mirror of
				https://github.com/acmesh-official/acme.sh
				synced 2025-11-04 22:11:07 +08:00 
			
		
		
		
	Compare commits
	
		
			2192 Commits
		
	
	
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 
						 | 
					f62a4a0c0c | ||
| 
						 | 
					8dacd51abb | ||
| 
						 | 
					06302871bc | ||
| 
						 | 
					c1ec2afeca | ||
| 
						 | 
					572adbaad2 | ||
| 
						 | 
					f4c7822bc9 | ||
| 
						 | 
					89561b8d45 | ||
| 
						 | 
					b0775f7a58 | ||
| 
						 | 
					2dc50e6633 | ||
| 
						 | 
					ad2a3d603e | ||
| 
						 | 
					545f23551f | ||
| 
						 | 
					b15c1ffedc | ||
| 
						 | 
					56d70e4ea7 | ||
| 
						 | 
					0b934232fd | ||
| 
						 | 
					a4a53e1355 | ||
| 
						 | 
					c445e70cff | ||
| 
						 | 
					e8eec2cb41 | ||
| 
						 | 
					dd6fa4af00 | ||
| 
						 | 
					afdb9a63ff | ||
| 
						 | 
					10ba2cd312 | ||
| 
						 | 
					4c1fa9c242 | ||
| 
						 | 
					3c6b707353 | ||
| 
						 | 
					96efc8c7f0 | ||
| 
						 | 
					0cd6afde6f | ||
| 
						 | 
					82b11da4ca | ||
| 
						 | 
					4ec39ab707 | ||
| 
						 | 
					d2a60f3ca4 | ||
| 
						 | 
					3bc6628227 | ||
| 
						 | 
					27579e0701 | ||
| 
						 | 
					f91bcfeb4b | ||
| 
						 | 
					e19809d5b5 | ||
| 
						 | 
					dd068467de | ||
| 
						 | 
					3099c799b2 | ||
| 
						 | 
					cd3ef8fa5a | ||
| 
						 | 
					72ce37704b | ||
| 
						 | 
					4420d073bb | ||
| 
						 | 
					9cc9f519fc | ||
| 
						 | 
					0483d841e3 | ||
| 
						 | 
					5546120312 | ||
| 
						 | 
					ad613e2437 | ||
| 
						 | 
					c544759d36 | ||
| 
						 | 
					20503d3c58 | ||
| 
						 | 
					3fb17c5de8 | ||
| 
						 | 
					a5e4bf16d3 | ||
| 
						 | 
					68d9aad3a2 | ||
| 
						 | 
					0aba1b4ad3 | ||
| 
						 | 
					e12c7c8d27 | ||
| 
						 | 
					83a040722e | ||
| 
						 | 
					b7b504d43a | ||
| 
						 | 
					b18804f57f | ||
| 
						 | 
					550a5fb4c0 | ||
| 
						 | 
					40f0238bb7 | ||
| 
						 | 
					089823785e | ||
| 
						 | 
					ecf7dded07 | ||
| 
						 | 
					909aba27d1 | ||
| 
						 | 
					cd4f29135b | ||
| 
						 | 
					68c5c366f4 | ||
| 
						 | 
					29a5311ae0 | ||
| 
						 | 
					62d774a548 | ||
| 
						 | 
					c9baca7910 | ||
| 
						 | 
					86366ae157 | ||
| 
						 | 
					c4094c68ee | ||
| 
						 | 
					ec67a1b2c1 | ||
| 
						 | 
					7ba9a5972d | ||
| 
						 | 
					b32071ad04 | ||
| 
						 | 
					b38c4e1a28 | ||
| 
						 | 
					a13b2b4018 | ||
| 
						 | 
					65a2f789dc | ||
| 
						 | 
					8bd12ed040 | ||
| 
						 | 
					6914662dd8 | ||
| 
						 | 
					bcb11d9b7e | ||
| 
						 | 
					920cab6f12 | ||
| 
						 | 
					9756adb933 | ||
| 
						 | 
					2671af13cd | ||
| 
						 | 
					37792e9b38 | ||
| 
						 | 
					ebb1a8af1b | ||
| 
						 | 
					f4ba7fcaf4 | ||
| 
						 | 
					13964ac726 | ||
| 
						 | 
					c8c1140f15 | ||
| 
						 | 
					9a473640fb | ||
| 
						 | 
					405173a0b4 | ||
| 
						 | 
					8e43b86f06 | ||
| 
						 | 
					eea9aaf940 | ||
| 
						 | 
					67d3e8d049 | ||
| 
						 | 
					f99ca918db | ||
| 
						 | 
					79a0a66f1f | ||
| 
						 | 
					08681f4a8b | ||
| 
						 | 
					a58ef94a9c | ||
| 
						 | 
					2b9ebd6662 | ||
| 
						 | 
					6fdd2f40ed | ||
| 
						 | 
					238990a285 | ||
| 
						 | 
					1a77490969 | ||
| 
						 | 
					5431d05168 | ||
| 
						 | 
					eb97cdc33a | ||
| 
						 | 
					b54d6589c3 | ||
| 
						 | 
					463768fcf7 | ||
| 
						 | 
					a43545c6ea | ||
| 
						 | 
					9f067d7f56 | ||
| 
						 | 
					8907e2d850 | ||
| 
						 | 
					c84466b131 | ||
| 
						 | 
					f62b956e74 | ||
| 
						 | 
					9841063df9 | ||
| 
						 | 
					803c8177d3 | ||
| 
						 | 
					7ff525468f | ||
| 
						 | 
					7c1c36f043 | ||
| 
						 | 
					565e3f75c7 | ||
| 
						 | 
					842f030355 | ||
| 
						 | 
					f4ad42bb84 | ||
| 
						 | 
					fb08b53f0b | ||
| 
						 | 
					598becf619 | ||
| 
						 | 
					9a27b38976 | ||
| 
						 | 
					7917aa2a7c | ||
| 
						 | 
					d0c97a589b | ||
| 
						 | 
					8ec1ea7b7a | ||
| 
						 | 
					71cb6d2bce | ||
| 
						 | 
					ee258f1425 | ||
| 
						 | 
					50278674f0 | ||
| 
						 | 
					be5085f205 | ||
| 
						 | 
					ca9476f72a | ||
| 
						 | 
					d55c64c838 | ||
| 
						 | 
					563de2cc90 | ||
| 
						 | 
					6afe3ccc3b | ||
| 
						 | 
					14ad5955b5 | ||
| 
						 | 
					a6f2110141 | ||
| 
						 | 
					393d8b9ded | ||
| 
						 | 
					137dc1eac0 | ||
| 
						 | 
					5fee82ce39 | ||
| 
						 | 
					552710ac2a | ||
| 
						 | 
					0a9a11636a | ||
| 
						 | 
					e550631275 | ||
| 
						 | 
					87d2f7f27a | ||
| 
						 | 
					a40cd2b46f | ||
| 
						 | 
					4b581f3720 | ||
| 
						 | 
					12956679e7 | ||
| 
						 | 
					7903fcb48c | ||
| 
						 | 
					9672c6b885 | ||
| 
						 | 
					55369d30a6 | ||
| 
						 | 
					a894b7cc9b | ||
| 
						 | 
					46b3a9158c | ||
| 
						 | 
					26421684dc | ||
| 
						 | 
					fd536d373e | ||
| 
						 | 
					4f59a821d3 | ||
| 
						 | 
					b29e21efa8 | ||
| 
						 | 
					9f6f721a13 | ||
| 
						 | 
					4c1f70af4b | ||
| 
						 | 
					6a81b0f807 | ||
| 
						 | 
					3322630732 | ||
| 
						 | 
					d8885984ab | ||
| 
						 | 
					4a18c45e4f | ||
| 
						 | 
					5b7cac1002 | ||
| 
						 | 
					5aef9266cb | ||
| 
						 | 
					80b40c02b4 | ||
| 
						 | 
					56d6079c4a | ||
| 
						 | 
					3975792bf1 | ||
| 
						 | 
					697e694de6 | ||
| 
						 | 
					828d8eaadb | ||
| 
						 | 
					30ee00ff50 | ||
| 
						 | 
					7e130c2618 | ||
| 
						 | 
					b859dd660c | ||
| 
						 | 
					8868783476 | ||
| 
						 | 
					dc0dd6588c | ||
| 
						 | 
					f7e7e885a9 | ||
| 
						 | 
					d813be1f48 | ||
| 
						 | 
					0d03309c2f | ||
| 
						 | 
					1dab353fdb | ||
| 
						 | 
					8eb4efaddb | ||
| 
						 | 
					12c900ea7d | ||
| 
						 | 
					c31db83b26 | ||
| 
						 | 
					98ce8f4c2f | ||
| 
						 | 
					1f25b4a8a9 | ||
| 
						 | 
					1756bbff84 | ||
| 
						 | 
					21b2ffa42e | ||
| 
						 | 
					b6efdac1db | ||
| 
						 | 
					fc9d321ebe | ||
| 
						 | 
					68a290c347 | ||
| 
						 | 
					9133de50e9 | ||
| 
						 | 
					73d04b976e | ||
| 
						 | 
					a35d271669 | ||
| 
						 | 
					72a7f932c6 | ||
| 
						 | 
					2e74df2583 | ||
| 
						 | 
					4fffb3c816 | ||
| 
						 | 
					840b3a34cb | ||
| 
						 | 
					dc267663a7 | ||
| 
						 | 
					8d6443b25d | ||
| 
						 | 
					e3c7fc8077 | ||
| 
						 | 
					bbf2a15f27 | ||
| 
						 | 
					5a326b82bd | ||
| 
						 | 
					f1b0dd7836 | ||
| 
						 | 
					c205777542 | ||
| 
						 | 
					329a1e6f16 | ||
| 
						 | 
					9c39121e99 | ||
| 
						 | 
					e5e57e684e | ||
| 
						 | 
					659a60aeec | ||
| 
						 | 
					b0268adad9 | ||
| 
						 | 
					71e4bbfc99 | ||
| 
						 | 
					c6bd004d63 | ||
| 
						 | 
					8b6986ba18 | ||
| 
						 | 
					b23718f3ad | ||
| 
						 | 
					8113548920 | ||
| 
						 | 
					b401dbbf65 | ||
| 
						 | 
					75dd0a770f | ||
| 
						 | 
					6d8292cdd8 | ||
| 
						 | 
					0575eb671a | ||
| 
						 | 
					d06eea53ef | ||
| 
						 | 
					9e96a93172 | ||
| 
						 | 
					441f8f3ce8 | ||
| 
						 | 
					1d4dec5510 | ||
| 
						 | 
					167758003c | ||
| 
						 | 
					0a3ac1f5c3 | ||
| 
						 | 
					9173140ddf | ||
| 
						 | 
					7aeb113c62 | ||
| 
						 | 
					22cd408efb | ||
| 
						 | 
					4fbd21da57 | ||
| 
						 | 
					ed95509a4f | ||
| 
						 | 
					4162975f9f | ||
| 
						 | 
					ac0cdcf70b | ||
| 
						 | 
					63134fafec | ||
| 
						 | 
					5494e88e08 | ||
| 
						 | 
					86276ad17b | ||
| 
						 | 
					c883ec40d7 | ||
| 
						 | 
					d19bc328f3 | ||
| 
						 | 
					f286f904dc | ||
| 
						 | 
					150029a5e2 | ||
| 
						 | 
					709a3fb06f | ||
| 
						 | 
					d3c9d0b331 | ||
| 
						 | 
					cc2d59468d | ||
| 
						 | 
					91391fba5d | ||
| 
						 | 
					4369402855 | ||
| 
						 | 
					0bc556618f | ||
| 
						 | 
					cb11580981 | ||
| 
						 | 
					0366e8758c | ||
| 
						 | 
					8d230dd798 | ||
| 
						 | 
					411b342a27 | ||
| 
						 | 
					b9b7032386 | ||
| 
						 | 
					c38ef9023b | ||
| 
						 | 
					9cecd525e2 | ||
| 
						 | 
					4f5995abc0 | ||
| 
						 | 
					2945b230e4 | ||
| 
						 | 
					261cc448f7 | ||
| 
						 | 
					616b0b6baa | ||
| 
						 | 
					d99968ee6d | ||
| 
						 | 
					4a65ff6ae2 | ||
| 
						 | 
					94f91ae687 | ||
| 
						 | 
					28e4bcf67f | ||
| 
						 | 
					884461f1a6 | ||
| 
						 | 
					26c669e42d | ||
| 
						 | 
					f60dde4138 | ||
| 
						 | 
					9c545059ae | ||
| 
						 | 
					05dea7b22a | ||
| 
						 | 
					5b3f915d90 | ||
| 
						 | 
					d987d61ea9 | ||
| 
						 | 
					dedb56d295 | ||
| 
						 | 
					8697972d5d | ||
| 
						 | 
					f90a2ae195 | ||
| 
						 | 
					084de9d8e0 | ||
| 
						 | 
					69b780ee32 | ||
| 
						 | 
					c7b904501c | ||
| 
						 | 
					206be3c161 | ||
| 
						 | 
					48e8022095 | ||
| 
						 | 
					4715a1a5e0 | ||
| 
						 | 
					ed2ba6bc3a | ||
| 
						 | 
					ca1d62bec0 | ||
| 
						 | 
					6a4aad1aa8 | ||
| 
						 | 
					3f0462b68b | ||
| 
						 | 
					f3a622d1a7 | ||
| 
						 | 
					3cd5b9ca2e | ||
| 
						 | 
					e9782c3219 | ||
| 
						 | 
					39ba697e19 | ||
| 
						 | 
					c9818ea2c4 | ||
| 
						 | 
					afe5cb588d | ||
| 
						 | 
					e9e999542d | ||
| 
						 | 
					d9db90752e | ||
| 
						 | 
					f7c3f52817 | ||
| 
						 | 
					681e3785ef | ||
| 
						 | 
					5f593994c7 | ||
| 
						 | 
					ec73aeba16 | ||
| 
						 | 
					7573e560b6 | ||
| 
						 | 
					c8bc155cfe | ||
| 
						 | 
					1eae73105a | ||
| 
						 | 
					360dc140ea | ||
| 
						 | 
					03a1386902 | ||
| 
						 | 
					70b56eb527 | ||
| 
						 | 
					4e05062def | ||
| 
						 | 
					266333468b | ||
| 
						 | 
					e32b3aac22 | ||
| 
						 | 
					676402d918 | ||
| 
						 | 
					edb4d066a9 | ||
| 
						 | 
					03f4518da9 | ||
| 
						 | 
					8259e82787 | ||
| 
						 | 
					838d3ddc17 | ||
| 
						 | 
					66686de4e4 | ||
| 
						 | 
					ce8dca7afe | ||
| 
						 | 
					9f5ef4c1cb | ||
| 
						 | 
					f0a87da375 | ||
| 
						 | 
					263e30d25d | ||
| 
						 | 
					15ffc30d88 | ||
| 
						 | 
					8a5c4979ad | ||
| 
						 | 
					e36fbd6af5 | ||
| 
						 | 
					3216806fae | ||
| 
						 | 
					f8526f027c | ||
| 
						 | 
					ed3066aae7 | ||
| 
						 | 
					98a7e72f0a | ||
| 
						 | 
					a2259865b3 | ||
| 
						 | 
					63f3283591 | ||
| 
						 | 
					d670ea4f59 | ||
| 
						 | 
					d0d10bc6e7 | ||
| 
						 | 
					4fea06c9fa | ||
| 
						 | 
					09fed60dec | ||
| 
						 | 
					75b9c39b0e | ||
| 
						 | 
					5957a1068f | ||
| 
						 | 
					df5229c7c8 | ||
| 
						 | 
					ed817c81de | ||
| 
						 | 
					dd72f7638d | ||
| 
						 | 
					a77e4aa6fa | ||
| 
						 | 
					792f3775ce | ||
| 
						 | 
					4c7700ec3b | ||
| 
						 | 
					eee296c4c2 | ||
| 
						 | 
					499f745732 | ||
| 
						 | 
					446388e0ba | ||
| 
						 | 
					e1628bcdd8 | ||
| 
						 | 
					6d5874fc45 | ||
| 
						 | 
					3d563dea87 | ||
| 
						 | 
					09304c33c1 | ||
| 
						 | 
					521d8c4b1f | ||
| 
						 | 
					b7d573a4b8 | ||
| 
						 | 
					4a62385dcc | ||
| 
						 | 
					98e15f658e | ||
| 
						 | 
					0a3fa35c5d | ||
| 
						 | 
					02e095bec2 | ||
| 
						 | 
					696d9c6bd3 | ||
| 
						 | 
					50dee5d464 | ||
| 
						 | 
					87a8dda955 | ||
| 
						 | 
					d7c73f590c | ||
| 
						 | 
					d1b197e339 | ||
| 
						 | 
					8f5ee989ba | ||
| 
						 | 
					ce9c227425 | ||
| 
						 | 
					e32c2b84ee | ||
| 
						 | 
					ce9f77afed | ||
| 
						 | 
					2bc38b2063 | ||
| 
						 | 
					b4f4c28871 | ||
| 
						 | 
					b14ef537e1 | ||
| 
						 | 
					84ac386481 | ||
| 
						 | 
					f0365d32aa | ||
| 
						 | 
					795764f22f | ||
| 
						 | 
					986f61ac92 | ||
| 
						 | 
					09576f2f4f | ||
| 
						 | 
					bba474dc6b | ||
| 
						 | 
					fde971fe81 | ||
| 
						 | 
					882e1db1d6 | ||
| 
						 | 
					6b0333e919 | ||
| 
						 | 
					914808b867 | ||
| 
						 | 
					2d1d512d0f | ||
| 
						 | 
					37bc099d39 | ||
| 
						 | 
					9e3c931b34 | ||
| 
						 | 
					f8fb0e67b4 | ||
| 
						 | 
					86ef6e6987 | ||
| 
						 | 
					e8fd373e6c | ||
| 
						 | 
					7efa546665 | ||
| 
						 | 
					4d2a0697ed | ||
| 
						 | 
					c6023782a4 | ||
| 
						 | 
					30283282d2 | ||
| 
						 | 
					7588fc0989 | ||
| 
						 | 
					fe843bc466 | ||
| 
						 | 
					5b355c6ca7 | ||
| 
						 | 
					a3f7ff90e3 | ||
| 
						 | 
					1f3f8a5073 | ||
| 
						 | 
					9c88971bc1 | ||
| 
						 | 
					aad309ee4f | ||
| 
						 | 
					e80ca4ddbc | ||
| 
						 | 
					28ccad28c2 | ||
| 
						 | 
					ba9e7fbf64 | ||
| 
						 | 
					28c85cf8e7 | ||
| 
						 | 
					526b5a8d25 | ||
| 
						 | 
					6b15cf3f72 | ||
| 
						 | 
					fbd8ab47ea | ||
| 
						 | 
					893917a25d | ||
| 
						 | 
					af5ff2bb93 | ||
| 
						 | 
					8995d3434f | ||
| 
						 | 
					5f9b0675e2 | ||
| 
						 | 
					46ac97a3ff | ||
| 
						 | 
					db3264ab8c | ||
| 
						 | 
					a0923622ae | ||
| 
						 | 
					aa9975ad0d | ||
| 
						 | 
					6787c81abe | ||
| 
						 | 
					72205176e1 | ||
| 
						 | 
					480742cc15 | ||
| 
						 | 
					48bdfa2377 | ||
| 
						 | 
					2ff6f4d3cf | ||
| 
						 | 
					ae32938531 | ||
| 
						 | 
					d3da603292 | ||
| 
						 | 
					912bcf9487 | ||
| 
						 | 
					413f071861 | ||
| 
						 | 
					668c43abf3 | ||
| 
						 | 
					43e9553ebc | ||
| 
						 | 
					e8b54a5087 | ||
| 
						 | 
					39852662a6 | ||
| 
						 | 
					6a66ba8a21 | ||
| 
						 | 
					36a7a84080 | ||
| 
						 | 
					7e0b334b38 | ||
| 
						 | 
					5d8d217a13 | ||
| 
						 | 
					f2aa5c0235 | ||
| 
						 | 
					323febe8c7 | ||
| 
						 | 
					32d8f349c9 | ||
| 
						 | 
					3910495cce | ||
| 
						 | 
					fe69afdefb | ||
| 
						 | 
					9082862b9d | ||
| 
						 | 
					4ae108009c | ||
| 
						 | 
					a5c1c30368 | ||
| 
						 | 
					8cd3086be0 | ||
| 
						 | 
					dd37ae26a5 | ||
| 
						 | 
					fdaebc7365 | ||
| 
						 | 
					a8b62261f6 | ||
| 
						 | 
					47eb913c22 | ||
| 
						 | 
					7a46293f7a | ||
| 
						 | 
					6b26d2b62d | ||
| 
						 | 
					cac3b3ea35 | ||
| 
						 | 
					dff4d03bd4 | ||
| 
						 | 
					28d83d42e2 | ||
| 
						 | 
					38f1b4d205 | ||
| 
						 | 
					931d19eece | ||
| 
						 | 
					88bbe55b85 | ||
| 
						 | 
					dd17124ec6 | ||
| 
						 | 
					674b50889e | ||
| 
						 | 
					263c38caec | ||
| 
						 | 
					3881f22192 | ||
| 
						 | 
					664446631f | ||
| 
						 | 
					c5f1cca3a0 | ||
| 
						 | 
					a7407097e1 | ||
| 
						 | 
					14bb60c61f | ||
| 
						 | 
					749c0e51e6 | ||
| 
						 | 
					0f120c41f1 | ||
| 
						 | 
					8ab8a6eefb | ||
| 
						 | 
					224e0c298a | ||
| 
						 | 
					a5a0e564dd | ||
| 
						 | 
					b8c94fc7cf | ||
| 
						 | 
					62dd3a5380 | ||
| 
						 | 
					e3ddb677e1 | ||
| 
						 | 
					716f727753 | ||
| 
						 | 
					7e381f8e5d | ||
| 
						 | 
					183063a244 | ||
| 
						 | 
					ef871775b7 | ||
| 
						 | 
					45e386b26d | ||
| 
						 | 
					e1db5db8ac | ||
| 
						 | 
					c3a289cebc | ||
| 
						 | 
					20e51f0b4d | ||
| 
						 | 
					464dc93751 | ||
| 
						 | 
					7445a3be59 | ||
| 
						 | 
					2bbc25c1eb | ||
| 
						 | 
					fd56fe6eb2 | ||
| 
						 | 
					92dfa8becc | ||
| 
						 | 
					ae8f9561ad | ||
| 
						 | 
					3052ba433a | ||
| 
						 | 
					508012342d | ||
| 
						 | 
					9fa207e613 | ||
| 
						 | 
					2d7b9817cb | ||
| 
						 | 
					e8d808d708 | ||
| 
						 | 
					d71595fc75 | ||
| 
						 | 
					399d6592b8 | ||
| 
						 | 
					628a6ffa07 | ||
| 
						 | 
					3e1a94cbcd | ||
| 
						 | 
					a6c2d4b0e2 | ||
| 
						 | 
					19277aec87 | ||
| 
						 | 
					14c2755436 | ||
| 
						 | 
					50a9145386 | ||
| 
						 | 
					9046509b95 | ||
| 
						 | 
					61eaa44cf8 | ||
| 
						 | 
					2d1e9abb60 | ||
| 
						 | 
					d064260bf1 | ||
| 
						 | 
					a19ad3fd1d | ||
| 
						 | 
					3bc59a0327 | ||
| 
						 | 
					5a883889a2 | ||
| 
						 | 
					fbaa7a4d67 | ||
| 
						 | 
					6baa6d488b | ||
| 
						 | 
					e26f9b8095 | ||
| 
						 | 
					f92fae7625 | ||
| 
						 | 
					3d0e269241 | ||
| 
						 | 
					c17c47f18a | ||
| 
						 | 
					98b8bfb3fa | ||
| 
						 | 
					83b1a98db1 | ||
| 
						 | 
					f49f55f4a5 | ||
| 
						 | 
					e58d19b420 | ||
| 
						 | 
					58f753136a | ||
| 
						 | 
					22d827adf1 | ||
| 
						 | 
					d3de50e0f9 | ||
| 
						 | 
					432037d20d | ||
| 
						 | 
					86ef0a2609 | ||
| 
						 | 
					bae50da799 | ||
| 
						 | 
					2c45f27356 | ||
| 
						 | 
					759f4f2c62 | ||
| 
						 | 
					28355335f8 | ||
| 
						 | 
					9f6832d636 | ||
| 
						 | 
					5309afc347 | ||
| 
						 | 
					693627a858 | ||
| 
						 | 
					48eaa0e5bf | ||
| 
						 | 
					9ad7ac632a | ||
| 
						 | 
					41e3ecad46 | ||
| 
						 | 
					d6f8d63742 | ||
| 
						 | 
					28b0929554 | ||
| 
						 | 
					55787ff7b9 | ||
| 
						 | 
					b00919c692 | ||
| 
						 | 
					d43392628b | ||
| 
						 | 
					aa831fee5b | ||
| 
						 | 
					5c568d6999 | ||
| 
						 | 
					d84665cb64 | ||
| 
						 | 
					4bb5d27c59 | ||
| 
						 | 
					11a9f1d1f0 | ||
| 
						 | 
					123e8f21b5 | ||
| 
						 | 
					6d6b2efdb5 | ||
| 
						 | 
					94b925f5ef | ||
| 
						 | 
					c86755f1ab | ||
| 
						 | 
					b8418ced44 | ||
| 
						 | 
					fac0beaa0a | ||
| 
						 | 
					c1f5229906 | ||
| 
						 | 
					d5865989cf | ||
| 
						 | 
					90e587a974 | ||
| 
						 | 
					4a6b31fbe2 | ||
| 
						 | 
					a63766a005 | ||
| 
						 | 
					47359c1a3b | ||
| 
						 | 
					abd0dad2bf | ||
| 
						 | 
					54a52f7048 | ||
| 
						 | 
					f213215c81 | ||
| 
						 | 
					96cde120b4 | ||
| 
						 | 
					0096ef4ddb | ||
| 
						 | 
					ce6c7d4b59 | ||
| 
						 | 
					b51ed9bbb7 | ||
| 
						 | 
					5c6af92a0d | ||
| 
						 | 
					d8eb08e214 | ||
| 
						 | 
					c6f5c7f1a3 | ||
| 
						 | 
					a6b6e31cda | ||
| 
						 | 
					28145a9deb | ||
| 
						 | 
					fa991c8501 | ||
| 
						 | 
					5f345d2089 | ||
| 
						 | 
					520c454f22 | ||
| 
						 | 
					cc81668c8f | ||
| 
						 | 
					6426e044d6 | ||
| 
						 | 
					7b92371a03 | ||
| 
						 | 
					6105d4a4e6 | ||
| 
						 | 
					84649e9d20 | ||
| 
						 | 
					1f7df33e28 | ||
| 
						 | 
					3c394f08b0 | ||
| 
						 | 
					64f07d9bf3 | ||
| 
						 | 
					849a6c12be | ||
| 
						 | 
					9144ce746e | ||
| 
						 | 
					64821ad4f5 | ||
| 
						 | 
					2655e726c9 | ||
| 
						 | 
					de2970d7ef | ||
| 
						 | 
					012dd6986b | ||
| 
						 | 
					2ef9904d00 | ||
| 
						 | 
					2c83224f07 | ||
| 
						 | 
					0c63090a23 | ||
| 
						 | 
					0159277dbf | ||
| 
						 | 
					6ca5f3d8f6 | ||
| 
						 | 
					875625b147 | ||
| 
						 | 
					da0bd5a9dc | ||
| 
						 | 
					ce02ad641b | ||
| 
						 | 
					78915896d5 | ||
| 
						 | 
					4a5d2e16d0 | ||
| 
						 | 
					3e3161c747 | ||
| 
						 | 
					694af4aeb1 | ||
| 
						 | 
					7f59d7ea48 | ||
| 
						 | 
					52b945164c | ||
| 
						 | 
					584fb2904b | ||
| 
						 | 
					71013b372d | ||
| 
						 | 
					338b3ba590 | ||
| 
						 | 
					6b798b01a8 | ||
| 
						 | 
					7df20e5049 | ||
| 
						 | 
					7128d79935 | ||
| 
						 | 
					e27dfbb0bb | ||
| 
						 | 
					a51f109930 | ||
| 
						 | 
					3e101521dd | ||
| 
						 | 
					726c7a4d32 | ||
| 
						 | 
					767f05cfa7 | ||
| 
						 | 
					47b49f1be9 | ||
| 
						 | 
					a4964b9073 | ||
| 
						 | 
					40e2ec3ae9 | ||
| 
						 | 
					120cde169b | ||
| 
						 | 
					1c35f46b45 | ||
| 
						 | 
					eea713eed2 | ||
| 
						 | 
					8c88757451 | ||
| 
						 | 
					dd171ca44a | ||
| 
						 | 
					cfd086a140 | ||
| 
						 | 
					72fe7396d6 | ||
| 
						 | 
					03140865f0 | ||
| 
						 | 
					a4fc802d1b | ||
| 
						 | 
					b6d760b903 | ||
| 
						 | 
					e4b24d20ac | ||
| 
						 | 
					91607bb2a1 | ||
| 
						 | 
					fce8223663 | ||
| 
						 | 
					d1067c60bf | ||
| 
						 | 
					441c26dd32 | ||
| 
						 | 
					00781dd4e1 | ||
| 
						 | 
					c7b8debb6e | ||
| 
						 | 
					d51c383866 | ||
| 
						 | 
					f7d4698ef0 | ||
| 
						 | 
					3fdbbafcb5 | ||
| 
						 | 
					c82cd90ed6 | ||
| 
						 | 
					b6fc8398cf | ||
| 
						 | 
					e90f3b84c1 | ||
| 
						 | 
					9134b6ea98 | ||
| 
						 | 
					4a380ad7fc | ||
| 
						 | 
					c05eb0b1b2 | ||
| 
						 | 
					66feebfc0e | ||
| 
						 | 
					04a609b51f | ||
| 
						 | 
					258cf20c92 | ||
| 
						 | 
					41c8d88217 | ||
| 
						 | 
					37f39c0870 | ||
| 
						 | 
					6ba4f8b54c | ||
| 
						 | 
					c1f8ffa386 | ||
| 
						 | 
					97893d293b | ||
| 
						 | 
					78d1cfb464 | ||
| 
						 | 
					b5fdfe27d5 | ||
| 
						 | 
					cd9fb3b635 | ||
| 
						 | 
					9e9f839d96 | ||
| 
						 | 
					60814ecfe1 | ||
| 
						 | 
					0170c20e9a | ||
| 
						 | 
					01cc2e13d8 | ||
| 
						 | 
					f823f170e6 | ||
| 
						 | 
					be186bd39b | ||
| 
						 | 
					ea25492c28 | ||
| 
						 | 
					79a2bed640 | ||
| 
						 | 
					cd8fc35968 | ||
| 
						 | 
					d2cde379ad | ||
| 
						 | 
					506c41cb15 | ||
| 
						 | 
					72f54ca6c1 | ||
| 
						 | 
					f8d22c486e | ||
| 
						 | 
					c1151b0d45 | ||
| 
						 | 
					0e65fdd6f7 | ||
| 
						 | 
					3164b5ab13 | ||
| 
						 | 
					e6cda79ee8 | ||
| 
						 | 
					45e21d5000 | ||
| 
						 | 
					7e212c4d40 | ||
| 
						 | 
					775aae7082 | ||
| 
						 | 
					a01da2fd92 | ||
| 
						 | 
					cd2fe698bb | ||
| 
						 | 
					4f209e8992 | ||
| 
						 | 
					eb207322d3 | ||
| 
						 | 
					06a2e5fc82 | ||
| 
						 | 
					a8ae23d0a2 | ||
| 
						 | 
					2befb5e784 | ||
| 
						 | 
					6d5e7826ae | ||
| 
						 | 
					c99d4948b7 | ||
| 
						 | 
					ee6f78805f | ||
| 
						 | 
					9a419bd63f | ||
| 
						 | 
					4a139934f6 | ||
| 
						 | 
					2823306810 | ||
| 
						 | 
					4f3b3a273f | ||
| 
						 | 
					6ae3911972 | ||
| 
						 | 
					136aebc009 | ||
| 
						 | 
					6541492a55 | ||
| 
						 | 
					59e9750602 | ||
| 
						 | 
					8ea800205c | ||
| 
						 | 
					59bb9268a1 | ||
| 
						 | 
					a582e7c2fb | ||
| 
						 | 
					6e2669ed1d | ||
| 
						 | 
					7b8a82ce90 | ||
| 
						 | 
					a8bad622ff | ||
| 
						 | 
					9c4f7aa688 | ||
| 
						 | 
					e75b56073b | ||
| 
						 | 
					a95ccc7e4c | ||
| 
						 | 
					8101aceab5 | ||
| 
						 | 
					1c9b19833c | ||
| 
						 | 
					488745f378 | ||
| 
						 | 
					b140e2553b | ||
| 
						 | 
					ae29929714 | ||
| 
						 | 
					9f80909f6a | ||
| 
						 | 
					8201458332 | ||
| 
						 | 
					7a88d80a10 | ||
| 
						 | 
					3ced411769 | ||
| 
						 | 
					f7c346de09 | ||
| 
						 | 
					731ed6952f | ||
| 
						 | 
					454ad6f8bd | ||
| 
						 | 
					8a3b6bf0e6 | ||
| 
						 | 
					fb6e0658cf | ||
| 
						 | 
					f9b8d7a9d8 | ||
| 
						 | 
					f763e1edd7 | ||
| 
						 | 
					dbc3ad1304 | ||
| 
						 | 
					4249e13eb4 | ||
| 
						 | 
					ca7ebd9333 | ||
| 
						 | 
					3f1e6c128f | ||
| 
						 | 
					1f635b90e7 | ||
| 
						 | 
					db3043553c | ||
| 
						 | 
					f87890cb4b | ||
| 
						 | 
					5911594906 | ||
| 
						 | 
					9a1f769828 | ||
| 
						 | 
					b91c0a0616 | ||
| 
						 | 
					4a9f607d31 | ||
| 
						 | 
					a00169451f | ||
| 
						 | 
					ecba959dd9 | ||
| 
						 | 
					a8202d4b37 | ||
| 
						 | 
					657334fb67 | ||
| 
						 | 
					78712245f7 | ||
| 
						 | 
					70702e41e9 | ||
| 
						 | 
					0ca3141088 | ||
| 
						 | 
					ac0970abba | ||
| 
						 | 
					9eeebb147f | ||
| 
						 | 
					dcf8457f4d | ||
| 
						 | 
					534a5ad688 | ||
| 
						 | 
					529cbc0379 | ||
| 
						 | 
					b6aff65997 | ||
| 
						 | 
					b615cce92d | ||
| 
						 | 
					aea631d9d2 | ||
| 
						 | 
					bf942a4cb3 | ||
| 
						 | 
					ceafe389af | ||
| 
						 | 
					f62457a24e | ||
| 
						 | 
					bab4f691c5 | ||
| 
						 | 
					c7becddb78 | ||
| 
						 | 
					cc3660e259 | ||
| 
						 | 
					6e93ff8bca | ||
| 
						 | 
					212d0f24d8 | ||
| 
						 | 
					114003406d | ||
| 
						 | 
					4c99c0127b | ||
| 
						 | 
					c809b33161 | ||
| 
						 | 
					3f1c7da15e | ||
| 
						 | 
					a46695581e | ||
| 
						 | 
					7902d10a3a | ||
| 
						 | 
					8aff2bd74c | ||
| 
						 | 
					352dd907ac | ||
| 
						 | 
					43f195160e | ||
| 
						 | 
					872bfe4757 | ||
| 
						 | 
					70bd493a25 | ||
| 
						 | 
					bd065838fa | ||
| 
						 | 
					5f6e3da766 | ||
| 
						 | 
					ee56b9cd4e | ||
| 
						 | 
					1a27172f20 | ||
| 
						 | 
					4ef1159666 | ||
| 
						 | 
					c924e7c537 | ||
| 
						 | 
					814bd7cb0d | ||
| 
						 | 
					5f2d8c0155 | ||
| 
						 | 
					372f691fd6 | ||
| 
						 | 
					5f05a452fc | ||
| 
						 | 
					afe3283c53 | ||
| 
						 | 
					641a2895a6 | ||
| 
						 | 
					c73c33f94c | ||
| 
						 | 
					6c7da215e7 | ||
| 
						 | 
					754a4a7c8b | ||
| 
						 | 
					0427e8bbb4 | ||
| 
						 | 
					c47f6ed30a | ||
| 
						 | 
					3bdc317fc8 | ||
| 
						 | 
					20cce349e4 | ||
| 
						 | 
					5261162fdf | ||
| 
						 | 
					acf117584b | ||
| 
						 | 
					7b4bbed553 | ||
| 
						 | 
					270ce87582 | ||
| 
						 | 
					2fc0225bc9 | ||
| 
						 | 
					3536cd336d | ||
| 
						 | 
					86dd290c1d | ||
| 
						 | 
					95949b6519 | ||
| 
						 | 
					6499a7298d | ||
| 
						 | 
					042e09d29f | ||
| 
						 | 
					36309e6dbc | ||
| 
						 | 
					e1ac201de1 | ||
| 
						 | 
					f0c4e44d2f | ||
| 
						 | 
					1dc3036822 | ||
| 
						 | 
					a6b399286e | ||
| 
						 | 
					856811bd2e | ||
| 
						 | 
					53273a15bf | ||
| 
						 | 
					3eeb090578 | ||
| 
						 | 
					a9726fde19 | ||
| 
						 | 
					f81d4033fa | ||
| 
						 | 
					5e864ea3b5 | ||
| 
						 | 
					8148bfeacf | ||
| 
						 | 
					1e30718df6 | ||
| 
						 | 
					72e1eb88d9 | ||
| 
						 | 
					8ee5ede834 | ||
| 
						 | 
					bd8b1a2501 | ||
| 
						 | 
					a098167bdb | ||
| 
						 | 
					7790208126 | ||
| 
						 | 
					e52304edb4 | ||
| 
						 | 
					afdd02a80d | ||
| 
						 | 
					c73fdd4022 | ||
| 
						 | 
					4356eefbb1 | ||
| 
						 | 
					6104680caa | ||
| 
						 | 
					4373fdf48c | ||
| 
						 | 
					f9cdfd3e5b | ||
| 
						 | 
					b6c2fc5a69 | ||
| 
						 | 
					cc6610edc2 | ||
| 
						 | 
					7b8ddfdd96 | ||
| 
						 | 
					443a5ca0c2 | ||
| 
						 | 
					3794b5cb58 | ||
| 
						 | 
					6cb5377d73 | ||
| 
						 | 
					a3a92ff1df | ||
| 
						 | 
					2068efdb38 | ||
| 
						 | 
					258ca1b434 | ||
| 
						 | 
					103fa959cb | ||
| 
						 | 
					b6d48b7a14 | ||
| 
						 | 
					412e4e6cf9 | ||
| 
						 | 
					e6f81173a3 | ||
| 
						 | 
					d50281453d | ||
| 
						 | 
					4bb488258d | ||
| 
						 | 
					f6da19ba83 | ||
| 
						 | 
					88bb7b780d | ||
| 
						 | 
					3805e5d37e | ||
| 
						 | 
					a2d6daaef4 | ||
| 
						 | 
					48e9006cd1 | ||
| 
						 | 
					a25a4b5d11 | ||
| 
						 | 
					309bec474f | ||
| 
						 | 
					d36440a06d | ||
| 
						 | 
					2a2f772412 | ||
| 
						 | 
					6a524bff9d | ||
| 
						 | 
					5def1169db | ||
| 
						 | 
					a07395fb56 | ||
| 
						 | 
					e25a375f43 | ||
| 
						 | 
					96801e3478 | ||
| 
						 | 
					90100aa169 | ||
| 
						 | 
					415f375ce6 | ||
| 
						 | 
					94e9844179 | ||
| 
						 | 
					50d238b60f | ||
| 
						 | 
					5c3b41bd93 | ||
| 
						 | 
					3e0971c159 | ||
| 
						 | 
					57740fbd18 | ||
| 
						 | 
					16bc8f7040 | ||
| 
						 | 
					c145f24621 | ||
| 
						 | 
					cd3a4573f2 | ||
| 
						 | 
					8eab77f3c6 | ||
| 
						 | 
					4af339424a | ||
| 
						 | 
					4dd69a8b1a | ||
| 
						 | 
					baa1160594 | ||
| 
						 | 
					f438ff4bab | ||
| 
						 | 
					a25b2af66c | ||
| 
						 | 
					31b67ab92e | ||
| 
						 | 
					5303b36913 | ||
| 
						 | 
					a5c56c547d | ||
| 
						 | 
					ccf9a9976c | ||
| 
						 | 
					ab1efd923b | ||
| 
						 | 
					d6780f9e49 | ||
| 
						 | 
					8534e3b2f7 | ||
| 
						 | 
					8e6cf669ad | ||
| 
						 | 
					577380e98e | ||
| 
						 | 
					235b5b0c15 | ||
| 
						 | 
					aefed1d1b9 | ||
| 
						 | 
					d39649f30d | ||
| 
						 | 
					1546b7e5a9 | ||
| 
						 | 
					ff74778dea | ||
| 
						 | 
					29b21b828b | ||
| 
						 | 
					a6a0495392 | ||
| 
						 | 
					3281043e27 | ||
| 
						 | 
					f7299403f7 | ||
| 
						 | 
					a0d251a336 | ||
| 
						 | 
					8ca45d3d03 | ||
| 
						 | 
					d988542afc | ||
| 
						 | 
					4285d81ca9 | ||
| 
						 | 
					4286b2917e | ||
| 
						 | 
					d09b5cb80e | ||
| 
						 | 
					90fd18bf42 | ||
| 
						 | 
					cae6c8e5f5 | ||
| 
						 | 
					473340c53b | ||
| 
						 | 
					ae302ee600 | ||
| 
						 | 
					27934ac4ca | ||
| 
						 | 
					283ef9adb7 | ||
| 
						 | 
					377fe5ecde | ||
| 
						 | 
					c848d3ee22 | ||
| 
						 | 
					eb6be88fac | ||
| 
						 | 
					fceb728501 | ||
| 
						 | 
					a0df46258d | ||
| 
						 | 
					57d1db58db | ||
| 
						 | 
					d61b687853 | ||
| 
						 | 
					42ab7a5d72 | ||
| 
						 | 
					18cb11dcbf | ||
| 
						 | 
					e9d5407792 | ||
| 
						 | 
					a09b2c0074 | ||
| 
						 | 
					a460ac021f | ||
| 
						 | 
					bdee66fe29 | ||
| 
						 | 
					84a251c8c7 | ||
| 
						 | 
					cea763bb11 | ||
| 
						 | 
					accbda9d2f | ||
| 
						 | 
					7d64e141e4 | ||
| 
						 | 
					6a9b4db448 | ||
| 
						 | 
					e6a95ecd08 | ||
| 
						 | 
					10cb7585a7 | ||
| 
						 | 
					a577c7215f | ||
| 
						 | 
					e5244cf3c0 | ||
| 
						 | 
					c4d0aec536 | ||
| 
						 | 
					796647158e | ||
| 
						 | 
					266e9d0619 | ||
| 
						 | 
					9ec54ef89b | ||
| 
						 | 
					256cb90f3c | ||
| 
						 | 
					8f3a3b293d | ||
| 
						 | 
					975a7359a2 | ||
| 
						 | 
					ac7361a55e | ||
| 
						 | 
					bd41f50ba5 | ||
| 
						 | 
					a2038ab07e | ||
| 
						 | 
					6445a7674b | ||
| 
						 | 
					3bf2e89a1a | ||
| 
						 | 
					e6a13bf386 | ||
| 
						 | 
					42b2adc03e | ||
| 
						 | 
					f2b9af01e8 | ||
| 
						 | 
					9bd2d92755 | ||
| 
						 | 
					babe884b7c | ||
| 
						 | 
					200287254b | ||
| 
						 | 
					0b797f5964 | ||
| 
						 | 
					13a8c309f5 | ||
| 
						 | 
					528d2f29d3 | ||
| 
						 | 
					0aba5dc8de | ||
| 
						 | 
					72fcf5ab85 | ||
| 
						 | 
					dd9df068b0 | ||
| 
						 | 
					81772fb703 | ||
| 
						 | 
					6304566603 | ||
| 
						 | 
					5f8b60a0e5 | ||
| 
						 | 
					4964e075df | ||
| 
						 | 
					e2accaf70e | ||
| 
						 | 
					7b32bbfc26 | ||
| 
						 | 
					6963f3880d | ||
| 
						 | 
					6c3430b6e5 | ||
| 
						 | 
					c53f36a777 | ||
| 
						 | 
					bb4d378733 | ||
| 
						 | 
					333090a967 | ||
| 
						 | 
					c8f5646d53 | ||
| 
						 | 
					3002f6dfd5 | ||
| 
						 | 
					3f8a50e2ae | ||
| 
						 | 
					1a504118e5 | ||
| 
						 | 
					2e602ef6b0 | ||
| 
						 | 
					d55c3faaeb | ||
| 
						 | 
					6b185d20c0 | ||
| 
						 | 
					1bbc33a0cf | ||
| 
						 | 
					a71eba07a1 | ||
| 
						 | 
					422dd1fa4f | ||
| 
						 | 
					c4b2e5829e | ||
| 
						 | 
					1be222f6ed | ||
| 
						 | 
					5463f459e6 | ||
| 
						 | 
					14d7bfdab2 | ||
| 
						 | 
					ea722da3de | ||
| 
						 | 
					9aed1e2d17 | ||
| 
						 | 
					63c6ed3fd0 | ||
| 
						 | 
					744bfc1982 | ||
| 
						 | 
					d04434e3ec | ||
| 
						 | 
					dc3b7b5775 | ||
| 
						 | 
					17fbfd14db | ||
| 
						 | 
					d0f5aece5f | ||
| 
						 | 
					eeda3062e1 | ||
| 
						 | 
					168d712dec | ||
| 
						 | 
					e64ad5176e | ||
| 
						 | 
					0e1469f359 | ||
| 
						 | 
					7d2b6cfeaf | ||
| 
						 | 
					8e7d029946 | ||
| 
						 | 
					9dd62ae0f8 | ||
| 
						 | 
					e7dff4756f | ||
| 
						 | 
					fa98d72f3a | ||
| 
						 | 
					ccf0492890 | ||
| 
						 | 
					eb0ef6bd3d | ||
| 
						 | 
					19aa2ccf4d | ||
| 
						 | 
					841b762796 | ||
| 
						 | 
					63fb90806c | ||
| 
						 | 
					88ada80686 | ||
| 
						 | 
					7d5ddf5e6a | ||
| 
						 | 
					8f01919f62 | ||
| 
						 | 
					98394f99b5 | ||
| 
						 | 
					cae50e16a7 | ||
| 
						 | 
					4a2ac7bd2e | ||
| 
						 | 
					a3bdaa85f2 | ||
| 
						 | 
					40ef86f475 | ||
| 
						 | 
					4cee14f3c5 | ||
| 
						 | 
					48d9a8c180 | ||
| 
						 | 
					1d384e3192 | ||
| 
						 | 
					87f3dc4558 | ||
| 
						 | 
					8afec596aa | ||
| 
						 | 
					26e3263aec | ||
| 
						 | 
					08b4e1a744 | ||
| 
						 | 
					d68f0999a4 | ||
| 
						 | 
					2c9ed4c565 | ||
| 
						 | 
					be4f87c760 | ||
| 
						 | 
					b963dadc14 | ||
| 
						 | 
					26e7fd8b80 | ||
| 
						 | 
					b9a972bccd | ||
| 
						 | 
					bb7b9280d3 | ||
| 
						 | 
					395fbbfd14 | ||
| 
						 | 
					896dfe3def | ||
| 
						 | 
					6c4f33910c | ||
| 
						 | 
					0a301cdd21 | ||
| 
						 | 
					ce59fc6c10 | ||
| 
						 | 
					cbb74c984f | ||
| 
						 | 
					287623df58 | ||
| 
						 | 
					f8c1d97a25 | ||
| 
						 | 
					2a188905da | ||
| 
						 | 
					c2b1e38d7f | ||
| 
						 | 
					fcc0aef7f4 | ||
| 
						 | 
					eaa3de2dce | ||
| 
						 | 
					f3dc5dd12f | ||
| 
						 | 
					d2f0178fab | ||
| 
						 | 
					326c386b2e | ||
| 
						 | 
					6e68c4e2d6 | ||
| 
						 | 
					a79e96802f | ||
| 
						 | 
					65b22b493c | ||
| 
						 | 
					b73f5a4e94 | ||
| 
						 | 
					3b74ac841e | ||
| 
						 | 
					253bf776b5 | ||
| 
						 | 
					eef4acd07d | ||
| 
						 | 
					b6f00ea241 | ||
| 
						 | 
					0bd4a4f98f | ||
| 
						 | 
					0b52645bb6 | ||
| 
						 | 
					8e845d9f21 | ||
| 
						 | 
					d29aa43ba4 | ||
| 
						 | 
					450efea191 | ||
| 
						 | 
					241cfc4342 | ||
| 
						 | 
					7c67e3d7e2 | ||
| 
						 | 
					674790a511 | ||
| 
						 | 
					4e3c82e329 | ||
| 
						 | 
					df711b0ea2 | ||
| 
						 | 
					1019fd9a9d | ||
| 
						 | 
					8a420dd853 | ||
| 
						 | 
					f8bcfeb2ab | ||
| 
						 | 
					34e5beda6a | ||
| 
						 | 
					6185244754 | ||
| 
						 | 
					60d9509e39 | ||
| 
						 | 
					ded4469efe | ||
| 
						 | 
					1f95d8eedf | ||
| 
						 | 
					aa66dfff57 | ||
| 
						 | 
					25263ce40f | ||
| 
						 | 
					e85deb54e1 | ||
| 
						 | 
					4750fd159e | ||
| 
						 | 
					7eea9533e8 | ||
| 
						 | 
					ec675b9ad2 | ||
| 
						 | 
					486e77f474 | ||
| 
						 | 
					048059ba1f | ||
| 
						 | 
					ed3dda7da9 | ||
| 
						 | 
					fa93d68b08 | ||
| 
						 | 
					6093a4f9f8 | ||
| 
						 | 
					4e20d89d9c | ||
| 
						 | 
					b420ec6cb9 | ||
| 
						 | 
					375f6101e9 | ||
| 
						 | 
					2844d73dc7 | ||
| 
						 | 
					6c1176f853 | ||
| 
						 | 
					df037db0bb | ||
| 
						 | 
					949cc7d21b | ||
| 
						 | 
					9244529007 | ||
| 
						 | 
					319d49ddbe | ||
| 
						 | 
					96fcfdb6c6 | ||
| 
						 | 
					d61ef6b49a | ||
| 
						 | 
					804a6c8d47 | ||
| 
						 | 
					c487cd6af2 | ||
| 
						 | 
					6a2592a9d9 | ||
| 
						 | 
					0f48b15695 | ||
| 
						 | 
					4320b8a5a5 | ||
| 
						 | 
					a20707cd73 | ||
| 
						 | 
					5da1d3b73b | ||
| 
						 | 
					be15e63d41 | ||
| 
						 | 
					9bc5f686eb | ||
| 
						 | 
					5bed21dace | ||
| 
						 | 
					a97e651582 | ||
| 
						 | 
					dff641a665 | ||
| 
						 | 
					47a25cc3e8 | ||
| 
						 | 
					5e3a5f627a | ||
| 
						 | 
					9201e0a5b9 | ||
| 
						 | 
					4c80ed3208 | ||
| 
						 | 
					f34579e921 | ||
| 
						 | 
					cc1d3b20b6 | ||
| 
						 | 
					21f728f0ea | ||
| 
						 | 
					8051b6e8b6 | ||
| 
						 | 
					4c38fec3b5 | ||
| 
						 | 
					c4cdcf44c5 | ||
| 
						 | 
					347dab0c14 | ||
| 
						 | 
					a3d3ea2b4b | ||
| 
						 | 
					5332387125 | ||
| 
						 | 
					5b21cbe0de | ||
| 
						 | 
					2f4111a2e2 | ||
| 
						 | 
					326ac485b3 | ||
| 
						 | 
					f9b419d1e4 | ||
| 
						 | 
					f4e81953ce | ||
| 
						 | 
					2b09253961 | ||
| 
						 | 
					1994c6828e | ||
| 
						 | 
					f5c381d5b4 | ||
| 
						 | 
					7e2af8364f | ||
| 
						 | 
					0a2ab2aed2 | ||
| 
						 | 
					2310a9bbc0 | ||
| 
						 | 
					5b3e3d9cf4 | ||
| 
						 | 
					c97c79ab2f | ||
| 
						 | 
					1231b71245 | ||
| 
						 | 
					824ffa24f4 | ||
| 
						 | 
					148f869bec | ||
| 
						 | 
					c140fe9bae | ||
| 
						 | 
					4b02ee5b46 | ||
| 
						 | 
					de3bac53bf | ||
| 
						 | 
					3f1a76d9e4 | ||
| 
						 | 
					0138e167e9 | ||
| 
						 | 
					bcd2ee6204 | ||
| 
						 | 
					4c1d521711 | ||
| 
						 | 
					90c70fa5bf | ||
| 
						 | 
					8e15c48092 | ||
| 
						 | 
					9cf65e31cd | ||
| 
						 | 
					a6e5876d96 | ||
| 
						 | 
					937e723036 | ||
| 
						 | 
					3a439063a6 | ||
| 
						 | 
					12d876a005 | ||
| 
						 | 
					4e2426a2b4 | ||
| 
						 | 
					020f9cd2a6 | ||
| 
						 | 
					d7eebe9df0 | ||
| 
						 | 
					cebc5bf9fc | ||
| 
						 | 
					dbe68684a0 | ||
| 
						 | 
					27a05ff271 | ||
| 
						 | 
					1489ddc49a | ||
| 
						 | 
					9be2c1beb9 | ||
| 
						 | 
					9964e6eba3 | ||
| 
						 | 
					8bcc19d91e | ||
| 
						 | 
					3c07f57aad | ||
| 
