This commit is contained in:
Dmitry 2025-12-03 04:05:31 +03:00
parent fdf3aea2e3
commit cf929a3a30
3 changed files with 134 additions and 0 deletions

Binary file not shown.

View file

@ -86,6 +86,7 @@ else
-d api.mnemo-cards.online \
-d code.mnemo-cards.online \
-d vscode.mnemo-cards.online \
-d admin.mnemo-cards.online \
--cert-name mnemo-cards.online \
--non-interactive --agree-tos --email admin@mnemo-cards.online; then
echo "✅ Let's Encrypt multi-domain сертификат успешно создан!"

133
tools/ssl/renew_admin_ssl.sh Executable file
View file

@ -0,0 +1,133 @@
#!/bin/bash
# SSL Certificate Renewal Script for admin.mnemo-cards.online
# This script obtains Let's Encrypt SSL certificate for admin panel
# Usage: ./renew_admin_ssl.sh
set -e
DOMAIN="admin.mnemo-cards.online"
EMAIL="admin@mnemo-cards.online"
echo "🔐 Starting SSL certificate renewal for $DOMAIN..."
# Colors for output
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[1;33m'
BLUE='\033[0;34m'
NC='\033[0m' # No Color
print_status() {
echo -e "${GREEN}[INFO]${NC} $1"
}
print_warning() {
echo -e "${YELLOW}[WARNING]${NC} $1"
}
print_error() {
echo -e "${RED}[ERROR]${NC} $1"
}
print_success() {
echo -e "${GREEN}[SUCCESS]${NC} $1"
}
# Check if certbot is installed
if ! command -v certbot &> /dev/null; then
print_status "Installing certbot..."
apt update
apt install -y certbot
fi
# Check current nginx status
NGINX_RUNNING=false
if systemctl is-active --quiet nginx; then
NGINX_RUNNING=true
print_status "nginx is currently running"
else
print_status "nginx is currently stopped"
fi
# Stop nginx for standalone mode
if [ "$NGINX_RUNNING" = true ]; then
print_status "Stopping nginx for certificate renewal..."
systemctl stop nginx
sleep 2
fi
# Obtain certificate
print_status "Obtaining SSL certificate for $DOMAIN..."
if certbot certonly --standalone \
-d "$DOMAIN" \
--email "$EMAIL" \
--agree-tos \
--non-interactive; then
print_success "SSL certificate obtained successfully!"
# Verify certificate files exist
if [ -f "/etc/letsencrypt/live/$DOMAIN/fullchain.pem" ] && [ -f "/etc/letsencrypt/live/$DOMAIN/privkey.pem" ]; then
print_success "Certificate files verified"
# Set proper permissions
chmod 600 "/etc/letsencrypt/live/$DOMAIN/privkey.pem"
chmod 644 "/etc/letsencrypt/live/$DOMAIN/fullchain.pem"
print_success "Certificate permissions set"
else
print_error "Certificate files not found after renewal!"
exit 1
fi
else
print_error "Failed to obtain SSL certificate!"
exit 1
fi
# Start nginx back
if [ "$NGINX_RUNNING" = true ]; then
print_status "Starting nginx..."
systemctl start nginx
sleep 2
if systemctl is-active --quiet nginx; then
print_success "nginx started successfully"
else
print_error "Failed to start nginx!"
exit 1
fi
fi
# Test certificate validity
print_status "Testing certificate validity..."
if openssl x509 -in "/etc/letsencrypt/live/$DOMAIN/cert.pem" -text -noout | grep -q "Subject:.*$DOMAIN"; then
print_success "Certificate is valid for $DOMAIN"
else
print_error "Certificate validation failed!"
exit 1
fi
# Test HTTPS connection
print_status "Testing HTTPS connection..."
if curl -I --max-time 10 "https://$DOMAIN/" 2>/dev/null | grep -q "200\|301\|302"; then
print_success "HTTPS connection to $DOMAIN is working"
else
print_warning "HTTPS connection test failed - this may be normal if nginx config needs reloading"
fi
# Setup auto-renewal cron job
print_status "Setting up automatic renewal..."
CRON_JOB="0 12 * * * /usr/bin/certbot renew --quiet --post-hook \"systemctl reload nginx\" --cert-name $DOMAIN"
# Check if cron job already exists
if ! crontab -l 2>/dev/null | grep -q "certbot.*$DOMAIN"; then
(crontab -l 2>/dev/null; echo "$CRON_JOB") | crontab -
print_success "Auto-renewal cron job added"
else
print_info "Auto-renewal cron job already exists"
fi
print_success "SSL certificate renewal completed successfully! 🎉"
print_info "Certificate will auto-renew before expiration"
print_info "Admin panel is now available at: https://$DOMAIN"