|
c) [ -n "$OPTARG" ] || usage
|
|
|
|
curve=$OPTARG
|
|
|
|
;;
|
|
|
|
d) days=$(tonumber "$OPTARG") || usage
|
|
|
|
;;
|
|
|
|
*) usage
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
done
|
|
|
|
shift $((OPTIND - 1))
|
|
|
|
[ $# -eq 1 ] && [ -n "$1" ] || usage
|
|
|
|
domain=$1
|
|
|
|
|
2020-02-13 11:52:55 +01:00
|
|
|
if [ -f "$domain.key" ]; then
|
|
|
|
printf "%s: key for %s already exists; reusing it.\n" \
|
|
|
|
"${0##*/}" "$domain" >&2
|
|
|
|
else
|
2020-03-14 14:36:41 +01:00
|
|
|
(umask 0377 &&
|
2020-02-14 04:02:52 +01:00
|
|
|
openssl ecparam -genkey -name "$curve" -out "$domain.key")
|
2020-02-13 11:49:45 +01:00
|
|
|
fi
|
2020-02-13 11:52:55 +01:00
|
|
|
|
2020-03-14 14:36:41 +01:00
|
|
|
umask 0333 && openssl req -new -x509 -days "$days" -subj "/CN=$domain" \
|
2020-02-13 03:59:09 +01:00
|
|
|
-key "$domain.key" -out "$domain.pem"
|