						 | 
					3262a916e0 | ||
| 
						 | 
					7883cc5891 | ||
| 
						 | 
					ded7a5438c | ||
| 
						 | 
					cd98951001 | ||
| 
						 | 
					8470c60e06 | ||
| 
						 | 
					394b1002b3 | ||
| 
						 | 
					9a61d6293d | ||
| 
						 | 
					192ad27f8f | ||
| 
						 | 
					eb0fc67461 | ||
| 
						 | 
					adbe5e9048 | ||
| 
						 | 
					fcdf41ba29 | ||
| 
						 | 
					7b40cbe8c1 | ||
| 
						 | 
					0933929cfe | ||
| 
						 | 
					7f618e7ecc | ||
| 
						 | 
					482cb73702 | ||
| 
						 | 
					fd1598017a | ||
| 
						 | 
					96f79475f1 | ||
| 
						 | 
					3576754c21 | ||
| 
						 | 
					6c3a0bc72c | ||
| 
						 | 
					49d75a0cd4 | ||
| 
						 | 
					756dbac39f | ||
| 
						 | 
					7df062b7d7 | ||
| 
						 | 
					e485e8f60d | ||
| 
						 | 
					fde8ea081a | ||
| 
						 | 
					f7217c5f26 | ||
| 
						 | 
					fd77e463a1 | ||
| 
						 | 
					6d7f6750e9 | ||
| 
						 | 
					695482ded7 | ||
| 
						 | 
					fc9649dbc4 | ||
| 
						 | 
					afb67d375f | ||
| 
						 | 
					66e38ae69e | ||
| 
						 | 
					1f4e64f81d | ||
| 
						 | 
					ad541f713d | ||
| 
						 | 
					f3b434397b | ||
| 
						 | 
					1d5d49312c | ||
| 
						 | 
					232c7361a9 | ||
| 
						 | 
					721543653b | ||
| 
						 | 
					d8ba26e664 | ||
| 
						 | 
					7ecabeac97 | ||
| 
						 | 
					6cf7be4b7e | ||
| 
						 | 
					5f2e56674c | ||
| 
						 | 
					58d4c74b0b | ||
| 
						 | 
					e137792efd | ||
| 
						 | 
					b7b934913e | ||
| 
						 | 
					cd8fcbf9c6 | ||
| 
						 | 
					d0300d4443 | ||
| 
						 | 
					40acd9a4c3 | ||
| 
						 | 
					e66b4d5390 | ||
| 
						 | 
					f94433e504 | ||
| 
						 | 
					7f32488b78 | ||
| 
						 | 
					8f73e24175 | ||
| 
						 | 
					f3c984281c | ||
| 
						 | 
					00777a10ae | ||
| 
						 | 
					0d6ce9f977 | ||
| 
						 | 
					997c517ba2 | ||
| 
						 | 
					849bed4bef | ||
| 
						 | 
					61a48a5b9f | ||
| 
						 | 
					df14085ec8 | ||
| 
						 | 
					00b34eb2a4 | ||
| 
						 | 
					84a6730b1a | ||
| 
						 | 
					357b514bc9 | ||
| 
						 | 
					d39b108274 | ||
| 
						 | 
					39f3239682 | ||
| 
						 | 
					506f36b26d | ||
| 
						 | 
					4cedbf80df | ||
| 
						 | 
					b54ce31078 | ||
| 
						 | 
					9b2aa974ba | ||
| 
						 | 
					291c97dc81 | ||
| 
						 | 
					bcbecff6f6 | ||
| 
						 | 
					3d22708f67 | ||
| 
						 | 
					8afd31902f | ||
| 
						 | 
					89f66ebf6d | ||
| 
						 | 
					d1a2208196 | ||
| 
						 | 
					42d1fe5422 | ||
| 
						 | 
					1424e8a2de | ||
| 
						 | 
					7dc548b4b8 | ||
| 
						 | 
					2c37d94611 | ||
| 
						 | 
					b1e4a7c615 | ||
| 
						 | 
					b0561058c6 | ||
| 
						 | 
					d039295070 | ||
| 
						 | 
					4ddafb8e84 | ||
| 
						 | 
					a536231ded | ||
| 
						 | 
					13fe54c938 | ||
| 
						 | 
					d54ffdd187 | ||
| 
						 | 
					5c539af7d7 | ||
| 
						 | 
					47d9a9cf20 | ||
| 
						 | 
					7f25205aeb | ||
| 
						 | 
					688973fa44 | ||
| 
						 | 
					7ebecf3851 | ||
| 
						 | 
					0a5eaec0f2 | ||
| 
						 | 
					4bdab73dd5 | ||
| 
						 | 
					f19f21007c | ||
| 
						 | 
					f21dd9117d | ||
| 
						 | 
					2aa75f034f | ||
| 
						 | 
					5c78e0a462 | ||
| 
						 | 
					52cdedcba0 | ||
| 
						 | 
					c87cd0de73 | ||
| 
						 | 
					12530655df | ||
| 
						 | 
					7479706b29 | ||
| 
						 | 
					070a141601 | ||
| 
						 | 
					7044236824 | ||
| 
						 | 
					3e9478b58d | ||
| 
						 | 
					5ffca2d138 | ||
| 
						 | 
					a8d4a98621 | ||
| 
						 | 
					905f7f4ecc | ||
| 
						 | 
					819d2bc560 | ||
| 
						 | 
					c0b2027588 | ||
| 
						 | 
					136d1b04b5 | ||
| 
						 | 
					f063dd195e | ||
| 
						 | 
					be972fc0b5 | ||
| 
						 | 
					ac11ba3d60 | ||
| 
						 | 
					3d8598654c | ||
| 
						 | 
					55a5da2102 | ||
| 
						 | 
					f881d6c44f | ||
| 
						 | 
					5df2ca3ef3 | ||
| 
						 | 
					a15f87ae39 | ||
| 
						 | 
					0dd6377fe6 | ||
| 
						 | 
					c7257e0a3c | ||
| 
						 | 
					3b7fbcd0c3 | ||
| 
						 | 
					5fe91af6c3 | ||
| 
						 | 
					4dd646a424 | ||
| 
						 | 
					dcbd90ce04 | ||
| 
						 | 
					04683338a2 | ||
| 
						 | 
					b778f9c40e | ||
| 
						 | 
					e0a96be378 | ||
| 
						 | 
					ac690fceaf | ||
| 
						 | 
					1e5e03cc46 | ||
| 
						 | 
					d3c4cd8270 | ||
| 
						 | 
					17361df66b | ||
| 
						 | 
					7d0452c7e3 | ||
| 
						 | 
					dd0b0cae93 | ||
| 
						 | 
					c4bf5eef73 | ||
| 
						 | 
					2587639914 | ||
| 
						 | 
					bfa1ae59cc | ||
| 
						 | 
					9e8575c315 | ||
| 
						 | 
					e36340ce64 | ||
| 
						 | 
					63ec05a66c | ||
| 
						 | 
					6f1c72f5b4 | ||
| 
						 | 
					27924ffd5b | ||
| 
						 | 
					527029574c | ||
| 
						 | 
					cf3aeafcdb | ||
| 
						 | 
					f08a79d372 | ||
| 
						 | 
					eb2a26cfaa | ||
| 
						 | 
					5378d9ca26 | ||
| 
						 | 
					bce11af09a | ||
| 
						 | 
					158abf5c6c | ||
| 
						 | 
					b30c1daf72 | ||
| 
						 | 
					0649206796 | ||
| 
						 | 
					f589a1d245 | ||
| 
						 | 
					68eb627d62 | ||
| 
						 | 
					9c87a5890d | ||
| 
						 | 
					e538a13e28 | ||
| 
						 | 
					6fb2a1ed39 | ||
| 
						 | 
					6b00787f45 | ||
| 
						 | 
					e735d8d4e5 | ||
| 
						 | 
					8cd4fd0b50 | ||
| 
						 | 
					8f4b0559ce | ||
| 
						 | 
					5288c54aad | ||
| 
						 | 
					51f8bec81b | ||
| 
						 | 
					49d3e5d324 | ||
| 
						 | 
					1fff0e5592 | ||
| 
						 | 
					8d53ec5353 | ||
| 
						 | 
					a1e1bfc71b | ||
| 
						 | 
					29992f54a3 | ||
| 
						 | 
					4ab6786163 | ||
| 
						 | 
					eaad34a69a | ||
| 
						 | 
					839f18d052 | ||
| 
						 | 
					58ef6d8385 | ||
| 
						 | 
					a0037c9333 | ||
| 
						 | 
					177b57e1c0 | ||
| 
						 | 
					810c129ca9 | ||
| 
						 | 
					f731a4c704 | ||
| 
						 | 
					39a1f1ef64 | ||
| 
						 | 
					d24a87caf1 | ||
| 
						 | 
					9683ffe13a | ||
| 
						 | 
					fab2d9dc6a | ||
| 
						 | 
					59f7a2f6ef | ||
| 
						 | 
					9b12407028 | ||
| 
						 | 
					96c4bb7fd0 | ||
| 
						 | 
					81532f375e | ||
| 
						 | 
					79eb8e2b35 | ||
| 
						 | 
					7c2e875494 | ||
| 
						 | 
					c715b4637d | ||
| 
						 | 
					c719a61ea7 | ||
| 
						 | 
					58e4d337e4 | ||
| 
						 | 
					509c802045 | ||
| 
						 | 
					4fd63f4e30 | ||
| 
						 | 
					f5c28c72fd | ||
| 
						 | 
					342128a457 | ||
| 
						 | 
					b1931828e1 | ||
| 
						 | 
					4410226db1 | ||
| 
						 | 
					945bd4b1b0 | ||
| 
						 | 
					77f1ea40cd | ||
| 
						 | 
					98c8c7ce0d | ||
| 
						 | 
					795bf9e101 | ||
| 
						 | 
					851fedf751 | ||
| 
						 | 
					5be6ab8c89 | ||
| 
						 | 
					3670412c7c | ||
| 
						 | 
					e6cd596dc9 | ||
| 
						 | 
					abf4278d09 | ||
| 
						 | 
					2b2b65fe18 | ||
| 
						 | 
					3d6a125bdc | ||
| 
						 | 
					9efd40a366 | ||
| 
						 | 
					383fa8401d | ||
| 
						 | 
					bf8ffade29 | ||
| 
						 | 
					1633d14547 | ||
| 
						 | 
					e55605dbe9 | ||
| 
						 | 
					cdec38ba12 | ||
| 
						 | 
					1cb6e9e7d0 | ||
| 
						 | 
					d1d2f6f451 | ||
| 
						 | 
					743f821f1e | ||
| 
						 | 
					b95a99e0c2 | ||
| 
						 | 
					3ebbeb103c | ||
| 
						 | 
					0d4035e996 | ||
| 
						 | 
					88ed5e506a | ||
| 
						 | 
					76a3371b40 | ||
| 
						 | 
					7b2fa1edb4 | ||
| 
						 | 
					1965035166 | ||
| 
						 | 
					76d4ff056a | ||
| 
						 | 
					a239a9efd5 | ||
| 
						 | 
					4747e7c5b9 | ||
| 
						 | 
					35ca729cb9 | ||
| 
						 | 
					a0fa7421d1 | ||
| 
						 | 
					ddf293bbcd | ||
| 
						 | 
					45d6e00ff1 | ||
| 
						 | 
					6dfc8fe0ea | ||
| 
						 | 
					96f106d6aa | ||
| 
						 | 
					044da37c95 | ||
| 
						 | 
					e0b00ee11a | ||
| 
						 | 
					086444c73a | ||
| 
						 | 
					1efb2085e9 | ||
| 
						 | 
					e1c42eb6cc | ||
| 
						 | 
					a2da26cbdd | ||
| 
						 | 
					8796adfd63 | ||
| 
						 | 
					95a6c28d98 | ||
| 
						 | 
					85e1f4ea13 | ||
| 
						 | 
					d9c9114b3b | ||
| 
						 | 
					02140ce763 | ||
| 
						 | 
					af1cc3b331 | ||
| 
						 | 
					e852044b64 | ||
| 
						 | 
					f845b371ce | ||
| 
						 | 
					3a1bd3114b | ||
| 
						 | 
					a6d2e3a1e6 | ||
| 
						 | 
					93bce1b24c | ||
| 
						 | 
					7b87f29c9c | ||
| 
						 | 
					cb6f622957 | ||
| 
						 | 
					43d3b51bde | ||
| 
						 | 
					57e015155a | ||
| 
						 | 
					2436d7e0ba | ||
| 
						 | 
					e6e85b0c55 | ||
| 
						 | 
					e43fd39594 | ||
| 
						 | 
					52765466c1 | ||
| 
						 | 
					fa9afb0860 | ||
| 
						 | 
					e02bede4f5 | ||
| 
						 | 
					113089be5d | ||
| 
						 | 
					712b895170 | ||
| 
						 | 
					dca163f54d | ||
| 
						 | 
					fc6cf4d963 | ||
| 
						 | 
					4126c7e188 | ||
| 
						 | 
					db50462920 | ||
| 
						 | 
					9310b44cef | ||
| 
						 | 
					6480250221 | ||
| 
						 | 
					710ce7c2e9 | ||
| 
						 | 
					b88e64f0d0 | ||
| 
						 | 
					c70432996a | ||
| 
						 | 
					c6dcf2a0e2 | ||
| 
						 | 
					2aec627503 | ||
| 
						 | 
					b7924ce58b | ||
| 
						 | 
					0bc745f68f | ||
| 
						 | 
					8acdf823a2 | ||
| 
						 | 
					52f8b787c9 | ||
| 
						 | 
					ad153ae041 | ||
| 
						 | 
					2527f8f599 | ||
| 
						 | 
					72af092cc1 | ||
| 
						 | 
					2751060b91 | ||
| 
						 | 
					b3449db2f8 | ||
| 
						 | 
					7db28745c8 | ||
| 
						 | 
					6921211461 | ||
| 
						 | 
					9f90618a70 | ||
| 
						 | 
					302c41edc9 | ||
| 
						 | 
					5d943a35f8 | ||
| 
						 | 
					03f8d6e946 | ||
| 
						 | 
					68a35155e4 | ||
| 
						 | 
					9d725af602 | ||
| 
						 | 
					d04ccb7a3f | ||
| 
						 | 
					76c1ed6628 | ||
| 
						 | 
					6f4abe95cb | ||
| 
						 | 
					e35e313240 | ||
| 
						 | 
					3a77a6eded | ||
| 
						 | 
					0a7a1b9bfb | ||
| 
						 | 
					3e1418d662 | ||
| 
						 | 
					884f70fb39 | ||
| 
						 | 
					9499a1142b | ||
| 
						 | 
					6e8dcdce78 | ||
| 
						 | 
					ce9fae82bd | ||
| 
						 | 
					afa3fc8bf9 | ||
| 
						 | 
					09eccf6fc0 | ||
| 
						 | 
					edfefb6763 | ||
| 
						 | 
					98b3dcbf37 | ||
| 
						 | 
					2698ef6c5f | ||
| 
						 | 
					46b2ee3bae | ||
| 
						 | 
					e7ee3a7dd5 | ||
| 
						 | 
					0085e6f83b | ||
| 
						 | 
					c90fa3bcfc | ||
| 
						 | 
					0ec9b9823f | ||
| 
						 | 
					50d7b8452d | ||
| 
						 | 
					d88f8e862b | ||
| 
						 | 
					fd72cced13 | ||
| 
						 | 
					18a90734d9 | ||
| 
						 | 
					a4b2cebef6 | ||
| 
						 | 
					68d708e56d | ||
| 
						 | 
					e925ab0999 | ||
| 
						 | 
					a6feb0a887 | ||
| 
						 | 
					cd9c3a79e5 | ||
| 
						 | 
					f3685bdef9 | ||
| 
						 | 
					e2edf20833 | ||
| 
						 | 
					31e39f1f6d | ||
| 
						 | 
					d47c5eaf60 | ||
| 
						 | 
					b8e515a738 | ||
| 
						 | 
					0984585d58 | ||
| 
						 | 
					f3e0eb705b | ||
| 
						 | 
					04e0f87c03 | ||
| 
						 | 
					8ccfcd272f | ||
| 
						 | 
					ba69062a36 | ||
| 
						 | 
					cea24b5f70 | ||
| 
						 | 
					f3a71f62a1 | ||
| 
						 | 
					4e4a6d8397 | ||
| 
						 | 
					d8beaf727f | ||
| 
						 | 
					c961c865ee | ||
| 
						 | 
					34f25fa590 | ||
| 
						 | 
					7af1155c11 | ||
| 
						 | 
					c9d7daab70 | ||
| 
						 | 
					e3feac3fd8 | ||
| 
						 | 
					1a5989350f | ||
| 
						 | 
					3365df7778 | ||
| 
						 | 
					3be5a68e12 | ||
| 
						 | 
					f158caa2eb | ||
| 
						 | 
					e02c94eb00 | ||
| 
						 | 
					981077516b | ||
| 
						 | 
					7c488b5913 | ||
| 
						 | 
					0e44f587a5 | ||
| 
						 | 
					e593d86b80 | ||
| 
						 | 
					339a8ad610 | ||
| 
						 | 
					d1190febec | ||
| 
						 | 
					5d2c5b01a8 | ||
| 
						 | 
					0f954c20ff | ||
| 
						 | 
					d6edff3182 | ||
| 
						 | 
					dba26c3240 | ||
| 
						 | 
					0ca5b7996c | ||
| 
						 | 
					9507b121ac | ||
| 
						 | 
					3812b275e9 | ||
| 
						 | 
					6c1561f415 | ||
| 
						 | 
					9ab6353d73 | ||
| 
						 | 
					ff60dc4d24 | ||
| 
						 | 
					62e7d904b4 | ||
| 
						 | 
					5d3de4b670 | ||
| 
						 | 
					7d75ad4c56 | ||
| 
						 | 
					63e1d3610c | ||
| 
						 | 
					b4325026b1 | ||
| 
						 | 
					b072ef2e82 | ||
| 
						 | 
					562a4c056e | ||
| 
						 | 
					bb8248556d | ||
| 
						 | 
					b22b085b50 | ||
| 
						 | 
					e82ea94bb6 | ||
| 
						 | 
					a50252382a | ||
| 
						 | 
					9bdb799b41 | ||
| 
						 | 
					989651c23b | ||
| 
						 | 
					259cefab72 | ||
| 
						 | 
					09ed421948 | ||
| 
						 | 
					87f5ec5be5 | ||
| 
						 | 
					f78b656f5f | ||
| 
						 | 
					e6b940e247 | ||
| 
						 | 
					50a9680f17 | ||
| 
						 | 
					f2a6dc4dfd | ||
| 
						 | 
					67e3dd36b3 | ||
| 
						 | 
					6c4cc357b5 | ||
| 
						 | 
					94965a418f | ||
| 
						 | 
					40e6ba1100 | ||
| 
						 | 
					0aed065a75 | ||
| 
						 | 
					70b63a5ed4 | ||
| 
						 | 
					1476a9ecf1 | ||
| 
						 | 
					600a235140 | ||
| 
						 | 
					ffa9f104db | ||
| 
						 | 
					b807ec0956 | ||
| 
						 | 
					5f8daeeb6d | ||
| 
						 | 
					aec8307417 | ||
| 
						 | 
					e96a1b01b9 | ||
| 
						 | 
					d78ba322bf | ||
| 
						 | 
					ab5c1b0a3a | ||
| 
						 | 
					53fa16d39f | ||
| 
						 | 
					05cf405cb5 | ||
| 
						 | 
					5d833336d3 | ||
| 
						 | 
					13be9d8d79 | ||
| 
						 | 
					bb6326f4d4 | ||
| 
						 | 
					c070407ab2 | ||
| 
						 | 
					6b27bdadcd | ||
| 
						 | 
					1c22c2f76a | ||
| 
						 | 
					aa262d4124 | ||
| 
						 | 
					646c0bfcb9 | ||
| 
						 | 
					da68775472 | ||
| 
						 | 
					bcf96608d1 | ||
| 
						 | 
					dd17ac5045 | ||
| 
						 | 
					59182dbc97 | ||
| 
						 | 
					11df7187b3 | ||
| 
						 | 
					0899803294 | ||
| 
						 | 
					4742e0951c | ||
| 
						 | 
					c3b1eb0837 | ||
| 
						 | 
					542d7977db | ||
| 
						 | 
					11927a768e | ||
| 
						 | 
					ecd5bcec0c | ||
| 
						 | 
					911a2084d4 | ||
| 
						 | 
					839bf0e2c9 | ||
| 
						 | 
					25555b8c3e | ||
| 
						 | 
					cd7ac94f35 | ||
| 
						 | 
					68aea3af9e | ||
| 
						 | 
					cdb3216cc9 | ||
| 
						 | 
					78f0201dfa | ||
| 
						 | 
					2cd47b0240 | ||
| 
						 | 
					be83a6a37a | ||
| 
						 | 
					8ca99e85b0 | ||
| 
						 | 
					f5b546b3c8 | ||
| 
						 | 
					50c9d17830 | ||
| 
						 | 
					d87af4788e | ||
| 
						 | 
					0f21537f14 | ||
| 
						 | 
					0533bde9f2 | ||
| 
						 | 
					32b3717c32 | ||
| 
						 | 
					d950f801af | ||
| 
						 | 
					a8ab028b84 | ||
| 
						 | 
					2aff36e74b | ||
| 
						 | 
					db7e4bf940 | ||
| 
						 | 
					ee20015d44 | ||
| 
						 | 
					80941f8413 | ||
| 
						 | 
					cf909db159 | ||
| 
						 | 
					27dbe77fad | ||
| 
						 | 
					38f2334360 | ||
| 
						 | 
					6489a48e1f | ||
| 
						 | 
					ca24d1762e | ||
| 
						 | 
					2f4b84c074 | ||
| 
						 | 
					6ae810a1fa | ||
| 
						 | 
					3e3f695536 | ||
| 
						 | 
					3ca93f4a4c | ||
| 
						 | 
					f2d9930773 | ||
| 
						 | 
					2fbf399156 | ||
| 
						 | 
					5fe91d6577 | ||
| 
						 | 
					753d0e7df7 | ||
| 
						 | 
					e2cc350fbc | ||
| 
						 | 
					07feb87dee | ||
| 
						 | 
					1699e94f0f | ||
| 
						 | 
					8a1e335bf5 | ||
| 
						 | 
					5413bf8753 | ||
| 
						 | 
					c4c5ecd03d | ||
| 
						 | 
					3b67cf4378 | ||
| 
						 | 
					f3c937f9ed | ||
| 
						 | 
					671a699472 | ||
| 
						 | 
					cc4fa1c6bd | ||
| 
						 | 
					d11d476126 | ||
| 
						 | 
					1ce06c7cdd | ||
| 
						 | 
					800f02ba38 | ||
| 
						 | 
					79964b0e85 | ||
| 
						 | 
					0924d11bbf | ||
| 
						 | 
					3cf85634eb | ||
| 
						 | 
					ec01175d37 | ||
| 
						 | 
					5bb518ff0f | ||
| 
						 | 
					5415381cf4 | ||
| 
						 | 
					129ae06354 | ||
| 
						 | 
					058e5d5f4b | ||
| 
						 | 
					2ec493f033 | ||
| 
						 | 
					a33e8a8509 | ||
| 
						 | 
					7b4be7be40 | ||
| 
						 | 
					b90917a529 | ||
| 
						 | 
					180f05f6f0 | ||
| 
						 | 
					b2686e5b6d | ||
| 
						 | 
					831b95f13a | ||
| 
						 | 
					331b599a81 | ||
| 
						 | 
					3ef817ebc2 | ||
| 
						 | 
					d0f7c309ab | ||
| 
						 | 
					e5079b9dad | ||
| 
						 | 
					9e773c9143 | ||
| 
						 | 
					fe600441c9 | ||
| 
						 | 
					291b56db93 | ||
| 
						 | 
					ec9975c3d9 | ||
| 
						 | 
					9e57161941 | ||
| 
						 | 
					20444bf253 | ||
| 
						 | 
					e428c4402e | ||
| 
						 | 
					15af89d51c | ||
| 
						 | 
					ed95865696 | ||
| 
						 | 
					8c71bd57e7 | ||
| 
						 | 
					d204be4b2c | ||
| 
						 | 
					4743171b4f | ||
| 
						 | 
					1fb800f7a7 | ||
| 
						 | 
					3a3b0dd5c1 | ||
| 
						 | 
					2959281d42 | ||
| 
						 | 
					e2c939fb97 | ||
| 
						 | 
					51d0e4325e | ||
| 
						 | 
					08b6cf0231 | ||
| 
						 | 
					059147b74a | ||
| 
						 | 
					c96ceeb1bd | ||
| 
						 | 
					0a3b6c4813 | ||
| 
						 | 
					8636a15695 | ||
| 
						 | 
					96db9362c5 | ||
| 
						 | 
					f81f93e9c3 | ||
| 
						 | 
					a3a04b5f76 | ||
| 
						 | 
					329174b6d9 | ||
| 
						 | 
					b171aff418 | ||
| 
						 | 
					1f6ffa3e88 | ||
| 
						 | 
					24d2a8b9d5 | ||
| 
						 | 
					4d8b99a307 | ||
| 
						 | 
					f9085fedd7 | ||
| 
						 | 
					c4236e58d1 | ||
| 
						 | 
					eb91f9575a | ||
| 
						 | 
					947d14ffeb | ||
| 
						 | 
					b3f915b5b2 | ||
| 
						 | 
					03d3f3afc3 | ||
| 
						 | 
					2728170c01 | ||
| 
						 | 
					c107f3632a | ||
| 
						 | 
					7d1c5fca0b | ||
| 
						 | 
					e71887e1a8 | ||
| 
						 | 
					39d1eeda23 | ||
| 
						 | 
					b482f3ce94 | ||
| 
						 | 
					122cc48c29 | ||
| 
						 | 
					c7c57cfa0e | ||
| 
						 | 
					1f9ca20dfd | ||
| 
						 | 
					5efbaa4849 | ||
| 
						 | 
					c6f55bc4ab | ||
| 
						 | 
					b28a3db3d6 | ||
| 
						 | 
					b9ece28f68 | ||
| 
						 | 
					79b4907cb9 | ||
| 
						 | 
					dfbc244b00 | ||
| 
						 | 
					b23d5e26e2 | ||
| 
						 | 
					f1f3074306 | ||
| 
						 | 
					f162ad193f | ||
| 
						 | 
					5254f300f9 | ||
| 
						 | 
					c0d0100ca8 | ||
| 
						 | 
					21f201e371 | ||
| 
						 | 
					bbc378ed8f | ||
| 
						 | 
					e2d494321c | ||
| 
						 | 
					c2df8043db | ||
| 
						 | 
					df62150b5a | ||
| 
						 | 
					eea52a5fa6 | ||
| 
						 | 
					2d9015b840 | ||
| 
						 | 
					187ef29914 | ||
| 
						 | 
					c12be766e9 | ||
| 
						 | 
					2168458f11 | ||
| 
						 | 
					8cf0725593 | ||
| 
						 | 
					8379f015d7 | ||
| 
						 | 
					f08c01800f | ||
| 
						 | 
					a62706678e | ||
| 
						 | 
					e4468562d2 | ||
| 
						 | 
					7316bf7bc5 | ||
| 
						 | 
					3747b7d930 | ||
| 
						 | 
					5be3f22d06 | ||
| 
						 | 
					c572ce946b | ||
| 
						 | 
					d69f0289ca | ||
| 
						 | 
					048e5210f7 | ||
| 
						 | 
					219e9115c0 | ||
| 
						 | 
					b43416af97 | ||
| 
						 | 
					6d84da588b | ||
| 
						 | 
					569d6c557c | ||
| 
						 | 
					58bb94d7c7 | ||
| 
						 | 
					4f8f775e69 | ||
| 
						 | 
					5eed02f7e9 | ||
| 
						 | 
					983f1f28ca | ||
| 
						 | 
					192ede5e64 | ||
| 
						 | 
					803a7aa878 | ||
| 
						 | 
					93f3098aec | ||
| 
						 | 
					dbd94d047b | ||
| 
						 | 
					be39ab32d1 | ||
| 
						 | 
					8b1fb3cb0c | ||
| 
						 | 
					9e04222ee6 | ||
| 
						 | 
					72349507c4 | ||
| 
						 | 
					79db8daddd | ||
| 
						 | 
					b967f83f20 | ||
| 
						 | 
					74a7592b4b | ||
| 
						 | 
					486f23538f | ||
| 
						 | 
					df86ff2191 | ||
| 
						 | 
					41266f05e9 | ||
| 
						 | 
					d2aa331838 | ||
| 
						 | 
					670cb9d223 | ||
| 
						 | 
					a205762bf0 | ||
| 
						 | 
					2ffab66d97 | ||
| 
						 | 
					10a6aec998 | ||
| 
						 | 
					7cbe31baad | ||
| 
						 | 
					8a09dc1b9b | ||
| 
						 | 
					fa6e174651 | ||
| 
						 | 
					8dee328eae | ||
| 
						 | 
					340155e6a6 | ||
| 
						 | 
					7fe19a030a | ||
| 
						 | 
					11e0ccdc91 | ||
| 
						 | 
					e55b2f4f8d | ||
| 
						 | 
					d78c1f695e | ||
| 
						 | 
					cfbb3e86b3 | ||
| 
						 | 
					fa6234e417 | ||
| 
						 | 
					9eeae9ad7e | ||
| 
						 | 
					28688488ff | ||
| 
						 | 
					41d804719f | ||
| 
						 | 
					bc18168662 | ||
| 
						 | 
					1fadae82c7 | ||
| 
						 | 
					791c62ca64 | ||
| 
						 | 
					4441a6ff59 | ||
| 
						 | 
					63a7002477 | ||
| 
						 | 
					a746139c53 | ||
| 
						 | 
					697a060132 | ||
| 
						 | 
					7834c25253 | ||
| 
						 | 
					2e7cbfcff5 | ||
| 
						 | 
					5b771039fc | ||
| 
						 | 
					2f1bc5864f | ||
| 
						 | 
					16d79ebaac | ||
| 
						 | 
					e009ec8b93 | ||
| 
						 | 
					738ece513f | ||
| 
						 | 
					5a7b7b51c5 | ||
| 
						 | 
					5bba9bddfd | ||
| 
						 | 
					a3c0c7546d | ||
| 
						 | 
					05d7ae4efa | ||
| 
						 | 
					44483dba21 | ||
| 
						 | 
					3498a5856a | ||
| 
						 | 
					cd79b0343a | ||
| 
						 | 
					abba00d595 | ||
| 
						 | 
					88a8d7d901 | ||
| 
						 | 
					d5c00071d3 | ||
| 
						 | 
					c7a6cf5463 | ||
| 
						 | 
					2ce2a15fc6 | ||
| 
						 | 
					ce4be4e91e | ||
| 
						 | 
					82dc2244c0 | ||
| 
						 | 
					ab45b7783f | ||
| 
						 | 
					4a56b2406b | ||
| 
						 | 
					e0cd2cdb9c | ||
| 
						 | 
					7575094cf3 | ||
| 
						 | 
					40a3ae04b6 | ||
| 
						 | 
					ac26f84170 | ||
| 
						 | 
					fa574fe833 | ||
| 
						 | 
					9a6e18ce80 | ||
| 
						 | 
					8f9034fc8b | ||
| 
						 | 
					3e5b102445 | ||
| 
						 | 
					d8b1a8d439 | ||
| 
						 | 
					54ae008dd7 | ||
| 
						 | 
					9c1747581f | ||
| 
						 | 
					ae4f7b6d7a | ||
| 
						 | 
					c947322a69 | ||
| 
						 | 
					14db45215f | ||
| 
						 | 
					d20831e41a | ||
| 
						 | 
					1bb902984b | ||
| 
						 | 
					09f1c58872 | ||
| 
						 | 
					7f944c2c8b | ||
| 
						 | 
					1c02b85802 | ||
| 
						 | 
					a2801649b4 | ||
| 
						 | 
					15777732d3 | ||
| 
						 | 
					b875037150 | ||
| 
						 | 
					a6d583cb5e | ||
| 
						 | 
					9882f3429a | ||
| 
						 | 
					29d47c4de2 | ||
| 
						 | 
					a9b15f1c36 | ||
| 
						 | 
					ce38ecb966 | ||
| 
						 | 
					13ffa17048 | ||
| 
						 | 
					a387682dfb | ||
| 
						 | 
					f6ed197cd3 | ||
| 
						 | 
					243593cdaa | ||
| 
						 | 
					1e2d559859 | ||
| 
						 | 
					20ea859183 | ||
| 
						 | 
					86b24ea059 | ||
| 
						 | 
					07af42476d | ||
| 
						 | 
					87edf71e93 | ||
| 
						 | 
					e3ea2ed420 | ||
| 
						 | 
					8f9a1881a4 | ||
| 
						 | 
					a8c6111197 | ||
| 
						 | 
					3de8570022 | ||
| 
						 | 
					a0311b0134 | ||
| 
						 | 
					158a628c0e | ||
| 
						 | 
					422e5026d6 | ||
| 
						 | 
					797cbb9b20 | ||
| 
						 | 
					be68fbd4f5 | ||
| 
						 | 
					e440223b40 | ||
| 
						 | 
					5766250288 | ||
| 
						 | 
					870274ad9d | ||
| 
						 | 
					9d6abcd9be | ||
| 
						 | 
					432771dfe3 | ||
| 
						 | 
					69925ce823 | ||
| 
						 | 
					e9f9f515bd | ||
| 
						 | 
					efd96153d8 | ||
| 
						 | 
					c7b8f223ee | ||
| 
						 | 
					a0636d5a87 | ||
| 
						 | 
					c7b16249b8 | ||
| 
						 | 
					031e885e4d | ||
| 
						 | 
					796e2cc156 | ||
| 
						 | 
					7af784adce | ||
| 
						 | 
					a988a91e2e | ||
| 
						 | 
					a8b564fa64 | ||
| 
						 | 
					b97e140389 | ||
| 
						 | 
					e51bef6d12 | ||
| 
						 | 
					4bd31f4967 | ||
| 
						 | 
					7ff7a7c527 | ||
| 
						 | 
					c4a375b3a5 | ||
| 
						 | 
					e3698edd19 | ||
| 
						 | 
					e591d5cfe4 | ||
| 
						 | 
					a2e62f8e1d | ||
| 
						 | 
					764963e986 | ||
| 
						 | 
					4da493f3f3 | ||
| 
						 | 
					dec90f7e5e | ||
| 
						 | 
					2ea5b283a8 | ||
| 
						 | 
					eb23549cd6 | ||
| 
						 | 
					cd90062850 | ||
| 
						 | 
					3ec72fcee9 | ||
| 
						 | 
					b9091e14b3 | ||
| 
						 | 
					5daefc0194 | ||
| 
						 | 
					44edb2bd2f | ||
| 
						 | 
					201aa24448 | ||
| 
						 | 
					e799ef2977 | ||
| 
						 | 
					0c538f7527 | ||
| 
						 | 
					ca7202eb0a | ||
| 
						 | 
					d5ec5f80ff | ||
| 
						 | 
					0c944a03fe | ||
| 
						 | 
					79a267ab08 | ||
| 
						 | 
					f9a6988ece | ||
| 
						 | 
					95e06de5de | ||
| 
						 | 
					f530a5074b | ||
| 
						 | 
					439580b91b | ||
| 
						 | 
					4c2a384159 | ||
| 
						 | 
					22b83d7630 | ||
| 
						 | 
					cfd0b040e4 | ||
| 
						 | 
					b001840dee | ||
| 
						 | 
					0b5bff01e1 | ||
| 
						 | 
					4fe7b6cd65 | ||
| 
						 | 
					49e1f7d8bf | ||
| 
						 | 
					803fb243bf | ||
| 
						 | 
					20a6ab3d1a | ||
| 
						 | 
					21f16b50f3 | ||
| 
						 | 
					f58e83ee87 | ||
| 
						 | 
					a9b4a2a1ac | ||
| 
						 | 
					5be1449db5 | ||
| 
						 | 
					37d7f89c6d | ||
| 
						 | 
					57e58ce76c | ||
| 
						 | 
					1d9f76e2c8 | ||
| 
						 | 
					56e0269e5e | ||
| 
						 | 
					662df85e54 | ||
| 
						 | 
					2be4a5e486 | ||
| 
						 | 
					a43d697225 | ||
| 
						 | 
					f06c1e6c78 | ||
| 
						 | 
					b5d1918401 | ||
| 
						 | 
					d018be5d36 | ||
| 
						 | 
					67184d7b20 | ||
| 
						 | 
					dfdd48b990 | ||
| 
						 | 
					cae9cee295 | ||
| 
						 | 
					067d586c1c | ||
| 
						 | 
					d22b7938da | ||
| 
						 | 
					29b7510957 | ||
| 
						 | 
					9d548d81ac | ||
| 
						 | 
					3c33cdfa3d | ||
| 
						 | 
					288485b209 | ||
| 
						 | 
					1cbf416b10 | ||
| 
						 | 
					3b46d3dd74 | ||
| 
						 | 
					c243829234 | ||
| 
						 | 
					fd80faa389 | ||
| 
						 | 
					e7d4352292 | ||
| 
						 | 
					610e0f21d6 | ||
| 
						 | 
					7e512bad96 | ||
| 
						 | 
					98c4ce0c45 | ||
| 
						 | 
					93fc48a2db | ||
| 
						 | 
					d7eea12a6f | ||
| 
						 | 
					2a1e06f8a9 | ||
| 
						 | 
					02d54a783a | ||
| 
						 | 
					5961d44339 | ||
| 
						 | 
					fb3be8509d | ||
| 
						 | 
					97be53741d | ||
| 
						 | 
					0d2c26735e | ||
| 
						 | 
					2d0a8ddb58 | ||
| 
						 | 
					72518d4827 | ||
| 
						 | 
					c6cd744186 | ||
| 
						 | 
					ae2db62f1c | ||
| 
						 | 
					8c76b8bc36 | ||
| 
						 | 
					18256c4923 | ||
| 
						 | 
					f345cc66cf | ||
| 
						 | 
					5dbf664a6b | ||
| 
						 | 
					d7c6679d70 | ||
| 
						 | 
					cae203be71 | ||
| 
						 | 
					8a29fbc850 | ||
| 
						 | 
					00bcbd367f | ||
| 
						 | 
					1befee5aca | ||
| 
						 | 
					5982f4bcf0 | ||
| 
						 | 
					2399476a21 | ||
| 
						 | 
					9e45ac939b | ||
| 
						 | 
					34f231f9f3 | ||
| 
						 | 
					f940b2a58e | ||
| 
						 | 
					0383c33558 | ||
| 
						 | 
					3afa4b210d | ||
| 
						 | 
					998783eb9d | ||
| 
						 | 
					54d61bdc4a | ||
| 
						 | 
					2d279c4c5c | ||
| 
						 | 
					0fb206fe15 | ||
| 
						 | 
					5d6fd8099f | ||
| 
						 | 
					800e3f4599 | ||
| 
						 | 
					35c61f52fe | ||
| 
						 | 
					3db446633c | ||
| 
						 | 
					e3b4a0213c | ||
| 
						 | 
					9910ff5fa1 | ||
| 
						 | 
					049be10406 | ||
| 
						 | 
					9aa3be7f9f | ||
| 
						 | 
					aba5c634ae | ||
| 
						 | 
					9774b01b0e | ||
| 
						 | 
					ecf0a710e1 | ||
| 
						 | 
					c9febbdd87 | ||
| 
						 | 
					caa2e45a8c | ||
| 
						 | 
					d9130c9852 | ||
| 
						 | 
					661f05837c | ||
| 
						 | 
					a61fe418b2 | ||
| 
						 | 
					b15cfc2c5a | ||
| 
						 | 
					c575c9af3d | ||
| 
						 | 
					81f27e9077 | ||
| 
						 | 
					f78babfaa0 | ||
| 
						 | 
					66990cf872 | ||
| 
						 | 
					095fe2ed1b | ||
| 
						 | 
					483ebc8141 | ||
| 
						 | 
					b9311282eb | ||
| 
						 | 
					d6f0c2b52b | ||
| 
						 | 
					bb25febd70 | ||
| 
						 | 
					19ab2a29ce | ||
| 
						 | 
					24b4fe9867 | ||
| 
						 | 
					aa7b82de04 | ||
| 
						 | 
					3d826bed3a | ||
| 
						 | 
					d2ae7e78ef | ||
| 
						 | 
					656bd330f8 | ||
| 
						 | 
					c2c8f32010 | ||
| 
						 | 
					9f43c270e6 | ||
| 
						 | 
					50827188ff | ||
| 
						 | 
					6ae0f7f5c6 | ||
| 
						 | 
					c583d6bb49 | ||
| 
						 | 
					fdcb6b721c | ||
| 
						 | 
					ef858ef062 | ||
| 
						 | 
					fe04faf675 | ||
| 
						 | 
					ad752b317d | ||
| 
						 | 
					59649e9b1e | ||
| 
						 | 
					6bf281f905 | ||
| 
						 | 
					4dfc8b262c | ||
| 
						 | 
					f08ffe9feb | ||
| 
						 | 
					65de3110a9 | ||
| 
						 | 
					f6dcd98995 | ||
| 
						 | 
					950172dc01 | ||
| 
						 | 
					5c48e139d4 | ||
| 
						 | 
					150e9c8a48 | ||
| 
						 | 
					b19ba13aff | ||
| 
						 | 
					30bfc2cea7 | ||
| 
						 | 
					30c2d84c6d | ||
| 
						 | 
					fbd2038fa7 | ||
| 
						 | 
					e4b8d9b9d6 | ||
| 
						 | 
					6b50003697 | ||
| 
						 | 
					a73c5b3355 | ||
| 
						 | 
					eb59817e81 | ||
| 
						 | 
					d404e92d16 | ||
| 
						 | 
					86c017ec9d | ||
| 
						 | 
					0407c4e0f7 | ||
| 
						 | 
					0ba95a3dd4 | ||
| 
						 | 
					0463b5d6cd | ||
| 
						 | 
					3f4513b3a9 | ||
| 
						 | 
					fb2029e717 | ||
| 
						 | 
					48f02fb61b | ||
| 
						 | 
					0c00e870c6 | ||
| 
						 | 
					7da50703fb | ||
| 
						 | 
					cfdaff5a46 | ||
| 
						 | 
					18e46962c2 | ||
| 
						 | 
					319e0ae3cf | ||
| 
						 | 
					e69a7c38d9 | ||
| 
						 | 
					ecd685755b | ||
| 
						 | 
					276b51d927 | ||
| 
						 | 
					251d1c5c9f | ||
| 
						 | 
					028e17475f | ||
| 
						 | 
					1ab630435d | ||
| 
						 | 
					89002ed298 | ||
| 
						 | 
					d0871bdae3 | ||
| 
						 | 
					5ea6e9c9c0 | ||
| 
						 | 
					267f283a31 | ||
| 
						 | 
					3324c0ae79 | ||
| 
						 | 
					811bff6db0 | ||
| 
						 | 
					0c9546ccb0 | ||
| 
						 | 
					7b16442656 | ||
| 
						 | 
					b0070f03af | ||
| 
						 | 
					08ee072f11 | ||
| 
						 | 
					f3e4cea34f | ||
| 
						 | 
					2d12b68952 | ||
| 
						 | 
					1643b476eb | ||
| 
						 | 
					5980ebc79a | ||
| 
						 | 
					8371b030cf | ||
| 
						 | 
					10afcaca2f | ||
| 
						 | 
					2fb4b62330 | ||
| 
						 | 
					cbcd7e0f86 | ||
| 
						 | 
					df1c9d88a8 | ||
| 
						 | 
					3aae1ae3d9 | ||
| 
						 | 
					775bd1abd0 | ||
| 
						 | 
					78009539d1 | ||
| 
						 | 
					36246ad9ac | ||
| 
						 | 
					e2053b22b4 | ||
| 
						 | 
					dfdc402fbb | ||
| 
						 | 
					73ba54a502 | ||
| 
						 | 
					690a5e205d | ||
| 
						 | 
					a6014bf04e | ||
| 
						 | 
					d4d1f0f4a9 | ||
| 
						 | 
					5fbc47eb3a | ||
| 
						 | 
					6d4e903b08 | ||
| 
						 | 
					66f08eb236 | ||
| 
						 | 
					933c169da5 | ||
| 
						 | 
					a8df88ab91 | ||
| 
						 | 
					df9547ae39 | ||
| 
						 | 
					d529eb6d00 | ||
| 
						 | 
					fac1e367c9 | ||
| 
						 | 
					31a5487cba | ||
| 
						 | 
					43822d37a7 | ||
| 
						 | 
					527dd31c70 | ||
| 
						 | 
					e3c66532c5 | ||
| 
						 | 
					22ea4004e1 | ||
| 
						 | 
					d190a43e0a | ||
| 
						 | 
					bd5e57d879 | ||
| 
						 | 
					08928b486b | ||
| 
						 | 
					75da0713d2 | ||
| 
						 | 
					d35bf51780 | ||
| 
						 | 
					ec603beeb0 | ||
| 
						 | 
					7820467d59 | ||
| 
						 | 
					fe09757cb3 | ||
| 
						 | 
					1e6b68f5d1 | ||
| 
						 | 
					f574e5813f | ||
| 
						 | 
					30684246d2 | ||
| 
						 | 
					8bdf5cf854 | ||
| 
						 | 
					c93ec9331b | ||
| 
						 | 
					0886e67df7 | ||
| 
						 | 
					30de13b4df | ||
| 
						 | 
					7a60c14b31 | ||
| 
						 | 
					3ad08e9515 | ||
| 
						 | 
					32fdc19697 | ||
| 
						 | 
					c9c31c04c3 | ||
| 
						 | 
					c3dd3ef0d7 | ||
| 
						 | 
					fa989a554d | ||
| 
						 | 
					4a4dacb52c | ||
| 
						 | 
					dcf9cb581d | ||
| 
						 | 
					1a6305c93f | ||
| 
						 | 
					bdbf323fee | ||
| 
						 | 
					7270f277a7 | ||
| 
						 | 
					32dfc387c8 | ||
| 
						 | 
					b3752e78b6 | ||
| 
						 | 
					4c0d3f1b75 | ||
| 
						 | 
					2e3cb75530 | ||
| 
						 | 
					3e99ffe692 | ||
| 
						 | 
					096d8992a1 | ||
| 
						 | 
					0bbe6eef89 | ||
| 
						 | 
					d0b748a4f2 | ||
| 
						 | 
					58f41a194a | ||
| 
						 | 
					d8d10bc478 | ||
| 
						 | 
					61623d22d8 | ||
| 
						 | 
					bc96082fa9 | ||
| 
						 | 
					52677b0a88 | ||
| 
						 | 
					e4a1958573 | ||
| 
						 | 
					523c7682fa | ||
| 
						 | 
					87ab2d9085 | ||
| 
						 | 
					687cfcc2b1 | ||
| 
						 | 
					c8e9a31ee5 | ||
| 
						 | 
					2ce87fe264 | ||
| 
						 | 
					13d7cae9e2 | ||
| 
						 | 
					8814a348a8 | ||
| 
						 | 
					5aa146a53f | ||
| 
						 | 
					cc17973113 | ||
| 
						 | 
					423966a505 | ||
| 
						 | 
					fbad6a392d | ||
| 
						 | 
					331c4bb669 | ||
| 
						 | 
					63a195e5cc | ||
| 
						 | 
					e22bcf7cb4 | ||
| 
						 | 
					869578ce4a | ||
| 
						 | 
					5fc5016d2c | ||
| 
						 | 
					22e7ba3f7b | ||
| 
						 | 
					dcf4f8f64e | ||
| 
						 | 
					d07e8f91c4 | ||
| 
						 | 
					054cb72e55 | ||
| 
						 | 
					0e38c60da3 | ||
| 
						 | 
					6d7eda3e8d | ||
| 
						 | 
					ee1737a52e | ||
| 
						 | 
					432c589722 | ||
| 
						 | 
					c083e078d4 | ||
| 
						 | 
					9003525210 | ||
| 
						 | 
					bf233fbd48 | ||
| 
						 | 
					cc7fdbd661 | ||
| 
						 | 
					199067e8ab | ||
| 
						 | 
					d65e3d9a6e | ||
| 
						 | 
					ec9fc8cbf7 | ||
| 
						 | 
					9aaf36cd0c | ||
| 
						 | 
					c4d8fd83d4 | ||
| 
						 | 
					a272ee4f59 | ||
| 
						 | 
					7012b91f05 | ||
| 
						 | 
					16679b572f | ||
| 
						 | 
					6e18034333 | ||
| 
						 | 
					b7ec6789b3 | ||
| 
						 | 
					c835ab025a | ||
| 
						 | 
					39c8f79f3e | ||
| 
						 | 
					eae290992f | ||
| 
						 | 
					bb276fc985 | ||
| 
						 | 
					8d5618c44a | ||
| 
						 | 
					8f63baf7e4 | ||
| 
						 | 
					78768e985b | ||
| 
						 | 
					2ee5d873db | ||
| 
						 | 
					6cd3a8a549 | ||
| 
						 | 
					5778811a18 | ||
| 
						 | 
					4e1f39cdec | ||
| 
						 | 
					2c554a4bbb | ||
| 
						 | 
					8fb9a709b0 | ||
| 
						 | 
					484d9d2ad8 | ||
| 
						 | 
					1953957506 | ||
| 
						 | 
					06e8b869b9 | ||
| 
						 | 
					8f48168c73 | ||
| 
						 | 
					d3595686f6 | ||
| 
						 | 
					c839b2b039 | ||
| 
						 | 
					acafa585f4 | ||
| 
						 | 
					7939b419f7 | ||
| 
						 | 
					61579ec329 | ||
| 
						 | 
					1786a5e55a | ||
| 
						 | 
					2ed01ff040 | ||
| 
						 | 
					9bf69d30e0 | ||
| 
						 | 
					218dc3390f | ||
| 
						 | 
					6626371d87 | ||
| 
						 | 
					a4270efac9 | ||
| 
						 | 
					94dc5f330c | ||
| 
						 | 
					c53da1ef72 | ||
| 
						 | 
					01f54558b9 | ||
| 
						 | 
					ca2a96b3f3 | ||
| 
						 | 
					4d2f38b03a | ||
| 
						 | 
					762978f8d8 | ||
| 
						 | 
					bfdf1f482e | ||
| 
						 | 
					990d46d659 | ||
| 
						 | 
					620f86130c | ||
| 
						 | 
					c0205b0ad5 | ||
| 
						 | 
					ff3bce3287 | ||
| 
						 | 
					2b3fc6656c | ||
| 
						 | 
					4fa08fc78c | ||
| 
						 | 
					5c5705789e | ||
| 
						 | 
					ac0a1661f3 | ||
| 
						 | 
					7cde2f8526 | ||
| 
						 | 
					5bdad8448c | ||
| 
						 | 
					63c6a3b089 | ||
| 
						 | 
					230234e701 | ||
| 
						 | 
					e4739512e6 | ||
| 
						 | 
					14f3dbb71a | ||
| 
						 | 
					0103f59f82 | ||
| 
						 | 
					d9ded9f3f3 | ||
| 
						 | 
					1f60d2bbb4 | ||
| 
						 | 
					daf5650445 | ||
| 
						 | 
					998c92d57e | ||
| 
						 | 
					6de38fbf08 | ||
| 
						 | 
					073ca4bf8d | ||
| 
						 | 
					0cca212843 | ||
| 
						 | 
					c8b6fe62a1 | ||
| 
						 | 
					f321c3c7ea | ||
| 
						 | 
					80a0a7b5c5 | ||
| 
						 | 
					51e85716ee | ||
| 
						 | 
					641989fdee | ||
| 
						 | 
					e4f67c626a | ||
| 
						 | 
					db0534ed97 | ||
| 
						 | 
					2d39b3df88 | ||
| 
						 | 
					a79b26af6c | ||
| 
						 | 
					a1048c48e4 | ||
| 
						 | 
					fc33dbb54e | ||
| 
						 | 
					0a7c936442 | ||
| 
						 | 
					c5f2df5c93 | ||
| 
						 | 
					cada9dc0a0 | ||
| 
						 | 
					cbd13a123f | ||
| 
						 | 
					c1c7d87bc5 | ||
| 
						 | 
					f4312b4428 | ||
| 
						 | 
					00a506053c | ||
| 
						 | 
					c191ab7c07 | ||
| 
						 | 
					8663fb7e64 | ||
| 
						 | 
					99dc89c051 | ||
| 
						 | 
					158f22f733 | ||
| 
						 | 
					eccec5f6d5 | ||
| 
						 | 
					dceb3acace | ||
| 
						 | 
					036e9d1074 | ||
| 
						 | 
					6ed1c718b9 | ||
| 
						 | 
					8f7ad693a8 | ||
| 
						 | 
					eac18b1c99 | ||
| 
						 | 
					6f93064114 | ||
| 
						 | 
					b281789777 | ||
| 
						 | 
					5ef501c5ec | ||
| 
						 | 
					0662507116 | ||
| 
						 | 
					b5eb4b904e | ||
| 
						 | 
					93c9216b69 | ||
| 
						 | 
					635695ec84 | ||
| 
						 | 
					41e3eafa90 | ||
| 
						 | 
					937cbf6df8 | ||
| 
						 | 
					432c14b86a | ||
| 
						 | 
					6ce00fcdb8 | ||
| 
						 | 
					fb67522324 | ||
| 
						 | 
					2b45dba57c | ||
| 
						 | 
					b0515cf8c0 | ||
| 
						 | 
					6cc11ffb7d | ||
| 
						 | 
					65938b73e1 | ||
| 
						 | 
					70a5587513 | ||
| 
						 | 
					3d434e43ad | ||
| 
						 | 
					a7b7355dcf | ||
| 
						 | 
					63f5d07ed7 | ||
| 
						 | 
					233e8a2085 | ||
| 
						 | 
					770dc4b230 | ||
| 
						 | 
					dca09dedac | ||
| 
						 | 
					6fc1447fa6 | ||
| 
						 | 
					fb6d3ab285 | ||
| 
						 | 
					3ed4102a3c | ||
| 
						 | 
					d53289d707 | ||
| 
						 | 
					e8cce73a17 | ||
| 
						 | 
					5c917113e8 | ||
| 
						 | 
					a63b05a9e7 | 
							
