s
This commit is contained in:
parent
fdf3aea2e3
commit
cf929a3a30
3 changed files with 134 additions and 0 deletions
Binary file not shown.
|
|
@ -86,6 +86,7 @@ else
|
|||
-d api.mnemo-cards.online \
|
||||
-d code.mnemo-cards.online \
|
||||
-d vscode.mnemo-cards.online \
|
||||
-d admin.mnemo-cards.online \
|
||||
--cert-name mnemo-cards.online \
|
||||
--non-interactive --agree-tos --email admin@mnemo-cards.online; then
|
||||
echo "✅ Let's Encrypt multi-domain сертификат успешно создан!"
|
||||
|
|
|
|||
133
tools/ssl/renew_admin_ssl.sh
Executable file
133
tools/ssl/renew_admin_ssl.sh
Executable file
|
|
@ -0,0 +1,133 @@
|
|||
#!/bin/bash
|
||||
|
||||
# SSL Certificate Renewal Script for admin.mnemo-cards.online
|
||||
# This script obtains Let's Encrypt SSL certificate for admin panel
|
||||
# Usage: ./renew_admin_ssl.sh
|
||||
|
||||
set -e
|
||||
|
||||
DOMAIN="admin.mnemo-cards.online"
|
||||
EMAIL="admin@mnemo-cards.online"
|
||||
|
||||
echo "🔐 Starting SSL certificate renewal for $DOMAIN..."
|
||||
|
||||
# Colors for output
|
||||
RED='\033[0;31m'
|
||||
GREEN='\033[0;32m'
|
||||
YELLOW='\033[1;33m'
|
||||
BLUE='\033[0;34m'
|
||||
NC='\033[0m' # No Color
|
||||
|
||||
print_status() {
|
||||
echo -e "${GREEN}[INFO]${NC} $1"
|
||||
}
|
||||
|
||||
print_warning() {
|
||||
echo -e "${YELLOW}[WARNING]${NC} $1"
|
||||
}
|
||||
|
||||
print_error() {
|
||||
echo -e "${RED}[ERROR]${NC} $1"
|
||||
}
|
||||
|
||||
print_success() {
|
||||
echo -e "${GREEN}[SUCCESS]${NC} $1"
|
||||
}
|
||||
|
||||
# Check if certbot is installed
|
||||
if ! command -v certbot &> /dev/null; then
|
||||
print_status "Installing certbot..."
|
||||
apt update
|
||||
apt install -y certbot
|
||||
fi
|
||||
|
||||
# Check current nginx status
|
||||
NGINX_RUNNING=false
|
||||
if systemctl is-active --quiet nginx; then
|
||||
NGINX_RUNNING=true
|
||||
print_status "nginx is currently running"
|
||||
else
|
||||
print_status "nginx is currently stopped"
|
||||
fi
|
||||
|
||||
# Stop nginx for standalone mode
|
||||
if [ "$NGINX_RUNNING" = true ]; then
|
||||
print_status "Stopping nginx for certificate renewal..."
|
||||
systemctl stop nginx
|
||||
sleep 2
|
||||
fi
|
||||
|
||||
# Obtain certificate
|
||||
print_status "Obtaining SSL certificate for $DOMAIN..."
|
||||
if certbot certonly --standalone \
|
||||
-d "$DOMAIN" \
|
||||
--email "$EMAIL" \
|
||||
--agree-tos \
|
||||
--non-interactive; then
|
||||
|
||||
print_success "SSL certificate obtained successfully!"
|
||||
|
||||
# Verify certificate files exist
|
||||
if [ -f "/etc/letsencrypt/live/$DOMAIN/fullchain.pem" ] && [ -f "/etc/letsencrypt/live/$DOMAIN/privkey.pem" ]; then
|
||||
print_success "Certificate files verified"
|
||||
|
||||
# Set proper permissions
|
||||
chmod 600 "/etc/letsencrypt/live/$DOMAIN/privkey.pem"
|
||||
chmod 644 "/etc/letsencrypt/live/$DOMAIN/fullchain.pem"
|
||||
|
||||
print_success "Certificate permissions set"
|
||||
else
|
||||
print_error "Certificate files not found after renewal!"
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
print_error "Failed to obtain SSL certificate!"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Start nginx back
|
||||
if [ "$NGINX_RUNNING" = true ]; then
|
||||
print_status "Starting nginx..."
|
||||
systemctl start nginx
|
||||
sleep 2
|
||||
|
||||
if systemctl is-active --quiet nginx; then
|
||||
print_success "nginx started successfully"
|
||||
else
|
||||
print_error "Failed to start nginx!"
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
# Test certificate validity
|
||||
print_status "Testing certificate validity..."
|
||||
if openssl x509 -in "/etc/letsencrypt/live/$DOMAIN/cert.pem" -text -noout | grep -q "Subject:.*$DOMAIN"; then
|
||||
print_success "Certificate is valid for $DOMAIN"
|
||||
else
|
||||
print_error "Certificate validation failed!"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Test HTTPS connection
|
||||
print_status "Testing HTTPS connection..."
|
||||
if curl -I --max-time 10 "https://$DOMAIN/" 2>/dev/null | grep -q "200\|301\|302"; then
|
||||
print_success "HTTPS connection to $DOMAIN is working"
|
||||
else
|
||||
print_warning "HTTPS connection test failed - this may be normal if nginx config needs reloading"
|
||||
fi
|
||||
|
||||
# Setup auto-renewal cron job
|
||||
print_status "Setting up automatic renewal..."
|
||||
CRON_JOB="0 12 * * * /usr/bin/certbot renew --quiet --post-hook \"systemctl reload nginx\" --cert-name $DOMAIN"
|
||||
|
||||
# Check if cron job already exists
|
||||
if ! crontab -l 2>/dev/null | grep -q "certbot.*$DOMAIN"; then
|
||||
(crontab -l 2>/dev/null; echo "$CRON_JOB") | crontab -
|
||||
print_success "Auto-renewal cron job added"
|
||||
else
|
||||
print_info "Auto-renewal cron job already exists"
|
||||
fi
|
||||
|
||||
print_success "SSL certificate renewal completed successfully! 🎉"
|
||||
print_info "Certificate will auto-renew before expiration"
|
||||
print_info "Admin panel is now available at: https://$DOMAIN"
|
||||
Loading…
Reference in a new issue