								
								
									
										25
									
								
								.github/ISSUE_TEMPLATE.md
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										25
									
								
								.github/ISSUE_TEMPLATE.md
									
									
									
									
										vendored
									
									
										Normal file
									
								
							@@ -0,0 +1,25 @@
 | 
			
		||||
<!--
 | 
			
		||||
请确保已经更新到最新的代码, 然后贴上来 `--debug 2` 的调试输出. 没有调试输出,我帮不了你.
 | 
			
		||||
如何调试 https://github.com/Neilpang/acme.sh/wiki/How-to-debug-acme.sh
 | 
			
		||||
 | 
			
		||||
If it is a bug report:
 | 
			
		||||
- make sure you are able to repro it on the latest released version. 
 | 
			
		||||
You can install the latest version by: `acme.sh --upgrade`
 | 
			
		||||
 | 
			
		||||
- Search the existing issues.
 | 
			
		||||
- Refer to the [WIKI](https://wiki.acme.sh).
 | 
			
		||||
- Debug info [Debug](https://github.com/Neilpang/acme.sh/wiki/How-to-debug-acme.sh).
 | 
			
		||||
 | 
			
		||||
-->
 | 
			
		||||
 | 
			
		||||
Steps to reproduce
 | 
			
		||||
------------------
 | 
			
		||||
 | 
			
		||||
Debug log
 | 
			
		||||
-----------------
 | 
			
		||||
 | 
			
		||||
```
 | 
			
		||||
acme.sh  --issue .....   --debug 2
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
							
								
								
									
										9
									
								
								.github/PULL_REQUEST_TEMPLATE.md
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										9
									
								
								.github/PULL_REQUEST_TEMPLATE.md
									
									
									
									
										vendored
									
									
										Normal file
									
								
							@@ -0,0 +1,9 @@
 | 
			
		||||
<!--
 | 
			
		||||
 | 
			
		||||
Do NOT send pull request to `master` branch.
 | 
			
		||||
 | 
			
		||||
Please send to `dev` branch instead.
 | 
			
		||||
 | 
			
		||||
Any PR to `master` branch will NOT be merged.
 | 
			
		||||
 | 
			
		||||
-->
 | 
			
		||||
							
								
								
									
										38
									
								
								.travis.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										38
									
								
								.travis.yml
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,38 @@
 | 
			
		||||
language: shell
 | 
			
		||||
sudo: required
 | 
			
		||||
dist: trusty
 | 
			
		||||
 | 
			
		||||
os:
 | 
			
		||||
  - linux
 | 
			
		||||
  - osx
 | 
			
		||||
 | 
			
		||||
services:
 | 
			
		||||
  - docker
 | 
			
		||||
 | 
			
		||||
env:
 | 
			
		||||
  global:
 | 
			
		||||
    - SHFMT_URL=https://github.com/mvdan/sh/releases/download/v0.4.0/shfmt_v0.4.0_linux_amd64
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
install:
 | 
			
		||||
  - if [ "$TRAVIS_OS_NAME" = 'osx' ]; then
 | 
			
		||||
      brew update && brew install socat;
 | 
			
		||||
      export PATH="/usr/local/opt/openssl@1.1/bin:$PATH" ;
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
script:
 | 
			
		||||
  - echo "NGROK_TOKEN=$(echo "$NGROK_TOKEN" | wc -c)"
 | 
			
		||||
  - command -V openssl && openssl version
 | 
			
		||||
  - if [ "$TRAVIS_OS_NAME" = "linux" ]; then curl -sSL $SHFMT_URL -o ~/shfmt && chmod +x ~/shfmt && ~/shfmt -l -w -i 2 . ; fi
 | 
			
		||||
  - if [ "$TRAVIS_OS_NAME" = "linux" ]; then git diff --exit-code && echo "shfmt OK" ; fi
 | 
			
		||||
  - if [ "$TRAVIS_OS_NAME" = "linux" ]; then shellcheck -V ; fi
 | 
			
		||||
  - if [ "$TRAVIS_OS_NAME" = "linux" ]; then shellcheck -e SC2181 **/*.sh && echo "shellcheck OK" ; fi
 | 
			
		||||
  - cd ..
 | 
			
		||||
  - git clone https://github.com/Neilpang/acmetest.git && cp -r acme.sh acmetest/ && cd acmetest
 | 
			
		||||
  - if [ "$TRAVIS_OS_NAME" = "linux" -a "$NGROK_TOKEN" ]; then sudo TEST_LOCAL="$TEST_LOCAL" NGROK_TOKEN="$NGROK_TOKEN" ./rundocker.sh testplat ubuntu:latest ; fi
 | 
			
		||||
  - if [ "$TRAVIS_OS_NAME" = "osx" -a "$NGROK_TOKEN" ]; then sudo TEST_LOCAL="$TEST_LOCAL" NGROK_TOKEN="$NGROK_TOKEN" ACME_OPENSSL_BIN="$ACME_OPENSSL_BIN" ./letest.sh ; fi
 | 
			
		||||
 | 
			
		||||
matrix:
 | 
			
		||||
  fast_finish: true
 | 
			
		||||
  
 | 
			
		||||
  
 | 
			
		||||
							
								
								
									
										65
									
								
								Dockerfile
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										65
									
								
								Dockerfile
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,65 @@
 | 
			
		||||
FROM alpine:3.6
 | 
			
		||||
 | 
			
		||||
RUN apk update -f \
 | 
			
		||||
  && apk --no-cache add -f \
 | 
			
		||||
  openssl \
 | 
			
		||||
  coreutils \
 | 
			
		||||
  bind-tools \
 | 
			
		||||
  curl \
 | 
			
		||||
  socat \
 | 
			
		||||
  && rm -rf /var/cache/apk/*
 | 
			
		||||
 | 
			
		||||
ENV LE_CONFIG_HOME /acme.sh
 | 
			
		||||
 | 
			
		||||
ENV AUTO_UPGRADE 1
 | 
			
		||||
 | 
			
		||||
#Install
 | 
			
		||||
ADD ./ /install_acme.sh/
 | 
			
		||||
RUN cd /install_acme.sh && ([ -f /install_acme.sh/acme.sh ] && /install_acme.sh/acme.sh --install || curl https://get.acme.sh | sh) && rm -rf /install_acme.sh/
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
RUN ln -s  /root/.acme.sh/acme.sh  /usr/local/bin/acme.sh && crontab -l | grep acme.sh | sed 's#> /dev/null##' | crontab -
 | 
			
		||||
 | 
			
		||||
RUN for verb in help \ 
 | 
			
		||||
  version \
 | 
			
		||||
  install \
 | 
			
		||||
  uninstall \
 | 
			
		||||
  upgrade \
 | 
			
		||||
  issue \
 | 
			
		||||
  signcsr \
 | 
			
		||||
  deploy \
 | 
			
		||||
  install-cert \
 | 
			
		||||
  renew \
 | 
			
		||||
  renew-all \
 | 
			
		||||
  revoke \
 | 
			
		||||
  remove \
 | 
			
		||||
  list \
 | 
			
		||||
  showcsr \
 | 
			
		||||
  install-cronjob \
 | 
			
		||||
  uninstall-cronjob \
 | 
			
		||||
  cron \
 | 
			
		||||
  toPkcs \
 | 
			
		||||
  toPkcs8 \
 | 
			
		||||
  update-account \
 | 
			
		||||
  register-account \
 | 
			
		||||
  create-account-key \
 | 
			
		||||
  create-domain-key \
 | 
			
		||||
  createCSR \
 | 
			
		||||
  deactivate \
 | 
			
		||||
  deactivate-account \
 | 
			
		||||
  ; do \
 | 
			
		||||
    printf -- "%b" "#!/usr/bin/env sh\n/root/.acme.sh/acme.sh --${verb} --config-home /acme.sh \"\$@\"" >/usr/local/bin/--${verb} && chmod +x /usr/local/bin/--${verb} \
 | 
			
		||||
  ; done
 | 
			
		||||
 | 
			
		||||
RUN printf "%b" '#!'"/usr/bin/env sh\n \
 | 
			
		||||
if [ \"\$1\" = \"daemon\" ];  then \n \
 | 
			
		||||
 trap \"echo stop && killall crond && exit 0\" SIGTERM SIGINT \n \
 | 
			
		||||
 crond && while true; do sleep 1; done;\n \
 | 
			
		||||
else \n \
 | 
			
		||||
 exec -- \"\$@\"\n \
 | 
			
		||||
fi" >/entry.sh && chmod +x /entry.sh
 | 
			
		||||
 | 
			
		||||
VOLUME /acme.sh
 | 
			
		||||
 | 
			
		||||
ENTRYPOINT ["/entry.sh"]
 | 
			
		||||
CMD ["--help"]
 | 
			
		||||
							
								
								
									
										623
									
								
								README.md
									
									
									
									
									
								
							
							
						
						
									
										623
									
								
								README.md
									
									
									
									
									
								
							@@ -1,286 +1,531 @@
 | 
			
		||||
# le: means simp`Le`
 | 
			
		||||
Simplest shell script for LetsEncrypt free Certificate client
 | 
			
		||||
# An ACME Shell script: acme.sh [](https://travis-ci.org/Neilpang/acme.sh)
 | 
			
		||||
 | 
			
		||||
Simple and Powerful, you only need 3 minutes to learn.
 | 
			
		||||
[](https://gitter.im/acme-sh/Lobby?utm_source=badge&utm_medium=badge&utm_campaign=pr-badge&utm_content=badge)
 | 
			
		||||
- An ACME protocol client written purely in Shell (Unix shell) language.
 | 
			
		||||
- Full ACME protocol implementation.
 | 
			
		||||
- Support ACME v1 and ACME v2
 | 
			
		||||
- Support ACME v2 wildcard certs
 | 
			
		||||
- Simple, powerful and very easy to use. You only need 3 minutes to learn it.
 | 
			
		||||
- Bash, dash and sh compatible.
 | 
			
		||||
- Simplest shell script for Let's Encrypt free certificate client.
 | 
			
		||||
- Purely written in Shell with no dependencies on python or the official Let's Encrypt client.
 | 
			
		||||
- Just one script to issue, renew and install your certificates automatically.
 | 
			
		||||
- DOES NOT require `root/sudoer` access.
 | 
			
		||||
- Docker friendly
 | 
			
		||||
- IPv6 support
 | 
			
		||||
 | 
			
		||||
Pure written in bash, no dependencies to python, acme-tiny or LetsEncrypt official client.
 | 
			
		||||
Just one script, to issue, renew your certificates automatically.
 | 
			
		||||
It's probably the `easiest & smartest` shell script to automatically issue & renew the free certificates from Let's Encrypt.
 | 
			
		||||
 | 
			
		||||
Probably it's the smallest&easiest&smartest shell script to automatically issue & renew the free certificates from LetsEncrypt.
 | 
			
		||||
Wiki: https://github.com/Neilpang/acme.sh/wiki
 | 
			
		||||
 | 
			
		||||
NOT require to be `root/sudoer`.
 | 
			
		||||
For Docker Fans: [acme.sh :two_hearts: Docker ](https://github.com/Neilpang/acme.sh/wiki/Run-acme.sh-in-docker)
 | 
			
		||||
 | 
			
		||||
Wiki: https://github.com/Neilpang/le/wiki
 | 
			
		||||
 | 
			
		||||
#Tested OS
 | 
			
		||||
1. Ubuntu [](https://github.com/Neilpang/letest#here-are-the-latest-status)
 | 
			
		||||
2. Debian [](https://github.com/Neilpang/letest#here-are-the-latest-status)
 | 
			
		||||
3. CentOS [](https://github.com/Neilpang/letest#here-are-the-latest-status)
 | 
			
		||||
4. Windows (cygwin with curl, openssl and crontab included) [](https://github.com/Neilpang/letest#here-are-the-latest-status)
 | 
			
		||||
5. FreeBSD with bash [](https://github.com/Neilpang/letest#here-are-the-latest-status)
 | 
			
		||||
6. pfsense with bash and curl
 | 
			
		||||
7. openSUSE [](https://github.com/Neilpang/letest#here-are-the-latest-status)
 | 
			
		||||
8. Alpine Linux [](https://github.com/Neilpang/letest#here-are-the-latest-status) (with bash, curl. https://github.com/Neilpang/le/issues/94)
 | 
			
		||||
9. Archlinux [](https://github.com/Neilpang/letest#here-are-the-latest-status)
 | 
			
		||||
10. fedora [](https://github.com/Neilpang/letest#here-are-the-latest-status)
 | 
			
		||||
11. Kali Linux [](https://github.com/Neilpang/letest#here-are-the-latest-status)
 | 
			
		||||
12. Oracle Linux [](https://github.com/Neilpang/letest#here-are-the-latest-status)
 | 
			
		||||
13. Cloud Linux  https://github.com/Neilpang/le/issues/111
 | 
			
		||||
14. Proxmox https://pve.proxmox.com/wiki/HTTPSCertificateConfiguration#Let.27s_Encrypt_using_le.sh
 | 
			
		||||
Twitter: [@neilpangxa](https://twitter.com/neilpangxa)
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
For all the build status, check our daily build project: 
 | 
			
		||||
# [中文说明](https://github.com/Neilpang/acme.sh/wiki/%E8%AF%B4%E6%98%8E)
 | 
			
		||||
 | 
			
		||||
https://github.com/Neilpang/letest.git
 | 
			
		||||
# Who:
 | 
			
		||||
- [FreeBSD.org](https://blog.crashed.org/letsencrypt-in-freebsd-org/)
 | 
			
		||||
- [ruby-china.org](https://ruby-china.org/topics/31983)
 | 
			
		||||
- [Proxmox](https://pve.proxmox.com/wiki/HTTPS_Certificate_Configuration_(Version_4.x_and_newer))
 | 
			
		||||
- [pfsense](https://github.com/pfsense/FreeBSD-ports/pull/89)
 | 
			
		||||
- [webfaction](https://community.webfaction.com/questions/19988/using-letsencrypt)
 | 
			
		||||
- [Loadbalancer.org](https://www.loadbalancer.org/blog/loadbalancer-org-with-lets-encrypt-quick-and-dirty)
 | 
			
		||||
- [discourse.org](https://meta.discourse.org/t/setting-up-lets-encrypt/40709)
 | 
			
		||||
- [Centminmod](https://centminmod.com/letsencrypt-acmetool-https.html)
 | 
			
		||||
- [splynx](https://forum.splynx.com/t/free-ssl-cert-for-splynx-lets-encrypt/297)
 | 
			
		||||
- [archlinux](https://www.archlinux.org/packages/community/any/acme.sh)
 | 
			
		||||
- [opnsense.org](https://github.com/opnsense/plugins/tree/master/security/acme-client/src/opnsense/scripts/OPNsense/AcmeClient)
 | 
			
		||||
- [CentOS Web Panel](http://centos-webpanel.com/)
 | 
			
		||||
- [lnmp.org](https://lnmp.org/)
 | 
			
		||||
- [more...](https://github.com/Neilpang/acme.sh/wiki/Blogs-and-tutorials)
 | 
			
		||||
 | 
			
		||||
#Supported Mode
 | 
			
		||||
1. Webroot mode
 | 
			
		||||
2. Standalone mode
 | 
			
		||||
3. Apache mode
 | 
			
		||||
4. Dns mode
 | 
			
		||||
# Tested OS
 | 
			
		||||
 | 
			
		||||
#How to install
 | 
			
		||||
| NO | Status| Platform|
 | 
			
		||||
|----|-------|---------|
 | 
			
		||||
|1|[](https://github.com/Neilpang/letest#here-are-the-latest-status)| Ubuntu
 | 
			
		||||
|2|[](https://github.com/Neilpang/letest#here-are-the-latest-status)| Debian
 | 
			
		||||
|3|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|CentOS
 | 
			
		||||
|4|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|Windows (cygwin with curl, openssl and crontab included)
 | 
			
		||||
|5|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|FreeBSD
 | 
			
		||||
|6|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|pfsense
 | 
			
		||||
|7|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|openSUSE
 | 
			
		||||
|8|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|Alpine Linux (with curl)
 | 
			
		||||
|9|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|Archlinux
 | 
			
		||||
|10|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|fedora
 | 
			
		||||
|11|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|Kali Linux
 | 
			
		||||
|12|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|Oracle Linux
 | 
			
		||||
|13|[](https://github.com/Neilpang/letest#here-are-the-latest-status)| Proxmox https://pve.proxmox.com/wiki/HTTPSCertificateConfiguration#Let.27s_Encrypt_using_acme.sh
 | 
			
		||||
|14|-----| Cloud Linux  https://github.com/Neilpang/le/issues/111
 | 
			
		||||
|15|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|OpenBSD
 | 
			
		||||
|16|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|Mageia
 | 
			
		||||
|17|-----| OpenWRT: Tested and working. See [wiki page](https://github.com/Neilpang/acme.sh/wiki/How-to-run-on-OpenWRT)
 | 
			
		||||
|18|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|SunOS/Solaris
 | 
			
		||||
|19|[](https://github.com/Neilpang/letest#here-are-the-latest-status)|Gentoo Linux
 | 
			
		||||
|20|[](https://travis-ci.org/Neilpang/acme.sh)|Mac OSX
 | 
			
		||||
 | 
			
		||||
1. Install online:
 | 
			
		||||
For all build statuses, check our [weekly build project](https://github.com/Neilpang/acmetest):
 | 
			
		||||
 | 
			
		||||
```
 | 
			
		||||
curl https://raw.githubusercontent.com/Neilpang/le/master/le.sh | INSTALLONLINE=1  bash
 | 
			
		||||
https://github.com/Neilpang/acmetest
 | 
			
		||||
 | 
			
		||||
# Supported CA
 | 
			
		||||
 | 
			
		||||
- Letsencrypt.org CA(default)
 | 
			
		||||
- [BuyPass.com CA](https://github.com/Neilpang/acme.sh/wiki/BuyPass.com-CA)
 | 
			
		||||
 | 
			
		||||
# Supported modes
 | 
			
		||||
 | 
			
		||||
- Webroot mode
 | 
			
		||||
- Standalone mode
 | 
			
		||||
- Standalone tls-alpn mode
 | 
			
		||||
- Apache mode
 | 
			
		||||
- Nginx mode
 | 
			
		||||
- DNS mode
 | 
			
		||||
- [DNS alias mode](https://github.com/Neilpang/acme.sh/wiki/DNS-alias-mode)
 | 
			
		||||
- [Stateless mode](https://github.com/Neilpang/acme.sh/wiki/Stateless-Mode)
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
# 1. How to install
 | 
			
		||||
 | 
			
		||||
### 1. Install online
 | 
			
		||||
 | 
			
		||||
Check this project: https://github.com/Neilpang/get.acme.sh
 | 
			
		||||
 | 
			
		||||
```bash
 | 
			
		||||
curl https://get.acme.sh | sh
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
Or:
 | 
			
		||||
```
 | 
			
		||||
wget -O -  https://raw.githubusercontent.com/Neilpang/le/master/le.sh | INSTALLONLINE=1  bash
 | 
			
		||||
 | 
			
		||||
```bash
 | 
			
		||||
wget -O -  https://get.acme.sh | sh
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
2. Or, Install from git:
 | 
			
		||||
Clone this project: 
 | 
			
		||||
```
 | 
			
		||||
git clone https://github.com/Neilpang/le.git
 | 
			
		||||
cd le
 | 
			
		||||
./le.sh install
 | 
			
		||||
### 2. Or, Install from git
 | 
			
		||||
 | 
			
		||||
Clone this project and launch installation:
 | 
			
		||||
 | 
			
		||||
```bash
 | 
			
		||||
git clone https://github.com/Neilpang/acme.sh.git
 | 
			
		||||
cd ./acme.sh
 | 
			
		||||
./acme.sh --install
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
You don't have to be root then, although it is recommended.
 | 
			
		||||
You `don't have to be root` then, although `it is recommended`.
 | 
			
		||||
 | 
			
		||||
Which does 3 jobs:
 | 
			
		||||
* create and copy `le.sh` to your home dir:  `~/.le`
 | 
			
		||||
All the certs will be placed in this folder.
 | 
			
		||||
* create alias : `le.sh=~/.le/le.sh` and `le=~/.le/le.sh`. 
 | 
			
		||||
* create everyday cron job to check and renew the cert if needed.
 | 
			
		||||
Advanced Installation: https://github.com/Neilpang/acme.sh/wiki/How-to-install
 | 
			
		||||
 | 
			
		||||
After install, you must close current terminal and reopen again to make the alias take effect.
 | 
			
		||||
The installer will perform 3 actions:
 | 
			
		||||
 | 
			
		||||
1. Create and copy `acme.sh` to your home dir (`$HOME`): `~/.acme.sh/`.
 | 
			
		||||
All certs will be placed in this folder too.
 | 
			
		||||
2. Create alias for: `acme.sh=~/.acme.sh/acme.sh`.
 | 
			
		||||
3. Create daily cron job to check and renew the certs if needed.
 | 
			
		||||
 | 
			
		||||
Cron entry example:
 | 
			
		||||
 | 
			
		||||
```bash
 | 
			
		||||
0 0 * * * "/home/user/.acme.sh"/acme.sh --cron --home "/home/user/.acme.sh" > /dev/null
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
After the installation, you must close the current terminal and reopen it to make the alias take effect.
 | 
			
		||||
 | 
			
		||||
Ok, you are ready to issue certs now.
 | 
			
		||||
 | 
			
		||||
Ok, you are ready to issue cert now.
 | 
			
		||||
Show help message:
 | 
			
		||||
```
 | 
			
		||||
root@v1:~# le.sh
 | 
			
		||||
https://github.com/Neilpang/le
 | 
			
		||||
v1.2.3
 | 
			
		||||
Usage: le.sh  [command] ...[args]....
 | 
			
		||||
Available commands:
 | 
			
		||||
 | 
			
		||||
install:
 | 
			
		||||
  Install le.sh to your system.
 | 
			
		||||
issue:
 | 
			
		||||
  Issue a cert.
 | 
			
		||||
installcert:
 | 
			
		||||
  Install the issued cert to apache/nginx or any other server.
 | 
			
		||||
renew:
 | 
			
		||||
  Renew a cert.
 | 
			
		||||
renewAll:
 | 
			
		||||
  Renew all the certs.
 | 
			
		||||
uninstall:
 | 
			
		||||
  Uninstall le.sh, and uninstall the cron job.
 | 
			
		||||
revoke:
 | 
			
		||||
  Revoke a cert.
 | 
			
		||||
version:
 | 
			
		||||
  Show version info.
 | 
			
		||||
installcronjob:
 | 
			
		||||
  Install the cron job to renew certs, you don't need to call this. The 'install' command can automatically install the cron job.
 | 
			
		||||
uninstallcronjob:
 | 
			
		||||
  Uninstall the cron job. The 'uninstall' command can do this automatically.
 | 
			
		||||
toPkcs:
 | 
			
		||||
  Export the certificate and key to a pfx file.
 | 
			
		||||
createAccountKey:
 | 
			
		||||
  Create an account private key, professional use.
 | 
			
		||||
createDomainKey:
 | 
			
		||||
  Create an domain private key, professional use.
 | 
			
		||||
createCSR:
 | 
			
		||||
  Create CSR , professional use.
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
root@v1:~/le# le issue
 | 
			
		||||
Usage: le  issue  webroot|no|apache|dns   a.com  [www.a.com,b.com,c.com]|no   [key-length]|no
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
root@v1:~# acme.sh -h
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
Set the param value to "no" means you want to ignore it.
 | 
			
		||||
# 2. Just issue a cert
 | 
			
		||||
 | 
			
		||||
For example, if you give "no" to "key-length", it will use default length 2048.
 | 
			
		||||
**Example 1:** Single domain.
 | 
			
		||||
 | 
			
		||||
And if you give 'no' to 'cert-file-path', it will not copy the issued cert to the "cert-file-path".
 | 
			
		||||
 | 
			
		||||
In all the cases, the issued cert will be placed in "~/.le/domain.com/"
 | 
			
		||||
 | 
			
		||||
 
 | 
			
		||||
# Just issue a cert:
 | 
			
		||||
Example 1:
 | 
			
		||||
Only one domain:
 | 
			
		||||
```
 | 
			
		||||
le issue   /home/wwwroot/aa.com    aa.com 
 | 
			
		||||
```bash
 | 
			
		||||
acme.sh --issue -d example.com -w /home/wwwroot/example.com
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
Example 2:
 | 
			
		||||
Multiple domains in the same cert:
 | 
			
		||||
or:
 | 
			
		||||
 | 
			
		||||
```
 | 
			
		||||
le issue   /home/wwwroot/aa.com    aa.com    www.aa.com,cp.aa.com
 | 
			
		||||
```bash
 | 
			
		||||
acme.sh --issue -d example.com -w /home/username/public_html
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
First argument `/home/wwwroot/aa.com` is the web root folder, You must have `write` access to this folder.
 | 
			
		||||
or:
 | 
			
		||||
 | 
			
		||||
Second argument "aa.com" is the main domain you want to issue cert for.
 | 
			
		||||
 | 
			
		||||
Third argument is the additional domain list you want to use. Comma separated list,  which is Optional.
 | 
			
		||||
 | 
			
		||||
You must point and bind all the domains to the same webroot dir:`/home/wwwroot/aa.com`
 | 
			
		||||
 | 
			
		||||
The cert will be placed in `~/.le/aa.com/`
 | 
			
		||||
 | 
			
		||||
The issued cert will be renewed every 80 days automatically.
 | 
			
		||||
 | 
			
		||||
# Install issued cert to apache/nginx etc.
 | 
			
		||||
```
 | 
			
		||||
le installcert  aa.com /path/to/certfile/in/apache/nginx  /path/to/keyfile/in/apache/nginx  /path/to/ca/certfile/apache/nginx   "service apache2|nginx reload"
 | 
			
		||||
```bash
 | 
			
		||||
acme.sh --issue -d example.com -w /var/www/html
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
Install the issued cert/key to the production apache or nginx path.
 | 
			
		||||
**Example 2:** Multiple domains in the same cert.
 | 
			
		||||
 | 
			
		||||
The cert will be renewed every 80 days by default (which is configurable), Once the cert is renewed, the apache/nginx will be automatically reloaded by the command: `service apache2 reload` or `service nginx reload`
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
# Use Standalone server to issue cert (requires you be root/sudoer, or you have permission to listen tcp 80 port):
 | 
			
		||||
Same usage as all above,  just give `no` as the webroot.
 | 
			
		||||
The tcp `80` port must be free to listen, otherwise you will be prompted to free the `80` port and try again.
 | 
			
		||||
 | 
			
		||||
```
 | 
			
		||||
le issue    no    aa.com    www.aa.com,cp.aa.com
 | 
			
		||||
```bash
 | 
			
		||||
acme.sh --issue -d example.com -d www.example.com -d cp.example.com -w /home/wwwroot/example.com
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
# Use Apache mode (requires you be root/sudoer, since it is required to interact with apache server):
 | 
			
		||||
If you are running a web server, apache or nginx, it is recommended to use the Webroot mode.
 | 
			
		||||
Particularly,  if you are running an apache server, you can use apache mode instead. Which doesn't write any file to your web root folder.
 | 
			
		||||
The parameter `/home/wwwroot/example.com` or `/home/username/public_html` or `/var/www/html` is the web root folder where you host your website files. You **MUST** have `write access` to this folder.
 | 
			
		||||
 | 
			
		||||
Just set string "apache" to the first argument, it will use apache plugin automatically.
 | 
			
		||||
Second argument **"example.com"** is the main domain you want to issue the cert for.
 | 
			
		||||
You must have at least one domain there.
 | 
			
		||||
 | 
			
		||||
```
 | 
			
		||||
le  issue  apache  aa.com   www.aa.com,user.aa.com
 | 
			
		||||
```
 | 
			
		||||
All the other arguments are the same with previous.
 | 
			
		||||
You must point and bind all the domains to the same webroot dir: `/home/wwwroot/example.com`.
 | 
			
		||||
 | 
			
		||||
The certs will be placed in `~/.acme.sh/example.com/`
 | 
			
		||||
 | 
			
		||||
The certs will be renewed automatically every **60** days.
 | 
			
		||||
 | 
			
		||||
More examples: https://github.com/Neilpang/acme.sh/wiki/How-to-issue-a-cert
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
# Use DNS mode:
 | 
			
		||||
Support the latest dns-01 challenge.
 | 
			
		||||
# 3. Install the cert to Apache/Nginx etc.
 | 
			
		||||
 | 
			
		||||
```
 | 
			
		||||
le  issue   dns   aa.com  www.aa.com,user.aa.com
 | 
			
		||||
After the cert is generated, you probably want to install/copy the cert to your Apache/Nginx or other servers.
 | 
			
		||||
You **MUST** use this command to copy the certs to the target files, **DO NOT** use the certs files in **~/.acme.sh/** folder, they are for internal use only, the folder structure may change in the future.
 | 
			
		||||
 | 
			
		||||
**Apache** example:
 | 
			
		||||
```bash
 | 
			
		||||
acme.sh --install-cert -d example.com \
 | 
			
		||||
--cert-file      /path/to/certfile/in/apache/cert.pem  \
 | 
			
		||||
--key-file       /path/to/keyfile/in/apache/key.pem  \
 | 
			
		||||
--fullchain-file /path/to/fullchain/certfile/apache/fullchain.pem \
 | 
			
		||||
--reloadcmd     "service apache2 force-reload"
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
You will get the output like bellow:
 | 
			
		||||
**Nginx** example:
 | 
			
		||||
```bash
 | 
			
		||||
acme.sh --install-cert -d example.com \
 | 
			
		||||
--key-file       /path/to/keyfile/in/nginx/key.pem  \
 | 
			
		||||
--fullchain-file /path/to/fullchain/nginx/cert.pem \
 | 
			
		||||
--reloadcmd     "service nginx force-reload"
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
Only the domain is required, all the other parameters are optional.
 | 
			
		||||
 | 
			
		||||
The ownership and permission info of existing files are preserved. You can pre-create the files to define the ownership and permission.
 | 
			
		||||
 | 
			
		||||
Install/copy the cert/key to the production Apache or Nginx path.
 | 
			
		||||
 | 
			
		||||
The cert will be renewed every **60** days by default (which is configurable). Once the cert is renewed, the Apache/Nginx service will be reloaded automatically by the command: `service apache2 force-reload` or `service nginx force-reload`.
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
**Please take care:  The reloadcmd is very important. The cert can be automatically renewed, but, without a correct 'reloadcmd' the cert may not be flushed to your server(like nginx or apache), then your website will not be able to show renewed cert in 60 days.**
 | 
			
		||||
 | 
			
		||||
# 4. Use Standalone server to issue cert
 | 
			
		||||
 | 
			
		||||
**(requires you to be root/sudoer or have permission to listen on port 80 (TCP))**
 | 
			
		||||
 | 
			
		||||
Port `80` (TCP) **MUST** be free to listen on, otherwise you will be prompted to free it and try again.
 | 
			
		||||
 | 
			
		||||
```bash
 | 
			
		||||
acme.sh --issue --standalone -d example.com -d www.example.com -d cp.example.com
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
More examples: https://github.com/Neilpang/acme.sh/wiki/How-to-issue-a-cert
 | 
			
		||||
 | 
			
		||||
# 5. Use Standalone ssl server to issue cert
 | 
			
		||||
 | 
			
		||||
**(requires you to be root/sudoer or have permission to listen on port 443 (TCP))**
 | 
			
		||||
 | 
			
		||||
Port `443` (TCP) **MUST** be free to listen on, otherwise you will be prompted to free it and try again.
 | 
			
		||||
 | 
			
		||||
```bash
 | 
			
		||||
acme.sh --issue --alpn -d example.com -d www.example.com -d cp.example.com
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
More examples: https://github.com/Neilpang/acme.sh/wiki/How-to-issue-a-cert
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
# 6. Use Apache mode
 | 
			
		||||
 | 
			
		||||
**(requires you to be root/sudoer, since it is required to interact with Apache server)**
 | 
			
		||||
 | 
			
		||||
If you are running a web server, Apache or Nginx, it is recommended to use the `Webroot mode`.
 | 
			
		||||
 | 
			
		||||
Particularly, if you are running an Apache server, you can use Apache mode instead. This mode doesn't write any files to your web root folder.
 | 
			
		||||
 | 
			
		||||
Just set string "apache" as the second argument and it will force use of apache plugin automatically.
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --issue --apache -d example.com -d www.example.com -d cp.example.com
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
**This apache mode is only to issue the cert, it will not change your apache config files. 
 | 
			
		||||
You will need to configure your website config files to use the cert by yourself.
 | 
			
		||||
We don't want to mess your apache server, don't worry.**
 | 
			
		||||
 | 
			
		||||
More examples: https://github.com/Neilpang/acme.sh/wiki/How-to-issue-a-cert
 | 
			
		||||
 | 
			
		||||
# 7. Use Nginx mode
 | 
			
		||||
 | 
			
		||||
**(requires you to be root/sudoer, since it is required to interact with Nginx server)**
 | 
			
		||||
 | 
			
		||||
If you are running a web server, Apache or Nginx, it is recommended to use the `Webroot mode`.
 | 
			
		||||
 | 
			
		||||
Particularly, if you are running an nginx server, you can use nginx mode instead. This mode doesn't write any files to your web root folder.
 | 
			
		||||
 | 
			
		||||
Just set string "nginx" as the second argument.
 | 
			
		||||
 | 
			
		||||
It will configure nginx server automatically to verify the domain and then restore the nginx config to the original version.
 | 
			
		||||
 | 
			
		||||
So, the config is not changed.
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --issue --nginx -d example.com -d www.example.com -d cp.example.com
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
**This nginx mode is only to issue the cert, it will not change your nginx config files. 
 | 
			
		||||
You will need to configure your website config files to use the cert by yourself.
 | 
			
		||||
We don't want to mess your nginx server, don't worry.**
 | 
			
		||||
 | 
			
		||||
More examples: https://github.com/Neilpang/acme.sh/wiki/How-to-issue-a-cert
 | 
			
		||||
 | 
			
		||||
# 8. Automatic DNS API integration
 | 
			
		||||
 | 
			
		||||
If your DNS provider supports API access, we can use that API to automatically issue the certs.
 | 
			
		||||
 | 
			
		||||
You don't have to do anything manually!
 | 
			
		||||
 | 
			
		||||
### Currently acme.sh supports:
 | 
			
		||||
 | 
			
		||||
1. CloudFlare.com API
 | 
			
		||||
1. DNSPod.cn API
 | 
			
		||||
1. CloudXNS.com API
 | 
			
		||||
1. GoDaddy.com API
 | 
			
		||||
1. PowerDNS.com API
 | 
			
		||||
1. OVH, kimsufi, soyoustart and runabove API
 | 
			
		||||
1. nsupdate API
 | 
			
		||||
1. LuaDNS.com API
 | 
			
		||||
1. DNSMadeEasy.com API
 | 
			
		||||
1. AWS Route 53
 | 
			
		||||
1. aliyun.com(阿里云) API
 | 
			
		||||
1. ISPConfig 3.1 API
 | 
			
		||||
1. Alwaysdata.com API
 | 
			
		||||
1. Linode.com API
 | 
			
		||||
1. FreeDNS (https://freedns.afraid.org/)
 | 
			
		||||
1. cyon.ch
 | 
			
		||||
1. Domain-Offensive/Resellerinterface/Domainrobot API
 | 
			
		||||
1. Gandi LiveDNS API
 | 
			
		||||
1. Knot DNS API
 | 
			
		||||
1. DigitalOcean API (native)
 | 
			
		||||
1. ClouDNS.net API
 | 
			
		||||
1. Infoblox NIOS API (https://www.infoblox.com/)
 | 
			
		||||
1. VSCALE (https://vscale.io/)
 | 
			
		||||
1. Dynu API (https://www.dynu.com)
 | 
			
		||||
1. DNSimple API
 | 
			
		||||
1. NS1.com API
 | 
			
		||||
1. DuckDNS.org API
 | 
			
		||||
1. Name.com API
 | 
			
		||||
1. Dyn Managed DNS API
 | 
			
		||||
1. Yandex PDD API (https://pdd.yandex.ru)
 | 
			
		||||
1. Hurricane Electric DNS service (https://dns.he.net)
 | 
			
		||||
1. UnoEuro API (https://www.unoeuro.com/)
 | 
			
		||||
1. INWX (https://www.inwx.de/)
 | 
			
		||||
1. Servercow (https://servercow.de)
 | 
			
		||||
1. Namesilo (https://www.namesilo.com)
 | 
			
		||||
1. InternetX autoDNS API (https://internetx.com)
 | 
			
		||||
1. Azure DNS
 | 
			
		||||
1. selectel.com(selectel.ru) DNS API
 | 
			
		||||
1. zonomi.com DNS API
 | 
			
		||||
1. DreamHost.com API
 | 
			
		||||
1. DirectAdmin API
 | 
			
		||||
1. KingHost (https://www.kinghost.com.br/)
 | 
			
		||||
1. Zilore (https://zilore.com)
 | 
			
		||||
1. Loopia.se API
 | 
			
		||||
1. acme-dns (https://github.com/joohoi/acme-dns)
 | 
			
		||||
1. TELE3 (https://www.tele3.cz)
 | 
			
		||||
1. EUSERV.EU (https://www.euserv.eu)
 | 
			
		||||
1. DNSPod.com API (https://www.dnspod.com)
 | 
			
		||||
1. Google Cloud DNS API
 | 
			
		||||
1. ConoHa (https://www.conoha.jp)
 | 
			
		||||
1. netcup DNS API (https://www.netcup.de)
 | 
			
		||||
1. GratisDNS.dk (https://gratisdns.dk)
 | 
			
		||||
1. Namecheap API (https://www.namecheap.com/)
 | 
			
		||||
1. MyDNS.JP API (https://www.mydns.jp/)
 | 
			
		||||
1. hosting.de (https://www.hosting.de)
 | 
			
		||||
1. Neodigit.net API (https://www.neodigit.net)
 | 
			
		||||
1. Exoscale.com API (https://www.exoscale.com/)
 | 
			
		||||
1. PointDNS API (https://pointhq.com/)
 | 
			
		||||
1. Active24.cz API (https://www.active24.cz/)
 | 
			
		||||
 | 
			
		||||
And:
 | 
			
		||||
 | 
			
		||||
**lexicon DNS API: https://github.com/Neilpang/acme.sh/wiki/How-to-use-lexicon-dns-api
 | 
			
		||||
   (DigitalOcean, DNSimple, DNSMadeEasy, DNSPark, EasyDNS, Namesilo, NS1, PointHQ, Rage4 and Vultr etc.)**
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
**More APIs coming soon...**
 | 
			
		||||
 | 
			
		||||
If your DNS provider is not on the supported list above, you can write your own DNS API script easily. If you do, please consider submitting a [Pull Request](https://github.com/Neilpang/acme.sh/pulls) and contribute it to the project.
 | 
			
		||||
 | 
			
		||||
For more details: [How to use DNS API](dnsapi)
 | 
			
		||||
 | 
			
		||||
# 9. Use DNS manual mode:
 | 
			
		||||
 | 
			
		||||
See: https://github.com/Neilpang/acme.sh/wiki/dns-manual-mode first.
 | 
			
		||||
 | 
			
		||||
If your dns provider doesn't support any api access, you can add the txt record by your hand.
 | 
			
		||||
 | 
			
		||||
```bash
 | 
			
		||||
acme.sh --issue --dns -d example.com -d www.example.com -d cp.example.com
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
You should get an output like below:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
Add the following txt record:
 | 
			
		||||
Domain:_acme-challenge.aa.com
 | 
			
		||||
Domain:_acme-challenge.example.com
 | 
			
		||||
Txt value:9ihDbjYfTExAYeDs4DBUeuTo18KBzwvTEjUnSwd32-c
 | 
			
		||||
 | 
			
		||||
Add the following txt record:
 | 
			
		||||
Domain:_acme-challenge.www.aa.com
 | 
			
		||||
Domain:_acme-challenge.www.example.com
 | 
			
		||||
Txt value:9ihDbjxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
Please add those txt records to the domains. Waiting for the dns to take effect.
 | 
			
		||||
 | 
			
		||||
Then just retry with 'renew' command:
 | 
			
		||||
 | 
			
		||||
```
 | 
			
		||||
le renew  aa.com
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
Ok, it's finished.
 | 
			
		||||
Then just rerun with `renew` argument:
 | 
			
		||||
 | 
			
		||||
```bash
 | 
			
		||||
acme.sh --renew -d example.com
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
#Automatic dns api integeration
 | 
			
		||||
Ok, it's done.
 | 
			
		||||
 | 
			
		||||
If your dns provider supports api access, we can use api to automatically issue certs.
 | 
			
		||||
You don't have do anything manually.
 | 
			
		||||
**Take care, this is dns manual mode, it can not be renewed automatically. you will have to add a new txt record to your domain by your hand when you renew your cert.**
 | 
			
		||||
 | 
			
		||||
###Currently we support:
 | 
			
		||||
**Please use dns api mode instead.**
 | 
			
		||||
 | 
			
		||||
1. Cloudflare.com api
 | 
			
		||||
2. Dnspod.cn api
 | 
			
		||||
3. Cloudxns.com api
 | 
			
		||||
4. AWS Route 53, see: https://github.com/Neilpang/le/issues/65
 | 
			
		||||
# 10. Issue ECC certificates
 | 
			
		||||
 | 
			
		||||
More apis are coming soon....
 | 
			
		||||
`Let's Encrypt` can now issue **ECDSA** certificates.
 | 
			
		||||
 | 
			
		||||
If your dns provider is not in the supported list above, you can write your own script api easily.
 | 
			
		||||
And we support them too!
 | 
			
		||||
 | 
			
		||||
For more details: [How to use dns api](dnsapi)
 | 
			
		||||
Just set the `keylength` parameter with a prefix `ec-`.
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
# Issue ECC certificate:
 | 
			
		||||
LetsEncrypt now can issue ECDSA certificate.
 | 
			
		||||
And we also support it.
 | 
			
		||||
 | 
			
		||||
Just set the `length` parameter with a prefix `ec-`.
 | 
			
		||||
For example:
 | 
			
		||||
 | 
			
		||||
Single domain:
 | 
			
		||||
```
 | 
			
		||||
le issue  /home/wwwroot/aa.com    aa.com   no      ec-256
 | 
			
		||||
### Single domain ECC certificate
 | 
			
		||||
 | 
			
		||||
```bash
 | 
			
		||||
acme.sh --issue -w /home/wwwroot/example.com -d example.com --keylength ec-256
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
SAN multiple domains:
 | 
			
		||||
```
 | 
			
		||||
le issue  /home/wwwroot/aa.com    aa.com   www.aa.com,cp.aa.com    ec-256
 | 
			
		||||
### SAN multi domain ECC certificate
 | 
			
		||||
 | 
			
		||||
```bash
 | 
			
		||||
acme.sh --issue -w /home/wwwroot/example.com -d example.com -d www.example.com --keylength ec-256
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
Please look at the last parameter above.
 | 
			
		||||
Please look at the `keylength` parameter above.
 | 
			
		||||
 | 
			
		||||
Valid values are:
 | 
			
		||||
 | 
			
		||||
1. ec-256 (prime256v1,  "ECDSA P-256")
 | 
			
		||||
2. ec-384 (secp384r1,   "ECDSA P-384")
 | 
			
		||||
3. ec-521 (secp521r1,   "ECDSA P-521", which is not supported by letsencrypt yet.)
 | 
			
		||||
1. **ec-256 (prime256v1, "ECDSA P-256")**
 | 
			
		||||
2. **ec-384 (secp384r1,  "ECDSA P-384")**
 | 
			
		||||
3. **ec-521 (secp521r1,  "ECDSA P-521", which is not supported by Let's Encrypt yet.)**
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#Under the Hood
 | 
			
		||||
# 11. Issue Wildcard certificates
 | 
			
		||||
 | 
			
		||||
Speak ACME language with bash directly to Let's encrypt.
 | 
			
		||||
It's simple, just give a wildcard domain as the `-d` parameter.
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh  --issue -d example.com  -d '*.example.com'  --dns dns_cf
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
# 12. How to renew the certs
 | 
			
		||||
 | 
			
		||||
No, you don't need to renew the certs manually. All the certs will be renewed automatically every **60** days.
 | 
			
		||||
 | 
			
		||||
However, you can also force to renew a cert:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --renew -d example.com --force
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
or, for ECC cert:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --renew -d example.com --force --ecc
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
# 13. How to stop cert renewal
 | 
			
		||||
 | 
			
		||||
To stop renewal of a cert, you can execute the following to remove the cert from the renewal list:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --remove -d example.com [--ecc]
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
The cert/key file is not removed from the disk.
 | 
			
		||||
 | 
			
		||||
You can remove the respective directory (e.g. `~/.acme.sh/example.com`) by yourself.
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
# 14. How to upgrade `acme.sh`
 | 
			
		||||
 | 
			
		||||
acme.sh is in constant development, so it's strongly recommended to use the latest code.
 | 
			
		||||
 | 
			
		||||
You can update acme.sh to the latest code:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --upgrade
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
You can also enable auto upgrade:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --upgrade --auto-upgrade
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
Then **acme.sh** will be kept up to date automatically.
 | 
			
		||||
 | 
			
		||||
Disable auto upgrade:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --upgrade --auto-upgrade 0
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
# 15. Issue a cert from an existing CSR
 | 
			
		||||
 | 
			
		||||
https://github.com/Neilpang/acme.sh/wiki/Issue-a-cert-from-existing-CSR
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
# 16. Under the Hood
 | 
			
		||||
 | 
			
		||||
Speak ACME language using shell, directly to "Let's Encrypt".
 | 
			
		||||
 | 
			
		||||
TODO:
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#Acknowledgment
 | 
			
		||||
# 17. Acknowledgments
 | 
			
		||||
 | 
			
		||||
1. Acme-tiny: https://github.com/diafygi/acme-tiny
 | 
			
		||||
2. ACME protocol: https://github.com/ietf-wg-acme/acme
 | 
			
		||||
3. letsencrypt: https://github.com/letsencrypt/letsencrypt
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#License & Other
 | 
			
		||||
# 18. License & Others
 | 
			
		||||
 | 
			
		||||
License is GPLv3
 | 
			
		||||
 | 
			
		||||
Please Star and Fork me.
 | 
			
		||||
 | 
			
		||||
Issues and pull requests are welcomed.
 | 
			
		||||
[Issues](https://github.com/Neilpang/acme.sh/issues) and [pull requests](https://github.com/Neilpang/acme.sh/pulls) are welcome.
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
# 19. Donate
 | 
			
		||||
Your donation makes **acme.sh** better:
 | 
			
		||||
 | 
			
		||||
1. PayPal/Alipay(支付宝)/Wechat(微信): [https://donate.acme.sh/](https://donate.acme.sh/)
 | 
			
		||||
  
 | 
			
		||||
[Donate List](https://github.com/Neilpang/acme.sh/wiki/Donate-list)
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										383
									
								
								deploy/README.md
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										383
									
								
								deploy/README.md
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,383 @@
 | 
			
		||||
# Using deploy api
 | 
			
		||||
 | 
			
		||||
Before you can deploy your cert, you must [issue the cert first](https://github.com/Neilpang/acme.sh/wiki/How-to-issue-a-cert).
 | 
			
		||||
 | 
			
		||||
Here are the scripts to deploy the certs/key to the server/services.
 | 
			
		||||
 | 
			
		||||
## 1. Deploy the certs to your cpanel host
 | 
			
		||||
 | 
			
		||||
If you want to deploy using cpanel UAPI see 7.
 | 
			
		||||
 | 
			
		||||
(cpanel deploy hook is not finished yet, this is just an example.)
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
Then you can deploy now:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
export DEPLOY_CPANEL_USER=myusername
 | 
			
		||||
export DEPLOY_CPANEL_PASSWORD=PASSWORD
 | 
			
		||||
acme.sh --deploy -d example.com --deploy-hook cpanel
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
## 2. Deploy ssl cert on kong proxy engine based on api
 | 
			
		||||
 | 
			
		||||
Before you can deploy your cert, you must [issue the cert first](https://github.com/Neilpang/acme.sh/wiki/How-to-issue-a-cert).
 | 
			
		||||
Currently supports Kong-v0.10.x.
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --deploy -d ftp.example.com --deploy-hook kong
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
## 3. Deploy the cert to remote server through SSH access
 | 
			
		||||
 | 
			
		||||
The ssh deploy plugin allows you to deploy certificates to a remote host
 | 
			
		||||
using SSH command to connect to the remote server.  The ssh plugin is invoked
 | 
			
		||||
with the following command...
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --deploy -d example.com --deploy-hook ssh
 | 
			
		||||
```
 | 
			
		||||
Prior to running this for the first time you must tell the plugin where
 | 
			
		||||
and how to deploy the certificates.  This is done by exporting the following
 | 
			
		||||
environment variables.  This is not required for subsequent runs as the
 | 
			
		||||
values are stored by acme.sh in the domain configuration files.
 | 
			
		||||
 | 
			
		||||
Required...
 | 
			
		||||
```
 | 
			
		||||
export DEPLOY_SSH_USER=username
 | 
			
		||||
```
 | 
			
		||||
Optional...
 | 
			
		||||
```
 | 
			
		||||
export DEPLOY_SSH_CMD=custom ssh command
 | 
			
		||||
export DEPLOY_SSH_SERVER=url or ip address of remote host
 | 
			
		||||
export DEPLOY_SSH_KEYFILE=filename for private key
 | 
			
		||||
export DEPLOY_SSH_CERTFILE=filename for certificate file
 | 
			
		||||
export DEPLOY_SSH_CAFILE=filename for intermediate CA file
 | 
			
		||||
export DEPLOY_SSH_FULLCHAIN=filename for fullchain file
 | 
			
		||||
export DEPLOY_SSH_REMOTE_CMD=command to execute on remote host
 | 
			
		||||
export DEPLOY_SSH_BACKUP=yes or no
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
**DEPLOY_SSH_USER**
 | 
			
		||||
Username at the remote host that SSH will login with. Note that
 | 
			
		||||
SSH must be able to login to remote host without a password... SSH Keys
 | 
			
		||||
must have been exchanged with the remote host. Validate and test that you
 | 
			
		||||
can login to USER@URL from the host running acme.sh before using this script.
 | 
			
		||||
 | 
			
		||||
The USER@URL at the remote server must also have has permissions to write to
 | 
			
		||||
the target location of the certificate files and to execute any commands
 | 
			
		||||
(e.g. to stop/start services).
 | 
			
		||||
 | 
			
		||||
**DEPLOY_SSH_CMD**
 | 
			
		||||
You can customize the ssh command used to connect to the remote host. For example
 | 
			
		||||
if you need to connect to a specific port at the remote server you can set this
 | 
			
		||||
to, for example, "ssh -p 22" or to use `sshpass` to provide password inline
 | 
			
		||||
instead of exchanging ssh keys (this is not recommended, using keys is
 | 
			
		||||
more secure).
 | 
			
		||||
 | 
			
		||||
**DEPLOY_SSH_SERVER**
 | 
			
		||||
URL or IP Address of the remote server.  If not provided then the domain
 | 
			
		||||
name provided on the acme.sh --deploy command line is used.
 | 
			
		||||
 | 
			
		||||
**DEPLOY_SSH_KEYFILE**
 | 
			
		||||
Target filename for the private key issued by LetsEncrypt.
 | 
			
		||||
 | 
			
		||||
**DEPLOY_SSH_CERTFILE**
 | 
			
		||||
Target filename for the certificate issued by LetsEncrypt.
 | 
			
		||||
If this is the same as the previous filename (for keyfile) then it is
 | 
			
		||||
appended to the same file.
 | 
			
		||||
 | 
			
		||||
**DEPLOY_SSH_CAFILE**
 | 
			
		||||
Target filename for the CA intermediate certificate issued by LetsEncrypt.
 | 
			
		||||
If this is the same as a previous filename (for keyfile or certfile) then
 | 
			
		||||
it is appended to the same file.
 | 
			
		||||
 | 
			
		||||
**DEPLOY_SSH_FULLCHAIN**
 | 
			
		||||
Target filename for the fullchain certificate issued by LetsEncrypt.
 | 
			
		||||
If this is the same as a previous filename (for keyfile, certfile or
 | 
			
		||||
cafile) then it is appended to the same file.
 | 
			
		||||
 | 
			
		||||
**DEPLOY_SSH_REMOTE_CMD**
 | 
			
		||||
Command to execute on the remote server after copying any certificates.  This
 | 
			
		||||
could be any additional command required for example to stop and restart
 | 
			
		||||
the service.
 | 
			
		||||
 | 
			
		||||
**DEPLOY_SSH_BACKUP**
 | 
			
		||||
Before writing a certificate file to the remote server the existing
 | 
			
		||||
certificate will be copied to a backup directory on the remote server.
 | 
			
		||||
These are placed in a hidden directory in the home directory of the SSH
 | 
			
		||||
user
 | 
			
		||||
```sh
 | 
			
		||||
~/.acme_ssh_deploy/[domain name]-backup-[timestamp]
 | 
			
		||||
```
 | 
			
		||||
Any backups older than 180 days will be deleted when new certificates
 | 
			
		||||
are deployed.  This defaults to "yes" set to "no" to disable backup.
 | 
			
		||||
 | 
			
		||||
###Examples using SSH deploy
 | 
			
		||||
The following example illustrates deploying certificates to a QNAP NAS
 | 
			
		||||
(tested with QTS version 4.2.3)
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
export DEPLOY_SSH_USER="admin"
 | 
			
		||||
export DEPLOY_SSH_KEYFILE="/etc/stunnel/stunnel.pem"
 | 
			
		||||
export DEPLOY_SSH_CERTFILE="/etc/stunnel/stunnel.pem"
 | 
			
		||||
export DEPLOY_SSH_CAFILE="/etc/stunnel/uca.pem"
 | 
			
		||||
export DEPLOY_SSH_REMOTE_CMD="/etc/init.d/stunnel.sh restart"
 | 
			
		||||
 | 
			
		||||
acme.sh --deploy -d qnap.example.com --deploy-hook ssh
 | 
			
		||||
```
 | 
			
		||||
Note how in this example both the private key and certificate point to
 | 
			
		||||
the same file.  This will result in the certificate being appended
 | 
			
		||||
to the same file as the private key... a common requirement of several
 | 
			
		||||
services.
 | 
			
		||||
 | 
			
		||||
The next example illustrates deploying certificates to a Unifi
 | 
			
		||||
Controller (tested with version 5.4.11).
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
export DEPLOY_SSH_USER="root"
 | 
			
		||||
export DEPLOY_SSH_KEYFILE="/var/lib/unifi/unifi.example.com.key"
 | 
			
		||||
export DEPLOY_SSH_FULLCHAIN="/var/lib/unifi/unifi.example.com.cer"
 | 
			
		||||
export DEPLOY_SSH_REMOTE_CMD="openssl pkcs12 -export \
 | 
			
		||||
   -inkey /var/lib/unifi/unifi.example.com.key \
 | 
			
		||||
   -in /var/lib/unifi/unifi.example.com.cer \
 | 
			
		||||
   -out /var/lib/unifi/unifi.example.com.p12 \
 | 
			
		||||
   -name ubnt -password pass:temppass \
 | 
			
		||||
 && keytool -importkeystore -deststorepass aircontrolenterprise \
 | 
			
		||||
   -destkeypass aircontrolenterprise \
 | 
			
		||||
   -destkeystore /var/lib/unifi/keystore \
 | 
			
		||||
   -srckeystore /var/lib/unifi/unifi.example.com.p12 \
 | 
			
		||||
   -srcstoretype PKCS12 -srcstorepass temppass -alias ubnt -noprompt \
 | 
			
		||||
 && service unifi restart"
 | 
			
		||||
 | 
			
		||||
acme.sh --deploy -d unifi.example.com --deploy-hook ssh
 | 
			
		||||
```
 | 
			
		||||
In this example we execute several commands on the remote host
 | 
			
		||||
after the certificate files have been copied... to generate a pkcs12 file
 | 
			
		||||
compatible with Unifi, to import it into the Unifi keystore and then finally
 | 
			
		||||
to restart the service.
 | 
			
		||||
 | 
			
		||||
Note also that once the certificate is imported
 | 
			
		||||
into the keystore the individual certificate files are no longer
 | 
			
		||||
required. We could if we desired delete those files immediately. If we
 | 
			
		||||
do that then we should disable backup at the remote host (as there are
 | 
			
		||||
no files to backup -- they were erased during deployment). For example...
 | 
			
		||||
```sh
 | 
			
		||||
export DEPLOY_SSH_BACKUP=no
 | 
			
		||||
# modify the end of the remote command...
 | 
			
		||||
&& rm /var/lib/unifi/unifi.example.com.key \
 | 
			
		||||
      /var/lib/unifi/unifi.example.com.cer \
 | 
			
		||||
      /var/lib/unifi/unifi.example.com.p12 \
 | 
			
		||||
&& service unifi restart
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
## 4. Deploy the cert to local vsftpd server
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --deploy -d ftp.example.com --deploy-hook vsftpd
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
The default vsftpd conf file is `/etc/vsftpd.conf`,  if your vsftpd conf is not in the default location, you can specify one:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
export DEPLOY_VSFTPD_CONF="/etc/vsftpd.conf"
 | 
			
		||||
 | 
			
		||||
acme.sh --deploy -d ftp.example.com --deploy-hook vsftpd
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
The default command to restart vsftpd server is `service vsftpd restart`, if it doesn't work, you can specify one:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
export DEPLOY_VSFTPD_RELOAD="/etc/init.d/vsftpd restart"
 | 
			
		||||
 | 
			
		||||
acme.sh --deploy -d ftp.example.com --deploy-hook vsftpd
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
## 5. Deploy the cert to local exim4 server
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --deploy -d ftp.example.com --deploy-hook exim4
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
The default exim4 conf file is `/etc/exim/exim.conf`,  if your exim4 conf is not in the default location, you can specify one:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
export DEPLOY_EXIM4_CONF="/etc/exim4/exim4.conf.template"
 | 
			
		||||
 | 
			
		||||
acme.sh --deploy -d ftp.example.com --deploy-hook exim4
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
The default command to restart exim4 server is `service exim4 restart`, if it doesn't work, you can specify one:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
export DEPLOY_EXIM4_RELOAD="/etc/init.d/exim4 restart"
 | 
			
		||||
 | 
			
		||||
acme.sh --deploy -d ftp.example.com --deploy-hook exim4
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
## 6. Deploy the cert to OSX Keychain
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --deploy -d ftp.example.com --deploy-hook keychain
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
## 7. Deploy to cpanel host using UAPI
 | 
			
		||||
 | 
			
		||||
This hook is using UAPI and works in cPanel & WHM version 56 or newer.
 | 
			
		||||
```
 | 
			
		||||
acme.sh  --deploy  -d example.com  --deploy-hook cpanel_uapi
 | 
			
		||||
```
 | 
			
		||||
DEPLOY_CPANEL_USER is required only if you run the script as root and it should contain cpanel username.
 | 
			
		||||
```sh
 | 
			
		||||
export DEPLOY_CPANEL_USER=username
 | 
			
		||||
acme.sh  --deploy  -d example.com  --deploy-hook cpanel_uapi
 | 
			
		||||
```
 | 
			
		||||
Please note, that the cpanel_uapi hook will deploy only the first domain when your certificate will automatically renew. Therefore you should issue a separate certificate for each domain. 
 | 
			
		||||
 | 
			
		||||
## 8. Deploy the cert to your FRITZ!Box router
 | 
			
		||||
 | 
			
		||||
You must specify the credentials that have administrative privileges on the FRITZ!Box in order to deploy the certificate, plus the URL of your FRITZ!Box, through the following environment variables:
 | 
			
		||||
```sh
 | 
			
		||||
$ export DEPLOY_FRITZBOX_USERNAME=my_username
 | 
			
		||||
$ export DEPLOY_FRITZBOX_PASSWORD=the_password
 | 
			
		||||
$ export DEPLOY_FRITZBOX_URL=https://fritzbox.example.com
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
After the first deployment, these values will be stored in your $HOME/.acme.sh/account.conf. You may now deploy the certificate like this:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --deploy -d fritzbox.example.com --deploy-hook fritzbox
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
## 9. Deploy the cert to strongswan
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --deploy -d ftp.example.com --deploy-hook strongswan
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
## 10. Deploy the cert to HAProxy
 | 
			
		||||
 | 
			
		||||
You must specify the path where you want the concatenated key and certificate chain written.
 | 
			
		||||
```sh
 | 
			
		||||
export DEPLOY_HAPROXY_PEM_PATH=/etc/haproxy
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
You may optionally define the command to reload HAProxy. The value shown below will be used as the default if you don't set this environment variable.
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
export DEPLOY_HAPROXY_RELOAD="/usr/sbin/service haproxy restart"
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
You can then deploy the certificate as follows
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --deploy -d haproxy.example.com --deploy-hook haproxy
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
The path for the PEM file will be stored with the domain configuration and will be available when renewing, so that deploy will happen automatically when renewed.
 | 
			
		||||
 | 
			
		||||
## 11. Deploy your cert to Gitlab pages
 | 
			
		||||
 | 
			
		||||
You must define the API key and the informations for the project and Gitlab page you are updating the certificate for.
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
# The token can be created in your user settings under "Access Tokens"
 | 
			
		||||
export GITLAB_TOKEN="xxxxxxxxxxx"
 | 
			
		||||
 | 
			
		||||
# The project ID is displayed on the home page of the project
 | 
			
		||||
export GITLAB_PROJECT_ID=12345678
 | 
			
		||||
 | 
			
		||||
# The domain must match the one defined for the Gitlab page, without "https://"
 | 
			
		||||
export GITLAB_DOMAIN="www.mydomain.com"
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
You can then deploy the certificate as follows
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --deploy -d www.mydomain.com --deploy-hook gitlab
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
## 12. Deploy your cert to Hashicorp Vault
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
export VAULT_PREFIX="acme"
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
You can then deploy the certificate as follows
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
acme.sh --deploy -d www.mydomain.com --deploy-hook vault_cli
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
Your certs will be saved in Vault using this structure:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
vault write "${VAULT_PREFIX}/${domain}/cert.pem"      value=@"..."
 | 
			
		||||
vault write "${VAULT_PREFIX}/${domain}/cert.key"      value=@"..."
 | 
			
		||||
vault write "${VAULT_PREFIX}/${domain}/chain.pem"     value=@"..."
 | 
			
		||||
vault write "${VAULT_PREFIX}/${domain}/fullchain.pem" value=@"..."
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
You might be using Fabio load balancer (which can get certs from
 | 
			
		||||
Vault). It needs a bit different structure of your certs in Vault. It
 | 
			
		||||
gets certs only from keys that were saved in `prefix/domain`, like this:
 | 
			
		||||
 | 
			
		||||
```bash
 | 
			
		||||
vault write <PREFIX>/www.domain.com cert=@cert.pem key=@key.pem
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
If you want to save certs in Vault this way just set "FABIO" env
 | 
			
		||||
variable to anything (ex: "1") before running `acme.sh`:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
export FABIO="1"
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
## 13. Deploy your certificate to Qiniu.com
 | 
			
		||||
 | 
			
		||||
使用 acme.sh 部署到七牛之前,需要确保部署的域名已打开 HTTPS 功能,您可以访问[融合 CDN - 域名管理](https://portal.qiniu.com/cdn/domain) 设置。
 | 
			
		||||
另外还需要先导出 AK/SK 环境变量,您可以访问[密钥管理](https://portal.qiniu.com/user/key) 获得。
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
$ export QINIU_AK="foo"
 | 
			
		||||
$ export QINIU_SK="bar"
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
完成准备工作之后,您就可以通过下面的命令开始部署 SSL 证书到七牛上:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
$ acme.sh --deploy -d example.com --deploy-hook qiniu
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
假如您部署的证书为泛域名证书,您还需要设置 `QINIU_CDN_DOMAIN` 变量,指定实际需要部署的域名:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
$ export QINIU_CDN_DOMAIN="cdn.example.com"
 | 
			
		||||
$ acme.sh --deploy -d example.com --deploy-hook qiniu
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
### English version
 | 
			
		||||
 | 
			
		||||
You should create AccessKey/SecretKey pair in https://portal.qiniu.com/user/key 
 | 
			
		||||
before deploying your certificate, and please ensure you have enabled HTTPS for
 | 
			
		||||
your domain name. You can enable it in https://portal.qiniu.com/cdn/domain.
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
$ export QINIU_AK="foo"
 | 
			
		||||
$ export QINIU_SK="bar"
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
then you can deploy certificate by following command:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
$ acme.sh --deploy -d example.com --deploy-hook qiniu
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
(Optional), If you are using wildcard certificate,
 | 
			
		||||
you may need export `QINIU_CDN_DOMAIN` to specify which domain
 | 
			
		||||
you want to update:
 | 
			
		||||
 | 
			
		||||
```sh
 | 
			
		||||
$ export QINIU_CDN_DOMAIN="cdn.example.com"
 | 
			
		||||
$ acme.sh --deploy -d example.com --deploy-hook qiniu
 | 
			
		||||
```
 | 
			
		||||
							
								
								
									
										26
									
								
								deploy/apache.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										26
									
								
								deploy/apache.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,26 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a script to deploy cert to apache server.
 | 
			
		||||
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
apache_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  _err "Deploy cert to apache server, Not implemented yet"
 | 
			
		||||
  return 1
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										62
									
								
								deploy/cpanel_uapi.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										62
									
								
								deploy/cpanel_uapi.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,62 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
# Here is the script to deploy the cert to your cpanel using the cpanel API.
 | 
			
		||||
# Uses command line uapi.  --user option is needed only if run as root.
 | 
			
		||||
# Returns 0 when success.
 | 
			
		||||
#
 | 
			
		||||
# Please note that I am no longer using Github. If you want to report an issue
 | 
			
		||||
# or contact me, visit https://forum.webseodesigners.com/web-design-seo-and-hosting-f16/
 | 
			
		||||
#
 | 
			
		||||
# Written by Santeri Kannisto <santeri.kannisto@webseodesigners.com>
 | 
			
		||||
# Public domain, 2017-2018
 | 
			
		||||
 | 
			
		||||
#export DEPLOY_CPANEL_USER=myusername
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
 | 
			
		||||
cpanel_uapi_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  if ! _exists uapi; then
 | 
			
		||||
    _err "The command uapi is not found."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  # read cert and key files and urlencode both
 | 
			
		||||
  _cert=$(_url_encode <"$_ccert")
 | 
			
		||||
  _key=$(_url_encode <"$_ckey")
 | 
			
		||||
 | 
			
		||||
  _debug _cert "$_cert"
 | 
			
		||||
  _debug _key "$_key"
 | 
			
		||||
 | 
			
		||||
  if [ "$(id -u)" = 0 ]; then
 | 
			
		||||
    if [ -z "$DEPLOY_CPANEL_USER" ]; then
 | 
			
		||||
      _err "It seems that you are root, please define the target user name: export DEPLOY_CPANEL_USER=username"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    _savedomainconf DEPLOY_CPANEL_USER "$DEPLOY_CPANEL_USER"
 | 
			
		||||
    _response=$(uapi --user="$DEPLOY_CPANEL_USER" SSL install_ssl domain="$_cdomain" cert="$_cert" key="$_key")
 | 
			
		||||
  else
 | 
			
		||||
    _response=$(uapi SSL install_ssl domain="$_cdomain" cert="$_cert" key="$_key")
 | 
			
		||||
  fi
 | 
			
		||||
  error_response="status: 0"
 | 
			
		||||
  if test "${_response#*$error_response}" != "$_response"; then
 | 
			
		||||
    _err "Error in deploying certificate:"
 | 
			
		||||
    _err "$_response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug response "$_response"
 | 
			
		||||
  _info "Certificate successfully deployed"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										26
									
								
								deploy/dovecot.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										26
									
								
								deploy/dovecot.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,26 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a script to deploy cert to dovecot server.
 | 
			
		||||
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
dovecot_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  _err "Not implemented yet"
 | 
			
		||||
  return 1
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										114
									
								
								deploy/exim4.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										114
									
								
								deploy/exim4.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,114 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a script to deploy cert to exim4 server.
 | 
			
		||||
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
#DEPLOY_EXIM4_CONF="/etc/exim/exim.conf"
 | 
			
		||||
#DEPLOY_EXIM4_RELOAD="service exim4 restart"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
exim4_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  _ssl_path="/etc/acme.sh/exim4"
 | 
			
		||||
  if ! mkdir -p "$_ssl_path"; then
 | 
			
		||||
    _err "Can not create folder:$_ssl_path"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Copying key and cert"
 | 
			
		||||
  _real_key="$_ssl_path/exim4.key"
 | 
			
		||||
  if ! cat "$_ckey" >"$_real_key"; then
 | 
			
		||||
    _err "Error: write key file to: $_real_key"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _real_fullchain="$_ssl_path/exim4.pem"
 | 
			
		||||
  if ! cat "$_cfullchain" >"$_real_fullchain"; then
 | 
			
		||||
    _err "Error: write key file to: $_real_fullchain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  DEFAULT_EXIM4_RELOAD="service exim4 restart"
 | 
			
		||||
  _reload="${DEPLOY_EXIM4_RELOAD:-$DEFAULT_EXIM4_RELOAD}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$IS_RENEW" ]; then
 | 
			
		||||
    DEFAULT_EXIM4_CONF="/etc/exim/exim.conf"
 | 
			
		||||
    if [ ! -f "$DEFAULT_EXIM4_CONF" ]; then
 | 
			
		||||
      DEFAULT_EXIM4_CONF="/etc/exim4/exim4.conf.template"
 | 
			
		||||
    fi
 | 
			
		||||
    _exim4_conf="${DEPLOY_EXIM4_CONF:-$DEFAULT_EXIM4_CONF}"
 | 
			
		||||
    _debug _exim4_conf "$_exim4_conf"
 | 
			
		||||
    if [ ! -f "$_exim4_conf" ]; then
 | 
			
		||||
      if [ -z "$DEPLOY_EXIM4_CONF" ]; then
 | 
			
		||||
        _err "exim4 conf is not found, please define DEPLOY_EXIM4_CONF"
 | 
			
		||||
        return 1
 | 
			
		||||
      else
 | 
			
		||||
        _err "It seems that the specified exim4 conf is not valid, please check."
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
    fi
 | 
			
		||||
    if [ ! -w "$_exim4_conf" ]; then
 | 
			
		||||
      _err "The file $_exim4_conf is not writable, please change the permission."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    _backup_conf="$DOMAIN_BACKUP_PATH/exim4.conf.bak"
 | 
			
		||||
    _info "Backup $_exim4_conf to $_backup_conf"
 | 
			
		||||
    cp "$_exim4_conf" "$_backup_conf"
 | 
			
		||||
 | 
			
		||||
    _info "Modify exim4 conf: $_exim4_conf"
 | 
			
		||||
    if _setopt "$_exim4_conf" "tls_certificate" "=" "$_real_fullchain" \
 | 
			
		||||
      && _setopt "$_exim4_conf" "tls_privatekey" "=" "$_real_key"; then
 | 
			
		||||
      _info "Set config success!"
 | 
			
		||||
    else
 | 
			
		||||
      _err "Config exim4 server error, please report bug to us."
 | 
			
		||||
      _info "Restoring exim4 conf"
 | 
			
		||||
      if cat "$_backup_conf" >"$_exim4_conf"; then
 | 
			
		||||
        _info "Restore conf success"
 | 
			
		||||
        eval "$_reload"
 | 
			
		||||
      else
 | 
			
		||||
        _err "Oops, error restore exim4 conf, please report bug to us."
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Run reload: $_reload"
 | 
			
		||||
  if eval "$_reload"; then
 | 
			
		||||
    _info "Reload success!"
 | 
			
		||||
    if [ "$DEPLOY_EXIM4_CONF" ]; then
 | 
			
		||||
      _savedomainconf DEPLOY_EXIM4_CONF "$DEPLOY_EXIM4_CONF"
 | 
			
		||||
    else
 | 
			
		||||
      _cleardomainconf DEPLOY_EXIM4_CONF
 | 
			
		||||
    fi
 | 
			
		||||
    if [ "$DEPLOY_EXIM4_RELOAD" ]; then
 | 
			
		||||
      _savedomainconf DEPLOY_EXIM4_RELOAD "$DEPLOY_EXIM4_RELOAD"
 | 
			
		||||
    else
 | 
			
		||||
      _cleardomainconf DEPLOY_EXIM4_RELOAD
 | 
			
		||||
    fi
 | 
			
		||||
    return 0
 | 
			
		||||
  else
 | 
			
		||||
    _err "Reload error, restoring"
 | 
			
		||||
    if cat "$_backup_conf" >"$_exim4_conf"; then
 | 
			
		||||
      _info "Restore conf success"
 | 
			
		||||
      eval "$_reload"
 | 
			
		||||
    else
 | 
			
		||||
      _err "Oops, error restore exim4 conf, please report bug to us."
 | 
			
		||||
    fi
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										114
									
								
								deploy/fritzbox.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										114
									
								
								deploy/fritzbox.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,114 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a script to deploy cert to an AVM FRITZ!Box router.
 | 
			
		||||
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
#DEPLOY_FRITZBOX_USERNAME="username"
 | 
			
		||||
#DEPLOY_FRITZBOX_PASSWORD="password"
 | 
			
		||||
#DEPLOY_FRITZBOX_URL="https://fritz.box"
 | 
			
		||||
 | 
			
		||||
# Kudos to wikrie at Github for his FRITZ!Box update script:
 | 
			
		||||
# https://gist.github.com/wikrie/f1d5747a714e0a34d0582981f7cb4cfb
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
fritzbox_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  if ! _exists iconv; then
 | 
			
		||||
    if ! _exists perl; then
 | 
			
		||||
      _err "iconv or perl not found"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _fritzbox_username="${DEPLOY_FRITZBOX_USERNAME}"
 | 
			
		||||
  _fritzbox_password="${DEPLOY_FRITZBOX_PASSWORD}"
 | 
			
		||||
  _fritzbox_url="${DEPLOY_FRITZBOX_URL}"
 | 
			
		||||
 | 
			
		||||
  _debug _fritzbox_url "$_fritzbox_url"
 | 
			
		||||
  _debug _fritzbox_username "$_fritzbox_username"
 | 
			
		||||
  _secure_debug _fritzbox_password "$_fritzbox_password"
 | 
			
		||||
  if [ -z "$_fritzbox_username" ]; then
 | 
			
		||||
    _err "FRITZ!Box username is not found, please define DEPLOY_FRITZBOX_USERNAME."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  if [ -z "$_fritzbox_password" ]; then
 | 
			
		||||
    _err "FRITZ!Box password is not found, please define DEPLOY_FRITZBOX_PASSWORD."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  if [ -z "$_fritzbox_url" ]; then
 | 
			
		||||
    _err "FRITZ!Box url is not found, please define DEPLOY_FRITZBOX_URL."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf DEPLOY_FRITZBOX_USERNAME "${_fritzbox_username}"
 | 
			
		||||
  _saveaccountconf DEPLOY_FRITZBOX_PASSWORD "${_fritzbox_password}"
 | 
			
		||||
  _saveaccountconf DEPLOY_FRITZBOX_URL "${_fritzbox_url}"
 | 
			
		||||
 | 
			
		||||
  # Do not check for a valid SSL certificate, because initially the cert is not valid, so it could not install the LE generated certificate
 | 
			
		||||
  export HTTPS_INSECURE=1
 | 
			
		||||
 | 
			
		||||
  _info "Log in to the FRITZ!Box"
 | 
			
		||||
  _fritzbox_challenge="$(_get "${_fritzbox_url}/login_sid.lua" | sed -e 's/^.*<Challenge>//' -e 's/<\/Challenge>.*$//')"
 | 
			
		||||
  if _exists iconv; then
 | 
			
		||||
    _fritzbox_hash="$(printf "%s-%s" "${_fritzbox_challenge}" "${_fritzbox_password}" | iconv -f ASCII -t UTF16LE | md5sum | awk '{print $1}')"
 | 
			
		||||
  else
 | 
			
		||||
    _fritzbox_hash="$(printf "%s-%s" "${_fritzbox_challenge}" "${_fritzbox_password}" | perl -p -e 'use Encode qw/encode/; print encode("UTF-16LE","$_"); $_="";' | md5sum | awk '{print $1}')"
 | 
			
		||||
  fi
 | 
			
		||||
  _fritzbox_sid="$(_get "${_fritzbox_url}/login_sid.lua?sid=0000000000000000&username=${_fritzbox_username}&response=${_fritzbox_challenge}-${_fritzbox_hash}" | sed -e 's/^.*<SID>//' -e 's/<\/SID>.*$//')"
 | 
			
		||||
 | 
			
		||||
  if [ -z "${_fritzbox_sid}" ] || [ "${_fritzbox_sid}" = "0000000000000000" ]; then
 | 
			
		||||
    _err "Logging in to the FRITZ!Box failed. Please check username, password and URL."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Generate form POST request"
 | 
			
		||||
  _post_request="$(_mktemp)"
 | 
			
		||||
  _post_boundary="---------------------------$(date +%Y%m%d%H%M%S)"
 | 
			
		||||
  # _CERTPASSWORD_ is unset because Let's Encrypt certificates don't have a password. But if they ever do, here's the place to use it!
 | 
			
		||||
  _CERTPASSWORD_=
 | 
			
		||||
  {
 | 
			
		||||
    printf -- "--"
 | 
			
		||||
    printf -- "%s\r\n" "${_post_boundary}"
 | 
			
		||||
    printf "Content-Disposition: form-data; name=\"sid\"\r\n\r\n%s\r\n" "${_fritzbox_sid}"
 | 
			
		||||
    printf -- "--"
 | 
			
		||||
    printf -- "%s\r\n" "${_post_boundary}"
 | 
			
		||||
    printf "Content-Disposition: form-data; name=\"BoxCertPassword\"\r\n\r\n%s\r\n" "${_CERTPASSWORD_}"
 | 
			
		||||
    printf -- "--"
 | 
			
		||||
    printf -- "%s\r\n" "${_post_boundary}"
 | 
			
		||||
    printf "Content-Disposition: form-data; name=\"BoxCertImportFile\"; filename=\"BoxCert.pem\"\r\n"
 | 
			
		||||
    printf "Content-Type: application/octet-stream\r\n\r\n"
 | 
			
		||||
    cat "${_ckey}" "${_cfullchain}"
 | 
			
		||||
    printf "\r\n"
 | 
			
		||||
    printf -- "--"
 | 
			
		||||
    printf -- "%s--" "${_post_boundary}"
 | 
			
		||||
  } >>"${_post_request}"
 | 
			
		||||
 | 
			
		||||
  _info "Upload certificate to the FRITZ!Box"
 | 
			
		||||
 | 
			
		||||
  export _H1="Content-type: multipart/form-data boundary=${_post_boundary}"
 | 
			
		||||
  _post "$(cat "${_post_request}")" "${_fritzbox_url}/cgi-bin/firmwarecfg" | grep SSL
 | 
			
		||||
 | 
			
		||||
  retval=$?
 | 
			
		||||
  if [ $retval = 0 ]; then
 | 
			
		||||
    _info "Upload successful"
 | 
			
		||||
  else
 | 
			
		||||
    _err "Upload failed"
 | 
			
		||||
  fi
 | 
			
		||||
  rm "${_post_request}"
 | 
			
		||||
 | 
			
		||||
  return $retval
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										80
									
								
								deploy/gitlab.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										80
									
								
								deploy/gitlab.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,80 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# Script to deploy certificate to a Gitlab hosted page
 | 
			
		||||
 | 
			
		||||
# The following variables exported from environment will be used.
 | 
			
		||||
# If not set then values previously saved in domain.conf file are used.
 | 
			
		||||
 | 
			
		||||
# All the variables are required
 | 
			
		||||
 | 
			
		||||
# export GITLAB_TOKEN="xxxxxxx"
 | 
			
		||||
# export GITLAB_PROJECT_ID=012345
 | 
			
		||||
# export GITLAB_DOMAIN="mydomain.com"
 | 
			
		||||
 | 
			
		||||
gitlab_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$GITLAB_TOKEN" ]; then
 | 
			
		||||
    if [ -z "$Le_Deploy_gitlab_token" ]; then
 | 
			
		||||
      _err "GITLAB_TOKEN not defined."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  else
 | 
			
		||||
    Le_Deploy_gitlab_token="$GITLAB_TOKEN"
 | 
			
		||||
    _savedomainconf Le_Deploy_gitlab_token "$Le_Deploy_gitlab_token"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$GITLAB_PROJECT_ID" ]; then
 | 
			
		||||
    if [ -z "$Le_Deploy_gitlab_project_id" ]; then
 | 
			
		||||
      _err "GITLAB_PROJECT_ID not defined."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  else
 | 
			
		||||
    Le_Deploy_gitlab_project_id="$GITLAB_PROJECT_ID"
 | 
			
		||||
    _savedomainconf Le_Deploy_gitlab_project_id "$Le_Deploy_gitlab_project_id"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$GITLAB_DOMAIN" ]; then
 | 
			
		||||
    if [ -z "$Le_Deploy_gitlab_domain" ]; then
 | 
			
		||||
      _err "GITLAB_DOMAIN not defined."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  else
 | 
			
		||||
    Le_Deploy_gitlab_domain="$GITLAB_DOMAIN"
 | 
			
		||||
    _savedomainconf Le_Deploy_gitlab_domain "$Le_Deploy_gitlab_domain"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  string_fullchain=$(_url_encode <"$_cfullchain")
 | 
			
		||||
  string_key=$(_url_encode <"$_ckey")
 | 
			
		||||
 | 
			
		||||
  body="certificate=$string_fullchain&key=$string_key"
 | 
			
		||||
 | 
			
		||||
  export _H1="PRIVATE-TOKEN: $Le_Deploy_gitlab_token"
 | 
			
		||||
 | 
			
		||||
  gitlab_url="https://gitlab.com/api/v4/projects/$Le_Deploy_gitlab_project_id/pages/domains/$Le_Deploy_gitlab_domain"
 | 
			
		||||
 | 
			
		||||
  _response=$(_post "$body" "$gitlab_url" 0 PUT | _dbase64 "multiline")
 | 
			
		||||
 | 
			
		||||
  error_response="error"
 | 
			
		||||
 | 
			
		||||
  if test "${_response#*$error_response}" != "$_response"; then
 | 
			
		||||
    _err "Error in deploying certificate:"
 | 
			
		||||
    _err "$_response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug response "$_response"
 | 
			
		||||
  _info "Certificate successfully deployed"
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										58
									
								
								deploy/haproxy.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										58
									
								
								deploy/haproxy.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,58 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a script to deploy cert to haproxy server.
 | 
			
		||||
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
haproxy_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  # handle reload preference
 | 
			
		||||
  DEFAULT_HAPROXY_RELOAD="/usr/sbin/service haproxy restart"
 | 
			
		||||
  if [ -z "${DEPLOY_HAPROXY_RELOAD}" ]; then
 | 
			
		||||
    _reload="${DEFAULT_HAPROXY_RELOAD}"
 | 
			
		||||
    _cleardomainconf DEPLOY_HAPROXY_RELOAD
 | 
			
		||||
  else
 | 
			
		||||
    _reload="${DEPLOY_HAPROXY_RELOAD}"
 | 
			
		||||
    _savedomainconf DEPLOY_HAPROXY_RELOAD "$DEPLOY_HAPROXY_RELOAD"
 | 
			
		||||
  fi
 | 
			
		||||
  _savedomainconf DEPLOY_HAPROXY_PEM_PATH "$DEPLOY_HAPROXY_PEM_PATH"
 | 
			
		||||
 | 
			
		||||
  # work out the path where the PEM file should go
 | 
			
		||||
  _pem_path="${DEPLOY_HAPROXY_PEM_PATH}"
 | 
			
		||||
  if [ -z "$_pem_path" ]; then
 | 
			
		||||
    _err "Path to save PEM file not found. Please define DEPLOY_HAPROXY_PEM_PATH."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _pem_full_path="$_pem_path/$_cdomain.pem"
 | 
			
		||||
  _info "Full path to PEM $_pem_full_path"
 | 
			
		||||
 | 
			
		||||
  # combine the key and fullchain into a single pem and install
 | 
			
		||||
  cat "$_cfullchain" "$_ckey" >"$_pem_full_path"
 | 
			
		||||
  chmod 600 "$_pem_full_path"
 | 
			
		||||
  _info "Certificate successfully deployed"
 | 
			
		||||
 | 
			
		||||
  # restart HAProxy
 | 
			
		||||
  _info "Run reload: $_reload"
 | 
			
		||||
  if eval "$_reload"; then
 | 
			
		||||
    _info "Reload success!"
 | 
			
		||||
    return 0
 | 
			
		||||
  else
 | 
			
		||||
    _err "Reload error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										25
									
								
								deploy/keychain.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										25
									
								
								deploy/keychain.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,25 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
keychain_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  /usr/bin/security import "$_ckey" -k "/Library/Keychains/System.keychain"
 | 
			
		||||
  /usr/bin/security import "$_ccert" -k "/Library/Keychains/System.keychain"
 | 
			
		||||
  /usr/bin/security import "$_cca" -k "/Library/Keychains/System.keychain"
 | 
			
		||||
  /usr/bin/security import "$_cfullchain" -k "/Library/Keychains/System.keychain"
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										77
									
								
								deploy/kong.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										77
									
								
								deploy/kong.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,77 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
# If certificate already exist it will update only cert and key not touching other parameter
 | 
			
		||||
# If certificate  doesn't exist it will only upload cert and key and not set other parameter
 | 
			
		||||
# Note that we deploy full chain
 | 
			
		||||
# Written by Geoffroi Genot <ggenot@voxbone.com>
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
kong_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
  _info "Deploying certificate on Kong instance"
 | 
			
		||||
  if [ -z "$KONG_URL" ]; then
 | 
			
		||||
    _debug "KONG_URL Not set, using default http://localhost:8001"
 | 
			
		||||
    KONG_URL="http://localhost:8001"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  #Get ssl_uuid linked to the domain
 | 
			
		||||
  ssl_uuid=$(_get "$KONG_URL/certificates/$_cdomain" | _normalizeJson | _egrep_o '[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}')
 | 
			
		||||
  if [ -z "$ssl_uuid" ]; then
 | 
			
		||||
    _debug "Unable to get Kong ssl_uuid for domain $_cdomain"
 | 
			
		||||
    _debug "Make sure that KONG_URL is correctly configured"
 | 
			
		||||
    _debug "Make sure that a Kong certificate match the sni"
 | 
			
		||||
    _debug "Kong url: $KONG_URL"
 | 
			
		||||
    _info "No existing certificate, creating..."
 | 
			
		||||
    #return 1
 | 
			
		||||
  fi
 | 
			
		||||
  #Save kong url if it's succesful (First run case)
 | 
			
		||||
  _saveaccountconf KONG_URL "$KONG_URL"
 | 
			
		||||
  #Generate DEIM
 | 
			
		||||
  delim="-----MultipartDelimiter$(date "+%s%N")"
 | 
			
		||||
  nl="\015\012"
 | 
			
		||||
  #Set Header
 | 
			
		||||
  _H1="Content-Type: multipart/form-data; boundary=$delim"
 | 
			
		||||
  #Generate data for request (Multipart/form-data with mixed content)
 | 
			
		||||
  if [ -z "$ssl_uuid" ]; then
 | 
			
		||||
    #set sni to domain
 | 
			
		||||
    content="--$delim${nl}Content-Disposition: form-data; name=\"snis\"${nl}${nl}$_cdomain"
 | 
			
		||||
  fi
 | 
			
		||||
  #add key
 | 
			
		||||
  content="$content${nl}--$delim${nl}Content-Disposition: form-data; name=\"key\"; filename=\"$(basename "$_ckey")\"${nl}Content-Type: application/octet-stream${nl}${nl}$(cat "$_ckey")"
 | 
			
		||||
  #Add cert
 | 
			
		||||
  content="$content${nl}--$delim${nl}Content-Disposition: form-data; name=\"cert\"; filename=\"$(basename "$_cfullchain")\"${nl}Content-Type: application/octet-stream${nl}${nl}$(cat "$_cfullchain")"
 | 
			
		||||
  #Close multipart
 | 
			
		||||
  content="$content${nl}--$delim--${nl}"
 | 
			
		||||
  #Convert CRLF
 | 
			
		||||
  content=$(printf %b "$content")
 | 
			
		||||
  #DEBUG
 | 
			
		||||
  _debug header "$_H1"
 | 
			
		||||
  _debug content "$content"
 | 
			
		||||
  #Check if sslcreated (if not => POST else => PATCH)
 | 
			
		||||
 | 
			
		||||
  if [ -z "$ssl_uuid" ]; then
 | 
			
		||||
    #Post certificate to Kong
 | 
			
		||||
    response=$(_post "$content" "$KONG_URL/certificates" "" "POST")
 | 
			
		||||
  else
 | 
			
		||||
    #patch
 | 
			
		||||
    response=$(_post "$content" "$KONG_URL/certificates/$ssl_uuid" "" "PATCH")
 | 
			
		||||
  fi
 | 
			
		||||
  if ! [ "$(echo "$response" | _egrep_o "created_at")" = "created_at" ]; then
 | 
			
		||||
    _err "An error occurred with cert upload. Check response:"
 | 
			
		||||
    _err "$response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
  _info "Certificate successfully deployed"
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										28
									
								
								deploy/myapi.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										28
									
								
								deploy/myapi.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,28 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a sample custom api script.
 | 
			
		||||
#This file name is "myapi.sh"
 | 
			
		||||
#So, here must be a method   myapi_deploy()
 | 
			
		||||
#Which will be called by acme.sh to deploy the cert
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
myapi_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  _err "Not implemented yet"
 | 
			
		||||
  return 1
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										26
									
								
								deploy/mysqld.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										26
									
								
								deploy/mysqld.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,26 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a script to deploy cert to mysqld server.
 | 
			
		||||
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
mysqld_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  _err "deploy cert to mysqld server, Not implemented yet"
 | 
			
		||||
  return 1
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										26
									
								
								deploy/nginx.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										26
									
								
								deploy/nginx.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,26 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a script to deploy cert to nginx server.
 | 
			
		||||
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
nginx_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  _err "deploy cert to nginx server, Not implemented yet"
 | 
			
		||||
  return 1
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										26
									
								
								deploy/opensshd.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										26
									
								
								deploy/opensshd.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,26 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a script to deploy cert to opensshd server.
 | 
			
		||||
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
opensshd_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  _err "deploy cert to opensshd server, Not implemented yet"
 | 
			
		||||
  return 1
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										26
									
								
								deploy/pureftpd.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										26
									
								
								deploy/pureftpd.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,26 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a script to deploy cert to pureftpd server.
 | 
			
		||||
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
pureftpd_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  _err "deploy cert to pureftpd server, Not implemented yet"
 | 
			
		||||
  return 1
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										92
									
								
								deploy/qiniu.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										92
									
								
								deploy/qiniu.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,92 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# Script to create certificate to qiniu.com 
 | 
			
		||||
#
 | 
			
		||||
# This deployment required following variables
 | 
			
		||||
# export QINIU_AK="QINIUACCESSKEY"
 | 
			
		||||
# export QINIU_SK="QINIUSECRETKEY"
 | 
			
		||||
# export QINIU_CDN_DOMAIN="cdn.example.com"
 | 
			
		||||
 | 
			
		||||
QINIU_API_BASE="https://api.qiniu.com"
 | 
			
		||||
 | 
			
		||||
qiniu_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$QINIU_AK" ]; then
 | 
			
		||||
    _err "QINIU_AK is not defined."
 | 
			
		||||
    return 1
 | 
			
		||||
  else
 | 
			
		||||
    _savedomainconf QINIU_AK "$QINIU_AK"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$QINIU_SK" ]; then
 | 
			
		||||
    _err "QINIU_SK is not defined."
 | 
			
		||||
    return 1
 | 
			
		||||
  else
 | 
			
		||||
    _savedomainconf QINIU_SK "$QINIU_SK"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$QINIU_CDN_DOMAIN" ]; then
 | 
			
		||||
    _savedomainconf QINIU_CDN_DOMAIN "$QINIU_CDN_DOMAIN"
 | 
			
		||||
  else
 | 
			
		||||
    QINIU_CDN_DOMAIN="$_cdomain"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  ## upload certificate
 | 
			
		||||
  string_fullchain=$(sed 's/$/\\n/' "$_cfullchain" | tr -d '\n')
 | 
			
		||||
  string_key=$(sed 's/$/\\n/' "$_ckey" | tr -d '\n')
 | 
			
		||||
 | 
			
		||||
  sslcert_path="/sslcert"
 | 
			
		||||
  sslcerl_body="{\"name\":\"$_cdomain\",\"common_name\":\"$QINIU_CDN_DOMAIN\",\"ca\":\"$string_fullchain\",\"pri\":\"$string_key\"}"
 | 
			
		||||
  sslcert_access_token="$(_make_access_token "$sslcert_path")"
 | 
			
		||||
  _debug sslcert_access_token "$sslcert_access_token"
 | 
			
		||||
  export _H1="Authorization: QBox $sslcert_access_token"
 | 
			
		||||
  sslcert_response=$(_post "$sslcerl_body" "$QINIU_API_BASE$sslcert_path" 0 "POST" "application/json" | _dbase64 "multiline")
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$sslcert_response" "certID"; then
 | 
			
		||||
    _err "Error in creating certificate:"
 | 
			
		||||
    _err "$sslcert_response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug sslcert_response "$sslcert_response"
 | 
			
		||||
  _info "Certificate successfully uploaded, updating domain $_cdomain"
 | 
			
		||||
 | 
			
		||||
  ## extract certId
 | 
			
		||||
  _certId="$(printf "%s" "$sslcert_response" | _normalizeJson | _egrep_o "certID\": *\"[^\"]*\"" | cut -d : -f 2)"
 | 
			
		||||
  _debug certId "$_certId"
 | 
			
		||||
 | 
			
		||||
  ## update domain ssl config
 | 
			
		||||
  update_path="/domain/$QINIU_CDN_DOMAIN/httpsconf"
 | 
			
		||||
  update_body="{\"certid\":$_certId,\"forceHttps\":false}"
 | 
			
		||||
  update_access_token="$(_make_access_token "$update_path")"
 | 
			
		||||
  _debug update_access_token "$update_access_token"
 | 
			
		||||
  export _H1="Authorization: QBox $update_access_token"
 | 
			
		||||
  update_response=$(_post "$update_body" "$QINIU_API_BASE$update_path" 0 "PUT" "application/json" | _dbase64 "multiline")
 | 
			
		||||
 | 
			
		||||
  if _contains "$update_response" "error"; then
 | 
			
		||||
    _err "Error in updating domain httpsconf:"
 | 
			
		||||
    _err "$update_response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug update_response "$update_response"
 | 
			
		||||
  _info "Certificate successfully deployed"
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_make_access_token() {
 | 
			
		||||
  _token="$(printf "%s\n" "$1" | _hmac "sha1" "$(printf "%s" "$QINIU_SK" | _hex_dump | tr -d " ")" | _base64)"
 | 
			
		||||
  echo "$QINIU_AK:$_token"
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										205
									
								
								deploy/ssh.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										205
									
								
								deploy/ssh.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,205 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# Script to deploy certificates to remote server by SSH
 | 
			
		||||
# Note that SSH must be able to login to remote host without a password...
 | 
			
		||||
# SSH Keys must have been exchanged with the remote host.  Validate and
 | 
			
		||||
# test that you can login to USER@SERVER from the host running acme.sh before
 | 
			
		||||
# using this script.
 | 
			
		||||
#
 | 
			
		||||
# The following variables exported from environment will be used.
 | 
			
		||||
# If not set then values previously saved in domain.conf file are used.
 | 
			
		||||
#
 | 
			
		||||
# Only a username is required.  All others are optional.
 | 
			
		||||
#
 | 
			
		||||
# The following examples are for QNAP NAS running QTS 4.2
 | 
			
		||||
# export DEPLOY_SSH_CMD=""  # defaults to ssh
 | 
			
		||||
# export DEPLOY_SSH_USER="admin"  # required
 | 
			
		||||
# export DEPLOY_SSH_SERVER="qnap"  # defaults to domain name
 | 
			
		||||
# export DEPLOY_SSH_KEYFILE="/etc/stunnel/stunnel.pem"
 | 
			
		||||
# export DEPLOY_SSH_CERTFILE="/etc/stunnel/stunnel.pem"
 | 
			
		||||
# export DEPLOY_SSH_CAFILE="/etc/stunnel/uca.pem"
 | 
			
		||||
# export DEPLOY_SSH_FULLCHAIN=""
 | 
			
		||||
# export DEPLOY_SSH_REMOTE_CMD="/etc/init.d/stunnel.sh restart"
 | 
			
		||||
# export DEPLOY_SSH_BACKUP=""  # yes or no, default to yes
 | 
			
		||||
#
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
ssh_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
  _cmdstr=""
 | 
			
		||||
  _homedir='~'
 | 
			
		||||
  _backupprefix="$_homedir/.acme_ssh_deploy/$_cdomain-backup"
 | 
			
		||||
  _backupdir="$_backupprefix-$(_utc_date | tr ' ' '-')"
 | 
			
		||||
 | 
			
		||||
  if [ -f "$DOMAIN_CONF" ]; then
 | 
			
		||||
    # shellcheck disable=SC1090
 | 
			
		||||
    . "$DOMAIN_CONF"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  # USER is required to login by SSH to remote host.
 | 
			
		||||
  if [ -z "$DEPLOY_SSH_USER" ]; then
 | 
			
		||||
    if [ -z "$Le_Deploy_ssh_user" ]; then
 | 
			
		||||
      _err "DEPLOY_SSH_USER not defined."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  else
 | 
			
		||||
    Le_Deploy_ssh_user="$DEPLOY_SSH_USER"
 | 
			
		||||
    _savedomainconf Le_Deploy_ssh_user "$Le_Deploy_ssh_user"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # SERVER is optional. If not provided then use _cdomain
 | 
			
		||||
  if [ -n "$DEPLOY_SSH_SERVER" ]; then
 | 
			
		||||
    Le_Deploy_ssh_server="$DEPLOY_SSH_SERVER"
 | 
			
		||||
    _savedomainconf Le_Deploy_ssh_server "$Le_Deploy_ssh_server"
 | 
			
		||||
  elif [ -z "$Le_Deploy_ssh_server" ]; then
 | 
			
		||||
    Le_Deploy_ssh_server="$_cdomain"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # CMD is optional. If not provided then use ssh
 | 
			
		||||
  if [ -n "$DEPLOY_SSH_CMD" ]; then
 | 
			
		||||
    Le_Deploy_ssh_cmd="$DEPLOY_SSH_CMD"
 | 
			
		||||
    _savedomainconf Le_Deploy_ssh_cmd "$Le_Deploy_ssh_cmd"
 | 
			
		||||
  elif [ -z "$Le_Deploy_ssh_cmd" ]; then
 | 
			
		||||
    Le_Deploy_ssh_cmd="ssh"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # BACKUP is optional. If not provided then default to yes
 | 
			
		||||
  if [ "$DEPLOY_SSH_BACKUP" = "no" ]; then
 | 
			
		||||
    Le_Deploy_ssh_backup="no"
 | 
			
		||||
  elif [ -z "$Le_Deploy_ssh_backup" ]; then
 | 
			
		||||
    Le_Deploy_ssh_backup="yes"
 | 
			
		||||
  fi
 | 
			
		||||
  _savedomainconf Le_Deploy_ssh_backup "$Le_Deploy_ssh_backup"
 | 
			
		||||
 | 
			
		||||
  _info "Deploy certificates to remote server $Le_Deploy_ssh_user@$Le_Deploy_ssh_server"
 | 
			
		||||
 | 
			
		||||
  # KEYFILE is optional.
 | 
			
		||||
  # If provided then private key will be copied to provided filename.
 | 
			
		||||
  if [ -n "$DEPLOY_SSH_KEYFILE" ]; then
 | 
			
		||||
    Le_Deploy_ssh_keyfile="$DEPLOY_SSH_KEYFILE"
 | 
			
		||||
    _savedomainconf Le_Deploy_ssh_keyfile "$Le_Deploy_ssh_keyfile"
 | 
			
		||||
  fi
 | 
			
		||||
  if [ -n "$Le_Deploy_ssh_keyfile" ]; then
 | 
			
		||||
    if [ "$Le_Deploy_ssh_backup" = "yes" ]; then
 | 
			
		||||
      # backup file we are about to overwrite.
 | 
			
		||||
      _cmdstr="$_cmdstr cp $Le_Deploy_ssh_keyfile $_backupdir >/dev/null;"
 | 
			
		||||
    fi
 | 
			
		||||
    # copy new certificate into file.
 | 
			
		||||
    _cmdstr="$_cmdstr echo \"$(cat "$_ckey")\" > $Le_Deploy_ssh_keyfile;"
 | 
			
		||||
    _info "will copy private key to remote file $Le_Deploy_ssh_keyfile"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # CERTFILE is optional.
 | 
			
		||||
  # If provided then certificate will be copied or appended to provided filename.
 | 
			
		||||
  if [ -n "$DEPLOY_SSH_CERTFILE" ]; then
 | 
			
		||||
    Le_Deploy_ssh_certfile="$DEPLOY_SSH_CERTFILE"
 | 
			
		||||
    _savedomainconf Le_Deploy_ssh_certfile "$Le_Deploy_ssh_certfile"
 | 
			
		||||
  fi
 | 
			
		||||
  if [ -n "$Le_Deploy_ssh_certfile" ]; then
 | 
			
		||||
    _pipe=">"
 | 
			
		||||
    if [ "$Le_Deploy_ssh_certfile" = "$Le_Deploy_ssh_keyfile" ]; then
 | 
			
		||||
      # if filename is same as previous file then append.
 | 
			
		||||
      _pipe=">>"
 | 
			
		||||
    elif [ "$Le_Deploy_ssh_backup" = "yes" ]; then
 | 
			
		||||
      # backup file we are about to overwrite.
 | 
			
		||||
      _cmdstr="$_cmdstr cp $Le_Deploy_ssh_certfile $_backupdir >/dev/null;"
 | 
			
		||||
    fi
 | 
			
		||||
    # copy new certificate into file.
 | 
			
		||||
    _cmdstr="$_cmdstr echo \"$(cat "$_ccert")\" $_pipe $Le_Deploy_ssh_certfile;"
 | 
			
		||||
    _info "will copy certificate to remote file $Le_Deploy_ssh_certfile"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # CAFILE is optional.
 | 
			
		||||
  # If provided then CA intermediate certificate will be copied or appended to provided filename.
 | 
			
		||||
  if [ -n "$DEPLOY_SSH_CAFILE" ]; then
 | 
			
		||||
    Le_Deploy_ssh_cafile="$DEPLOY_SSH_CAFILE"
 | 
			
		||||
    _savedomainconf Le_Deploy_ssh_cafile "$Le_Deploy_ssh_cafile"
 | 
			
		||||
  fi
 | 
			
		||||
  if [ -n "$Le_Deploy_ssh_cafile" ]; then
 | 
			
		||||
    _pipe=">"
 | 
			
		||||
    if [ "$Le_Deploy_ssh_cafile" = "$Le_Deploy_ssh_keyfile" ] \
 | 
			
		||||
      || [ "$Le_Deploy_ssh_cafile" = "$Le_Deploy_ssh_certfile" ]; then
 | 
			
		||||
      # if filename is same as previous file then append.
 | 
			
		||||
      _pipe=">>"
 | 
			
		||||
    elif [ "$Le_Deploy_ssh_backup" = "yes" ]; then
 | 
			
		||||
      # backup file we are about to overwrite.
 | 
			
		||||
      _cmdstr="$_cmdstr cp $Le_Deploy_ssh_cafile $_backupdir >/dev/null;"
 | 
			
		||||
    fi
 | 
			
		||||
    # copy new certificate into file.
 | 
			
		||||
    _cmdstr="$_cmdstr echo \"$(cat "$_cca")\" $_pipe $Le_Deploy_ssh_cafile;"
 | 
			
		||||
    _info "will copy CA file to remote file $Le_Deploy_ssh_cafile"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # FULLCHAIN is optional.
 | 
			
		||||
  # If provided then fullchain certificate will be copied or appended to provided filename.
 | 
			
		||||
  if [ -n "$DEPLOY_SSH_FULLCHAIN" ]; then
 | 
			
		||||
    Le_Deploy_ssh_fullchain="$DEPLOY_SSH_FULLCHAIN"
 | 
			
		||||
    _savedomainconf Le_Deploy_ssh_fullchain "$Le_Deploy_ssh_fullchain"
 | 
			
		||||
  fi
 | 
			
		||||
  if [ -n "$Le_Deploy_ssh_fullchain" ]; then
 | 
			
		||||
    _pipe=">"
 | 
			
		||||
    if [ "$Le_Deploy_ssh_fullchain" = "$Le_Deploy_ssh_keyfile" ] \
 | 
			
		||||
      || [ "$Le_Deploy_ssh_fullchain" = "$Le_Deploy_ssh_certfile" ] \
 | 
			
		||||
      || [ "$Le_Deploy_ssh_fullchain" = "$Le_Deploy_ssh_cafile" ]; then
 | 
			
		||||
      # if filename is same as previous file then append.
 | 
			
		||||
      _pipe=">>"
 | 
			
		||||
    elif [ "$Le_Deploy_ssh_backup" = "yes" ]; then
 | 
			
		||||
      # backup file we are about to overwrite.
 | 
			
		||||
      _cmdstr="$_cmdstr cp $Le_Deploy_ssh_fullchain $_backupdir >/dev/null;"
 | 
			
		||||
    fi
 | 
			
		||||
    # copy new certificate into file.
 | 
			
		||||
    _cmdstr="$_cmdstr echo \"$(cat "$_cfullchain")\" $_pipe $Le_Deploy_ssh_fullchain;"
 | 
			
		||||
    _info "will copy fullchain to remote file $Le_Deploy_ssh_fullchain"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # REMOTE_CMD is optional.
 | 
			
		||||
  # If provided then this command will be executed on remote host.
 | 
			
		||||
  if [ -n "$DEPLOY_SSH_REMOTE_CMD" ]; then
 | 
			
		||||
    Le_Deploy_ssh_remote_cmd="$DEPLOY_SSH_REMOTE_CMD"
 | 
			
		||||
    _savedomainconf Le_Deploy_ssh_remote_cmd "$Le_Deploy_ssh_remote_cmd"
 | 
			
		||||
  fi
 | 
			
		||||
  if [ -n "$Le_Deploy_ssh_remote_cmd" ]; then
 | 
			
		||||
    _cmdstr="$_cmdstr $Le_Deploy_ssh_remote_cmd;"
 | 
			
		||||
    _info "Will execute remote command $Le_Deploy_ssh_remote_cmd"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$_cmdstr" ]; then
 | 
			
		||||
    _err "No remote commands to excute. Failed to deploy certificates to remote server"
 | 
			
		||||
    return 1
 | 
			
		||||
  elif [ "$Le_Deploy_ssh_backup" = "yes" ]; then
 | 
			
		||||
    # run cleanup on the backup directory, erase all older
 | 
			
		||||
    # than 180 days (15552000 seconds).
 | 
			
		||||
    _cmdstr="{ now=\"\$(date -u +%s)\"; for fn in $_backupprefix*; \
 | 
			
		||||
do if [ -d \"\$fn\" ] && [ \"\$(expr \$now - \$(date -ur \$fn +%s) )\" -ge \"15552000\" ]; \
 | 
			
		||||
then rm -rf \"\$fn\"; echo \"Backup \$fn deleted as older than 180 days\"; fi; done; }; $_cmdstr"
 | 
			
		||||
    # Alternate version of above... _cmdstr="find $_backupprefix* -type d -mtime +180 2>/dev/null | xargs rm -rf; $_cmdstr"
 | 
			
		||||
    # Create our backup directory for overwritten cert files.
 | 
			
		||||
    _cmdstr="mkdir -p $_backupdir; $_cmdstr"
 | 
			
		||||
    _info "Backup of old certificate files will be placed in remote directory $_backupdir"
 | 
			
		||||
    _info "Backup directories erased after 180 days."
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _secure_debug "Remote commands to execute: " "$_cmdstr"
 | 
			
		||||
  _info "Submitting sequence of commands to remote server by ssh"
 | 
			
		||||
  # quotations in bash cmd below intended.  Squash travis spellcheck error
 | 
			
		||||
  # shellcheck disable=SC2029
 | 
			
		||||
  $Le_Deploy_ssh_cmd -T "$Le_Deploy_ssh_user@$Le_Deploy_ssh_server" sh -c "'$_cmdstr'"
 | 
			
		||||
  _ret="$?"
 | 
			
		||||
 | 
			
		||||
  if [ "$_ret" != "0" ]; then
 | 
			
		||||
    _err "Error code $_ret returned from $Le_Deploy_ssh_cmd"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return $_ret
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										55
									
								
								deploy/strongswan.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										55
									
								
								deploy/strongswan.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,55 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a sample custom api script.
 | 
			
		||||
#This file name is "myapi.sh"
 | 
			
		||||
#So, here must be a method   myapi_deploy()
 | 
			
		||||
#Which will be called by acme.sh to deploy the cert
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
strongswan_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _info "Using strongswan"
 | 
			
		||||
 | 
			
		||||
  if [ -x /usr/sbin/ipsec ]; then
 | 
			
		||||
    _ipsec=/usr/sbin/ipsec
 | 
			
		||||
  elif [ -x /usr/sbin/strongswan ]; then
 | 
			
		||||
    _ipsec=/usr/sbin/strongswan
 | 
			
		||||
  elif [ -x /usr/local/sbin/ipsec ]; then
 | 
			
		||||
    _ipsec=/usr/local/sbin/ipsec
 | 
			
		||||
  else
 | 
			
		||||
    _err "no strongswan or ipsec command is detected"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info _ipsec "$_ipsec"
 | 
			
		||||
 | 
			
		||||
  _confdir=$($_ipsec --confdir)
 | 
			
		||||
  if [ $? -ne 0 ] || [ -z "$_confdir" ]; then
 | 
			
		||||
    _err "no strongswan --confdir is detected"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info _confdir "$_confdir"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  cat "$_ckey" >"${_confdir}/ipsec.d/private/$(basename "$_ckey")"
 | 
			
		||||
  cat "$_ccert" >"${_confdir}/ipsec.d/certs/$(basename "$_ccert")"
 | 
			
		||||
  cat "$_cca" >"${_confdir}/ipsec.d/cacerts/$(basename "$_cca")"
 | 
			
		||||
  cat "$_cfullchain" >"${_confdir}/ipsec.d/cacerts/$(basename "$_cfullchain")"
 | 
			
		||||
 | 
			
		||||
  $_ipsec reload
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										100
									
								
								deploy/unifi.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										100
									
								
								deploy/unifi.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,100 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a script to deploy cert to unifi server.
 | 
			
		||||
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
#DEPLOY_UNIFI_KEYSTORE="/usr/lib/unifi/data/keystore"
 | 
			
		||||
#DEPLOY_UNIFI_KEYPASS="aircontrolenterprise"
 | 
			
		||||
#DEPLOY_UNIFI_RELOAD="service unifi restart"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
unifi_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  if ! _exists keytool; then
 | 
			
		||||
    _err "keytool not found"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  DEFAULT_UNIFI_KEYSTORE="/usr/lib/unifi/data/keystore"
 | 
			
		||||
  _unifi_keystore="${DEPLOY_UNIFI_KEYSTORE:-$DEFAULT_UNIFI_KEYSTORE}"
 | 
			
		||||
  DEFAULT_UNIFI_KEYPASS="aircontrolenterprise"
 | 
			
		||||
  _unifi_keypass="${DEPLOY_UNIFI_KEYPASS:-$DEFAULT_UNIFI_KEYPASS}"
 | 
			
		||||
  DEFAULT_UNIFI_RELOAD="service unifi restart"
 | 
			
		||||
  _reload="${DEPLOY_UNIFI_RELOAD:-$DEFAULT_UNIFI_RELOAD}"
 | 
			
		||||
 | 
			
		||||
  _debug _unifi_keystore "$_unifi_keystore"
 | 
			
		||||
  if [ ! -f "$_unifi_keystore" ]; then
 | 
			
		||||
    if [ -z "$DEPLOY_UNIFI_KEYSTORE" ]; then
 | 
			
		||||
      _err "unifi keystore is not found, please define DEPLOY_UNIFI_KEYSTORE"
 | 
			
		||||
      return 1
 | 
			
		||||
    else
 | 
			
		||||
      _err "It seems that the specified unifi keystore is not valid, please check."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  if [ ! -w "$_unifi_keystore" ]; then
 | 
			
		||||
    _err "The file $_unifi_keystore is not writable, please change the permission."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Generate import pkcs12"
 | 
			
		||||
  _import_pkcs12="$(_mktemp)"
 | 
			
		||||
  _toPkcs "$_import_pkcs12" "$_ckey" "$_ccert" "$_cca" "$_unifi_keypass" unifi root
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "Oops, error creating import pkcs12, please report bug to us."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Modify unifi keystore: $_unifi_keystore"
 | 
			
		||||
  if keytool -importkeystore \
 | 
			
		||||
    -deststorepass "$_unifi_keypass" -destkeypass "$_unifi_keypass" -destkeystore "$_unifi_keystore" \
 | 
			
		||||
    -srckeystore "$_import_pkcs12" -srcstoretype PKCS12 -srcstorepass "$_unifi_keypass" \
 | 
			
		||||
    -alias unifi -noprompt; then
 | 
			
		||||
    _info "Import keystore success!"
 | 
			
		||||
    rm "$_import_pkcs12"
 | 
			
		||||
  else
 | 
			
		||||
    _err "Import unifi keystore error, please report bug to us."
 | 
			
		||||
    rm "$_import_pkcs12"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Run reload: $_reload"
 | 
			
		||||
  if eval "$_reload"; then
 | 
			
		||||
    _info "Reload success!"
 | 
			
		||||
    if [ "$DEPLOY_UNIFI_KEYSTORE" ]; then
 | 
			
		||||
      _savedomainconf DEPLOY_UNIFI_KEYSTORE "$DEPLOY_UNIFI_KEYSTORE"
 | 
			
		||||
    else
 | 
			
		||||
      _cleardomainconf DEPLOY_UNIFI_KEYSTORE
 | 
			
		||||
    fi
 | 
			
		||||
    if [ "$DEPLOY_UNIFI_KEYPASS" ]; then
 | 
			
		||||
      _savedomainconf DEPLOY_UNIFI_KEYPASS "$DEPLOY_UNIFI_KEYPASS"
 | 
			
		||||
    else
 | 
			
		||||
      _cleardomainconf DEPLOY_UNIFI_KEYPASS
 | 
			
		||||
    fi
 | 
			
		||||
    if [ "$DEPLOY_UNIFI_RELOAD" ]; then
 | 
			
		||||
      _savedomainconf DEPLOY_UNIFI_RELOAD "$DEPLOY_UNIFI_RELOAD"
 | 
			
		||||
    else
 | 
			
		||||
      _cleardomainconf DEPLOY_UNIFI_RELOAD
 | 
			
		||||
    fi
 | 
			
		||||
    return 0
 | 
			
		||||
  else
 | 
			
		||||
    _err "Reload error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										61
									
								
								deploy/vault_cli.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										61
									
								
								deploy/vault_cli.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,61 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# Here is a script to deploy cert to hashicorp vault
 | 
			
		||||
# (https://www.vaultproject.io/)
 | 
			
		||||
# 
 | 
			
		||||
# it requires the vault binary to be available in PATH, and the following
 | 
			
		||||
# environment variables:
 | 
			
		||||
# 
 | 
			
		||||
# VAULT_PREFIX - this contains the prefix path in vault
 | 
			
		||||
# VAULT_ADDR - vault requires this to find your vault server
 | 
			
		||||
#
 | 
			
		||||
# additionally, you need to ensure that VAULT_TOKEN is avialable or
 | 
			
		||||
# `vault auth` has applied the appropriate authorization for the vault binary
 | 
			
		||||
# to access the vault server
 | 
			
		||||
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
vault_cli_deploy() {
 | 
			
		||||
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  # validate required env vars
 | 
			
		||||
  if [ -z "$VAULT_PREFIX" ]; then
 | 
			
		||||
    _err "VAULT_PREFIX needs to be defined (contains prefix path in vault)"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$VAULT_ADDR" ]; then
 | 
			
		||||
    _err "VAULT_ADDR needs to be defined (contains vault connection address)"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  VAULT_CMD=$(which vault)
 | 
			
		||||
  if [ ! $? ]; then
 | 
			
		||||
    _err "cannot find vault binary!"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -n "$FABIO" ]; then
 | 
			
		||||
    $VAULT_CMD write "${VAULT_PREFIX}/${_cdomain}" cert=@"$_cfullchain" key=@"$_ckey" || return 1
 | 
			
		||||
  else
 | 
			
		||||
    $VAULT_CMD write "${VAULT_PREFIX}/${_cdomain}/cert.pem" value=@"$_ccert" || return 1
 | 
			
		||||
    $VAULT_CMD write "${VAULT_PREFIX}/${_cdomain}/cert.key" value=@"$_ckey" || return 1
 | 
			
		||||
    $VAULT_CMD write "${VAULT_PREFIX}/${_cdomain}/chain.pem" value=@"$_cca" || return 1
 | 
			
		||||
    $VAULT_CMD write "${VAULT_PREFIX}/${_cdomain}/fullchain.pem" value=@"$_cfullchain" || return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										110
									
								
								deploy/vsftpd.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										110
									
								
								deploy/vsftpd.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,110 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a script to deploy cert to vsftpd server.
 | 
			
		||||
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
#DEPLOY_VSFTPD_CONF="/etc/vsftpd.conf"
 | 
			
		||||
#DEPLOY_VSFTPD_RELOAD="service vsftpd restart"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#domain keyfile certfile cafile fullchain
 | 
			
		||||
vsftpd_deploy() {
 | 
			
		||||
  _cdomain="$1"
 | 
			
		||||
  _ckey="$2"
 | 
			
		||||
  _ccert="$3"
 | 
			
		||||
  _cca="$4"
 | 
			
		||||
  _cfullchain="$5"
 | 
			
		||||
 | 
			
		||||
  _debug _cdomain "$_cdomain"
 | 
			
		||||
  _debug _ckey "$_ckey"
 | 
			
		||||
  _debug _ccert "$_ccert"
 | 
			
		||||
  _debug _cca "$_cca"
 | 
			
		||||
  _debug _cfullchain "$_cfullchain"
 | 
			
		||||
 | 
			
		||||
  _ssl_path="/etc/acme.sh/vsftpd"
 | 
			
		||||
  if ! mkdir -p "$_ssl_path"; then
 | 
			
		||||
    _err "Can not create folder:$_ssl_path"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Copying key and cert"
 | 
			
		||||
  _real_key="$_ssl_path/vsftpd.key"
 | 
			
		||||
  if ! cat "$_ckey" >"$_real_key"; then
 | 
			
		||||
    _err "Error: write key file to: $_real_key"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _real_fullchain="$_ssl_path/vsftpd.chain.pem"
 | 
			
		||||
  if ! cat "$_cfullchain" >"$_real_fullchain"; then
 | 
			
		||||
    _err "Error: write key file to: $_real_fullchain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  DEFAULT_VSFTPD_RELOAD="service vsftpd restart"
 | 
			
		||||
  _reload="${DEPLOY_VSFTPD_RELOAD:-$DEFAULT_VSFTPD_RELOAD}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$IS_RENEW" ]; then
 | 
			
		||||
    DEFAULT_VSFTPD_CONF="/etc/vsftpd.conf"
 | 
			
		||||
    _vsftpd_conf="${DEPLOY_VSFTPD_CONF:-$DEFAULT_VSFTPD_CONF}"
 | 
			
		||||
    if [ ! -f "$_vsftpd_conf" ]; then
 | 
			
		||||
      if [ -z "$DEPLOY_VSFTPD_CONF" ]; then
 | 
			
		||||
        _err "vsftpd conf is not found, please define DEPLOY_VSFTPD_CONF"
 | 
			
		||||
        return 1
 | 
			
		||||
      else
 | 
			
		||||
        _err "It seems that the specified vsftpd conf is not valid, please check."
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
    fi
 | 
			
		||||
    if [ ! -w "$_vsftpd_conf" ]; then
 | 
			
		||||
      _err "The file $_vsftpd_conf is not writable, please change the permission."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    _backup_conf="$DOMAIN_BACKUP_PATH/vsftpd.conf.bak"
 | 
			
		||||
    _info "Backup $_vsftpd_conf to $_backup_conf"
 | 
			
		||||
    cp "$_vsftpd_conf" "$_backup_conf"
 | 
			
		||||
 | 
			
		||||
    _info "Modify vsftpd conf: $_vsftpd_conf"
 | 
			
		||||
    if _setopt "$_vsftpd_conf" "rsa_cert_file" "=" "$_real_fullchain" \
 | 
			
		||||
      && _setopt "$_vsftpd_conf" "rsa_private_key_file" "=" "$_real_key" \
 | 
			
		||||
      && _setopt "$_vsftpd_conf" "ssl_enable" "=" "YES"; then
 | 
			
		||||
      _info "Set config success!"
 | 
			
		||||
    else
 | 
			
		||||
      _err "Config vsftpd server error, please report bug to us."
 | 
			
		||||
      _info "Restoring vsftpd conf"
 | 
			
		||||
      if cat "$_backup_conf" >"$_vsftpd_conf"; then
 | 
			
		||||
        _info "Restore conf success"
 | 
			
		||||
        eval "$_reload"
 | 
			
		||||
      else
 | 
			
		||||
        _err "Oops, error restore vsftpd conf, please report bug to us."
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Run reload: $_reload"
 | 
			
		||||
  if eval "$_reload"; then
 | 
			
		||||
    _info "Reload success!"
 | 
			
		||||
    if [ "$DEPLOY_VSFTPD_CONF" ]; then
 | 
			
		||||
      _savedomainconf DEPLOY_VSFTPD_CONF "$DEPLOY_VSFTPD_CONF"
 | 
			
		||||
    else
 | 
			
		||||
      _cleardomainconf DEPLOY_VSFTPD_CONF
 | 
			
		||||
    fi
 | 
			
		||||
    if [ "$DEPLOY_VSFTPD_RELOAD" ]; then
 | 
			
		||||
      _savedomainconf DEPLOY_VSFTPD_RELOAD "$DEPLOY_VSFTPD_RELOAD"
 | 
			
		||||
    else
 | 
			
		||||
      _cleardomainconf DEPLOY_VSFTPD_RELOAD
 | 
			
		||||
    fi
 | 
			
		||||
    return 0
 | 
			
		||||
  else
 | 
			
		||||
    _err "Reload error, restoring"
 | 
			
		||||
    if cat "$_backup_conf" >"$_vsftpd_conf"; then
 | 
			
		||||
      _info "Restore conf success"
 | 
			
		||||
      eval "$_reload"
 | 
			
		||||
    else
 | 
			
		||||
      _err "Oops, error restore vsftpd conf, please report bug to us."
 | 
			
		||||
    fi
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										1172
									
								
								dnsapi/README.md
									
									
									
									
									
								
							
							
						
						
									
										1172
									
								
								dnsapi/README.md
									
									
									
									
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										171
									
								
								dnsapi/dns-cf.sh
									
									
									
									
									
								
							
							
						
						
									
										171
									
								
								dnsapi/dns-cf.sh
									
									
									
									
									
								
							@@ -1,171 +0,0 @@
 | 
			
		||||
#!/bin/bash
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
#CF_Key="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
#
 | 
			
		||||
#CF_Email="xxxx@sss.com"
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
CF_Api="https://api.cloudflare.com/client/v4/"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns-cf-add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  
 | 
			
		||||
  if [ -z "$CF_Key" ] || [ -z "$CF_Email" ] ; then
 | 
			
		||||
    _err "You don't specify cloudflare api key and email yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf CF_Key "$CF_Key"
 | 
			
		||||
  _saveaccountconf CF_Email "$CF_Email"
 | 
			
		||||
  
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root $fulldomain ; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
  
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _cf_rest GET "/zones/${_domain_id}/dns_records?type=TXT&name=$fulldomain"
 | 
			
		||||
  
 | 
			
		||||
  if [ "$?" != "0" ] || ! printf $response | grep \"success\":true > /dev/null ; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  count=$(printf $response | grep -o \"count\":[^,]* | cut -d : -f 2)
 | 
			
		||||
  
 | 
			
		||||
  if [ "$count" == "0" ] ; then
 | 
			
		||||
    _info "Adding record"
 | 
			
		||||
    if _cf_rest POST "/zones/$_domain_id/dns_records"  "{\"type\":\"TXT\",\"name\":\"$fulldomain\",\"content\":\"$txtvalue\",\"ttl\":120}"; then
 | 
			
		||||
      if printf $response | grep $fulldomain > /dev/null ; then
 | 
			
		||||
        _info "Added, sleeping 10 seconds"
 | 
			
		||||
        sleep 10
 | 
			
		||||
        #todo: check if the record takes effect
 | 
			
		||||
        return 0
 | 
			
		||||
      else
 | 
			
		||||
        _err "Add txt record error."
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
    fi
 | 
			
		||||
    _err "Add txt record error."
 | 
			
		||||
  else
 | 
			
		||||
    _info "Updating record"
 | 
			
		||||
    record_id=$(printf $response | grep -o \"id\":\"[^\"]*\" | cut -d : -f 2 | tr -d \")
 | 
			
		||||
    _debug "record_id" $record_id
 | 
			
		||||
    
 | 
			
		||||
    _cf_rest PUT "/zones/$_domain_id/dns_records/$record_id"  "{\"id\":\"$record_id\",\"type\":\"TXT\",\"name\":\"$fulldomain\",\"content\":\"$txtvalue\",\"zone_id\":\"$_domain_id\",\"zone_name\":\"$_domain\"}"
 | 
			
		||||
    if [ "$?" == "0" ]; then
 | 
			
		||||
      _info "Updated, sleeping 10 seconds"
 | 
			
		||||
      sleep 10
 | 
			
		||||
      #todo: check if the record takes effect
 | 
			
		||||
      return 0;
 | 
			
		||||
    fi
 | 
			
		||||
    _err "Update error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
####################  Private functions bellow ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while [ '1' ] ; do
 | 
			
		||||
    h=$(printf $domain | cut -d . -f $i-100)
 | 
			
		||||
    if [ -z "$h" ] ; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1;
 | 
			
		||||
    fi
 | 
			
		||||
    
 | 
			
		||||
    if ! _cf_rest GET "zones?name=$h" ; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    
 | 
			
		||||
    if printf $response | grep \"name\":\"$h\" ; then
 | 
			
		||||
      _domain_id=$(printf "$response" | grep -o \"id\":\"[^\"]*\" | head -1 | cut -d : -f 2 | tr -d \")
 | 
			
		||||
      if [ "$_domain_id" ] ; then
 | 
			
		||||
        _sub_domain=$(printf $domain | cut -d . -f 1-$p)
 | 
			
		||||
        _domain=$h
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    let "i+=1"
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
_cf_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  _debug $ep
 | 
			
		||||
  if [ "$3" ] ; then
 | 
			
		||||
    data="$3"
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(curl --silent -X $m "$CF_Api/$ep" -H "X-Auth-Email: $CF_Email" -H "X-Auth-Key: $CF_Key" -H "Content-Type: application/json" --data $data)"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(curl --silent -X $m "$CF_Api/$ep" -H "X-Auth-Email: $CF_Email" -H "X-Auth-Key: $CF_Key" -H "Content-Type: application/json")"
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  if [ "$?" != "0" ] ; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
_debug() {
 | 
			
		||||
 | 
			
		||||
  if [ -z "$DEBUG" ] ; then
 | 
			
		||||
    return
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  if [ -z "$2" ] ; then
 | 
			
		||||
    echo $1
 | 
			
		||||
  else
 | 
			
		||||
    echo "$1"="$2"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_info() {
 | 
			
		||||
  if [ -z "$2" ] ; then
 | 
			
		||||
    echo "$1"
 | 
			
		||||
  else
 | 
			
		||||
    echo "$1"="$2"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_err() {
 | 
			
		||||
  if [ -z "$2" ] ; then
 | 
			
		||||
    echo "$1" >&2
 | 
			
		||||
  else
 | 
			
		||||
    echo "$1"="$2" >&2
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
							
								
								
									
										234
									
								
								dnsapi/dns-cx.sh
									
									
									
									
									
								
							
							
						
						
									
										234
									
								
								dnsapi/dns-cx.sh
									
									
									
									
									
								
							@@ -1,234 +0,0 @@
 | 
			
		||||
#!/bin/bash
 | 
			
		||||
 | 
			
		||||
# Cloudxns.com Domain api
 | 
			
		||||
#
 | 
			
		||||
#CX_Key="1234"
 | 
			
		||||
#
 | 
			
		||||
#CX_Secret="sADDsdasdgdsf"
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
CX_Api="https://www.cloudxns.net/api2"
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#REST_API
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns-cx-add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  
 | 
			
		||||
  if [ -z "$CX_Key" ] || [ -z "$CX_Secret" ] ; then
 | 
			
		||||
    _err "You don't specify cloudxns.com  api key or secret yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  REST_API=$CX_Api
 | 
			
		||||
  
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf CX_Key "$CX_Key"
 | 
			
		||||
  _saveaccountconf CX_Secret "$CX_Secret"
 | 
			
		||||
  
 | 
			
		||||
 
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root $fulldomain ; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  existing_records  $_domain  $_sub_domain
 | 
			
		||||
  _debug count "$count"
 | 
			
		||||
  if [ "$?" != "0" ] ; then
 | 
			
		||||
    _err "Error get existing records."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$count" == "0" ] ; then
 | 
			
		||||
    add_record $_domain $_sub_domain $txtvalue
 | 
			
		||||
  else
 | 
			
		||||
    update_record $_domain $_sub_domain $txtvalue
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  if [ "$?" == "0" ] ; then
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#usage:  root  sub
 | 
			
		||||
#return if the sub record already exists.
 | 
			
		||||
#echos the existing records count.
 | 
			
		||||
# '0' means doesn't exist
 | 
			
		||||
existing_records() {
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  root=$1
 | 
			
		||||
  sub=$2
 | 
			
		||||
  
 | 
			
		||||
  if ! _rest GET "record/$_domain_id?:domain_id?host_id=0&offset=0&row_num=100" ; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  count=0
 | 
			
		||||
  seg=$(printf "$response" | grep -o "{[^{]*host\":\"$_sub_domain[^}]*}")
 | 
			
		||||
  _debug seg "$seg"
 | 
			
		||||
  if [ -z "$seg" ] ; then
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if printf "$response" | grep '"type":"TXT"' > /dev/null ; then
 | 
			
		||||
    count=1
 | 
			
		||||
    record_id=$(printf "$seg" | grep -o \"record_id\":\"[^\"]*\" | cut -d : -f 2 | tr -d \")
 | 
			
		||||
    _debug record_id "$record_id"
 | 
			
		||||
    return 0    
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#add the txt record.
 | 
			
		||||
#usage: root  sub  txtvalue
 | 
			
		||||
add_record() {
 | 
			
		||||
  root=$1
 | 
			
		||||
  sub=$2
 | 
			
		||||
  txtvalue=$3
 | 
			
		||||
  fulldomain=$sub.$root
 | 
			
		||||
  
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  
 | 
			
		||||
  if ! _rest POST "record" "{\"domain_id\": $_domain_id, \"host\":\"$_sub_domain\", \"value\":\"$txtvalue\", \"type\":\"TXT\",\"ttl\":600, \"line_id\":1}"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#update the txt record
 | 
			
		||||
#Usage: root sub txtvalue
 | 
			
		||||
update_record() {
 | 
			
		||||
  root=$1
 | 
			
		||||
  sub=$2
 | 
			
		||||
  txtvalue=$3
 | 
			
		||||
  fulldomain=$sub.$root
 | 
			
		||||
  
 | 
			
		||||
  _info "Updating record"
 | 
			
		||||
  
 | 
			
		||||
  if _rest PUT "record/$record_id" "{\"domain_id\": $_domain_id, \"host\":\"$_sub_domain\", \"value\":\"$txtvalue\", \"type\":\"TXT\",\"ttl\":600, \"line_id\":1}" ; then
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
####################  Private functions bellow ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  
 | 
			
		||||
  if ! _rest GET "domain" ; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  while [ '1' ] ; do
 | 
			
		||||
    h=$(printf $domain | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ] ; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1;
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if printf "$response" | grep "$h." ; then
 | 
			
		||||
      seg=$(printf "$response" | grep -o "{[^{]*$h\.[^}]*\}" )
 | 
			
		||||
      _debug seg "$seg"
 | 
			
		||||
      _domain_id=$(printf "$seg" | grep -o \"id\":\"[^\"]*\" | cut -d : -f 2 | tr -d \")
 | 
			
		||||
      _debug _domain_id "$_domain_id"
 | 
			
		||||
      if [ "$_domain_id" ] ; then
 | 
			
		||||
        _sub_domain=$(printf $domain | cut -d . -f 1-$p)
 | 
			
		||||
        _debug _sub_domain $_sub_domain
 | 
			
		||||
        _domain=$h
 | 
			
		||||
        _debug _domain $_domain
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    let "i+=1"
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#Usage: method  URI  data
 | 
			
		||||
_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  _debug $ep
 | 
			
		||||
  url="$REST_API/$ep"
 | 
			
		||||
  _debug url "$url"
 | 
			
		||||
  
 | 
			
		||||
  cdate=$(date -u  "+%Y-%m-%d %H:%M:%S UTC")
 | 
			
		||||
  _debug cdate "$cdate"
 | 
			
		||||
  
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug data "$data"
 | 
			
		||||
    
 | 
			
		||||
  sec="$CX_Key$url$data$cdate$CX_Secret"
 | 
			
		||||
  _debug sec "$sec"
 | 
			
		||||
  hmac=$(printf "$sec"| openssl md5 |cut -d " " -f 2)
 | 
			
		||||
  _debug hmac "$hmac"
 | 
			
		||||
    
 | 
			
		||||
  if [ "$3" ] ; then
 | 
			
		||||
    response="$(curl --silent -X $m "$url" -H "API-KEY: $CX_Key" -H "API-REQUEST-DATE: $cdate" -H "API-HMAC: $hmac" -H 'Content-Type: application/json'  -d "$data")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(curl --silent -X $m "$url" -H "API-KEY: $CX_Key" -H "API-REQUEST-DATE: $cdate" -H "API-HMAC: $hmac" -H 'Content-Type: application/json')"
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  if [ "$?" != "0" ] ; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
  if ! printf "$response" | grep '"message":"success"' > /dev/null ; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
_debug() {
 | 
			
		||||
 | 
			
		||||
  if [ -z "$DEBUG" ] ; then
 | 
			
		||||
    return
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  if [ -z "$2" ] ; then
 | 
			
		||||
    echo $1
 | 
			
		||||
  else
 | 
			
		||||
    echo "$1"="$2"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_info() {
 | 
			
		||||
  if [ -z "$2" ] ; then
 | 
			
		||||
    echo "$1"
 | 
			
		||||
  else
 | 
			
		||||
    echo "$1"="$2"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_err() {
 | 
			
		||||
  if [ -z "$2" ] ; then
 | 
			
		||||
    echo "$1" >&2
 | 
			
		||||
  else
 | 
			
		||||
    echo "$1"="$2" >&2
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
							
								
								
									
										229
									
								
								dnsapi/dns-dp.sh
									
									
									
									
									
								
							
							
						
						
									
										229
									
								
								dnsapi/dns-dp.sh
									
									
									
									
									
								
							@@ -1,229 +0,0 @@
 | 
			
		||||
#!/bin/bash
 | 
			
		||||
 | 
			
		||||
# Dnspod.cn Domain api
 | 
			
		||||
#
 | 
			
		||||
#DP_Id="1234"
 | 
			
		||||
#
 | 
			
		||||
#DP_Key="sADDsdasdgdsf"
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
DP_Api="https://dnsapi.cn"
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#REST_API
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns-dp-add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  
 | 
			
		||||
  if [ -z "$DP_Id" ] || [ -z "$DP_Key" ] ; then
 | 
			
		||||
    _err "You don't specify dnspod api key and key id yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  REST_API=$DP_Api
 | 
			
		||||
  
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf DP_Id "$DP_Id"
 | 
			
		||||
  _saveaccountconf DP_Key "$DP_Key"
 | 
			
		||||
  
 | 
			
		||||
 
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root $fulldomain ; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  existing_records  $_domain  $_sub_domain
 | 
			
		||||
  _debug count "$count"
 | 
			
		||||
  if [ "$?" != "0" ] ; then
 | 
			
		||||
    _err "Error get existing records."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$count" == "0" ] ; then
 | 
			
		||||
    add_record $_domain $_sub_domain $txtvalue
 | 
			
		||||
  else
 | 
			
		||||
    update_record $_domain $_sub_domain $txtvalue
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#usage:  root  sub
 | 
			
		||||
#return if the sub record already exists.
 | 
			
		||||
#echos the existing records count.
 | 
			
		||||
# '0' means doesn't exist
 | 
			
		||||
existing_records() {
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  root=$1
 | 
			
		||||
  sub=$2
 | 
			
		||||
  
 | 
			
		||||
  if ! _rest POST "Record.List" "login_token=$DP_Id,$DP_Key&domain_id=$_domain_id&sub_domain=$_sub_domain"; then
 | 
			
		||||
      return 1
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  if  printf "$response" | grep 'No records' ; then
 | 
			
		||||
      count=0;
 | 
			
		||||
      return 0
 | 
			
		||||
  fi
 | 
			
		||||
    
 | 
			
		||||
  if printf "$response" | grep "Action completed successful" >/dev/null ; then
 | 
			
		||||
    count=$(printf "$response" | grep '<type>TXT</type>' | wc -l)
 | 
			
		||||
    
 | 
			
		||||
    record_id=$(printf "$response" | grep '^<id>' | tail -1 | cut -d '>' -f 2 | cut -d '<' -f 1)
 | 
			
		||||
    return 0    
 | 
			
		||||
  else
 | 
			
		||||
    _err "get existing records error."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  
 | 
			
		||||
  count=0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#add the txt record.
 | 
			
		||||
#usage: root  sub  txtvalue
 | 
			
		||||
add_record() {
 | 
			
		||||
  root=$1
 | 
			
		||||
  sub=$2
 | 
			
		||||
  txtvalue=$3
 | 
			
		||||
  fulldomain=$sub.$root
 | 
			
		||||
  
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  
 | 
			
		||||
  if ! _rest POST "Record.Create" "login_token=$DP_Id,$DP_Key&format=json&domain_id=$_domain_id&sub_domain=$_sub_domain&record_type=TXT&value=$txtvalue&record_line=默认"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  if printf "$response" | grep "Action completed successful" ; then
 | 
			
		||||
  
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  
 | 
			
		||||
  return 1 #error
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#update the txt record
 | 
			
		||||
#Usage: root sub txtvalue
 | 
			
		||||
update_record() {
 | 
			
		||||
  root=$1
 | 
			
		||||
  sub=$2
 | 
			
		||||
  txtvalue=$3
 | 
			
		||||
  fulldomain=$sub.$root
 | 
			
		||||
  
 | 
			
		||||
  _info "Updating record"
 | 
			
		||||
  
 | 
			
		||||
  if ! _rest POST "Record.Modify" "login_token=$DP_Id,$DP_Key&format=json&domain_id=$_domain_id&sub_domain=$_sub_domain&record_type=TXT&value=$txtvalue&record_line=默认&record_id=$record_id"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  if printf "$response" | grep "Action completed successful" ; then
 | 
			
		||||
  
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  return 1 #error
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
####################  Private functions bellow ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while [ '1' ] ; do
 | 
			
		||||
    h=$(printf $domain | cut -d . -f $i-100)
 | 
			
		||||
    if [ -z "$h" ] ; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1;
 | 
			
		||||
    fi
 | 
			
		||||
    
 | 
			
		||||
    if ! _rest POST "Domain.Info" "login_token=$DP_Id,$DP_Key&format=json&domain=$h"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    
 | 
			
		||||
    if printf "$response" | grep "Action completed successful" ; then
 | 
			
		||||
      _domain_id=$(printf "$response" | grep -o \"id\":\"[^\"]*\" | cut -d : -f 2 | tr -d \")
 | 
			
		||||
      _debug _domain_id "$_domain_id"
 | 
			
		||||
      if [ "$_domain_id" ] ; then
 | 
			
		||||
        _sub_domain=$(printf $domain | cut -d . -f 1-$p)
 | 
			
		||||
        _debug _sub_domain $_sub_domain
 | 
			
		||||
        _domain=$h
 | 
			
		||||
        _debug _domain $_domain
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    let "i+=1"
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#Usage: method  URI  data
 | 
			
		||||
_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  _debug $ep
 | 
			
		||||
  url="$REST_API/$ep"
 | 
			
		||||
  
 | 
			
		||||
  _debug url "$url"
 | 
			
		||||
  
 | 
			
		||||
  if [ "$3" ] ; then
 | 
			
		||||
    data="$3"
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(curl --silent -X $m "$url"  -d $data)"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(curl --silent -X $m "$url" )"
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  if [ "$?" != "0" ] ; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
_debug() {
 | 
			
		||||
 | 
			
		||||
  if [ -z "$DEBUG" ] ; then
 | 
			
		||||
    return
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  if [ -z "$2" ] ; then
 | 
			
		||||
    echo $1
 | 
			
		||||
  else
 | 
			
		||||
    echo "$1"="$2"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_info() {
 | 
			
		||||
  if [ -z "$2" ] ; then
 | 
			
		||||
    echo "$1"
 | 
			
		||||
  else
 | 
			
		||||
    echo "$1"="$2"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_err() {
 | 
			
		||||
  if [ -z "$2" ] ; then
 | 
			
		||||
    echo "$1" >&2
 | 
			
		||||
  else
 | 
			
		||||
    echo "$1"="$2" >&2
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
@@ -1,61 +0,0 @@
 | 
			
		||||
#!/bin/bash
 | 
			
		||||
 | 
			
		||||
#Here is a sample custom api script.
 | 
			
		||||
#This file name is "dns-myapi.sh"
 | 
			
		||||
#So, here must be a method   dns-myapi-add()
 | 
			
		||||
#Which will be called by le.sh to add the txt record to your api system.
 | 
			
		||||
#returns 0 meanst success, otherwise error.
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns-myapi-add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _err "Not implemented!"
 | 
			
		||||
  return 1;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
####################  Private functions bellow ##################################
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
_debug() {
 | 
			
		||||
 | 
			
		||||
  if [ -z "$DEBUG" ] ; then
 | 
			
		||||
    return
 | 
			
		||||
  fi
 | 
			
		||||
  
 | 
			
		||||
  if [ -z "$2" ] ; then
 | 
			
		||||
    echo $1
 | 
			
		||||
  else
 | 
			
		||||
    echo "$1"="$2"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_info() {
 | 
			
		||||
  if [ -z "$2" ] ; then
 | 
			
		||||
    echo "$1"
 | 
			
		||||
  else
 | 
			
		||||
    echo "$1"="$2"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_err() {
 | 
			
		||||
  if [ -z "$2" ] ; then
 | 
			
		||||
    echo "$1" >&2
 | 
			
		||||
  else
 | 
			
		||||
    echo "$1"="$2" >&2
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
							
								
								
									
										55
									
								
								dnsapi/dns_acmedns.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										55
									
								
								dnsapi/dns_acmedns.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,55 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
#
 | 
			
		||||
#Author: Wolfgang Ebner
 | 
			
		||||
#Report Bugs here: https://github.com/webner/acme.sh
 | 
			
		||||
#
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_acmedns_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_acmedns_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _info "Using acme-dns"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  ACMEDNS_UPDATE_URL="${ACMEDNS_UPDATE_URL:-$(_readaccountconf_mutable ACMEDNS_UPDATE_URL)}"
 | 
			
		||||
  ACMEDNS_USERNAME="${ACMEDNS_USERNAME:-$(_readaccountconf_mutable ACMEDNS_USERNAME)}"
 | 
			
		||||
  ACMEDNS_PASSWORD="${ACMEDNS_PASSWORD:-$(_readaccountconf_mutable ACMEDNS_PASSWORD)}"
 | 
			
		||||
  ACMEDNS_SUBDOMAIN="${ACMEDNS_SUBDOMAIN:-$(_readaccountconf_mutable ACMEDNS_SUBDOMAIN)}"
 | 
			
		||||
 | 
			
		||||
  if [ "$ACMEDNS_UPDATE_URL" = "" ]; then
 | 
			
		||||
    ACMEDNS_UPDATE_URL="https://auth.acme-dns.io/update"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf_mutable ACMEDNS_UPDATE_URL "$ACMEDNS_UPDATE_URL"
 | 
			
		||||
  _saveaccountconf_mutable ACMEDNS_USERNAME "$ACMEDNS_USERNAME"
 | 
			
		||||
  _saveaccountconf_mutable ACMEDNS_PASSWORD "$ACMEDNS_PASSWORD"
 | 
			
		||||
  _saveaccountconf_mutable ACMEDNS_SUBDOMAIN "$ACMEDNS_SUBDOMAIN"
 | 
			
		||||
 | 
			
		||||
  export _H1="X-Api-User: $ACMEDNS_USERNAME"
 | 
			
		||||
  export _H2="X-Api-Key: $ACMEDNS_PASSWORD"
 | 
			
		||||
  data="{\"subdomain\":\"$ACMEDNS_SUBDOMAIN\", \"txt\": \"$txtvalue\"}"
 | 
			
		||||
 | 
			
		||||
  _debug data "$data"
 | 
			
		||||
  response="$(_post "$data" "$ACMEDNS_UPDATE_URL" "" "POST")"
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
 | 
			
		||||
  if ! echo "$response" | grep "\"$txtvalue\"" >/dev/null; then
 | 
			
		||||
    _err "invalid response of acme-dns"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: fulldomain txtvalue
 | 
			
		||||
#Remove the txt record after validation.
 | 
			
		||||
dns_acmedns_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _info "Using acme-dns"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
							
								
								
									
										141
									
								
								dnsapi/dns_active24.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										141
									
								
								dnsapi/dns_active24.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,141 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#ACTIVE24_Token="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
 | 
			
		||||
ACTIVE24_Api="https://api.active24.com"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
# Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
# Used to add txt record
 | 
			
		||||
dns_active24_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  _active24_init
 | 
			
		||||
 | 
			
		||||
  _info "Adding txt record"
 | 
			
		||||
  if _active24_rest POST "dns/$_domain/txt/v1" "{\"name\":\"$_sub_domain\",\"text\":\"$txtvalue\",\"ttl\":0}"; then
 | 
			
		||||
    if _contains "$response" "errors"; then
 | 
			
		||||
      _err "Add txt record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    else
 | 
			
		||||
      _info "Added, OK"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  _err "Add txt record error."
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Usage: fulldomain txtvalue
 | 
			
		||||
# Used to remove the txt record after validation
 | 
			
		||||
dns_active24_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  _active24_init
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _active24_rest GET "dns/$_domain/records/v1"
 | 
			
		||||
 | 
			
		||||
  if _contains "$response" "errors"; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  hash_ids=$(echo "$response" | _egrep_o "[^{]+${txtvalue}[^}]+" | _egrep_o "hashId\":\"[^\"]+" | cut -c10-)
 | 
			
		||||
 | 
			
		||||
  for hash_id in $hash_ids; do
 | 
			
		||||
    _debug "Removing hash_id" "$hash_id"
 | 
			
		||||
    if _active24_rest DELETE "dns/$_domain/$hash_id/v1" ""; then
 | 
			
		||||
      if _contains "$response" "errors"; then
 | 
			
		||||
        _err "Unable to remove txt record."
 | 
			
		||||
        return 1
 | 
			
		||||
      else
 | 
			
		||||
        _info "Removed txt record."
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
    fi
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  _err "No txt records found."
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
 | 
			
		||||
  if ! _active24_rest GET "dns/domains/v1"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug "h" "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"$h\"" >/dev/null; then
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain=$h
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_active24_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="Authorization: Bearer $ACTIVE24_Token"
 | 
			
		||||
 | 
			
		||||
  if [ "$m" != "GET" ]; then
 | 
			
		||||
    _debug "data" "$data"
 | 
			
		||||
    response="$(_post "$data" "$ACTIVE24_Api/$ep" "" "$m" "application/json")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$ACTIVE24_Api/$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_active24_init() {
 | 
			
		||||
  ACTIVE24_Token="${ACTIVE24_Token:-$(_readaccountconf_mutable ACTIVE24_Token)}"
 | 
			
		||||
  if [ -z "$ACTIVE24_Token" ]; then
 | 
			
		||||
    ACTIVE24_Token=""
 | 
			
		||||
    _err "You didn't specify a Active24 api token yet."
 | 
			
		||||
    _err "Please create the token and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf_mutable ACTIVE24_Token "ACTIVE24_Token"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										147
									
								
								dnsapi/dns_ad.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										147
									
								
								dnsapi/dns_ad.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,147 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
#AD_API_KEY="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
 | 
			
		||||
#This is the Alwaysdata api wrapper for acme.sh
 | 
			
		||||
#
 | 
			
		||||
#Author: Paul Koppen
 | 
			
		||||
#Report Bugs here: https://github.com/wpk-/acme.sh
 | 
			
		||||
 | 
			
		||||
AD_API_URL="https://$AD_API_KEY:@api.alwaysdata.com/v1"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_myapi_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_ad_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AD_API_KEY" ]; then
 | 
			
		||||
    AD_API_KEY=""
 | 
			
		||||
    _err "You didn't specify the AD api key yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf AD_API_KEY "$AD_API_KEY"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _ad_tmpl_json="{\"domain\":$_domain_id,\"type\":\"TXT\",\"name\":\"$_sub_domain\",\"value\":\"$txtvalue\"}"
 | 
			
		||||
 | 
			
		||||
  if _ad_rest POST "record/" "$_ad_tmpl_json" && [ -z "$response" ]; then
 | 
			
		||||
    _info "txt record updated success."
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_ad_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _ad_rest GET "record/?domain=$_domain_id&name=$_sub_domain"
 | 
			
		||||
 | 
			
		||||
  if [ -n "$response" ]; then
 | 
			
		||||
    record_id=$(printf "%s\n" "$response" | _egrep_o "\"id\":\s*[0-9]+" | cut -d : -f 2 | tr -d " " | _head_n 1)
 | 
			
		||||
    _debug record_id "$record_id"
 | 
			
		||||
    if [ -z "$record_id" ]; then
 | 
			
		||||
      _err "Can not get record id to remove."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    if _ad_rest DELETE "record/$record_id/" && [ -z "$response" ]; then
 | 
			
		||||
      _info "txt record deleted success."
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    _debug response "$response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=12345
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  if _ad_rest GET "domain/"; then
 | 
			
		||||
    response="$(echo "$response" | tr -d "\n" | sed 's/{/\n&/g')"
 | 
			
		||||
    while true; do
 | 
			
		||||
      h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
      _debug h "$h"
 | 
			
		||||
      if [ -z "$h" ]; then
 | 
			
		||||
        #not valid
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
 | 
			
		||||
      hostedzone="$(echo "$response" | _egrep_o "{.*\"name\":\s*\"$h\".*}")"
 | 
			
		||||
      if [ "$hostedzone" ]; then
 | 
			
		||||
        _domain_id=$(printf "%s\n" "$hostedzone" | _egrep_o "\"id\":\s*[0-9]+" | _head_n 1 | cut -d : -f 2 | tr -d \ )
 | 
			
		||||
        if [ "$_domain_id" ]; then
 | 
			
		||||
          _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
          _domain=$h
 | 
			
		||||
          return 0
 | 
			
		||||
        fi
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
      p=$i
 | 
			
		||||
      i=$(_math "$i" + 1)
 | 
			
		||||
    done
 | 
			
		||||
  fi
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#method uri qstr data
 | 
			
		||||
_ad_rest() {
 | 
			
		||||
  mtd="$1"
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
 | 
			
		||||
  _debug mtd "$mtd"
 | 
			
		||||
  _debug ep "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="Accept: application/json"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  if [ "$mtd" != "GET" ]; then
 | 
			
		||||
    # both POST and DELETE.
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$AD_API_URL/$ep" "" "$mtd")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$AD_API_URL/$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										202
									
								
								dnsapi/dns_ali.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										202
									
								
								dnsapi/dns_ali.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,202 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
Ali_API="https://alidns.aliyuncs.com/"
 | 
			
		||||
 | 
			
		||||
#Ali_Key="LTqIA87hOKdjevsf5"
 | 
			
		||||
#Ali_Secret="0p5EYueFNq501xnCPzKNbx6K51qPH2"
 | 
			
		||||
 | 
			
		||||
#Usage: dns_ali_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_ali_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  Ali_Key="${Ali_Key:-$(_readaccountconf_mutable Ali_Key)}"
 | 
			
		||||
  Ali_Secret="${Ali_Secret:-$(_readaccountconf_mutable Ali_Secret)}"
 | 
			
		||||
  if [ -z "$Ali_Key" ] || [ -z "$Ali_Secret" ]; then
 | 
			
		||||
    Ali_Key=""
 | 
			
		||||
    Ali_Secret=""
 | 
			
		||||
    _err "You don't specify aliyun api key and secret yet."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and secret to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable Ali_Key "$Ali_Key"
 | 
			
		||||
  _saveaccountconf_mutable Ali_Secret "$Ali_Secret"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "Add record"
 | 
			
		||||
  _add_record_query "$_domain" "$_sub_domain" "$txtvalue" && _ali_rest "Add record"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
dns_ali_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  Ali_Key="${Ali_Key:-$(_readaccountconf_mutable Ali_Key)}"
 | 
			
		||||
  Ali_Secret="${Ali_Secret:-$(_readaccountconf_mutable Ali_Secret)}"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _clean
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    _describe_records_query "$h"
 | 
			
		||||
    if ! _ali_rest "Get root" "ignore"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "PageNumber"; then
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _debug _sub_domain "$_sub_domain"
 | 
			
		||||
      _domain="$h"
 | 
			
		||||
      _debug _domain "$_domain"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p="$i"
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_ali_rest() {
 | 
			
		||||
  signature=$(printf "%s" "GET&%2F&$(_ali_urlencode "$query")" | _hmac "sha1" "$(printf "%s" "$Ali_Secret&" | _hex_dump | tr -d " ")" | _base64)
 | 
			
		||||
  signature=$(_ali_urlencode "$signature")
 | 
			
		||||
  url="$Ali_API?$query&Signature=$signature"
 | 
			
		||||
 | 
			
		||||
  if ! response="$(_get "$url")"; then
 | 
			
		||||
    _err "Error <$1>"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  if [ -z "$2" ]; then
 | 
			
		||||
    message="$(echo "$response" | _egrep_o "\"Message\":\"[^\"]*\"" | cut -d : -f 2 | tr -d \")"
 | 
			
		||||
    if [ "$message" ]; then
 | 
			
		||||
      _err "$message"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_ali_urlencode() {
 | 
			
		||||
  _str="$1"
 | 
			
		||||
  _str_len=${#_str}
 | 
			
		||||
  _u_i=1
 | 
			
		||||
  while [ "$_u_i" -le "$_str_len" ]; do
 | 
			
		||||
    _str_c="$(printf "%s" "$_str" | cut -c "$_u_i")"
 | 
			
		||||
    case $_str_c in [a-zA-Z0-9.~_-])
 | 
			
		||||
      printf "%s" "$_str_c"
 | 
			
		||||
      ;;
 | 
			
		||||
    *)
 | 
			
		||||
      printf "%%%02X" "'$_str_c"
 | 
			
		||||
      ;;
 | 
			
		||||
    esac
 | 
			
		||||
    _u_i="$(_math "$_u_i" + 1)"
 | 
			
		||||
  done
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_ali_nonce() {
 | 
			
		||||
  #_head_n 1 </dev/urandom | _digest "sha256" hex | cut -c 1-31
 | 
			
		||||
  #Not so good...
 | 
			
		||||
  date +"%s%N"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_check_exist_query() {
 | 
			
		||||
  _qdomain="$1"
 | 
			
		||||
  _qsubdomain="$2"
 | 
			
		||||
  query=''
 | 
			
		||||
  query=$query'AccessKeyId='$Ali_Key
 | 
			
		||||
  query=$query'&Action=DescribeDomainRecords'
 | 
			
		||||
  query=$query'&DomainName='$_qdomain
 | 
			
		||||
  query=$query'&Format=json'
 | 
			
		||||
  query=$query'&RRKeyWord='$_qsubdomain
 | 
			
		||||
  query=$query'&SignatureMethod=HMAC-SHA1'
 | 
			
		||||
  query=$query"&SignatureNonce=$(_ali_nonce)"
 | 
			
		||||
  query=$query'&SignatureVersion=1.0'
 | 
			
		||||
  query=$query'&Timestamp='$(_timestamp)
 | 
			
		||||
  query=$query'&TypeKeyWord=TXT'
 | 
			
		||||
  query=$query'&Version=2015-01-09'
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_add_record_query() {
 | 
			
		||||
  query=''
 | 
			
		||||
  query=$query'AccessKeyId='$Ali_Key
 | 
			
		||||
  query=$query'&Action=AddDomainRecord'
 | 
			
		||||
  query=$query'&DomainName='$1
 | 
			
		||||
  query=$query'&Format=json'
 | 
			
		||||
  query=$query'&RR='$2
 | 
			
		||||
  query=$query'&SignatureMethod=HMAC-SHA1'
 | 
			
		||||
  query=$query"&SignatureNonce=$(_ali_nonce)"
 | 
			
		||||
  query=$query'&SignatureVersion=1.0'
 | 
			
		||||
  query=$query'&Timestamp='$(_timestamp)
 | 
			
		||||
  query=$query'&Type=TXT'
 | 
			
		||||
  query=$query'&Value='$3
 | 
			
		||||
  query=$query'&Version=2015-01-09'
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_delete_record_query() {
 | 
			
		||||
  query=''
 | 
			
		||||
  query=$query'AccessKeyId='$Ali_Key
 | 
			
		||||
  query=$query'&Action=DeleteDomainRecord'
 | 
			
		||||
  query=$query'&Format=json'
 | 
			
		||||
  query=$query'&RecordId='$1
 | 
			
		||||
  query=$query'&SignatureMethod=HMAC-SHA1'
 | 
			
		||||
  query=$query"&SignatureNonce=$(_ali_nonce)"
 | 
			
		||||
  query=$query'&SignatureVersion=1.0'
 | 
			
		||||
  query=$query'&Timestamp='$(_timestamp)
 | 
			
		||||
  query=$query'&Version=2015-01-09'
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_describe_records_query() {
 | 
			
		||||
  query=''
 | 
			
		||||
  query=$query'AccessKeyId='$Ali_Key
 | 
			
		||||
  query=$query'&Action=DescribeDomainRecords'
 | 
			
		||||
  query=$query'&DomainName='$1
 | 
			
		||||
  query=$query'&Format=json'
 | 
			
		||||
  query=$query'&SignatureMethod=HMAC-SHA1'
 | 
			
		||||
  query=$query"&SignatureNonce=$(_ali_nonce)"
 | 
			
		||||
  query=$query'&SignatureVersion=1.0'
 | 
			
		||||
  query=$query'&Timestamp='$(_timestamp)
 | 
			
		||||
  query=$query'&Version=2015-01-09'
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_clean() {
 | 
			
		||||
  _check_exist_query "$_domain" "$_sub_domain"
 | 
			
		||||
  if ! _ali_rest "Check exist records" "ignore"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  record_id="$(echo "$response" | tr '{' "\n" | grep "$_sub_domain" | grep "$txtvalue" | tr "," "\n" | grep RecordId | cut -d '"' -f 4)"
 | 
			
		||||
  _debug2 record_id "$record_id"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$record_id" ]; then
 | 
			
		||||
    _debug "record not found, skip"
 | 
			
		||||
  else
 | 
			
		||||
    _delete_record_query "$record_id"
 | 
			
		||||
    _ali_rest "Delete record $record_id" "ignore"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_timestamp() {
 | 
			
		||||
  date -u +"%Y-%m-%dT%H%%3A%M%%3A%SZ"
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										264
									
								
								dnsapi/dns_autodns.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										264
									
								
								dnsapi/dns_autodns.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,264 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
# -*- mode: sh; tab-width: 2; indent-tabs-mode: s; coding: utf-8 -*-
 | 
			
		||||
 | 
			
		||||
# This is the InternetX autoDNS xml api wrapper for acme.sh
 | 
			
		||||
# Author: auerswald@gmail.com
 | 
			
		||||
# Created: 2018-01-14
 | 
			
		||||
#
 | 
			
		||||
#     export AUTODNS_USER="username"
 | 
			
		||||
#     export AUTODNS_PASSWORD="password"
 | 
			
		||||
#     export AUTODNS_CONTEXT="context"
 | 
			
		||||
#
 | 
			
		||||
# Usage:
 | 
			
		||||
#     acme.sh --issue --dns dns_autodns -d example.com
 | 
			
		||||
 | 
			
		||||
AUTODNS_API="https://gateway.autodns.com"
 | 
			
		||||
 | 
			
		||||
# Arguments:
 | 
			
		||||
#   txtdomain
 | 
			
		||||
#   txt
 | 
			
		||||
dns_autodns_add() {
 | 
			
		||||
  fulldomain="$1"
 | 
			
		||||
  txtvalue="$2"
 | 
			
		||||
 | 
			
		||||
  AUTODNS_USER="${AUTODNS_USER:-$(_readaccountconf_mutable AUTODNS_USER)}"
 | 
			
		||||
  AUTODNS_PASSWORD="${AUTODNS_PASSWORD:-$(_readaccountconf_mutable AUTODNS_PASSWORD)}"
 | 
			
		||||
  AUTODNS_CONTEXT="${AUTODNS_CONTEXT:-$(_readaccountconf_mutable AUTODNS_CONTEXT)}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AUTODNS_USER" ] || [ -z "$AUTODNS_CONTEXT" ] || [ -z "$AUTODNS_PASSWORD" ]; then
 | 
			
		||||
    _err "You don't specify autodns user, password and context."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf_mutable AUTODNS_USER "$AUTODNS_USER"
 | 
			
		||||
  _saveaccountconf_mutable AUTODNS_PASSWORD "$AUTODNS_PASSWORD"
 | 
			
		||||
  _saveaccountconf_mutable AUTODNS_CONTEXT "$AUTODNS_CONTEXT"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
 | 
			
		||||
  if ! _get_autodns_zone "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _zone "$_zone"
 | 
			
		||||
  _debug _system_ns "$_system_ns"
 | 
			
		||||
 | 
			
		||||
  _info "Adding TXT record"
 | 
			
		||||
 | 
			
		||||
  autodns_response="$(_autodns_zone_update "$_zone" "$_sub_domain" "$txtvalue" "$_system_ns")"
 | 
			
		||||
 | 
			
		||||
  if [ "$?" -eq "0" ]; then
 | 
			
		||||
    _info "Added, OK"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Arguments:
 | 
			
		||||
#   txtdomain
 | 
			
		||||
#   txt
 | 
			
		||||
dns_autodns_rm() {
 | 
			
		||||
  fulldomain="$1"
 | 
			
		||||
  txtvalue="$2"
 | 
			
		||||
 | 
			
		||||
  AUTODNS_USER="${AUTODNS_USER:-$(_readaccountconf_mutable AUTODNS_USER)}"
 | 
			
		||||
  AUTODNS_PASSWORD="${AUTODNS_PASSWORD:-$(_readaccountconf_mutable AUTODNS_PASSWORD)}"
 | 
			
		||||
  AUTODNS_CONTEXT="${AUTODNS_CONTEXT:-$(_readaccountconf_mutable AUTODNS_CONTEXT)}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AUTODNS_USER" ] || [ -z "$AUTODNS_CONTEXT" ] || [ -z "$AUTODNS_PASSWORD" ]; then
 | 
			
		||||
    _err "You don't specify autodns user, password and context."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
 | 
			
		||||
  if ! _get_autodns_zone "$fulldomain"; then
 | 
			
		||||
    _err "zone not found"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _zone "$_zone"
 | 
			
		||||
  _debug _system_ns "$_system_ns"
 | 
			
		||||
 | 
			
		||||
  _info "Delete TXT record"
 | 
			
		||||
 | 
			
		||||
  autodns_response="$(_autodns_zone_cleanup "$_zone" "$_sub_domain" "$txtvalue" "$_system_ns")"
 | 
			
		||||
 | 
			
		||||
  if [ "$?" -eq "0" ]; then
 | 
			
		||||
    _info "Deleted, OK"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
# Arguments:
 | 
			
		||||
#   fulldomain
 | 
			
		||||
# Returns:
 | 
			
		||||
#   _sub_domain=_acme-challenge.www
 | 
			
		||||
#   _zone=domain.com
 | 
			
		||||
#   _system_ns
 | 
			
		||||
_get_autodns_zone() {
 | 
			
		||||
  domain="$1"
 | 
			
		||||
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      # not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    autodns_response="$(_autodns_zone_inquire "$h")"
 | 
			
		||||
 | 
			
		||||
    if [ "$?" -ne "0" ]; then
 | 
			
		||||
      _err "invalid domain"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$autodns_response" "<summary>1</summary>" >/dev/null; then
 | 
			
		||||
      _zone="$(echo "$autodns_response" | _egrep_o '<name>[^<]*</name>' | cut -d '>' -f 2 | cut -d '<' -f 1)"
 | 
			
		||||
      _system_ns="$(echo "$autodns_response" | _egrep_o '<system_ns>[^<]*</system_ns>' | cut -d '>' -f 2 | cut -d '<' -f 1)"
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_build_request_auth_xml() {
 | 
			
		||||
  printf "<auth>
 | 
			
		||||
    <user>%s</user>
 | 
			
		||||
    <password>%s</password>
 | 
			
		||||
    <context>%s</context>
 | 
			
		||||
  </auth>" "$AUTODNS_USER" "$AUTODNS_PASSWORD" "$AUTODNS_CONTEXT"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Arguments:
 | 
			
		||||
#   zone
 | 
			
		||||
_build_zone_inquire_xml() {
 | 
			
		||||
  printf "<?xml version=\"1.0\" encoding=\"UTF-8\"?>
 | 
			
		||||
  <request>
 | 
			
		||||
    %s
 | 
			
		||||
    <task>
 | 
			
		||||
      <code>0205</code>
 | 
			
		||||
      <view>
 | 
			
		||||
        <children>1</children>
 | 
			
		||||
        <limit>1</limit>
 | 
			
		||||
      </view>
 | 
			
		||||
      <where>
 | 
			
		||||
        <key>name</key>
 | 
			
		||||
        <operator>eq</operator>
 | 
			
		||||
        <value>%s</value>
 | 
			
		||||
      </where>
 | 
			
		||||
    </task>
 | 
			
		||||
  </request>" "$(_build_request_auth_xml)" "$1"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Arguments:
 | 
			
		||||
#   zone
 | 
			
		||||
#   subdomain
 | 
			
		||||
#   txtvalue
 | 
			
		||||
#   system_ns
 | 
			
		||||
_build_zone_update_xml() {
 | 
			
		||||
  printf "<?xml version=\"1.0\" encoding=\"UTF-8\"?>
 | 
			
		||||
  <request>
 | 
			
		||||
    %s
 | 
			
		||||
    <task>
 | 
			
		||||
      <code>0202001</code>
 | 
			
		||||
      <default>
 | 
			
		||||
        <rr_add>
 | 
			
		||||
          <name>%s</name>
 | 
			
		||||
          <ttl>600</ttl>
 | 
			
		||||
          <type>TXT</type>
 | 
			
		||||
          <value>%s</value>
 | 
			
		||||
        </rr_add>
 | 
			
		||||
      </default>
 | 
			
		||||
      <zone>
 | 
			
		||||
        <name>%s</name>
 | 
			
		||||
        <system_ns>%s</system_ns>
 | 
			
		||||
      </zone>
 | 
			
		||||
    </task>
 | 
			
		||||
  </request>" "$(_build_request_auth_xml)" "$2" "$3" "$1" "$4"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Arguments:
 | 
			
		||||
#   zone
 | 
			
		||||
_autodns_zone_inquire() {
 | 
			
		||||
  request_data="$(_build_zone_inquire_xml "$1")"
 | 
			
		||||
  autodns_response="$(_autodns_api_call "$request_data")"
 | 
			
		||||
  ret="$?"
 | 
			
		||||
 | 
			
		||||
  printf "%s" "$autodns_response"
 | 
			
		||||
  return "$ret"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Arguments:
 | 
			
		||||
#   zone
 | 
			
		||||
#   subdomain
 | 
			
		||||
#   txtvalue
 | 
			
		||||
#   system_ns
 | 
			
		||||
_autodns_zone_update() {
 | 
			
		||||
  request_data="$(_build_zone_update_xml "$1" "$2" "$3" "$4")"
 | 
			
		||||
  autodns_response="$(_autodns_api_call "$request_data")"
 | 
			
		||||
  ret="$?"
 | 
			
		||||
 | 
			
		||||
  printf "%s" "$autodns_response"
 | 
			
		||||
  return "$ret"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Arguments:
 | 
			
		||||
#   zone
 | 
			
		||||
#   subdomain
 | 
			
		||||
#   txtvalue
 | 
			
		||||
#   system_ns
 | 
			
		||||
_autodns_zone_cleanup() {
 | 
			
		||||
  request_data="$(_build_zone_update_xml "$1" "$2" "$3" "$4")"
 | 
			
		||||
  # replace 'rr_add>' with 'rr_rem>' in request_data
 | 
			
		||||
  request_data="$(printf -- "%s" "$request_data" | sed 's/rr_add>/rr_rem>/g')"
 | 
			
		||||
  autodns_response="$(_autodns_api_call "$request_data")"
 | 
			
		||||
  ret="$?"
 | 
			
		||||
 | 
			
		||||
  printf "%s" "$autodns_response"
 | 
			
		||||
  return "$ret"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Arguments:
 | 
			
		||||
#   request_data
 | 
			
		||||
_autodns_api_call() {
 | 
			
		||||
  request_data="$1"
 | 
			
		||||
 | 
			
		||||
  _debug request_data "$request_data"
 | 
			
		||||
 | 
			
		||||
  autodns_response="$(_post "$request_data" "$AUTODNS_API")"
 | 
			
		||||
  ret="$?"
 | 
			
		||||
 | 
			
		||||
  _debug autodns_response "$autodns_response"
 | 
			
		||||
 | 
			
		||||
  if [ "$ret" -ne "0" ]; then
 | 
			
		||||
    _err "error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if _contains "$autodns_response" "<type>success</type>" >/dev/null; then
 | 
			
		||||
    _info "success"
 | 
			
		||||
    printf "%s" "$autodns_response"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										340
									
								
								dnsapi/dns_aws.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										340
									
								
								dnsapi/dns_aws.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,340 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
#AWS_ACCESS_KEY_ID="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
#
 | 
			
		||||
#AWS_SECRET_ACCESS_KEY="xxxxxxx"
 | 
			
		||||
 | 
			
		||||
#This is the Amazon Route53 api wrapper for acme.sh
 | 
			
		||||
 | 
			
		||||
AWS_HOST="route53.amazonaws.com"
 | 
			
		||||
AWS_URL="https://$AWS_HOST"
 | 
			
		||||
 | 
			
		||||
AWS_WIKI="https://github.com/Neilpang/acme.sh/wiki/How-to-use-Amazon-Route53-API"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_myapi_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_aws_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  AWS_ACCESS_KEY_ID="${AWS_ACCESS_KEY_ID:-$(_readaccountconf_mutable AWS_ACCESS_KEY_ID)}"
 | 
			
		||||
  AWS_SECRET_ACCESS_KEY="${AWS_SECRET_ACCESS_KEY:-$(_readaccountconf_mutable AWS_SECRET_ACCESS_KEY)}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AWS_ACCESS_KEY_ID" ] || [ -z "$AWS_SECRET_ACCESS_KEY" ]; then
 | 
			
		||||
    _use_container_role || _use_instance_role
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AWS_ACCESS_KEY_ID" ] || [ -z "$AWS_SECRET_ACCESS_KEY" ]; then
 | 
			
		||||
    AWS_ACCESS_KEY_ID=""
 | 
			
		||||
    AWS_SECRET_ACCESS_KEY=""
 | 
			
		||||
    _err "You haven't specifed the aws route53 api key id and and api key secret yet."
 | 
			
		||||
    _err "Please create your key and try again. see $(__green $AWS_WIKI)"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save for future use, unless using a role which will be fetched as needed
 | 
			
		||||
  if [ -z "$_using_role" ]; then
 | 
			
		||||
    _saveaccountconf_mutable AWS_ACCESS_KEY_ID "$AWS_ACCESS_KEY_ID"
 | 
			
		||||
    _saveaccountconf_mutable AWS_SECRET_ACCESS_KEY "$AWS_SECRET_ACCESS_KEY"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _info "Geting existing records for $fulldomain"
 | 
			
		||||
  if ! aws_rest GET "2013-04-01$_domain_id/rrset" "name=$fulldomain&type=TXT"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if _contains "$response" "<Name>$fulldomain.</Name>"; then
 | 
			
		||||
    _resource_record="$(echo "$response" | sed 's/<ResourceRecordSet>/"/g' | tr '"' "\n" | grep "<Name>$fulldomain.</Name>" | _egrep_o "<ResourceRecords.*</ResourceRecords>" | sed "s/<ResourceRecords>//" | sed "s#</ResourceRecords>##")"
 | 
			
		||||
    _debug "_resource_record" "$_resource_record"
 | 
			
		||||
  else
 | 
			
		||||
    _debug "single new add"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$_resource_record" ] && _contains "$response" "$txtvalue"; then
 | 
			
		||||
    _info "The TXT record already exists. Skipping."
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "Adding records"
 | 
			
		||||
 | 
			
		||||
  _aws_tmpl_xml="<ChangeResourceRecordSetsRequest xmlns=\"https://route53.amazonaws.com/doc/2013-04-01/\"><ChangeBatch><Changes><Change><Action>UPSERT</Action><ResourceRecordSet><Name>$fulldomain</Name><Type>TXT</Type><TTL>300</TTL><ResourceRecords>$_resource_record<ResourceRecord><Value>\"$txtvalue\"</Value></ResourceRecord></ResourceRecords></ResourceRecordSet></Change></Changes></ChangeBatch></ChangeResourceRecordSetsRequest>"
 | 
			
		||||
 | 
			
		||||
  if aws_rest POST "2013-04-01$_domain_id/rrset/" "" "$_aws_tmpl_xml" && _contains "$response" "ChangeResourceRecordSetsResponse"; then
 | 
			
		||||
    _info "TXT record updated successfully."
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_aws_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  AWS_ACCESS_KEY_ID="${AWS_ACCESS_KEY_ID:-$(_readaccountconf_mutable AWS_ACCESS_KEY_ID)}"
 | 
			
		||||
  AWS_SECRET_ACCESS_KEY="${AWS_SECRET_ACCESS_KEY:-$(_readaccountconf_mutable AWS_SECRET_ACCESS_KEY)}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AWS_ACCESS_KEY_ID" ] || [ -z "$AWS_SECRET_ACCESS_KEY" ]; then
 | 
			
		||||
    _use_container_role || _use_instance_role
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _info "Getting existing records for $fulldomain"
 | 
			
		||||
  if ! aws_rest GET "2013-04-01$_domain_id/rrset" "name=$fulldomain&type=TXT"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if _contains "$response" "<Name>$fulldomain.</Name>"; then
 | 
			
		||||
    _resource_record="$(echo "$response" | sed 's/<ResourceRecordSet>/"/g' | tr '"' "\n" | grep "<Name>$fulldomain.</Name>" | _egrep_o "<ResourceRecords.*</ResourceRecords>" | sed "s/<ResourceRecords>//" | sed "s#</ResourceRecords>##")"
 | 
			
		||||
    _debug "_resource_record" "$_resource_record"
 | 
			
		||||
  else
 | 
			
		||||
    _debug "no records exist, skip"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _aws_tmpl_xml="<ChangeResourceRecordSetsRequest xmlns=\"https://route53.amazonaws.com/doc/2013-04-01/\"><ChangeBatch><Changes><Change><Action>DELETE</Action><ResourceRecordSet><ResourceRecords>$_resource_record</ResourceRecords><Name>$fulldomain.</Name><Type>TXT</Type><TTL>300</TTL></ResourceRecordSet></Change></Changes></ChangeBatch></ChangeResourceRecordSetsRequest>"
 | 
			
		||||
 | 
			
		||||
  if aws_rest POST "2013-04-01$_domain_id/rrset/" "" "$_aws_tmpl_xml" && _contains "$response" "ChangeResourceRecordSetsResponse"; then
 | 
			
		||||
    _info "TXT record deleted successfully."
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  if aws_rest GET "2013-04-01/hostedzone"; then
 | 
			
		||||
    while true; do
 | 
			
		||||
      h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
      _debug2 "Checking domain: $h"
 | 
			
		||||
      if [ -z "$h" ]; then
 | 
			
		||||
        if _contains "$response" "<IsTruncated>true</IsTruncated>" && _contains "$response" "<NextMarker>"; then
 | 
			
		||||
          _debug "IsTruncated"
 | 
			
		||||
          _nextMarker="$(echo "$response" | _egrep_o "<NextMarker>.*</NextMarker>" | cut -d '>' -f 2 | cut -d '<' -f 1)"
 | 
			
		||||
          _debug "NextMarker" "$_nextMarker"
 | 
			
		||||
          if aws_rest GET "2013-04-01/hostedzone" "marker=$_nextMarker"; then
 | 
			
		||||
            _debug "Truncated request OK"
 | 
			
		||||
            i=2
 | 
			
		||||
            p=1
 | 
			
		||||
            continue
 | 
			
		||||
          else
 | 
			
		||||
            _err "Truncated request error."
 | 
			
		||||
          fi
 | 
			
		||||
        fi
 | 
			
		||||
        #not valid
 | 
			
		||||
        _err "Invalid domain"
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
 | 
			
		||||
      if _contains "$response" "<Name>$h.</Name>"; then
 | 
			
		||||
        hostedzone="$(echo "$response" | sed 's/<HostedZone>/#&/g' | tr '#' '\n' | _egrep_o "<HostedZone><Id>[^<]*<.Id><Name>$h.<.Name>.*<PrivateZone>false<.PrivateZone>.*<.HostedZone>")"
 | 
			
		||||
        _debug hostedzone "$hostedzone"
 | 
			
		||||
        if [ "$hostedzone" ]; then
 | 
			
		||||
          _domain_id=$(printf "%s\n" "$hostedzone" | _egrep_o "<Id>.*<.Id>" | head -n 1 | _egrep_o ">.*<" | tr -d "<>")
 | 
			
		||||
          if [ "$_domain_id" ]; then
 | 
			
		||||
            _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
            _domain=$h
 | 
			
		||||
            return 0
 | 
			
		||||
          fi
 | 
			
		||||
          _err "Can't find domain with id: $h"
 | 
			
		||||
          return 1
 | 
			
		||||
        fi
 | 
			
		||||
      fi
 | 
			
		||||
      p=$i
 | 
			
		||||
      i=$(_math "$i" + 1)
 | 
			
		||||
    done
 | 
			
		||||
  fi
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_use_container_role() {
 | 
			
		||||
  # automatically set if running inside ECS
 | 
			
		||||
  if [ -z "$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" ]; then
 | 
			
		||||
    _debug "No ECS environment variable detected"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _use_metadata "169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_use_instance_role() {
 | 
			
		||||
  _url="http://169.254.169.254/latest/meta-data/iam/security-credentials/"
 | 
			
		||||
  _debug "_url" "$_url"
 | 
			
		||||
  if ! _get "$_url" true 1 | _head_n 1 | grep -Fq 200; then
 | 
			
		||||
    _debug "Unable to fetch IAM role from instance metadata"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _aws_role=$(_get "$_url" "" 1)
 | 
			
		||||
  _debug "_aws_role" "$_aws_role"
 | 
			
		||||
  _use_metadata "$_url$_aws_role"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_use_metadata() {
 | 
			
		||||
  _aws_creds="$(
 | 
			
		||||
    _get "$1" "" 1 \
 | 
			
		||||
      | _normalizeJson \
 | 
			
		||||
      | tr '{,}' '\n' \
 | 
			
		||||
      | while read -r _line; do
 | 
			
		||||
        _key="$(echo "${_line%%:*}" | tr -d '"')"
 | 
			
		||||
        _value="${_line#*:}"
 | 
			
		||||
        _debug3 "_key" "$_key"
 | 
			
		||||
        _secure_debug3 "_value" "$_value"
 | 
			
		||||
        case "$_key" in
 | 
			
		||||
          AccessKeyId) echo "AWS_ACCESS_KEY_ID=$_value" ;;
 | 
			
		||||
          SecretAccessKey) echo "AWS_SECRET_ACCESS_KEY=$_value" ;;
 | 
			
		||||
          Token) echo "AWS_SESSION_TOKEN=$_value" ;;
 | 
			
		||||
        esac
 | 
			
		||||
      done \
 | 
			
		||||
        | paste -sd' ' -
 | 
			
		||||
  )"
 | 
			
		||||
  _secure_debug "_aws_creds" "$_aws_creds"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$_aws_creds" ]; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  eval "$_aws_creds"
 | 
			
		||||
  _using_role=true
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#method uri qstr data
 | 
			
		||||
aws_rest() {
 | 
			
		||||
  mtd="$1"
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  qsr="$3"
 | 
			
		||||
  data="$4"
 | 
			
		||||
 | 
			
		||||
  _debug mtd "$mtd"
 | 
			
		||||
  _debug ep "$ep"
 | 
			
		||||
  _debug qsr "$qsr"
 | 
			
		||||
  _debug data "$data"
 | 
			
		||||
 | 
			
		||||
  CanonicalURI="/$ep"
 | 
			
		||||
  _debug2 CanonicalURI "$CanonicalURI"
 | 
			
		||||
 | 
			
		||||
  CanonicalQueryString="$qsr"
 | 
			
		||||
  _debug2 CanonicalQueryString "$CanonicalQueryString"
 | 
			
		||||
 | 
			
		||||
  RequestDate="$(date -u +"%Y%m%dT%H%M%SZ")"
 | 
			
		||||
  _debug2 RequestDate "$RequestDate"
 | 
			
		||||
 | 
			
		||||
  #RequestDate="20161120T141056Z" ##############
 | 
			
		||||
 | 
			
		||||
  export _H1="x-amz-date: $RequestDate"
 | 
			
		||||
 | 
			
		||||
  aws_host="$AWS_HOST"
 | 
			
		||||
  CanonicalHeaders="host:$aws_host\nx-amz-date:$RequestDate\n"
 | 
			
		||||
  SignedHeaders="host;x-amz-date"
 | 
			
		||||
  if [ -n "$AWS_SESSION_TOKEN" ]; then
 | 
			
		||||
    export _H3="x-amz-security-token: $AWS_SESSION_TOKEN"
 | 
			
		||||
    CanonicalHeaders="${CanonicalHeaders}x-amz-security-token:$AWS_SESSION_TOKEN\n"
 | 
			
		||||
    SignedHeaders="${SignedHeaders};x-amz-security-token"
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 CanonicalHeaders "$CanonicalHeaders"
 | 
			
		||||
  _debug2 SignedHeaders "$SignedHeaders"
 | 
			
		||||
 | 
			
		||||
  RequestPayload="$data"
 | 
			
		||||
  _debug2 RequestPayload "$RequestPayload"
 | 
			
		||||
 | 
			
		||||
  Hash="sha256"
 | 
			
		||||
 | 
			
		||||
  CanonicalRequest="$mtd\n$CanonicalURI\n$CanonicalQueryString\n$CanonicalHeaders\n$SignedHeaders\n$(printf "%s" "$RequestPayload" | _digest "$Hash" hex)"
 | 
			
		||||
  _debug2 CanonicalRequest "$CanonicalRequest"
 | 
			
		||||
 | 
			
		||||
  HashedCanonicalRequest="$(printf "$CanonicalRequest%s" | _digest "$Hash" hex)"
 | 
			
		||||
  _debug2 HashedCanonicalRequest "$HashedCanonicalRequest"
 | 
			
		||||
 | 
			
		||||
  Algorithm="AWS4-HMAC-SHA256"
 | 
			
		||||
  _debug2 Algorithm "$Algorithm"
 | 
			
		||||
 | 
			
		||||
  RequestDateOnly="$(echo "$RequestDate" | cut -c 1-8)"
 | 
			
		||||
  _debug2 RequestDateOnly "$RequestDateOnly"
 | 
			
		||||
 | 
			
		||||
  Region="us-east-1"
 | 
			
		||||
  Service="route53"
 | 
			
		||||
 | 
			
		||||
  CredentialScope="$RequestDateOnly/$Region/$Service/aws4_request"
 | 
			
		||||
  _debug2 CredentialScope "$CredentialScope"
 | 
			
		||||
 | 
			
		||||
  StringToSign="$Algorithm\n$RequestDate\n$CredentialScope\n$HashedCanonicalRequest"
 | 
			
		||||
 | 
			
		||||
  _debug2 StringToSign "$StringToSign"
 | 
			
		||||
 | 
			
		||||
  kSecret="AWS4$AWS_SECRET_ACCESS_KEY"
 | 
			
		||||
 | 
			
		||||
  #kSecret="wJalrXUtnFEMI/K7MDENG+bPxRfiCYEXAMPLEKEY" ############################
 | 
			
		||||
 | 
			
		||||
  _secure_debug2 kSecret "$kSecret"
 | 
			
		||||
 | 
			
		||||
  kSecretH="$(printf "%s" "$kSecret" | _hex_dump | tr -d " ")"
 | 
			
		||||
  _secure_debug2 kSecretH "$kSecretH"
 | 
			
		||||
 | 
			
		||||
  kDateH="$(printf "$RequestDateOnly%s" | _hmac "$Hash" "$kSecretH" hex)"
 | 
			
		||||
  _debug2 kDateH "$kDateH"
 | 
			
		||||
 | 
			
		||||
  kRegionH="$(printf "$Region%s" | _hmac "$Hash" "$kDateH" hex)"
 | 
			
		||||
  _debug2 kRegionH "$kRegionH"
 | 
			
		||||
 | 
			
		||||
  kServiceH="$(printf "$Service%s" | _hmac "$Hash" "$kRegionH" hex)"
 | 
			
		||||
  _debug2 kServiceH "$kServiceH"
 | 
			
		||||
 | 
			
		||||
  kSigningH="$(printf "%s" "aws4_request" | _hmac "$Hash" "$kServiceH" hex)"
 | 
			
		||||
  _debug2 kSigningH "$kSigningH"
 | 
			
		||||
 | 
			
		||||
  signature="$(printf "$StringToSign%s" | _hmac "$Hash" "$kSigningH" hex)"
 | 
			
		||||
  _debug2 signature "$signature"
 | 
			
		||||
 | 
			
		||||
  Authorization="$Algorithm Credential=$AWS_ACCESS_KEY_ID/$CredentialScope, SignedHeaders=$SignedHeaders, Signature=$signature"
 | 
			
		||||
  _debug2 Authorization "$Authorization"
 | 
			
		||||
 | 
			
		||||
  _H2="Authorization: $Authorization"
 | 
			
		||||
  _debug _H2 "$_H2"
 | 
			
		||||
 | 
			
		||||
  url="$AWS_URL/$ep"
 | 
			
		||||
  if [ "$qsr" ]; then
 | 
			
		||||
    url="$AWS_URL/$ep?$qsr"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$mtd" = "GET" ]; then
 | 
			
		||||
    response="$(_get "$url")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_post "$data" "$url")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _ret="$?"
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  if [ "$_ret" = "0" ]; then
 | 
			
		||||
    if _contains "$response" "<ErrorResponse"; then
 | 
			
		||||
      _err "Response error:$response"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return "$_ret"
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										348
									
								
								dnsapi/dns_azure.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										348
									
								
								dnsapi/dns_azure.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,348 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
WIKI="https://github.com/Neilpang/acme.sh/wiki/How-to-use-Azure-DNS"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
# Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
# Used to add txt record
 | 
			
		||||
#
 | 
			
		||||
# Ref: https://docs.microsoft.com/en-us/rest/api/dns/recordsets/createorupdate
 | 
			
		||||
#
 | 
			
		||||
dns_azure_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  AZUREDNS_SUBSCRIPTIONID="${AZUREDNS_SUBSCRIPTIONID:-$(_readaccountconf_mutable AZUREDNS_SUBSCRIPTIONID)}"
 | 
			
		||||
  AZUREDNS_TENANTID="${AZUREDNS_TENANTID:-$(_readaccountconf_mutable AZUREDNS_TENANTID)}"
 | 
			
		||||
  AZUREDNS_APPID="${AZUREDNS_APPID:-$(_readaccountconf_mutable AZUREDNS_APPID)}"
 | 
			
		||||
  AZUREDNS_CLIENTSECRET="${AZUREDNS_CLIENTSECRET:-$(_readaccountconf_mutable AZUREDNS_CLIENTSECRET)}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AZUREDNS_SUBSCRIPTIONID" ]; then
 | 
			
		||||
    AZUREDNS_SUBSCRIPTIONID=""
 | 
			
		||||
    AZUREDNS_TENANTID=""
 | 
			
		||||
    AZUREDNS_APPID=""
 | 
			
		||||
    AZUREDNS_CLIENTSECRET=""
 | 
			
		||||
    _err "You didn't specify the Azure Subscription ID "
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AZUREDNS_TENANTID" ]; then
 | 
			
		||||
    AZUREDNS_SUBSCRIPTIONID=""
 | 
			
		||||
    AZUREDNS_TENANTID=""
 | 
			
		||||
    AZUREDNS_APPID=""
 | 
			
		||||
    AZUREDNS_CLIENTSECRET=""
 | 
			
		||||
    _err "You didn't specify the Azure Tenant ID "
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AZUREDNS_APPID" ]; then
 | 
			
		||||
    AZUREDNS_SUBSCRIPTIONID=""
 | 
			
		||||
    AZUREDNS_TENANTID=""
 | 
			
		||||
    AZUREDNS_APPID=""
 | 
			
		||||
    AZUREDNS_CLIENTSECRET=""
 | 
			
		||||
    _err "You didn't specify the Azure App ID"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AZUREDNS_CLIENTSECRET" ]; then
 | 
			
		||||
    AZUREDNS_SUBSCRIPTIONID=""
 | 
			
		||||
    AZUREDNS_TENANTID=""
 | 
			
		||||
    AZUREDNS_APPID=""
 | 
			
		||||
    AZUREDNS_CLIENTSECRET=""
 | 
			
		||||
    _err "You didn't specify the Azure Client Secret"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  #save account details to account conf file.
 | 
			
		||||
  _saveaccountconf_mutable AZUREDNS_SUBSCRIPTIONID "$AZUREDNS_SUBSCRIPTIONID"
 | 
			
		||||
  _saveaccountconf_mutable AZUREDNS_TENANTID "$AZUREDNS_TENANTID"
 | 
			
		||||
  _saveaccountconf_mutable AZUREDNS_APPID "$AZUREDNS_APPID"
 | 
			
		||||
  _saveaccountconf_mutable AZUREDNS_CLIENTSECRET "$AZUREDNS_CLIENTSECRET"
 | 
			
		||||
 | 
			
		||||
  accesstoken=$(_azure_getaccess_token "$AZUREDNS_TENANTID" "$AZUREDNS_APPID" "$AZUREDNS_CLIENTSECRET")
 | 
			
		||||
 | 
			
		||||
  if ! _get_root "$fulldomain" "$AZUREDNS_SUBSCRIPTIONID" "$accesstoken"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  acmeRecordURI="https://management.azure.com$(printf '%s' "$_domain_id" | sed 's/\\//g')/TXT/$_sub_domain?api-version=2017-09-01"
 | 
			
		||||
  _debug "$acmeRecordURI"
 | 
			
		||||
  # Get existing TXT record
 | 
			
		||||
  _azure_rest GET "$acmeRecordURI" "" "$accesstoken"
 | 
			
		||||
  values="{\"value\":[\"$txtvalue\"]}"
 | 
			
		||||
  timestamp="$(_time)"
 | 
			
		||||
  if [ "$_code" = "200" ]; then
 | 
			
		||||
    vlist="$(echo "$response" | _egrep_o "\"value\"\\s*:\\s*\\[\\s*\"[^\"]*\"\\s*]" | cut -d : -f 2 | tr -d "[]\"")"
 | 
			
		||||
    _debug "existing TXT found"
 | 
			
		||||
    _debug "$vlist"
 | 
			
		||||
    existingts="$(echo "$response" | _egrep_o "\"acmetscheck\"\\s*:\\s*\"[^\"]*\"" | _head_n 1 | cut -d : -f 2 | tr -d "\"")"
 | 
			
		||||
    if [ -z "$existingts" ]; then
 | 
			
		||||
      # the record was not created by acme.sh. Copy the exisiting entires
 | 
			
		||||
      existingts=$timestamp
 | 
			
		||||
    fi
 | 
			
		||||
    _diff="$(_math "$timestamp - $existingts")"
 | 
			
		||||
    _debug "existing txt age: $_diff"
 | 
			
		||||
    # only use recently added records and discard if older than 2 hours because they are probably orphaned
 | 
			
		||||
    if [ "$_diff" -lt 7200 ]; then
 | 
			
		||||
      _debug "existing txt value: $vlist"
 | 
			
		||||
      for v in $vlist; do
 | 
			
		||||
        values="$values ,{\"value\":[\"$v\"]}"
 | 
			
		||||
      done
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  # Add the txtvalue TXT Record
 | 
			
		||||
  body="{\"properties\":{\"metadata\":{\"acmetscheck\":\"$timestamp\"},\"TTL\":10, \"TXTRecords\":[$values]}}"
 | 
			
		||||
  _azure_rest PUT "$acmeRecordURI" "$body" "$accesstoken"
 | 
			
		||||
  if [ "$_code" = "200" ] || [ "$_code" = '201' ]; then
 | 
			
		||||
    _info "validation value added"
 | 
			
		||||
    return 0
 | 
			
		||||
  else
 | 
			
		||||
    _err "error adding validation value ($_code)"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Usage: fulldomain txtvalue
 | 
			
		||||
# Used to remove the txt record after validation
 | 
			
		||||
#
 | 
			
		||||
# Ref: https://docs.microsoft.com/en-us/rest/api/dns/recordsets/delete
 | 
			
		||||
#
 | 
			
		||||
dns_azure_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  AZUREDNS_SUBSCRIPTIONID="${AZUREDNS_SUBSCRIPTIONID:-$(_readaccountconf_mutable AZUREDNS_SUBSCRIPTIONID)}"
 | 
			
		||||
  AZUREDNS_TENANTID="${AZUREDNS_TENANTID:-$(_readaccountconf_mutable AZUREDNS_TENANTID)}"
 | 
			
		||||
  AZUREDNS_APPID="${AZUREDNS_APPID:-$(_readaccountconf_mutable AZUREDNS_APPID)}"
 | 
			
		||||
  AZUREDNS_CLIENTSECRET="${AZUREDNS_CLIENTSECRET:-$(_readaccountconf_mutable AZUREDNS_CLIENTSECRET)}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AZUREDNS_SUBSCRIPTIONID" ]; then
 | 
			
		||||
    AZUREDNS_SUBSCRIPTIONID=""
 | 
			
		||||
    AZUREDNS_TENANTID=""
 | 
			
		||||
    AZUREDNS_APPID=""
 | 
			
		||||
    AZUREDNS_CLIENTSECRET=""
 | 
			
		||||
    _err "You didn't specify the Azure Subscription ID "
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AZUREDNS_TENANTID" ]; then
 | 
			
		||||
    AZUREDNS_SUBSCRIPTIONID=""
 | 
			
		||||
    AZUREDNS_TENANTID=""
 | 
			
		||||
    AZUREDNS_APPID=""
 | 
			
		||||
    AZUREDNS_CLIENTSECRET=""
 | 
			
		||||
    _err "You didn't specify the Azure Tenant ID "
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AZUREDNS_APPID" ]; then
 | 
			
		||||
    AZUREDNS_SUBSCRIPTIONID=""
 | 
			
		||||
    AZUREDNS_TENANTID=""
 | 
			
		||||
    AZUREDNS_APPID=""
 | 
			
		||||
    AZUREDNS_CLIENTSECRET=""
 | 
			
		||||
    _err "You didn't specify the Azure App ID"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$AZUREDNS_CLIENTSECRET" ]; then
 | 
			
		||||
    AZUREDNS_SUBSCRIPTIONID=""
 | 
			
		||||
    AZUREDNS_TENANTID=""
 | 
			
		||||
    AZUREDNS_APPID=""
 | 
			
		||||
    AZUREDNS_CLIENTSECRET=""
 | 
			
		||||
    _err "You didn't specify the Azure Client Secret"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  accesstoken=$(_azure_getaccess_token "$AZUREDNS_TENANTID" "$AZUREDNS_APPID" "$AZUREDNS_CLIENTSECRET")
 | 
			
		||||
 | 
			
		||||
  if ! _get_root "$fulldomain" "$AZUREDNS_SUBSCRIPTIONID" "$accesstoken"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  acmeRecordURI="https://management.azure.com$(printf '%s' "$_domain_id" | sed 's/\\//g')/TXT/$_sub_domain?api-version=2017-09-01"
 | 
			
		||||
  _debug "$acmeRecordURI"
 | 
			
		||||
  # Get existing TXT record
 | 
			
		||||
  _azure_rest GET "$acmeRecordURI" "" "$accesstoken"
 | 
			
		||||
  timestamp="$(_time)"
 | 
			
		||||
  if [ "$_code" = "200" ]; then
 | 
			
		||||
    vlist="$(echo "$response" | _egrep_o "\"value\"\\s*:\\s*\\[\\s*\"[^\"]*\"\\s*]" | cut -d : -f 2 | tr -d "[]\"" | grep -v "$txtvalue")"
 | 
			
		||||
    values=""
 | 
			
		||||
    comma=""
 | 
			
		||||
    for v in $vlist; do
 | 
			
		||||
      values="$values$comma{\"value\":[\"$v\"]}"
 | 
			
		||||
      comma=","
 | 
			
		||||
    done
 | 
			
		||||
    if [ -z "$values" ]; then
 | 
			
		||||
      # No values left remove record
 | 
			
		||||
      _debug "removing validation record completely $acmeRecordURI"
 | 
			
		||||
      _azure_rest DELETE "$acmeRecordURI" "" "$accesstoken"
 | 
			
		||||
      if [ "$_code" = "200" ] || [ "$_code" = '204' ]; then
 | 
			
		||||
        _info "validation record removed"
 | 
			
		||||
      else
 | 
			
		||||
        _err "error removing validation record ($_code)"
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
    else
 | 
			
		||||
      # Remove only txtvalue from the TXT Record
 | 
			
		||||
      body="{\"properties\":{\"metadata\":{\"acmetscheck\":\"$timestamp\"},\"TTL\":10, \"TXTRecords\":[$values]}}"
 | 
			
		||||
      _azure_rest PUT "$acmeRecordURI" "$body" "$accesstoken"
 | 
			
		||||
      if [ "$_code" = "200" ] || [ "$_code" = '201' ]; then
 | 
			
		||||
        _info "validation value removed"
 | 
			
		||||
        return 0
 | 
			
		||||
      else
 | 
			
		||||
        _err "error removing validation value ($_code)"
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
###################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_azure_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  accesstoken="$4"
 | 
			
		||||
 | 
			
		||||
  MAX_REQUEST_RETRY_TIMES=5
 | 
			
		||||
  _request_retry_times=0
 | 
			
		||||
  while [ "${_request_retry_times}" -lt "$MAX_REQUEST_RETRY_TIMES" ]; do
 | 
			
		||||
    _debug3 _request_retry_times "$_request_retry_times"
 | 
			
		||||
    export _H1="authorization: Bearer $accesstoken"
 | 
			
		||||
    export _H2="accept: application/json"
 | 
			
		||||
    export _H3="Content-Type: application/json"
 | 
			
		||||
    # clear headers from previous request to avoid getting wrong http code on timeouts
 | 
			
		||||
    :>"$HTTP_HEADER"
 | 
			
		||||
    _debug "$ep"
 | 
			
		||||
    if [ "$m" != "GET" ]; then
 | 
			
		||||
      _secure_debug2 "data $data"
 | 
			
		||||
      response="$(_post "$data" "$ep" "" "$m")"
 | 
			
		||||
    else
 | 
			
		||||
      response="$(_get "$ep")"
 | 
			
		||||
    fi
 | 
			
		||||
    _ret="$?"
 | 
			
		||||
    _secure_debug2 "response $response"
 | 
			
		||||
    _code="$(grep "^HTTP" "$HTTP_HEADER" | _tail_n 1 | cut -d " " -f 2 | tr -d "\\r\\n")"
 | 
			
		||||
    _debug "http response code $_code"
 | 
			
		||||
    if [ "$_code" = "401" ]; then
 | 
			
		||||
      # we have an invalid access token set to expired
 | 
			
		||||
      _saveaccountconf_mutable AZUREDNS_TOKENVALIDTO "0"
 | 
			
		||||
      _err "access denied make sure your Azure settings are correct. See $WIKI"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    # See https://docs.microsoft.com/en-us/azure/architecture/best-practices/retry-service-specific#general-rest-and-retry-guidelines for retryable HTTP codes
 | 
			
		||||
    if [ "$_ret" != "0" ] || [ -z "$_code" ] || [ "$_code" = "408" ] || [ "$_code" = "500" ] || [ "$_code" = "503" ] || [ "$_code" = "504" ]; then
 | 
			
		||||
      _request_retry_times="$(_math "$_request_retry_times" + 1)"
 | 
			
		||||
      _info "REST call error $_code retrying $ep in $_request_retry_times s"
 | 
			
		||||
      _sleep "$_request_retry_times"
 | 
			
		||||
      continue
 | 
			
		||||
    fi
 | 
			
		||||
    break
 | 
			
		||||
  done
 | 
			
		||||
  if [ "$_request_retry_times" = "$MAX_REQUEST_RETRY_TIMES" ]; then
 | 
			
		||||
    _err "Error Azure REST called was retried $MAX_REQUEST_RETRY_TIMES times."
 | 
			
		||||
    _err "Calling $ep failed."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  response="$(echo "$response" | _normalizeJson)"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
## Ref: https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-protocols-oauth-service-to-service#request-an-access-token
 | 
			
		||||
_azure_getaccess_token() {
 | 
			
		||||
  tenantID=$1
 | 
			
		||||
  clientID=$2
 | 
			
		||||
  clientSecret=$3
 | 
			
		||||
 | 
			
		||||
  accesstoken="${AZUREDNS_BEARERTOKEN:-$(_readaccountconf_mutable AZUREDNS_BEARERTOKEN)}"
 | 
			
		||||
  expires_on="${AZUREDNS_TOKENVALIDTO:-$(_readaccountconf_mutable AZUREDNS_TOKENVALIDTO)}"
 | 
			
		||||
 | 
			
		||||
  # can we reuse the bearer token?
 | 
			
		||||
  if [ -n "$accesstoken" ] && [ -n "$expires_on" ]; then
 | 
			
		||||
    if [ "$(_time)" -lt "$expires_on" ]; then
 | 
			
		||||
      # brearer token is still valid - reuse it
 | 
			
		||||
      _debug "reusing bearer token"
 | 
			
		||||
      printf "%s" "$accesstoken"
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _debug "bearer token expired"
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  _debug "getting new bearer token"
 | 
			
		||||
 | 
			
		||||
  export _H1="accept: application/json"
 | 
			
		||||
  export _H2="Content-Type: application/x-www-form-urlencoded"
 | 
			
		||||
 | 
			
		||||
  body="resource=$(printf "%s" 'https://management.core.windows.net/' | _url_encode)&client_id=$(printf "%s" "$clientID" | _url_encode)&client_secret=$(printf "%s" "$clientSecret" | _url_encode)&grant_type=client_credentials"
 | 
			
		||||
  _secure_debug2 "data $body"
 | 
			
		||||
  response="$(_post "$body" "https://login.microsoftonline.com/$tenantID/oauth2/token" "" "POST")"
 | 
			
		||||
  _ret="$?"
 | 
			
		||||
  _secure_debug2 "response $response"
 | 
			
		||||
  response="$(echo "$response" | _normalizeJson)"
 | 
			
		||||
  accesstoken=$(echo "$response" | _egrep_o "\"access_token\":\"[^\"]*\"" | _head_n 1 | cut -d : -f 2 | tr -d \")
 | 
			
		||||
  expires_on=$(echo "$response" | _egrep_o "\"expires_on\":\"[^\"]*\"" | _head_n 1 | cut -d : -f 2 | tr -d \")
 | 
			
		||||
 | 
			
		||||
  if [ -z "$accesstoken" ]; then
 | 
			
		||||
    _err "no acccess token received. Check your Azure settings see $WIKI"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  if [ "$_ret" != "0" ]; then
 | 
			
		||||
    _err "error $response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _saveaccountconf_mutable AZUREDNS_BEARERTOKEN "$accesstoken"
 | 
			
		||||
  _saveaccountconf_mutable AZUREDNS_TOKENVALIDTO "$expires_on"
 | 
			
		||||
  printf "%s" "$accesstoken"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  subscriptionId=$2
 | 
			
		||||
  accesstoken=$3
 | 
			
		||||
  i=1
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  ## Ref: https://docs.microsoft.com/en-us/rest/api/dns/zones/list
 | 
			
		||||
  ## returns up to 100 zones in one response therefore handling more results is not not implemented
 | 
			
		||||
  ## (ZoneListResult with  continuation token for the next page of results)
 | 
			
		||||
  ## Per https://docs.microsoft.com/en-us/azure/azure-subscription-service-limits#dns-limits you are limited to 100 Zone/subscriptions anyways
 | 
			
		||||
  ##
 | 
			
		||||
  _azure_rest GET "https://management.azure.com/subscriptions/$subscriptionId/providers/Microsoft.Network/dnszones?\$top=500&api-version=2017-09-01" "" "$accesstoken"
 | 
			
		||||
  # Find matching domain name is Json response
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug2 "Checking domain: $h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      _err "Invalid domain"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"name\":\"$h\"" >/dev/null; then
 | 
			
		||||
      _domain_id=$(echo "$response" | _egrep_o "\\{\"id\":\"[^\"]*$h\"" | head -n 1 | cut -d : -f 2 | tr -d \")
 | 
			
		||||
      if [ "$_domain_id" ]; then
 | 
			
		||||
        if [ "$i" = 1 ]; then
 | 
			
		||||
          #create the record at the domain apex (@) if only the domain name was provided as --domain-alias
 | 
			
		||||
          _sub_domain="@"
 | 
			
		||||
        else
 | 
			
		||||
          _sub_domain=$(echo "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
        fi
 | 
			
		||||
        _domain=$h
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										202
									
								
								dnsapi/dns_cf.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										202
									
								
								dnsapi/dns_cf.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,202 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
#CF_Key="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
#
 | 
			
		||||
#CF_Email="xxxx@sss.com"
 | 
			
		||||
 | 
			
		||||
CF_Api="https://api.cloudflare.com/client/v4"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_cf_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  CF_Key="${CF_Key:-$(_readaccountconf_mutable CF_Key)}"
 | 
			
		||||
  CF_Email="${CF_Email:-$(_readaccountconf_mutable CF_Email)}"
 | 
			
		||||
  if [ -z "$CF_Key" ] || [ -z "$CF_Email" ]; then
 | 
			
		||||
    CF_Key=""
 | 
			
		||||
    CF_Email=""
 | 
			
		||||
    _err "You didn't specify a Cloudflare api key and email yet."
 | 
			
		||||
    _err "You can get yours from here https://dash.cloudflare.com/profile."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$CF_Email" "@"; then
 | 
			
		||||
    _err "It seems that the CF_Email=$CF_Email is not a valid email address."
 | 
			
		||||
    _err "Please check and retry."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable CF_Key "$CF_Key"
 | 
			
		||||
  _saveaccountconf_mutable CF_Email "$CF_Email"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _cf_rest GET "zones/${_domain_id}/dns_records?type=TXT&name=$fulldomain"
 | 
			
		||||
 | 
			
		||||
  if ! printf "%s" "$response" | grep \"success\":true >/dev/null; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # For wildcard cert, the main root domain and the wildcard domain have the same txt subdomain name, so
 | 
			
		||||
  # we can not use updating anymore.
 | 
			
		||||
  #  count=$(printf "%s\n" "$response" | _egrep_o "\"count\":[^,]*" | cut -d : -f 2)
 | 
			
		||||
  #  _debug count "$count"
 | 
			
		||||
  #  if [ "$count" = "0" ]; then
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  if _cf_rest POST "zones/$_domain_id/dns_records" "{\"type\":\"TXT\",\"name\":\"$fulldomain\",\"content\":\"$txtvalue\",\"ttl\":120}"; then
 | 
			
		||||
    if _contains "$response" "$fulldomain"; then
 | 
			
		||||
      _info "Added, OK"
 | 
			
		||||
      return 0
 | 
			
		||||
    elif _contains "$response" "The record already exists"; then
 | 
			
		||||
      _info "Already exists, OK"
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Add txt record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  _err "Add txt record error."
 | 
			
		||||
  return 1
 | 
			
		||||
  #  else
 | 
			
		||||
  #    _info "Updating record"
 | 
			
		||||
  #    record_id=$(printf "%s\n" "$response" | _egrep_o "\"id\":\"[^\"]*\"" | cut -d : -f 2 | tr -d \" | head -n 1)
 | 
			
		||||
  #    _debug "record_id" "$record_id"
 | 
			
		||||
  #
 | 
			
		||||
  #    _cf_rest PUT "zones/$_domain_id/dns_records/$record_id" "{\"id\":\"$record_id\",\"type\":\"TXT\",\"name\":\"$fulldomain\",\"content\":\"$txtvalue\",\"zone_id\":\"$_domain_id\",\"zone_name\":\"$_domain\"}"
 | 
			
		||||
  #    if [ "$?" = "0" ]; then
 | 
			
		||||
  #      _info "Updated, OK"
 | 
			
		||||
  #      return 0
 | 
			
		||||
  #    fi
 | 
			
		||||
  #    _err "Update error"
 | 
			
		||||
  #    return 1
 | 
			
		||||
  #  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_cf_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  CF_Key="${CF_Key:-$(_readaccountconf_mutable CF_Key)}"
 | 
			
		||||
  CF_Email="${CF_Email:-$(_readaccountconf_mutable CF_Email)}"
 | 
			
		||||
  if [ -z "$CF_Key" ] || [ -z "$CF_Email" ]; then
 | 
			
		||||
    CF_Key=""
 | 
			
		||||
    CF_Email=""
 | 
			
		||||
    _err "You didn't specify a Cloudflare api key and email yet."
 | 
			
		||||
    _err "You can get yours from here https://dash.cloudflare.com/profile."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _cf_rest GET "zones/${_domain_id}/dns_records?type=TXT&name=$fulldomain&content=$txtvalue"
 | 
			
		||||
 | 
			
		||||
  if ! printf "%s" "$response" | grep \"success\":true >/dev/null; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  count=$(printf "%s\n" "$response" | _egrep_o "\"count\":[^,]*" | cut -d : -f 2)
 | 
			
		||||
  _debug count "$count"
 | 
			
		||||
  if [ "$count" = "0" ]; then
 | 
			
		||||
    _info "Don't need to remove."
 | 
			
		||||
  else
 | 
			
		||||
    record_id=$(printf "%s\n" "$response" | _egrep_o "\"id\":\"[^\"]*\"" | cut -d : -f 2 | tr -d \" | head -n 1)
 | 
			
		||||
    _debug "record_id" "$record_id"
 | 
			
		||||
    if [ -z "$record_id" ]; then
 | 
			
		||||
      _err "Can not get record id to remove."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    if ! _cf_rest DELETE "zones/$_domain_id/dns_records/$record_id"; then
 | 
			
		||||
      _err "Delete record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    _contains "$response" '"success":true'
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _cf_rest GET "zones?name=$h"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"name\":\"$h\"" >/dev/null; then
 | 
			
		||||
      _domain_id=$(echo "$response" | _egrep_o "\[.\"id\":\"[^\"]*\"" | _head_n 1 | cut -d : -f 2 | tr -d \")
 | 
			
		||||
      if [ "$_domain_id" ]; then
 | 
			
		||||
        _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
        _domain=$h
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cf_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="X-Auth-Email: $CF_Email"
 | 
			
		||||
  export _H2="X-Auth-Key: $CF_Key"
 | 
			
		||||
  export _H3="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  if [ "$m" != "GET" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$CF_Api/$ep" "" "$m")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$CF_Api/$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										184
									
								
								dnsapi/dns_cloudns.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										184
									
								
								dnsapi/dns_cloudns.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,184 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# Author: Boyan Peychev <boyan at cloudns dot net>
 | 
			
		||||
# Repository: https://github.com/ClouDNS/acme.sh/
 | 
			
		||||
 | 
			
		||||
#CLOUDNS_AUTH_ID=XXXXX
 | 
			
		||||
#CLOUDNS_SUB_AUTH_ID=XXXXX
 | 
			
		||||
#CLOUDNS_AUTH_PASSWORD="YYYYYYYYY"
 | 
			
		||||
CLOUDNS_API="https://api.cloudns.net"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_cloudns_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_cloudns_add() {
 | 
			
		||||
  _info "Using cloudns"
 | 
			
		||||
 | 
			
		||||
  if ! _dns_cloudns_init_check; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  zone="$(_dns_cloudns_get_zone_name "$1")"
 | 
			
		||||
  if [ -z "$zone" ]; then
 | 
			
		||||
    _err "Missing DNS zone at ClouDNS. Please log into your control panel and create the required DNS zone for the initial setup."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  host="$(echo "$1" | sed "s/\.$zone\$//")"
 | 
			
		||||
  record=$2
 | 
			
		||||
 | 
			
		||||
  _debug zone "$zone"
 | 
			
		||||
  _debug host "$host"
 | 
			
		||||
  _debug record "$record"
 | 
			
		||||
 | 
			
		||||
  _info "Adding the TXT record for $1"
 | 
			
		||||
  _dns_cloudns_http_api_call "dns/add-record.json" "domain-name=$zone&record-type=TXT&host=$host&record=$record&ttl=60"
 | 
			
		||||
  if ! _contains "$response" "\"status\":\"Success\""; then
 | 
			
		||||
    _err "Record cannot be added."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _info "Added."
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: dns_cloudns_rm   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_cloudns_rm() {
 | 
			
		||||
  _info "Using cloudns"
 | 
			
		||||
 | 
			
		||||
  if ! _dns_cloudns_init_check; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$zone" ]; then
 | 
			
		||||
    zone="$(_dns_cloudns_get_zone_name "$1")"
 | 
			
		||||
    if [ -z "$zone" ]; then
 | 
			
		||||
      _err "Missing DNS zone at ClouDNS. Please log into your control panel and create the required DNS zone for the initial setup."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  host="$(echo "$1" | sed "s/\.$zone\$//")"
 | 
			
		||||
  record=$2
 | 
			
		||||
 | 
			
		||||
  _dns_cloudns_http_api_call "dns/records.json" "domain-name=$zone&host=$host&type=TXT"
 | 
			
		||||
  if ! _contains "$response" "\"id\":"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  for i in $(echo "$response" | tr '{' "\n" | grep "$record"); do
 | 
			
		||||
    record_id=$(echo "$i" | tr ',' "\n" | grep -E '^"id"' | sed -re 's/^\"id\"\:\"([0-9]+)\"$/\1/g')
 | 
			
		||||
 | 
			
		||||
    if [ ! -z "$record_id" ]; then
 | 
			
		||||
      _debug zone "$zone"
 | 
			
		||||
      _debug host "$host"
 | 
			
		||||
      _debug record "$record"
 | 
			
		||||
      _debug record_id "$record_id"
 | 
			
		||||
 | 
			
		||||
      _info "Deleting the TXT record for $1"
 | 
			
		||||
      _dns_cloudns_http_api_call "dns/delete-record.json" "domain-name=$zone&record-id=$record_id"
 | 
			
		||||
 | 
			
		||||
      if ! _contains "$response" "\"status\":\"Success\""; then
 | 
			
		||||
        _err "The TXT record for $1 cannot be deleted."
 | 
			
		||||
      else
 | 
			
		||||
        _info "Deleted."
 | 
			
		||||
      fi
 | 
			
		||||
    fi
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
_dns_cloudns_init_check() {
 | 
			
		||||
  if [ ! -z "$CLOUDNS_INIT_CHECK_COMPLETED" ]; then
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  CLOUDNS_AUTH_ID="${CLOUDNS_AUTH_ID:-$(_readaccountconf_mutable CLOUDNS_AUTH_ID)}"
 | 
			
		||||
  CLOUDNS_SUB_AUTH_ID="${CLOUDNS_SUB_AUTH_ID:-$(_readaccountconf_mutable CLOUDNS_SUB_AUTH_ID)}"
 | 
			
		||||
  CLOUDNS_AUTH_PASSWORD="${CLOUDNS_AUTH_PASSWORD:-$(_readaccountconf_mutable CLOUDNS_AUTH_PASSWORD)}"
 | 
			
		||||
  if [ -z "$CLOUDNS_AUTH_ID$CLOUDNS_SUB_AUTH_ID" ] || [ -z "$CLOUDNS_AUTH_PASSWORD" ]; then
 | 
			
		||||
    CLOUDNS_AUTH_ID=""
 | 
			
		||||
    CLOUDNS_SUB_AUTH_ID=""
 | 
			
		||||
    CLOUDNS_AUTH_PASSWORD=""
 | 
			
		||||
    _err "You don't specify cloudns api id and password yet."
 | 
			
		||||
    _err "Please create you id and password and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$CLOUDNS_AUTH_ID" ] && [ -z "$CLOUDNS_SUB_AUTH_ID" ]; then
 | 
			
		||||
    _err "CLOUDNS_AUTH_ID or CLOUDNS_SUB_AUTH_ID is not configured"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$CLOUDNS_AUTH_PASSWORD" ]; then
 | 
			
		||||
    _err "CLOUDNS_AUTH_PASSWORD is not configured"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _dns_cloudns_http_api_call "dns/login.json" ""
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "\"status\":\"Success\""; then
 | 
			
		||||
    _err "Invalid CLOUDNS_AUTH_ID or CLOUDNS_AUTH_PASSWORD. Please check your login credentials."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # save the api id and password to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable CLOUDNS_AUTH_ID "$CLOUDNS_AUTH_ID"
 | 
			
		||||
  _saveaccountconf_mutable CLOUDNS_SUB_AUTH_ID "$CLOUDNS_SUB_AUTH_ID"
 | 
			
		||||
  _saveaccountconf_mutable CLOUDNS_AUTH_PASSWORD "$CLOUDNS_AUTH_PASSWORD"
 | 
			
		||||
 | 
			
		||||
  CLOUDNS_INIT_CHECK_COMPLETED=1
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_dns_cloudns_get_zone_name() {
 | 
			
		||||
  i=2
 | 
			
		||||
  while true; do
 | 
			
		||||
    zoneForCheck=$(printf "%s" "$1" | cut -d . -f $i-100)
 | 
			
		||||
 | 
			
		||||
    if [ -z "$zoneForCheck" ]; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    _debug zoneForCheck "$zoneForCheck"
 | 
			
		||||
 | 
			
		||||
    _dns_cloudns_http_api_call "dns/get-zone-info.json" "domain-name=$zoneForCheck"
 | 
			
		||||
 | 
			
		||||
    if ! _contains "$response" "\"status\":\"Failed\""; then
 | 
			
		||||
      echo "$zoneForCheck"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_dns_cloudns_http_api_call() {
 | 
			
		||||
  method=$1
 | 
			
		||||
 | 
			
		||||
  _debug CLOUDNS_AUTH_ID "$CLOUDNS_AUTH_ID"
 | 
			
		||||
  _debug CLOUDNS_SUB_AUTH_ID "$CLOUDNS_SUB_AUTH_ID"
 | 
			
		||||
  _debug CLOUDNS_AUTH_PASSWORD "$CLOUDNS_AUTH_PASSWORD"
 | 
			
		||||
 | 
			
		||||
  if [ ! -z "$CLOUDNS_SUB_AUTH_ID" ]; then
 | 
			
		||||
    auth_user="sub-auth-id=$CLOUDNS_SUB_AUTH_ID"
 | 
			
		||||
  else
 | 
			
		||||
    auth_user="auth-id=$CLOUDNS_AUTH_ID"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$2" ]; then
 | 
			
		||||
    data="$auth_user&auth-password=$CLOUDNS_AUTH_PASSWORD"
 | 
			
		||||
  else
 | 
			
		||||
    data="$auth_user&auth-password=$CLOUDNS_AUTH_PASSWORD&$2"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  response="$(_get "$CLOUDNS_API/$method?$data")"
 | 
			
		||||
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										253
									
								
								dnsapi/dns_conoha.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										253
									
								
								dnsapi/dns_conoha.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,253 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
CONOHA_DNS_EP_PREFIX_REGEXP="https://dns-service\."
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_conoha_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_conoha_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _info "Using conoha"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  _debug "Check uesrname and password"
 | 
			
		||||
  CONOHA_Username="${CONOHA_Username:-$(_readaccountconf_mutable CONOHA_Username)}"
 | 
			
		||||
  CONOHA_Password="${CONOHA_Password:-$(_readaccountconf_mutable CONOHA_Password)}"
 | 
			
		||||
  CONOHA_TenantId="${CONOHA_TenantId:-$(_readaccountconf_mutable CONOHA_TenantId)}"
 | 
			
		||||
  CONOHA_IdentityServiceApi="${CONOHA_IdentityServiceApi:-$(_readaccountconf_mutable CONOHA_IdentityServiceApi)}"
 | 
			
		||||
  if [ -z "$CONOHA_Username" ] || [ -z "$CONOHA_Password" ] || [ -z "$CONOHA_TenantId" ] || [ -z "$CONOHA_IdentityServiceApi" ]; then
 | 
			
		||||
    CONOHA_Username=""
 | 
			
		||||
    CONOHA_Password=""
 | 
			
		||||
    CONOHA_TenantId=""
 | 
			
		||||
    CONOHA_IdentityServiceApi=""
 | 
			
		||||
    _err "You didn't specify a conoha api username and password yet."
 | 
			
		||||
    _err "Please create the user and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf_mutable CONOHA_Username "$CONOHA_Username"
 | 
			
		||||
  _saveaccountconf_mutable CONOHA_Password "$CONOHA_Password"
 | 
			
		||||
  _saveaccountconf_mutable CONOHA_TenantId "$CONOHA_TenantId"
 | 
			
		||||
  _saveaccountconf_mutable CONOHA_IdentityServiceApi "$CONOHA_IdentityServiceApi"
 | 
			
		||||
 | 
			
		||||
  if token="$(_conoha_get_accesstoken "$CONOHA_IdentityServiceApi/tokens" "$CONOHA_Username" "$CONOHA_Password" "$CONOHA_TenantId")"; then
 | 
			
		||||
    accesstoken="$(printf "%s" "$token" | sed -n 1p)"
 | 
			
		||||
    CONOHA_Api="$(printf "%s" "$token" | sed -n 2p)"
 | 
			
		||||
  else
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain" "$CONOHA_Api" "$accesstoken"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  body="{\"type\":\"TXT\",\"name\":\"$fulldomain.\",\"data\":\"$txtvalue\",\"ttl\":60}"
 | 
			
		||||
  if _conoha_rest POST "$CONOHA_Api/v1/domains/$_domain_id/records" "$body" "$accesstoken"; then
 | 
			
		||||
    if _contains "$response" '"data":"'"$txtvalue"'"'; then
 | 
			
		||||
      _info "Added, OK"
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Add txt record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _err "Add txt record error."
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: fulldomain txtvalue
 | 
			
		||||
#Remove the txt record after validation.
 | 
			
		||||
dns_conoha_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _info "Using conoha"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  _debug "Check uesrname and password"
 | 
			
		||||
  CONOHA_Username="${CONOHA_Username:-$(_readaccountconf_mutable CONOHA_Username)}"
 | 
			
		||||
  CONOHA_Password="${CONOHA_Password:-$(_readaccountconf_mutable CONOHA_Password)}"
 | 
			
		||||
  CONOHA_TenantId="${CONOHA_TenantId:-$(_readaccountconf_mutable CONOHA_TenantId)}"
 | 
			
		||||
  CONOHA_IdentityServiceApi="${CONOHA_IdentityServiceApi:-$(_readaccountconf_mutable CONOHA_IdentityServiceApi)}"
 | 
			
		||||
  if [ -z "$CONOHA_Username" ] || [ -z "$CONOHA_Password" ] || [ -z "$CONOHA_TenantId" ] || [ -z "$CONOHA_IdentityServiceApi" ]; then
 | 
			
		||||
    CONOHA_Username=""
 | 
			
		||||
    CONOHA_Password=""
 | 
			
		||||
    CONOHA_TenantId=""
 | 
			
		||||
    CONOHA_IdentityServiceApi=""
 | 
			
		||||
    _err "You didn't specify a conoha api username and password yet."
 | 
			
		||||
    _err "Please create the user and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf_mutable CONOHA_Username "$CONOHA_Username"
 | 
			
		||||
  _saveaccountconf_mutable CONOHA_Password "$CONOHA_Password"
 | 
			
		||||
  _saveaccountconf_mutable CONOHA_TenantId "$CONOHA_TenantId"
 | 
			
		||||
  _saveaccountconf_mutable CONOHA_IdentityServiceApi "$CONOHA_IdentityServiceApi"
 | 
			
		||||
 | 
			
		||||
  if token="$(_conoha_get_accesstoken "$CONOHA_IdentityServiceApi/tokens" "$CONOHA_Username" "$CONOHA_Password" "$CONOHA_TenantId")"; then
 | 
			
		||||
    accesstoken="$(printf "%s" "$token" | sed -n 1p)"
 | 
			
		||||
    CONOHA_Api="$(printf "%s" "$token" | sed -n 2p)"
 | 
			
		||||
  else
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain" "$CONOHA_Api" "$accesstoken"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  if ! _conoha_rest GET "$CONOHA_Api/v1/domains/$_domain_id/records" "" "$accesstoken"; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  record_id=$(printf "%s" "$response" | _egrep_o '{[^}]*}' \
 | 
			
		||||
    | grep '"type":"TXT"' | grep "\"data\":\"$txtvalue\"" | _egrep_o "\"id\":\"[^\"]*\"" \
 | 
			
		||||
    | _head_n 1 | cut -d : -f 2 | tr -d \")
 | 
			
		||||
  if [ -z "$record_id" ]; then
 | 
			
		||||
    _err "Can not get record id to remove."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug record_id "$record_id"
 | 
			
		||||
 | 
			
		||||
  _info "Removing the txt record"
 | 
			
		||||
  if ! _conoha_rest DELETE "$CONOHA_Api/v1/domains/$_domain_id/records/$record_id" "" "$accesstoken"; then
 | 
			
		||||
    _err "Delete record error."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_conoha_rest() {
 | 
			
		||||
  m="$1"
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  accesstoken="$4"
 | 
			
		||||
 | 
			
		||||
  export _H1="Accept: application/json"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
  if [ -n "$accesstoken" ]; then
 | 
			
		||||
    export _H3="X-Auth-Token: $accesstoken"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
  if [ "$m" != "GET" ]; then
 | 
			
		||||
    _secure_debug2 data "$data"
 | 
			
		||||
    response="$(_post "$data" "$ep" "" "$m")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
  _ret="$?"
 | 
			
		||||
  _secure_debug2 response "$response"
 | 
			
		||||
  if [ "$_ret" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  response="$(printf "%s" "$response" | _normalizeJson)"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_conoha_get_accesstoken() {
 | 
			
		||||
  ep="$1"
 | 
			
		||||
  username="$2"
 | 
			
		||||
  password="$3"
 | 
			
		||||
  tenantId="$4"
 | 
			
		||||
 | 
			
		||||
  accesstoken="$(_readaccountconf_mutable conoha_accesstoken)"
 | 
			
		||||
  expires="$(_readaccountconf_mutable conoha_tokenvalidto)"
 | 
			
		||||
  CONOHA_Api="$(_readaccountconf_mutable conoha_dns_ep)"
 | 
			
		||||
 | 
			
		||||
  # can we reuse the access token?
 | 
			
		||||
  if [ -n "$accesstoken" ] && [ -n "$expires" ] && [ -n "$CONOHA_Api" ]; then
 | 
			
		||||
    utc_date="$(_utc_date | sed "s/ /T/")"
 | 
			
		||||
    if expr "$utc_date" "<" "$expires" >/dev/null; then
 | 
			
		||||
      # access token is still valid - reuse it
 | 
			
		||||
      _debug "reusing access token"
 | 
			
		||||
      printf "%s\n%s\n" "$accesstoken" "$CONOHA_Api"
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _debug "access token expired"
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  _debug "getting new access token"
 | 
			
		||||
 | 
			
		||||
  body="$(printf '{"auth":{"passwordCredentials":{"username":"%s","password":"%s"},"tenantId":"%s"}}' "$username" "$password" "$tenantId")"
 | 
			
		||||
  if ! _conoha_rest POST "$ep" "$body" ""; then
 | 
			
		||||
    _err error "$response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  accesstoken=$(printf "%s" "$response" | _egrep_o "\"id\":\"[^\"]*\"" | _head_n 1 | cut -d : -f 2 | tr -d \")
 | 
			
		||||
  expires=$(printf "%s" "$response" | _egrep_o "\"expires\":\"[^\"]*\"" | _head_n 1 | cut -d : -f 2-4 | tr -d \" | tr -d Z) #expect UTC
 | 
			
		||||
  if [ -z "$accesstoken" ] || [ -z "$expires" ]; then
 | 
			
		||||
    _err "no acccess token received. Check your Conoha settings see $WIKI"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _saveaccountconf_mutable conoha_accesstoken "$accesstoken"
 | 
			
		||||
  _saveaccountconf_mutable conoha_tokenvalidto "$expires"
 | 
			
		||||
 | 
			
		||||
  CONOHA_Api=$(printf "%s" "$response" | _egrep_o 'publicURL":"'"$CONOHA_DNS_EP_PREFIX_REGEXP"'[^"]*"' | _head_n 1 | cut -d : -f 2-3 | tr -d \")
 | 
			
		||||
  if [ -z "$CONOHA_Api" ]; then
 | 
			
		||||
    _err "failed to get conoha dns endpoint url"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _saveaccountconf_mutable conoha_dns_ep "$CONOHA_Api"
 | 
			
		||||
 | 
			
		||||
  printf "%s\n%s\n" "$accesstoken" "$CONOHA_Api"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain="$1"
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  accesstoken="$3"
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100).
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _conoha_rest GET "$ep/v1/domains?name=$h" "" "$accesstoken"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"name\":\"$h\"" >/dev/null; then
 | 
			
		||||
      _domain_id=$(printf "%s\n" "$response" | _egrep_o "\"id\":\"[^\"]*\"" | head -n 1 | cut -d : -f 2 | tr -d \")
 | 
			
		||||
      if [ "$_domain_id" ]; then
 | 
			
		||||
        _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
        _domain=$h
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										181
									
								
								dnsapi/dns_cx.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										181
									
								
								dnsapi/dns_cx.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,181 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# CloudXNS Domain api
 | 
			
		||||
#
 | 
			
		||||
#CX_Key="1234"
 | 
			
		||||
#
 | 
			
		||||
#CX_Secret="sADDsdasdgdsf"
 | 
			
		||||
 | 
			
		||||
CX_Api="https://www.cloudxns.net/api2"
 | 
			
		||||
 | 
			
		||||
#REST_API
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_cx_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if [ -z "$CX_Key" ] || [ -z "$CX_Secret" ]; then
 | 
			
		||||
    CX_Key=""
 | 
			
		||||
    CX_Secret=""
 | 
			
		||||
    _err "You don't specify cloudxns.net  api key or secret yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  REST_API="$CX_Api"
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf CX_Key "$CX_Key"
 | 
			
		||||
  _saveaccountconf CX_Secret "$CX_Secret"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  add_record "$_domain" "$_sub_domain" "$txtvalue"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_cx_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  REST_API="$CX_Api"
 | 
			
		||||
  if _get_root "$fulldomain"; then
 | 
			
		||||
    record_id=""
 | 
			
		||||
    existing_records "$_domain" "$_sub_domain" "$txtvalue"
 | 
			
		||||
    if [ "$record_id" ]; then
 | 
			
		||||
      _rest DELETE "record/$record_id/$_domain_id" "{}"
 | 
			
		||||
      _info "Deleted record ${fulldomain}"
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#usage:  root  sub
 | 
			
		||||
#return if the sub record already exists.
 | 
			
		||||
#echos the existing records count.
 | 
			
		||||
# '0' means doesn't exist
 | 
			
		||||
existing_records() {
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  root=$1
 | 
			
		||||
  sub=$2
 | 
			
		||||
  if ! _rest GET "record/$_domain_id?:domain_id?host_id=0&offset=0&row_num=100"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  seg=$(printf "%s\n" "$response" | _egrep_o '"record_id":[^{]*host":"'"$_sub_domain"'"[^}]*\}')
 | 
			
		||||
  _debug seg "$seg"
 | 
			
		||||
  if [ -z "$seg" ]; then
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if printf "%s" "$response" | grep '"type":"TXT"' >/dev/null; then
 | 
			
		||||
    record_id=$(printf "%s\n" "$seg" | _egrep_o '"record_id":"[^"]*"' | cut -d : -f 2 | tr -d \" | _head_n 1)
 | 
			
		||||
    _debug record_id "$record_id"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#add the txt record.
 | 
			
		||||
#usage: root  sub  txtvalue
 | 
			
		||||
add_record() {
 | 
			
		||||
  root=$1
 | 
			
		||||
  sub=$2
 | 
			
		||||
  txtvalue=$3
 | 
			
		||||
  fulldomain="$sub.$root"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
 | 
			
		||||
  if ! _rest POST "record" "{\"domain_id\": $_domain_id, \"host\":\"$_sub_domain\", \"value\":\"$txtvalue\", \"type\":\"TXT\",\"ttl\":600, \"line_id\":1}"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  if ! _rest GET "domain"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "$h."; then
 | 
			
		||||
      seg=$(printf "%s\n" "$response" | _egrep_o '"id":[^{]*"'"$h"'."[^}]*}')
 | 
			
		||||
      _debug seg "$seg"
 | 
			
		||||
      _domain_id=$(printf "%s\n" "$seg" | _egrep_o "\"id\":\"[^\"]*\"" | cut -d : -f 2 | tr -d \")
 | 
			
		||||
      _debug _domain_id "$_domain_id"
 | 
			
		||||
      if [ "$_domain_id" ]; then
 | 
			
		||||
        _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
        _debug _sub_domain "$_sub_domain"
 | 
			
		||||
        _domain="$h"
 | 
			
		||||
        _debug _domain "$_domain"
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p="$i"
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: method  URI  data
 | 
			
		||||
_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  _debug ep "$ep"
 | 
			
		||||
  url="$REST_API/$ep"
 | 
			
		||||
  _debug url "$url"
 | 
			
		||||
 | 
			
		||||
  cdate=$(date -u "+%Y-%m-%d %H:%M:%S UTC")
 | 
			
		||||
  _debug cdate "$cdate"
 | 
			
		||||
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug data "$data"
 | 
			
		||||
 | 
			
		||||
  sec="$CX_Key$url$data$cdate$CX_Secret"
 | 
			
		||||
  _debug sec "$sec"
 | 
			
		||||
  hmac=$(printf "%s" "$sec" | _digest md5 hex)
 | 
			
		||||
  _debug hmac "$hmac"
 | 
			
		||||
 | 
			
		||||
  export _H1="API-KEY: $CX_Key"
 | 
			
		||||
  export _H2="API-REQUEST-DATE: $cdate"
 | 
			
		||||
  export _H3="API-HMAC: $hmac"
 | 
			
		||||
  export _H4="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  if [ "$data" ]; then
 | 
			
		||||
    response="$(_post "$data" "$url" "" "$m")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$url")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
 | 
			
		||||
  _contains "$response" '"code":1'
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										328
									
								
								dnsapi/dns_cyon.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										328
									
								
								dnsapi/dns_cyon.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,328 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
########
 | 
			
		||||
# Custom cyon.ch DNS API for use with [acme.sh](https://github.com/Neilpang/acme.sh)
 | 
			
		||||
#
 | 
			
		||||
# Usage: acme.sh --issue --dns dns_cyon -d www.domain.com
 | 
			
		||||
#
 | 
			
		||||
# Dependencies:
 | 
			
		||||
# -------------
 | 
			
		||||
# - oathtool (When using 2 Factor Authentication)
 | 
			
		||||
#
 | 
			
		||||
# Issues:
 | 
			
		||||
# -------
 | 
			
		||||
# Any issues / questions / suggestions can be posted here:
 | 
			
		||||
# https://github.com/noplanman/cyon-api/issues
 | 
			
		||||
#
 | 
			
		||||
# Author: Armando Lüscher <armando@noplanman.ch>
 | 
			
		||||
########
 | 
			
		||||
 | 
			
		||||
dns_cyon_add() {
 | 
			
		||||
  _cyon_load_credentials \
 | 
			
		||||
    && _cyon_load_parameters "$@" \
 | 
			
		||||
    && _cyon_print_header "add" \
 | 
			
		||||
    && _cyon_login \
 | 
			
		||||
    && _cyon_change_domain_env \
 | 
			
		||||
    && _cyon_add_txt \
 | 
			
		||||
    && _cyon_logout
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
dns_cyon_rm() {
 | 
			
		||||
  _cyon_load_credentials \
 | 
			
		||||
    && _cyon_load_parameters "$@" \
 | 
			
		||||
    && _cyon_print_header "delete" \
 | 
			
		||||
    && _cyon_login \
 | 
			
		||||
    && _cyon_change_domain_env \
 | 
			
		||||
    && _cyon_delete_txt \
 | 
			
		||||
    && _cyon_logout
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#########################
 | 
			
		||||
### PRIVATE FUNCTIONS ###
 | 
			
		||||
#########################
 | 
			
		||||
 | 
			
		||||
_cyon_load_credentials() {
 | 
			
		||||
  # Convert loaded password to/from base64 as needed.
 | 
			
		||||
  if [ "${CY_Password_B64}" ]; then
 | 
			
		||||
    CY_Password="$(printf "%s" "${CY_Password_B64}" | _dbase64 "multiline")"
 | 
			
		||||
  elif [ "${CY_Password}" ]; then
 | 
			
		||||
    CY_Password_B64="$(printf "%s" "${CY_Password}" | _base64)"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "${CY_Username}" ] || [ -z "${CY_Password}" ]; then
 | 
			
		||||
    # Dummy entries to satisfy script checker.
 | 
			
		||||
    CY_Username=""
 | 
			
		||||
    CY_Password=""
 | 
			
		||||
    CY_OTP_Secret=""
 | 
			
		||||
 | 
			
		||||
    _err ""
 | 
			
		||||
    _err "You haven't set your cyon.ch login credentials yet."
 | 
			
		||||
    _err "Please set the required cyon environment variables."
 | 
			
		||||
    _err ""
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Save the login credentials to the account.conf file.
 | 
			
		||||
  _debug "Save credentials to account.conf"
 | 
			
		||||
  _saveaccountconf CY_Username "${CY_Username}"
 | 
			
		||||
  _saveaccountconf CY_Password_B64 "$CY_Password_B64"
 | 
			
		||||
  if [ ! -z "${CY_OTP_Secret}" ]; then
 | 
			
		||||
    _saveaccountconf CY_OTP_Secret "$CY_OTP_Secret"
 | 
			
		||||
  else
 | 
			
		||||
    _clearaccountconf CY_OTP_Secret
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cyon_is_idn() {
 | 
			
		||||
  _idn_temp="$(printf "%s" "${1}" | tr -d "0-9a-zA-Z.,-_")"
 | 
			
		||||
  _idn_temp2="$(printf "%s" "${1}" | grep -o "xn--")"
 | 
			
		||||
  [ "$_idn_temp" ] || [ "$_idn_temp2" ]
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cyon_load_parameters() {
 | 
			
		||||
  # Read the required parameters to add the TXT entry.
 | 
			
		||||
  # shellcheck disable=SC2018,SC2019
 | 
			
		||||
  fulldomain="$(printf "%s" "${1}" | tr "A-Z" "a-z")"
 | 
			
		||||
  fulldomain_idn="${fulldomain}"
 | 
			
		||||
 | 
			
		||||
  # Special case for IDNs, as cyon needs a domain environment change,
 | 
			
		||||
  # which uses the "pretty" instead of the punycode version.
 | 
			
		||||
  if _cyon_is_idn "${fulldomain}"; then
 | 
			
		||||
    if ! _exists idn; then
 | 
			
		||||
      _err "Please install idn to process IDN names."
 | 
			
		||||
      _err ""
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    fulldomain="$(idn -u "${fulldomain}")"
 | 
			
		||||
    fulldomain_idn="$(idn -a "${fulldomain}")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug fulldomain "${fulldomain}"
 | 
			
		||||
  _debug fulldomain_idn "${fulldomain_idn}"
 | 
			
		||||
 | 
			
		||||
  txtvalue="${2}"
 | 
			
		||||
  _debug txtvalue "${txtvalue}"
 | 
			
		||||
 | 
			
		||||
  # This header is required for curl calls.
 | 
			
		||||
  _H1="X-Requested-With: XMLHttpRequest"
 | 
			
		||||
  export _H1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cyon_print_header() {
 | 
			
		||||
  if [ "${1}" = "add" ]; then
 | 
			
		||||
    _info ""
 | 
			
		||||
    _info "+---------------------------------------------+"
 | 
			
		||||
    _info "| Adding DNS TXT entry to your cyon.ch domain |"
 | 
			
		||||
    _info "+---------------------------------------------+"
 | 
			
		||||
    _info ""
 | 
			
		||||
    _info "  * Full Domain: ${fulldomain}"
 | 
			
		||||
    _info "  * TXT Value:   ${txtvalue}"
 | 
			
		||||
    _info ""
 | 
			
		||||
  elif [ "${1}" = "delete" ]; then
 | 
			
		||||
    _info ""
 | 
			
		||||
    _info "+-------------------------------------------------+"
 | 
			
		||||
    _info "| Deleting DNS TXT entry from your cyon.ch domain |"
 | 
			
		||||
    _info "+-------------------------------------------------+"
 | 
			
		||||
    _info ""
 | 
			
		||||
    _info "  * Full Domain: ${fulldomain}"
 | 
			
		||||
    _info ""
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cyon_get_cookie_header() {
 | 
			
		||||
  printf "Cookie: %s" "$(grep "cyon=" "$HTTP_HEADER" | grep "^Set-Cookie:" | _tail_n 1 | _egrep_o 'cyon=[^;]*;' | tr -d ';')"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cyon_login() {
 | 
			
		||||
  _info "  - Logging in..."
 | 
			
		||||
 | 
			
		||||
  username_encoded="$(printf "%s" "${CY_Username}" | _url_encode)"
 | 
			
		||||
  password_encoded="$(printf "%s" "${CY_Password}" | _url_encode)"
 | 
			
		||||
 | 
			
		||||
  login_url="https://my.cyon.ch/auth/index/dologin-async"
 | 
			
		||||
  login_data="$(printf "%s" "username=${username_encoded}&password=${password_encoded}&pathname=%2F")"
 | 
			
		||||
 | 
			
		||||
  login_response="$(_post "$login_data" "$login_url")"
 | 
			
		||||
  _debug login_response "${login_response}"
 | 
			
		||||
 | 
			
		||||
  # Bail if login fails.
 | 
			
		||||
  if [ "$(printf "%s" "${login_response}" | _cyon_get_response_success)" != "success" ]; then
 | 
			
		||||
    _err "    $(printf "%s" "${login_response}" | _cyon_get_response_message)"
 | 
			
		||||
    _err ""
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "    success"
 | 
			
		||||
 | 
			
		||||
  # NECESSARY!! Load the main page after login, to get the new cookie.
 | 
			
		||||
  _H2="$(_cyon_get_cookie_header)"
 | 
			
		||||
  export _H2
 | 
			
		||||
 | 
			
		||||
  _get "https://my.cyon.ch/" >/dev/null
 | 
			
		||||
 | 
			
		||||
  # todo: instead of just checking if the env variable is defined, check if we actually need to do a 2FA auth request.
 | 
			
		||||
 | 
			
		||||
  # 2FA authentication with OTP?
 | 
			
		||||
  if [ ! -z "${CY_OTP_Secret}" ]; then
 | 
			
		||||
    _info "  - Authorising with OTP code..."
 | 
			
		||||
 | 
			
		||||
    if ! _exists oathtool; then
 | 
			
		||||
      _err "Please install oathtool to use 2 Factor Authentication."
 | 
			
		||||
      _err ""
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    # Get OTP code with the defined secret.
 | 
			
		||||
    otp_code="$(oathtool --base32 --totp "${CY_OTP_Secret}" 2>/dev/null)"
 | 
			
		||||
 | 
			
		||||
    login_otp_url="https://my.cyon.ch/auth/multi-factor/domultifactorauth-async"
 | 
			
		||||
    login_otp_data="totpcode=${otp_code}&pathname=%2F&rememberme=0"
 | 
			
		||||
 | 
			
		||||
    login_otp_response="$(_post "$login_otp_data" "$login_otp_url")"
 | 
			
		||||
    _debug login_otp_response "${login_otp_response}"
 | 
			
		||||
 | 
			
		||||
    # Bail if OTP authentication fails.
 | 
			
		||||
    if [ "$(printf "%s" "${login_otp_response}" | _cyon_get_response_success)" != "success" ]; then
 | 
			
		||||
      _err "    $(printf "%s" "${login_otp_response}" | _cyon_get_response_message)"
 | 
			
		||||
      _err ""
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    _info "    success"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info ""
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cyon_logout() {
 | 
			
		||||
  _info "  - Logging out..."
 | 
			
		||||
 | 
			
		||||
  _get "https://my.cyon.ch/auth/index/dologout" >/dev/null
 | 
			
		||||
 | 
			
		||||
  _info "    success"
 | 
			
		||||
  _info ""
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cyon_change_domain_env() {
 | 
			
		||||
  _info "  - Changing domain environment..."
 | 
			
		||||
 | 
			
		||||
  # Get the "example.com" part of the full domain name.
 | 
			
		||||
  domain_env="$(printf "%s" "${fulldomain}" | sed -E -e 's/.*\.(.*\..*)$/\1/')"
 | 
			
		||||
  _debug "Changing domain environment to ${domain_env}"
 | 
			
		||||
 | 
			
		||||
  gloo_item_key="$(_get "https://my.cyon.ch/domain/" | tr '\n' ' ' | sed -E -e "s/.*data-domain=\"${domain_env}\"[^<]*data-itemkey=\"([^\"]*).*/\1/")"
 | 
			
		||||
  _debug gloo_item_key "${gloo_item_key}"
 | 
			
		||||
 | 
			
		||||
  domain_env_url="https://my.cyon.ch/user/environment/setdomain/d/${domain_env}/gik/${gloo_item_key}"
 | 
			
		||||
 | 
			
		||||
  domain_env_response="$(_get "${domain_env_url}")"
 | 
			
		||||
  _debug domain_env_response "${domain_env_response}"
 | 
			
		||||
 | 
			
		||||
  if ! _cyon_check_if_2fa_missed "${domain_env_response}"; then return 1; fi
 | 
			
		||||
 | 
			
		||||
  domain_env_success="$(printf "%s" "${domain_env_response}" | _egrep_o '"authenticated":\w*' | cut -d : -f 2)"
 | 
			
		||||
 | 
			
		||||
  # Bail if domain environment change fails.
 | 
			
		||||
  if [ "${domain_env_success}" != "true" ]; then
 | 
			
		||||
    _err "    $(printf "%s" "${domain_env_response}" | _cyon_get_response_message)"
 | 
			
		||||
    _err ""
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "    success"
 | 
			
		||||
  _info ""
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cyon_add_txt() {
 | 
			
		||||
  _info "  - Adding DNS TXT entry..."
 | 
			
		||||
 | 
			
		||||
  add_txt_url="https://my.cyon.ch/domain/dnseditor/add-record-async"
 | 
			
		||||
  add_txt_data="zone=${fulldomain_idn}.&ttl=900&type=TXT&value=${txtvalue}"
 | 
			
		||||
 | 
			
		||||
  add_txt_response="$(_post "$add_txt_data" "$add_txt_url")"
 | 
			
		||||
  _debug add_txt_response "${add_txt_response}"
 | 
			
		||||
 | 
			
		||||
  if ! _cyon_check_if_2fa_missed "${add_txt_response}"; then return 1; fi
 | 
			
		||||
 | 
			
		||||
  add_txt_message="$(printf "%s" "${add_txt_response}" | _cyon_get_response_message)"
 | 
			
		||||
  add_txt_status="$(printf "%s" "${add_txt_response}" | _cyon_get_response_status)"
 | 
			
		||||
 | 
			
		||||
  # Bail if adding TXT entry fails.
 | 
			
		||||
  if [ "${add_txt_status}" != "true" ]; then
 | 
			
		||||
    _err "    ${add_txt_message}"
 | 
			
		||||
    _err ""
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "    success (TXT|${fulldomain_idn}.|${txtvalue})"
 | 
			
		||||
  _info ""
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cyon_delete_txt() {
 | 
			
		||||
  _info "  - Deleting DNS TXT entry..."
 | 
			
		||||
 | 
			
		||||
  list_txt_url="https://my.cyon.ch/domain/dnseditor/list-async"
 | 
			
		||||
 | 
			
		||||
  list_txt_response="$(_get "${list_txt_url}" | sed -e 's/data-hash/\\ndata-hash/g')"
 | 
			
		||||
  _debug list_txt_response "${list_txt_response}"
 | 
			
		||||
 | 
			
		||||
  if ! _cyon_check_if_2fa_missed "${list_txt_response}"; then return 1; fi
 | 
			
		||||
 | 
			
		||||
  # Find and delete all acme challenge entries for the $fulldomain.
 | 
			
		||||
  _dns_entries="$(printf "%b\n" "${list_txt_response}" | sed -n 's/data-hash=\\"\([^"]*\)\\" data-identifier=\\"\([^"]*\)\\".*/\1 \2/p')"
 | 
			
		||||
 | 
			
		||||
  printf "%s" "${_dns_entries}" | while read -r _hash _identifier; do
 | 
			
		||||
    dns_type="$(printf "%s" "$_identifier" | cut -d'|' -f1)"
 | 
			
		||||
    dns_domain="$(printf "%s" "$_identifier" | cut -d'|' -f2)"
 | 
			
		||||
 | 
			
		||||
    if [ "${dns_type}" != "TXT" ] || [ "${dns_domain}" != "${fulldomain_idn}." ]; then
 | 
			
		||||
      continue
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    hash_encoded="$(printf "%s" "${_hash}" | _url_encode)"
 | 
			
		||||
    identifier_encoded="$(printf "%s" "${_identifier}" | _url_encode)"
 | 
			
		||||
 | 
			
		||||
    delete_txt_url="https://my.cyon.ch/domain/dnseditor/delete-record-async"
 | 
			
		||||
    delete_txt_data="$(printf "%s" "hash=${hash_encoded}&identifier=${identifier_encoded}")"
 | 
			
		||||
 | 
			
		||||
    delete_txt_response="$(_post "$delete_txt_data" "$delete_txt_url")"
 | 
			
		||||
    _debug delete_txt_response "${delete_txt_response}"
 | 
			
		||||
 | 
			
		||||
    if ! _cyon_check_if_2fa_missed "${delete_txt_response}"; then return 1; fi
 | 
			
		||||
 | 
			
		||||
    delete_txt_message="$(printf "%s" "${delete_txt_response}" | _cyon_get_response_message)"
 | 
			
		||||
    delete_txt_status="$(printf "%s" "${delete_txt_response}" | _cyon_get_response_status)"
 | 
			
		||||
 | 
			
		||||
    # Skip if deleting TXT entry fails.
 | 
			
		||||
    if [ "${delete_txt_status}" != "true" ]; then
 | 
			
		||||
      _err "    ${delete_txt_message} (${_identifier})"
 | 
			
		||||
    else
 | 
			
		||||
      _info "    success (${_identifier})"
 | 
			
		||||
    fi
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  _info "    done"
 | 
			
		||||
  _info ""
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cyon_get_response_message() {
 | 
			
		||||
  _egrep_o '"message":"[^"]*"' | cut -d : -f 2 | tr -d '"'
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cyon_get_response_status() {
 | 
			
		||||
  _egrep_o '"status":\w*' | cut -d : -f 2
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cyon_get_response_success() {
 | 
			
		||||
  _egrep_o '"onSuccess":"[^"]*"' | cut -d : -f 2 | tr -d '"'
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_cyon_check_if_2fa_missed() {
 | 
			
		||||
  # Did we miss the 2FA?
 | 
			
		||||
  if test "${1#*multi_factor_form}" != "${1}"; then
 | 
			
		||||
    _err "    Missed OTP authentication!"
 | 
			
		||||
    _err ""
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										184
									
								
								dnsapi/dns_da.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										184
									
								
								dnsapi/dns_da.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,184 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
# -*- mode: sh; tab-width: 2; indent-tabs-mode: s; coding: utf-8 -*-
 | 
			
		||||
# vim: et ts=2 sw=2
 | 
			
		||||
#
 | 
			
		||||
# DirectAdmin 1.41.0 API
 | 
			
		||||
# The DirectAdmin interface has it's own Let's encrypt functionality, but this
 | 
			
		||||
# script can be used to generate certificates for names which are not hosted on
 | 
			
		||||
# DirectAdmin
 | 
			
		||||
#
 | 
			
		||||
# User must provide login data and URL to DirectAdmin incl. port.
 | 
			
		||||
# You can create login key, by using the Login Keys function
 | 
			
		||||
# ( https://da.example.com:8443/CMD_LOGIN_KEYS ), which only has access to 
 | 
			
		||||
# - CMD_API_DNS_CONTROL
 | 
			
		||||
# - CMD_API_SHOW_DOMAINS
 | 
			
		||||
#
 | 
			
		||||
# See also https://www.directadmin.com/api.php and
 | 
			
		||||
# https://www.directadmin.com/features.php?id=1298
 | 
			
		||||
#
 | 
			
		||||
# Report bugs to https://github.com/TigerP/acme.sh/issues
 | 
			
		||||
#
 | 
			
		||||
# Values to export:
 | 
			
		||||
# export DA_Api="https://remoteUser:remotePassword@da.example.com:8443"
 | 
			
		||||
# export DA_Api_Insecure=1
 | 
			
		||||
#
 | 
			
		||||
# Set DA_Api_Insecure to 1 for insecure and 0 for secure -> difference is
 | 
			
		||||
# whether ssl cert is checked for validity (0) or whether it is just accepted
 | 
			
		||||
# (1)
 | 
			
		||||
#
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
# Usage: dns_myapi_add  _acme-challenge.www.example.com  "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
# Used to add txt record
 | 
			
		||||
dns_da_add() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
  txtvalue="${2}"
 | 
			
		||||
  _debug "Calling: dns_da_add() '${fulldomain}' '${txtvalue}'"
 | 
			
		||||
  _DA_credentials && _DA_getDomainInfo && _DA_addTxt
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Usage: dns_da_rm  _acme-challenge.www.example.com  "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
# Used to remove the txt record after validation
 | 
			
		||||
dns_da_rm() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
  txtvalue="${2}"
 | 
			
		||||
  _debug "Calling: dns_da_rm() '${fulldomain}' '${txtvalue}'"
 | 
			
		||||
  _DA_credentials && _DA_getDomainInfo && _DA_rmTxt
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
# Usage: _DA_credentials
 | 
			
		||||
# It will check if the needed settings are available
 | 
			
		||||
_DA_credentials() {
 | 
			
		||||
  DA_Api="${DA_Api:-$(_readaccountconf_mutable DA_Api)}"
 | 
			
		||||
  DA_Api_Insecure="${DA_Api_Insecure:-$(_readaccountconf_mutable DA_Api_Insecure)}"
 | 
			
		||||
  if [ -z "${DA_Api}" ] || [ -z "${DA_Api_Insecure}" ]; then
 | 
			
		||||
    DA_Api=""
 | 
			
		||||
    DA_Api_Insecure=""
 | 
			
		||||
    _err "You haven't specified the DirectAdmin Login data, URL and whether you want check the DirectAdmin SSL cert. Please try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  else
 | 
			
		||||
    _saveaccountconf_mutable DA_Api "${DA_Api}"
 | 
			
		||||
    _saveaccountconf_mutable DA_Api_Insecure "${DA_Api_Insecure}"
 | 
			
		||||
    # Set whether curl should use secure or insecure mode
 | 
			
		||||
    export HTTPS_INSECURE="${DA_Api_Insecure}"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Usage: _get_root _acme-challenge.www.example.com
 | 
			
		||||
# Split the full domain to a domain and subdomain
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=example.com
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  # Get a list of all the domains
 | 
			
		||||
  # response will contain "list[]=example.com&list[]=example.org"
 | 
			
		||||
  _da_api CMD_API_SHOW_DOMAINS "" "${domain}"
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      # not valid
 | 
			
		||||
      _debug "The given domain $h is not valid"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    if _contains "$response" "$h" >/dev/null; then
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain=$h
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  _debug "Stop on 100"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Usage: _da_api CMD_API_* data example.com
 | 
			
		||||
# Use the DirectAdmin API and check the result
 | 
			
		||||
# returns
 | 
			
		||||
#  response="error=0&text=Result text&details="
 | 
			
		||||
_da_api() {
 | 
			
		||||
  cmd=$1
 | 
			
		||||
  data=$2
 | 
			
		||||
  domain=$3
 | 
			
		||||
  _debug "$domain; $data"
 | 
			
		||||
  response="$(_post "$data" "$DA_Api/$cmd" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $cmd"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
 | 
			
		||||
  case "${cmd}" in
 | 
			
		||||
    CMD_API_DNS_CONTROL)
 | 
			
		||||
      # Parse the result in general
 | 
			
		||||
      # error=0&text=Records Deleted&details=
 | 
			
		||||
      # error=1&text=Cannot View Dns Record&details=No domain provided
 | 
			
		||||
      err_field="$(_getfield "$response" 1 '&')"
 | 
			
		||||
      txt_field="$(_getfield "$response" 2 '&')"
 | 
			
		||||
      details_field="$(_getfield "$response" 3 '&')"
 | 
			
		||||
      error="$(_getfield "$err_field" 2 '=')"
 | 
			
		||||
      text="$(_getfield "$txt_field" 2 '=')"
 | 
			
		||||
      details="$(_getfield "$details_field" 2 '=')"
 | 
			
		||||
      _debug "error: ${error}, text: ${text}, details: ${details}"
 | 
			
		||||
      if [ "$error" != "0" ]; then
 | 
			
		||||
        _err "error $response"
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
      ;;
 | 
			
		||||
    CMD_API_SHOW_DOMAINS) ;;
 | 
			
		||||
  esac
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Usage: _DA_getDomainInfo
 | 
			
		||||
# Get the root zone if possible
 | 
			
		||||
_DA_getDomainInfo() {
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  else
 | 
			
		||||
    _debug "The root domain: $_domain"
 | 
			
		||||
    _debug "The sub domain: $_sub_domain"
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Usage: _DA_addTxt
 | 
			
		||||
# Use the API to add a record
 | 
			
		||||
_DA_addTxt() {
 | 
			
		||||
  curData="domain=${_domain}&action=add&type=TXT&name=${_sub_domain}&value=\"${txtvalue}\""
 | 
			
		||||
  _debug "Calling _DA_addTxt: '${curData}' '${DA_Api}/CMD_API_DNS_CONTROL'"
 | 
			
		||||
  _da_api CMD_API_DNS_CONTROL "${curData}" "${_domain}"
 | 
			
		||||
  _debug "Result of _DA_addTxt: '$response'"
 | 
			
		||||
  if _contains "${response}" 'error=0'; then
 | 
			
		||||
    _debug "Add TXT succeeded"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
  _debug "Add TXT failed"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Usage: _DA_rmTxt
 | 
			
		||||
# Use the API to remove a record
 | 
			
		||||
_DA_rmTxt() {
 | 
			
		||||
  curData="domain=${_domain}&action=select&txtrecs0=name=${_sub_domain}&value=\"${txtvalue}\""
 | 
			
		||||
  _debug "Calling _DA_rmTxt: '${curData}' '${DA_Api}/CMD_API_DNS_CONTROL'"
 | 
			
		||||
  if _da_api CMD_API_DNS_CONTROL "${curData}" "${_domain}"; then
 | 
			
		||||
    _debug "Result of _DA_rmTxt: '$response'"
 | 
			
		||||
  else
 | 
			
		||||
    _err "Result of _DA_rmTxt: '$response'"
 | 
			
		||||
  fi
 | 
			
		||||
  if _contains "${response}" 'error=0'; then
 | 
			
		||||
    _debug "RM TXT succeeded"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
  _debug "RM TXT failed"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										250
									
								
								dnsapi/dns_dgon.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										250
									
								
								dnsapi/dns_dgon.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,250 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
## Will be called by acme.sh to add the txt record to your api system.
 | 
			
		||||
## returns 0 means success, otherwise error.
 | 
			
		||||
 | 
			
		||||
## Author: thewer <github at thewer.com>
 | 
			
		||||
## GitHub: https://github.com/gitwer/acme.sh
 | 
			
		||||
 | 
			
		||||
##
 | 
			
		||||
## Environment Variables Required:
 | 
			
		||||
##
 | 
			
		||||
## DO_API_KEY="75310dc4ca779ac39a19f6355db573b49ce92ae126553ebd61ac3a3ae34834cc"
 | 
			
		||||
##
 | 
			
		||||
 | 
			
		||||
#####################  Public functions  #####################
 | 
			
		||||
 | 
			
		||||
## Create the text record for validation.
 | 
			
		||||
## Usage: fulldomain txtvalue
 | 
			
		||||
## EG: "_acme-challenge.www.other.domain.com" "XKrxpRBosdq0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_dgon_add() {
 | 
			
		||||
  fulldomain="$(echo "$1" | _lower_case)"
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  DO_API_KEY="${DO_API_KEY:-$(_readaccountconf_mutable DO_API_KEY)}"
 | 
			
		||||
  # Check if API Key Exist
 | 
			
		||||
  if [ -z "$DO_API_KEY" ]; then
 | 
			
		||||
    DO_API_KEY=""
 | 
			
		||||
    _err "You did not specify DigitalOcean API key."
 | 
			
		||||
    _err "Please export DO_API_KEY and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Using digitalocean dns validation - add record"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  ## save the env vars (key and domain split location) for later automated use
 | 
			
		||||
  _saveaccountconf_mutable DO_API_KEY "$DO_API_KEY"
 | 
			
		||||
 | 
			
		||||
  ## split the domain for DO API
 | 
			
		||||
  if ! _get_base_domain "$fulldomain"; then
 | 
			
		||||
    _err "domain not found in your account for addition"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  ## Set the header with our post type and key auth key
 | 
			
		||||
  export _H1="Content-Type: application/json"
 | 
			
		||||
  export _H2="Authorization: Bearer $DO_API_KEY"
 | 
			
		||||
  PURL='https://api.digitalocean.com/v2/domains/'$_domain'/records'
 | 
			
		||||
  PBODY='{"type":"TXT","name":"'$_sub_domain'","data":"'$txtvalue'","ttl":120}'
 | 
			
		||||
 | 
			
		||||
  _debug PURL "$PURL"
 | 
			
		||||
  _debug PBODY "$PBODY"
 | 
			
		||||
 | 
			
		||||
  ## the create request - post
 | 
			
		||||
  ## args: BODY, URL, [need64, httpmethod]
 | 
			
		||||
  response="$(_post "$PBODY" "$PURL")"
 | 
			
		||||
 | 
			
		||||
  ## check response
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error in response: $response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
 | 
			
		||||
  ## finished correctly
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
## Remove the txt record after validation.
 | 
			
		||||
## Usage: fulldomain txtvalue
 | 
			
		||||
## EG: "_acme-challenge.www.other.domain.com" "XKrxpRBosdq0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_dgon_rm() {
 | 
			
		||||
  fulldomain="$(echo "$1" | _lower_case)"
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  DO_API_KEY="${DO_API_KEY:-$(_readaccountconf_mutable DO_API_KEY)}"
 | 
			
		||||
  # Check if API Key Exist
 | 
			
		||||
  if [ -z "$DO_API_KEY" ]; then
 | 
			
		||||
    DO_API_KEY=""
 | 
			
		||||
    _err "You did not specify DigitalOcean API key."
 | 
			
		||||
    _err "Please export DO_API_KEY and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Using digitalocean dns validation - remove record"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  ## split the domain for DO API
 | 
			
		||||
  if ! _get_base_domain "$fulldomain"; then
 | 
			
		||||
    _err "domain not found in your account for removal"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  ## Set the header with our post type and key auth key
 | 
			
		||||
  export _H1="Content-Type: application/json"
 | 
			
		||||
  export _H2="Authorization: Bearer $DO_API_KEY"
 | 
			
		||||
  ## get URL for the list of domains
 | 
			
		||||
  ## may get: "links":{"pages":{"last":".../v2/domains/DOM/records?page=2","next":".../v2/domains/DOM/records?page=2"}}
 | 
			
		||||
  GURL="https://api.digitalocean.com/v2/domains/$_domain/records"
 | 
			
		||||
 | 
			
		||||
  ## Get all the matching records
 | 
			
		||||
  while true; do
 | 
			
		||||
    ## 1) get the URL
 | 
			
		||||
    ## the create request - get
 | 
			
		||||
    ## args: URL, [onlyheader, timeout]
 | 
			
		||||
    domain_list="$(_get "$GURL")"
 | 
			
		||||
 | 
			
		||||
    ## check response
 | 
			
		||||
    if [ "$?" != "0" ]; then
 | 
			
		||||
      _err "error in domain_list response: $domain_list"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    _debug2 domain_list "$domain_list"
 | 
			
		||||
 | 
			
		||||
    ## 2) find records
 | 
			
		||||
    ## check for what we are looking for: "type":"A","name":"$_sub_domain"
 | 
			
		||||
    record="$(echo "$domain_list" | _egrep_o "\"id\"\s*\:\s*\"*[0-9]+\"*[^}]*\"name\"\s*\:\s*\"$_sub_domain\"[^}]*\"data\"\s*\:\s*\"$txtvalue\"")"
 | 
			
		||||
 | 
			
		||||
    if [ ! -z "$record" ]; then
 | 
			
		||||
 | 
			
		||||
      ## we found records
 | 
			
		||||
      rec_ids="$(echo "$record" | _egrep_o "id\"\s*\:\s*\"*[0-9]+" | _egrep_o "[0-9]+")"
 | 
			
		||||
      _debug rec_ids "$rec_ids"
 | 
			
		||||
      if [ ! -z "$rec_ids" ]; then
 | 
			
		||||
        echo "$rec_ids" | while IFS= read -r rec_id; do
 | 
			
		||||
          ## delete the record
 | 
			
		||||
          ## delete URL for removing the one we dont want
 | 
			
		||||
          DURL="https://api.digitalocean.com/v2/domains/$_domain/records/$rec_id"
 | 
			
		||||
 | 
			
		||||
          ## the create request - delete
 | 
			
		||||
          ## args: BODY, URL, [need64, httpmethod]
 | 
			
		||||
          response="$(_post "" "$DURL" "" "DELETE")"
 | 
			
		||||
 | 
			
		||||
          ## check response (sort of)
 | 
			
		||||
          if [ "$?" != "0" ]; then
 | 
			
		||||
            _err "error in remove response: $response"
 | 
			
		||||
            return 1
 | 
			
		||||
          fi
 | 
			
		||||
          _debug2 response "$response"
 | 
			
		||||
 | 
			
		||||
        done
 | 
			
		||||
      fi
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    ## 3) find the next page
 | 
			
		||||
    nextpage="$(echo "$domain_list" | _egrep_o "\"links\".*" | _egrep_o "\"next\".*" | _egrep_o "http.*page\=[0-9]+")"
 | 
			
		||||
    if [ -z "$nextpage" ]; then
 | 
			
		||||
      break
 | 
			
		||||
    fi
 | 
			
		||||
    _debug2 nextpage "$nextpage"
 | 
			
		||||
    GURL="$nextpage"
 | 
			
		||||
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  ## finished correctly
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#####################  Private functions below  #####################
 | 
			
		||||
 | 
			
		||||
## Split the domain provided into the "bade domain" and the "start prefix".
 | 
			
		||||
## This function searches for the longest subdomain in your account
 | 
			
		||||
## for the full domain given and splits it into the base domain (zone)
 | 
			
		||||
## and the prefix/record to be added/removed
 | 
			
		||||
## USAGE: fulldomain
 | 
			
		||||
## EG: "_acme-challenge.two.three.four.domain.com"
 | 
			
		||||
## returns
 | 
			
		||||
## _sub_domain="_acme-challenge.two"
 | 
			
		||||
## _domain="three.four.domain.com" *IF* zone "three.four.domain.com" exists
 | 
			
		||||
## if only "domain.com" exists it will return
 | 
			
		||||
## _sub_domain="_acme-challenge.two.three.four"
 | 
			
		||||
## _domain="domain.com"
 | 
			
		||||
_get_base_domain() {
 | 
			
		||||
  # args
 | 
			
		||||
  fulldomain="$(echo "$1" | tr '[:upper:]' '[:lower:]')"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
 | 
			
		||||
  # domain max legal length = 253
 | 
			
		||||
  MAX_DOM=255
 | 
			
		||||
 | 
			
		||||
  ## get a list of domains for the account to check thru
 | 
			
		||||
  ## Set the headers
 | 
			
		||||
  export _H1="Content-Type: application/json"
 | 
			
		||||
  export _H2="Authorization: Bearer $DO_API_KEY"
 | 
			
		||||
  _debug DO_API_KEY "$DO_API_KEY"
 | 
			
		||||
  ## get URL for the list of domains
 | 
			
		||||
  ## may get: "links":{"pages":{"last":".../v2/domains/DOM/records?page=2","next":".../v2/domains/DOM/records?page=2"}}
 | 
			
		||||
  DOMURL="https://api.digitalocean.com/v2/domains"
 | 
			
		||||
 | 
			
		||||
  ## while we dont have a matching domain we keep going
 | 
			
		||||
  while [ -z "$found" ]; do
 | 
			
		||||
    ## get the domain list (current page)
 | 
			
		||||
    domain_list="$(_get "$DOMURL")"
 | 
			
		||||
 | 
			
		||||
    ## check response
 | 
			
		||||
    if [ "$?" != "0" ]; then
 | 
			
		||||
      _err "error in domain_list response: $domain_list"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    _debug2 domain_list "$domain_list"
 | 
			
		||||
 | 
			
		||||
    ## for each shortening of our $fulldomain, check if it exists in the $domain_list
 | 
			
		||||
    ## can never start on 1 (aka whole $fulldomain) as $fulldomain starts with "_acme-challenge"
 | 
			
		||||
    i=2
 | 
			
		||||
    while [ $i -gt 0 ]; do
 | 
			
		||||
      ## get next longest domain
 | 
			
		||||
      _domain=$(printf "%s" "$fulldomain" | cut -d . -f "$i"-"$MAX_DOM")
 | 
			
		||||
      ## check we got something back from our cut (or are we at the end)
 | 
			
		||||
      if [ -z "$_domain" ]; then
 | 
			
		||||
        break
 | 
			
		||||
      fi
 | 
			
		||||
      ## we got part of a domain back - grep it out
 | 
			
		||||
      found="$(echo "$domain_list" | _egrep_o "\"name\"\s*\:\s*\"$_domain\"")"
 | 
			
		||||
      ## check if it exists
 | 
			
		||||
      if [ ! -z "$found" ]; then
 | 
			
		||||
        ## exists - exit loop returning the parts
 | 
			
		||||
        sub_point=$(_math $i - 1)
 | 
			
		||||
        _sub_domain=$(printf "%s" "$fulldomain" | cut -d . -f 1-"$sub_point")
 | 
			
		||||
        _debug _domain "$_domain"
 | 
			
		||||
        _debug _sub_domain "$_sub_domain"
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      ## increment cut point $i
 | 
			
		||||
      i=$(_math $i + 1)
 | 
			
		||||
    done
 | 
			
		||||
 | 
			
		||||
    if [ -z "$found" ]; then
 | 
			
		||||
      ## find the next page if we dont have a match
 | 
			
		||||
      nextpage="$(echo "$domain_list" | _egrep_o "\"links\".*" | _egrep_o "\"next\".*" | _egrep_o "http.*page\=[0-9]+")"
 | 
			
		||||
      if [ -z "$nextpage" ]; then
 | 
			
		||||
        _err "no record and no nextpage in digital ocean DNS removal"
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
      _debug2 nextpage "$nextpage"
 | 
			
		||||
      DOMURL="$nextpage"
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  ## we went through the entire domain zone list and dint find one that matched
 | 
			
		||||
  ## doesnt look like we can add in the record
 | 
			
		||||
  _err "domain not found in DigitalOcean account, but we should never get here"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										198
									
								
								dnsapi/dns_dnsimple.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										198
									
								
								dnsapi/dns_dnsimple.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,198 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# DNSimple domain api
 | 
			
		||||
# https://github.com/pho3nixf1re/acme.sh/issues
 | 
			
		||||
#
 | 
			
		||||
# This is your oauth token which can be acquired on the account page. Please
 | 
			
		||||
# note that this must be an _account_ token and not a _user_ token.
 | 
			
		||||
# https://dnsimple.com/a/<your account id>/account/access_tokens
 | 
			
		||||
# DNSimple_OAUTH_TOKEN="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
 | 
			
		||||
DNSimple_API="https://api.dnsimple.com/v2"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
# Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_dnsimple_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if [ -z "$DNSimple_OAUTH_TOKEN" ]; then
 | 
			
		||||
    DNSimple_OAUTH_TOKEN=""
 | 
			
		||||
    _err "You have not set the dnsimple oauth token yet."
 | 
			
		||||
    _err "Please visit https://dnsimple.com/user to generate it."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # save the oauth token for later
 | 
			
		||||
  _saveaccountconf DNSimple_OAUTH_TOKEN "$DNSimple_OAUTH_TOKEN"
 | 
			
		||||
 | 
			
		||||
  if ! _get_account_id; then
 | 
			
		||||
    _err "failed to retrive account id"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _get_records "$_account_id" "$_domain" "$_sub_domain"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  if _dnsimple_rest POST "$_account_id/zones/$_domain/records" "{\"type\":\"TXT\",\"name\":\"$_sub_domain\",\"content\":\"$txtvalue\",\"ttl\":120}"; then
 | 
			
		||||
    if printf -- "%s" "$response" | grep "\"name\":\"$_sub_domain\"" >/dev/null; then
 | 
			
		||||
      _info "Added"
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Unexpected response while adding text record."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  _err "Add txt record error."
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# fulldomain
 | 
			
		||||
dns_dnsimple_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
 | 
			
		||||
  if ! _get_account_id; then
 | 
			
		||||
    _err "failed to retrive account id"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _get_records "$_account_id" "$_domain" "$_sub_domain"
 | 
			
		||||
 | 
			
		||||
  _extract_record_id "$_records" "$_sub_domain"
 | 
			
		||||
  if [ "$_record_id" ]; then
 | 
			
		||||
    echo "$_record_id" | while read -r item; do
 | 
			
		||||
      if _dnsimple_rest DELETE "$_account_id/zones/$_domain/records/$item"; then
 | 
			
		||||
        _info "removed record" "$item"
 | 
			
		||||
        return 0
 | 
			
		||||
      else
 | 
			
		||||
        _err "failed to remove record" "$item"
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
    done
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions bellow ##################################
 | 
			
		||||
# _acme-challenge.www.domain.com
 | 
			
		||||
# returns
 | 
			
		||||
#   _sub_domain=_acme-challenge.www
 | 
			
		||||
#   _domain=domain.com
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  previous=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      # not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _dnsimple_rest GET "$_account_id/zones/$h"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" 'not found'; then
 | 
			
		||||
      _debug "$h not found"
 | 
			
		||||
    else
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$previous)
 | 
			
		||||
      _domain="$h"
 | 
			
		||||
 | 
			
		||||
      _debug _domain "$_domain"
 | 
			
		||||
      _debug _sub_domain "$_sub_domain"
 | 
			
		||||
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    previous="$i"
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# returns _account_id
 | 
			
		||||
_get_account_id() {
 | 
			
		||||
  _debug "retrive account id"
 | 
			
		||||
  if ! _dnsimple_rest GET "whoami"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if _contains "$response" "\"account\":null"; then
 | 
			
		||||
    _err "no account associated with this token"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if _contains "$response" "timeout"; then
 | 
			
		||||
    _err "timeout retrieving account id"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _account_id=$(printf "%s" "$response" | _egrep_o "\"id\":[^,]*,\"email\":" | cut -d: -f2 | cut -d, -f1)
 | 
			
		||||
  _debug _account_id "$_account_id"
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# returns
 | 
			
		||||
#   _records
 | 
			
		||||
#   _records_count
 | 
			
		||||
_get_records() {
 | 
			
		||||
  account_id=$1
 | 
			
		||||
  domain=$2
 | 
			
		||||
  sub_domain=$3
 | 
			
		||||
 | 
			
		||||
  _debug "fetching txt records"
 | 
			
		||||
  _dnsimple_rest GET "$account_id/zones/$domain/records?per_page=5000&sort=id:desc"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "\"id\":"; then
 | 
			
		||||
    _err "failed to retrieve records"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _records_count=$(printf "%s" "$response" | _egrep_o "\"name\":\"$sub_domain\"" | wc -l | _egrep_o "[0-9]+")
 | 
			
		||||
  _records=$response
 | 
			
		||||
  _debug _records_count "$_records_count"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# returns _record_id
 | 
			
		||||
_extract_record_id() {
 | 
			
		||||
  _record_id=$(printf "%s" "$_records" | _egrep_o "\"id\":[^,]*,\"zone_id\":\"[^,]*\",\"parent_id\":null,\"name\":\"$_sub_domain\"" | cut -d: -f2 | cut -d, -f1)
 | 
			
		||||
  _debug "_record_id" "$_record_id"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# returns response
 | 
			
		||||
_dnsimple_rest() {
 | 
			
		||||
  method=$1
 | 
			
		||||
  path="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  request_url="$DNSimple_API/$path"
 | 
			
		||||
  _debug "$path"
 | 
			
		||||
 | 
			
		||||
  export _H1="Accept: application/json"
 | 
			
		||||
  export _H2="Authorization: Bearer $DNSimple_OAUTH_TOKEN"
 | 
			
		||||
 | 
			
		||||
  if [ "$data" ] || [ "$method" = "DELETE" ]; then
 | 
			
		||||
    _H1="Content-Type: application/json"
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$request_url" "" "$method")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$request_url" "" "" "$method")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $request_url"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										148
									
								
								dnsapi/dns_do.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										148
									
								
								dnsapi/dns_do.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,148 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# DNS API for Domain-Offensive / Resellerinterface / Domainrobot
 | 
			
		||||
 | 
			
		||||
# Report bugs at https://github.com/seidler2547/acme.sh/issues
 | 
			
		||||
 | 
			
		||||
# set these environment variables to match your customer ID and password:
 | 
			
		||||
# DO_PID="KD-1234567"
 | 
			
		||||
# DO_PW="cdfkjl3n2"
 | 
			
		||||
 | 
			
		||||
DO_URL="https://soap.resellerinterface.de/"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_myapi_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_do_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  if _dns_do_authenticate; then
 | 
			
		||||
    _info "Adding TXT record to ${_domain} as ${fulldomain}"
 | 
			
		||||
    _dns_do_soap createRR origin "${_domain}" name "${fulldomain}" type TXT data "${txtvalue}" ttl 300
 | 
			
		||||
    if _contains "${response}" '>success<'; then
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    _err "Could not create resource record, check logs"
 | 
			
		||||
  fi
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain
 | 
			
		||||
dns_do_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  if _dns_do_authenticate; then
 | 
			
		||||
    if _dns_do_list_rrs; then
 | 
			
		||||
      _dns_do_had_error=0
 | 
			
		||||
      for _rrid in ${_rr_list}; do
 | 
			
		||||
        _info "Deleting resource record $_rrid for $_domain"
 | 
			
		||||
        _dns_do_soap deleteRR origin "${_domain}" rrid "${_rrid}"
 | 
			
		||||
        if ! _contains "${response}" '>success<'; then
 | 
			
		||||
          _dns_do_had_error=1
 | 
			
		||||
          _err "Could not delete resource record for ${_domain}, id ${_rrid}"
 | 
			
		||||
        fi
 | 
			
		||||
      done
 | 
			
		||||
      return $_dns_do_had_error
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
_dns_do_authenticate() {
 | 
			
		||||
  _info "Authenticating as ${DO_PID}"
 | 
			
		||||
  _dns_do_soap authPartner partner "${DO_PID}" password "${DO_PW}"
 | 
			
		||||
  if _contains "${response}" '>success<'; then
 | 
			
		||||
    _get_root "$fulldomain"
 | 
			
		||||
    _debug "_domain $_domain"
 | 
			
		||||
    return 0
 | 
			
		||||
  else
 | 
			
		||||
    _err "Authentication failed, are DO_PID and DO_PW set correctly?"
 | 
			
		||||
  fi
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_dns_do_list_rrs() {
 | 
			
		||||
  _dns_do_soap getRRList origin "${_domain}"
 | 
			
		||||
  if ! _contains "${response}" 'SOAP-ENC:Array'; then
 | 
			
		||||
    _err "getRRList origin ${_domain} failed"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _rr_list="$(echo "${response}" \
 | 
			
		||||
    | tr -d "\n\r\t" \
 | 
			
		||||
    | sed -e 's/<item xsi:type="ns2:Map">/\n/g' \
 | 
			
		||||
    | grep ">$(_regexcape "$fulldomain")</value>" \
 | 
			
		||||
    | sed -e 's/<\/item>/\n/g' \
 | 
			
		||||
    | grep '>id</key><value' \
 | 
			
		||||
    | _egrep_o '>[0-9]{1,16}<' \
 | 
			
		||||
    | tr -d '><')"
 | 
			
		||||
  [ "${_rr_list}" ]
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_dns_do_soap() {
 | 
			
		||||
  func="$1"
 | 
			
		||||
  shift
 | 
			
		||||
  # put the parameters to xml
 | 
			
		||||
  body="<tns:${func} xmlns:tns=\"${DO_URL}\">"
 | 
			
		||||
  while [ "$1" ]; do
 | 
			
		||||
    _k="$1"
 | 
			
		||||
    shift
 | 
			
		||||
    _v="$1"
 | 
			
		||||
    shift
 | 
			
		||||
    body="$body<$_k>$_v</$_k>"
 | 
			
		||||
  done
 | 
			
		||||
  body="$body</tns:${func}>"
 | 
			
		||||
  _debug2 "SOAP request ${body}"
 | 
			
		||||
 | 
			
		||||
  # build SOAP XML
 | 
			
		||||
  _xml='<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
<env:Envelope xmlns:env="http://schemas.xmlsoap.org/soap/envelope/">
 | 
			
		||||
  <env:Body>'"$body"'</env:Body>
 | 
			
		||||
</env:Envelope>'
 | 
			
		||||
 | 
			
		||||
  # set SOAP headers
 | 
			
		||||
  export _H1="SOAPAction: ${DO_URL}#${func}"
 | 
			
		||||
 | 
			
		||||
  if ! response="$(_post "${_xml}" "${DO_URL}")"; then
 | 
			
		||||
    _err "Error <$1>"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 "SOAP response $response"
 | 
			
		||||
 | 
			
		||||
  # retrieve cookie header
 | 
			
		||||
  _H2="$(_egrep_o 'Cookie: [^;]+' <"$HTTP_HEADER" | _head_n 1)"
 | 
			
		||||
  export _H2
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=1
 | 
			
		||||
 | 
			
		||||
  _dns_do_soap getDomainList
 | 
			
		||||
  _all_domains="$(echo "${response}" \
 | 
			
		||||
    | tr -d "\n\r\t " \
 | 
			
		||||
    | _egrep_o 'domain</key><value[^>]+>[^<]+' \
 | 
			
		||||
    | sed -e 's/^domain<\/key><value[^>]*>//g')"
 | 
			
		||||
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "${_all_domains}" "^$(_regexcape "$h")\$"; then
 | 
			
		||||
      _domain="$h"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    i=$(_math $i + 1)
 | 
			
		||||
  done
 | 
			
		||||
  _debug "$domain not found"
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_regexcape() {
 | 
			
		||||
  echo "$1" | sed -e 's/\([]\.$*^[]\)/\\\1/g'
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										161
									
								
								dnsapi/dns_dp.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										161
									
								
								dnsapi/dns_dp.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,161 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# Dnspod.cn Domain api
 | 
			
		||||
#
 | 
			
		||||
#DP_Id="1234"
 | 
			
		||||
#
 | 
			
		||||
#DP_Key="sADDsdasdgdsf"
 | 
			
		||||
 | 
			
		||||
REST_API="https://dnsapi.cn"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_dp_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  DP_Id="${DP_Id:-$(_readaccountconf_mutable DP_Id)}"
 | 
			
		||||
  DP_Key="${DP_Key:-$(_readaccountconf_mutable DP_Key)}"
 | 
			
		||||
  if [ -z "$DP_Id" ] || [ -z "$DP_Key" ]; then
 | 
			
		||||
    DP_Id=""
 | 
			
		||||
    DP_Key=""
 | 
			
		||||
    _err "You don't specify dnspod api key and key id yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable DP_Id "$DP_Id"
 | 
			
		||||
  _saveaccountconf_mutable DP_Key "$DP_Key"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  add_record "$_domain" "$_sub_domain" "$txtvalue"
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_dp_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  DP_Id="${DP_Id:-$(_readaccountconf_mutable DP_Id)}"
 | 
			
		||||
  DP_Key="${DP_Key:-$(_readaccountconf_mutable DP_Key)}"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _rest POST "Record.List" "login_token=$DP_Id,$DP_Key&format=json&domain_id=$_domain_id&sub_domain=$_sub_domain"; then
 | 
			
		||||
    _err "Record.Lis error."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if _contains "$response" 'No records'; then
 | 
			
		||||
    _info "Don't need to remove."
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  record_id=$(echo "$response" | _egrep_o '{[^{]*"value":"'"$txtvalue"'"' | cut -d , -f 1 | cut -d : -f 2 | tr -d \")
 | 
			
		||||
  _debug record_id "$record_id"
 | 
			
		||||
  if [ -z "$record_id" ]; then
 | 
			
		||||
    _err "Can not get record id."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _rest POST "Record.Remove" "login_token=$DP_Id,$DP_Key&format=json&domain_id=$_domain_id&record_id=$record_id"; then
 | 
			
		||||
    _err "Record.Remove error."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _contains "$response" "Action completed successful"
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#add the txt record.
 | 
			
		||||
#usage: root  sub  txtvalue
 | 
			
		||||
add_record() {
 | 
			
		||||
  root=$1
 | 
			
		||||
  sub=$2
 | 
			
		||||
  txtvalue=$3
 | 
			
		||||
  fulldomain="$sub.$root"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
 | 
			
		||||
  if ! _rest POST "Record.Create" "login_token=$DP_Id,$DP_Key&format=json&domain_id=$_domain_id&sub_domain=$_sub_domain&record_type=TXT&value=$txtvalue&record_line=默认"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _contains "$response" "Action completed successful" || _contains "$response" "Domain record already exists"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _rest POST "Domain.Info" "login_token=$DP_Id,$DP_Key&format=json&domain=$h"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "Action completed successful"; then
 | 
			
		||||
      _domain_id=$(printf "%s\n" "$response" | _egrep_o "\"id\":\"[^\"]*\"" | cut -d : -f 2 | tr -d \")
 | 
			
		||||
      _debug _domain_id "$_domain_id"
 | 
			
		||||
      if [ "$_domain_id" ]; then
 | 
			
		||||
        _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
        _debug _sub_domain "$_sub_domain"
 | 
			
		||||
        _domain="$h"
 | 
			
		||||
        _debug _domain "$_domain"
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p="$i"
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: method  URI  data
 | 
			
		||||
_rest() {
 | 
			
		||||
  m="$1"
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
  url="$REST_API/$ep"
 | 
			
		||||
 | 
			
		||||
  _debug url "$url"
 | 
			
		||||
 | 
			
		||||
  if [ "$m" = "GET" ]; then
 | 
			
		||||
    response="$(_get "$url" | tr -d '\r')"
 | 
			
		||||
  else
 | 
			
		||||
    _debug2 data "$data"
 | 
			
		||||
    response="$(_post "$data" "$url" | tr -d '\r')"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										161
									
								
								dnsapi/dns_dpi.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										161
									
								
								dnsapi/dns_dpi.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,161 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# Dnspod.com Domain api
 | 
			
		||||
#
 | 
			
		||||
#DPI_Id="1234"
 | 
			
		||||
#
 | 
			
		||||
#DPI_Key="sADDsdasdgdsf"
 | 
			
		||||
 | 
			
		||||
REST_API="https://api.dnspod.com"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_dpi_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  DPI_Id="${DPI_Id:-$(_readaccountconf_mutable DPI_Id)}"
 | 
			
		||||
  DPI_Key="${DPI_Key:-$(_readaccountconf_mutable DPI_Key)}"
 | 
			
		||||
  if [ -z "$DPI_Id" ] || [ -z "$DPI_Key" ]; then
 | 
			
		||||
    DPI_Id=""
 | 
			
		||||
    DPI_Key=""
 | 
			
		||||
    _err "You don't specify dnspod api key and key id yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable DPI_Id "$DPI_Id"
 | 
			
		||||
  _saveaccountconf_mutable DPI_Key "$DPI_Key"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  add_record "$_domain" "$_sub_domain" "$txtvalue"
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_dpi_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  DPI_Id="${DPI_Id:-$(_readaccountconf_mutable DPI_Id)}"
 | 
			
		||||
  DPI_Key="${DPI_Key:-$(_readaccountconf_mutable DPI_Key)}"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _rest POST "Record.List" "user_token=$DPI_Id,$DPI_Key&format=json&domain_id=$_domain_id&sub_domain=$_sub_domain"; then
 | 
			
		||||
    _err "Record.Lis error."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if _contains "$response" 'No records'; then
 | 
			
		||||
    _info "Don't need to remove."
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  record_id=$(echo "$response" | _egrep_o '{[^{]*"value":"'"$txtvalue"'"' | cut -d , -f 1 | cut -d : -f 2 | tr -d \")
 | 
			
		||||
  _debug record_id "$record_id"
 | 
			
		||||
  if [ -z "$record_id" ]; then
 | 
			
		||||
    _err "Can not get record id."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _rest POST "Record.Remove" "user_token=$DPI_Id,$DPI_Key&format=json&domain_id=$_domain_id&record_id=$record_id"; then
 | 
			
		||||
    _err "Record.Remove error."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _contains "$response" "Action completed successful"
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#add the txt record.
 | 
			
		||||
#usage: root  sub  txtvalue
 | 
			
		||||
add_record() {
 | 
			
		||||
  root=$1
 | 
			
		||||
  sub=$2
 | 
			
		||||
  txtvalue=$3
 | 
			
		||||
  fulldomain="$sub.$root"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
 | 
			
		||||
  if ! _rest POST "Record.Create" "user_token=$DPI_Id,$DPI_Key&format=json&domain_id=$_domain_id&sub_domain=$_sub_domain&record_type=TXT&value=$txtvalue&record_line=default"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _contains "$response" "Action completed successful" || _contains "$response" "Domain record already exists"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _rest POST "Domain.Info" "user_token=$DPI_Id,$DPI_Key&format=json&domain=$h"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "Action completed successful"; then
 | 
			
		||||
      _domain_id=$(printf "%s\n" "$response" | _egrep_o "\"id\":\"[^\"]*\"" | cut -d : -f 2 | tr -d \")
 | 
			
		||||
      _debug _domain_id "$_domain_id"
 | 
			
		||||
      if [ "$_domain_id" ]; then
 | 
			
		||||
        _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
        _debug _sub_domain "$_sub_domain"
 | 
			
		||||
        _domain="$h"
 | 
			
		||||
        _debug _domain "$_domain"
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p="$i"
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: method  URI  data
 | 
			
		||||
_rest() {
 | 
			
		||||
  m="$1"
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
  url="$REST_API/$ep"
 | 
			
		||||
 | 
			
		||||
  _debug url "$url"
 | 
			
		||||
 | 
			
		||||
  if [ "$m" = "GET" ]; then
 | 
			
		||||
    response="$(_get "$url" | tr -d '\r')"
 | 
			
		||||
  else
 | 
			
		||||
    _debug2 data "$data"
 | 
			
		||||
    response="$(_post "$data" "$url" | tr -d '\r')"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										97
									
								
								dnsapi/dns_dreamhost.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										97
									
								
								dnsapi/dns_dreamhost.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,97 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Author: RhinoLance
 | 
			
		||||
#Report Bugs here: https://github.com/RhinoLance/acme.sh
 | 
			
		||||
#
 | 
			
		||||
 | 
			
		||||
#define the api endpoint
 | 
			
		||||
DH_API_ENDPOINT="https://api.dreamhost.com/"
 | 
			
		||||
querystring=""
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_myapi_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_dreamhost_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if ! validate "$fulldomain" "$txtvalue"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  querystring="key=$DH_API_KEY&cmd=dns-add_record&record=$fulldomain&type=TXT&value=$txtvalue"
 | 
			
		||||
  if ! submit "$querystring"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: fulldomain txtvalue
 | 
			
		||||
#Remove the txt record after validation.
 | 
			
		||||
dns_dreamhost_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if ! validate "$fulldomain" "$txtvalue"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  querystring="key=$DH_API_KEY&cmd=dns-remove_record&record=$fulldomain&type=TXT&value=$txtvalue"
 | 
			
		||||
  if ! submit "$querystring"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
#send the command to the api endpoint.
 | 
			
		||||
submit() {
 | 
			
		||||
  querystring=$1
 | 
			
		||||
 | 
			
		||||
  url="$DH_API_ENDPOINT?$querystring"
 | 
			
		||||
 | 
			
		||||
  _debug url "$url"
 | 
			
		||||
 | 
			
		||||
  if ! response="$(_get "$url")"; then
 | 
			
		||||
    _err "Error <$1>"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$2" ]; then
 | 
			
		||||
    message="$(echo "$response" | _egrep_o "\"Message\":\"[^\"]*\"" | cut -d : -f 2 | tr -d \")"
 | 
			
		||||
    if [ -n "$message" ]; then
 | 
			
		||||
      _err "$message"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#check that we have a valid API Key
 | 
			
		||||
validate() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  _info "Using dreamhost"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  #retrieve the API key from the environment variable if it exists, otherwise look for a saved key.
 | 
			
		||||
  DH_API_KEY="${DH_API_KEY:-$(_readaccountconf_mutable DH_API_KEY)}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$DH_API_KEY" ]; then
 | 
			
		||||
    DH_API_KEY=""
 | 
			
		||||
    _err "You didn't specify the DreamHost api key yet (export DH_API_KEY=\"<api key>\")"
 | 
			
		||||
    _err "Please login to your control panel, create a key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable DH_API_KEY "$DH_API_KEY"
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										128
									
								
								dnsapi/dns_duckdns.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										128
									
								
								dnsapi/dns_duckdns.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,128 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Created by RaidenII, to use DuckDNS's API to add/remove text records
 | 
			
		||||
#06/27/2017
 | 
			
		||||
 | 
			
		||||
# Pass credentials before "acme.sh --issue --dns dns_duckdns ..."
 | 
			
		||||
# --
 | 
			
		||||
# export DuckDNS_Token="aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee"
 | 
			
		||||
# --
 | 
			
		||||
#
 | 
			
		||||
# Due to the fact that DuckDNS uses StartSSL as cert provider, --insecure may need to be used with acme.sh
 | 
			
		||||
 | 
			
		||||
DuckDNS_API="https://www.duckdns.org/update"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_duckdns_add _acme-challenge.domain.duckdns.org "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_duckdns_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  DuckDNS_Token="${DuckDNS_Token:-$(_readaccountconf_mutable DuckDNS_Token)}"
 | 
			
		||||
  if [ -z "$DuckDNS_Token" ]; then
 | 
			
		||||
    _err "You must export variable: DuckDNS_Token"
 | 
			
		||||
    _err "The token for your DuckDNS account is necessary."
 | 
			
		||||
    _err "You can look it up in your DuckDNS account."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Now save the credentials.
 | 
			
		||||
  _saveaccountconf_mutable DuckDNS_Token "$DuckDNS_Token"
 | 
			
		||||
 | 
			
		||||
  # Unfortunately, DuckDNS does not seems to support lookup domain through API
 | 
			
		||||
  # So I assume your credentials (which are your domain and token) are correct
 | 
			
		||||
  # If something goes wrong, we will get a KO response from DuckDNS
 | 
			
		||||
 | 
			
		||||
  if ! _duckdns_get_domain; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Now add the TXT record to DuckDNS
 | 
			
		||||
  _info "Trying to add TXT record"
 | 
			
		||||
  if _duckdns_rest GET "domains=$_duckdns_domain&token=$DuckDNS_Token&txt=$txtvalue"; then
 | 
			
		||||
    if [ "$response" = "OK" ]; then
 | 
			
		||||
      _info "TXT record has been successfully added to your DuckDNS domain."
 | 
			
		||||
      _info "Note that all subdomains under this domain uses the same TXT record."
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Errors happened during adding the TXT record, response=$response"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  else
 | 
			
		||||
    _err "Errors happened during adding the TXT record."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: fulldomain txtvalue
 | 
			
		||||
#Remove the txt record after validation.
 | 
			
		||||
dns_duckdns_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  DuckDNS_Token="${DuckDNS_Token:-$(_readaccountconf_mutable DuckDNS_Token)}"
 | 
			
		||||
  if [ -z "$DuckDNS_Token" ]; then
 | 
			
		||||
    _err "You must export variable: DuckDNS_Token"
 | 
			
		||||
    _err "The token for your DuckDNS account is necessary."
 | 
			
		||||
    _err "You can look it up in your DuckDNS account."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _duckdns_get_domain; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Now remove the TXT record from DuckDNS
 | 
			
		||||
  _info "Trying to remove TXT record"
 | 
			
		||||
  if _duckdns_rest GET "domains=$_duckdns_domain&token=$DuckDNS_Token&txt=&clear=true"; then
 | 
			
		||||
    if [ "$response" = "OK" ]; then
 | 
			
		||||
      _info "TXT record has been successfully removed from your DuckDNS domain."
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Errors happened during removing the TXT record, response=$response"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  else
 | 
			
		||||
    _err "Errors happened during removing the TXT record."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
#fulldomain=_acme-challenge.domain.duckdns.org
 | 
			
		||||
#returns
 | 
			
		||||
# _duckdns_domain=domain
 | 
			
		||||
_duckdns_get_domain() {
 | 
			
		||||
 | 
			
		||||
  # We'll extract the domain/username from full domain
 | 
			
		||||
  _duckdns_domain="$(printf "%s" "$fulldomain" | _lower_case | _egrep_o '[.][^.][^.]*[.]duckdns.org' | cut -d . -f 2)"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$_duckdns_domain" ]; then
 | 
			
		||||
    _err "Error extracting the domain."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: method URI
 | 
			
		||||
_duckdns_rest() {
 | 
			
		||||
  method=$1
 | 
			
		||||
  param="$2"
 | 
			
		||||
  _debug param "$param"
 | 
			
		||||
  url="$DuckDNS_API?$param"
 | 
			
		||||
  _debug url "$url"
 | 
			
		||||
 | 
			
		||||
  # DuckDNS uses GET to update domain info
 | 
			
		||||
  if [ "$method" = "GET" ]; then
 | 
			
		||||
    response="$(_get "$url")"
 | 
			
		||||
  else
 | 
			
		||||
    _err "Unsupported method"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										339
									
								
								dnsapi/dns_dyn.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										339
									
								
								dnsapi/dns_dyn.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,339 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
#
 | 
			
		||||
# Dyn.com Domain API
 | 
			
		||||
#
 | 
			
		||||
# Author: Gerd Naschenweng
 | 
			
		||||
# https://github.com/magicdude4eva
 | 
			
		||||
#
 | 
			
		||||
# Dyn Managed DNS API
 | 
			
		||||
# https://help.dyn.com/dns-api-knowledge-base/
 | 
			
		||||
#
 | 
			
		||||
# It is recommended to add a "Dyn Managed DNS" user specific for API access.
 | 
			
		||||
# The "Zones & Records Permissions" required by this script are:
 | 
			
		||||
# --
 | 
			
		||||
# RecordAdd
 | 
			
		||||
# RecordUpdate
 | 
			
		||||
# RecordDelete
 | 
			
		||||
# RecordGet
 | 
			
		||||
# ZoneGet
 | 
			
		||||
# ZoneAddNode
 | 
			
		||||
# ZoneRemoveNode
 | 
			
		||||
# ZonePublish
 | 
			
		||||
# --
 | 
			
		||||
#
 | 
			
		||||
# Pass credentials before "acme.sh --issue --dns dns_dyn ..."
 | 
			
		||||
# --
 | 
			
		||||
# export DYN_Customer="customer"
 | 
			
		||||
# export DYN_Username="apiuser"
 | 
			
		||||
# export DYN_Password="secret"
 | 
			
		||||
# --
 | 
			
		||||
 | 
			
		||||
DYN_API="https://api.dynect.net/REST"
 | 
			
		||||
 | 
			
		||||
#REST_API
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "Challenge-code"
 | 
			
		||||
dns_dyn_add() {
 | 
			
		||||
  fulldomain="$1"
 | 
			
		||||
  txtvalue="$2"
 | 
			
		||||
 | 
			
		||||
  DYN_Customer="${DYN_Customer:-$(_readaccountconf_mutable DYN_Customer)}"
 | 
			
		||||
  DYN_Username="${DYN_Username:-$(_readaccountconf_mutable DYN_Username)}"
 | 
			
		||||
  DYN_Password="${DYN_Password:-$(_readaccountconf_mutable DYN_Password)}"
 | 
			
		||||
  if [ -z "$DYN_Customer" ] || [ -z "$DYN_Username" ] || [ -z "$DYN_Password" ]; then
 | 
			
		||||
    DYN_Customer=""
 | 
			
		||||
    DYN_Username=""
 | 
			
		||||
    DYN_Password=""
 | 
			
		||||
    _err "You must export variables: DYN_Customer, DYN_Username and DYN_Password"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the config variables to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable DYN_Customer "$DYN_Customer"
 | 
			
		||||
  _saveaccountconf_mutable DYN_Username "$DYN_Username"
 | 
			
		||||
  _saveaccountconf_mutable DYN_Password "$DYN_Password"
 | 
			
		||||
 | 
			
		||||
  if ! _dyn_get_authtoken; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$_dyn_authtoken" ]; then
 | 
			
		||||
    _dyn_end_session
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _dyn_get_zone; then
 | 
			
		||||
    _dyn_end_session
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _dyn_add_record; then
 | 
			
		||||
    _dyn_end_session
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _dyn_publish_zone; then
 | 
			
		||||
    _dyn_end_session
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _dyn_end_session
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: fulldomain txtvalue
 | 
			
		||||
#Remove the txt record after validation.
 | 
			
		||||
dns_dyn_rm() {
 | 
			
		||||
  fulldomain="$1"
 | 
			
		||||
  txtvalue="$2"
 | 
			
		||||
 | 
			
		||||
  DYN_Customer="${DYN_Customer:-$(_readaccountconf_mutable DYN_Customer)}"
 | 
			
		||||
  DYN_Username="${DYN_Username:-$(_readaccountconf_mutable DYN_Username)}"
 | 
			
		||||
  DYN_Password="${DYN_Password:-$(_readaccountconf_mutable DYN_Password)}"
 | 
			
		||||
  if [ -z "$DYN_Customer" ] || [ -z "$DYN_Username" ] || [ -z "$DYN_Password" ]; then
 | 
			
		||||
    DYN_Customer=""
 | 
			
		||||
    DYN_Username=""
 | 
			
		||||
    DYN_Password=""
 | 
			
		||||
    _err "You must export variables: DYN_Customer, DYN_Username and DYN_Password"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _dyn_get_authtoken; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$_dyn_authtoken" ]; then
 | 
			
		||||
    _dyn_end_session
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _dyn_get_zone; then
 | 
			
		||||
    _dyn_end_session
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _dyn_get_record_id; then
 | 
			
		||||
    _dyn_end_session
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$_dyn_record_id" ]; then
 | 
			
		||||
    _dyn_end_session
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _dyn_rm_record; then
 | 
			
		||||
    _dyn_end_session
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _dyn_publish_zone; then
 | 
			
		||||
    _dyn_end_session
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _dyn_end_session
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
#get Auth-Token
 | 
			
		||||
_dyn_get_authtoken() {
 | 
			
		||||
 | 
			
		||||
  _info "Start Dyn API Session"
 | 
			
		||||
 | 
			
		||||
  data="{\"customer_name\":\"$DYN_Customer\", \"user_name\":\"$DYN_Username\", \"password\":\"$DYN_Password\"}"
 | 
			
		||||
  dyn_url="$DYN_API/Session/"
 | 
			
		||||
  method="POST"
 | 
			
		||||
 | 
			
		||||
  _debug data "$data"
 | 
			
		||||
  _debug dyn_url "$dyn_url"
 | 
			
		||||
 | 
			
		||||
  export _H1="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$data" "$dyn_url" "" "$method")"
 | 
			
		||||
  sessionstatus="$(printf "%s\n" "$response" | _egrep_o '"status" *: *"[^"]*' | _head_n 1 | sed 's#^"status" *: *"##')"
 | 
			
		||||
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
  _debug sessionstatus "$sessionstatus"
 | 
			
		||||
 | 
			
		||||
  if [ "$sessionstatus" = "success" ]; then
 | 
			
		||||
    _dyn_authtoken="$(printf "%s\n" "$response" | _egrep_o '"token" *: *"[^"]*' | _head_n 1 | sed 's#^"token" *: *"##')"
 | 
			
		||||
    _info "Token received"
 | 
			
		||||
    _debug _dyn_authtoken "$_dyn_authtoken"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _dyn_authtoken=""
 | 
			
		||||
  _err "get token failed"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain=_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _dyn_zone=domain.com
 | 
			
		||||
_dyn_get_zone() {
 | 
			
		||||
  i=2
 | 
			
		||||
  while true; do
 | 
			
		||||
    domain="$(printf "%s" "$fulldomain" | cut -d . -f "$i-100")"
 | 
			
		||||
    if [ -z "$domain" ]; then
 | 
			
		||||
      break
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    dyn_url="$DYN_API/Zone/$domain/"
 | 
			
		||||
 | 
			
		||||
    export _H1="Auth-Token: $_dyn_authtoken"
 | 
			
		||||
    export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
    response="$(_get "$dyn_url" "" "")"
 | 
			
		||||
    sessionstatus="$(printf "%s\n" "$response" | _egrep_o '"status" *: *"[^"]*' | _head_n 1 | sed 's#^"status" *: *"##')"
 | 
			
		||||
 | 
			
		||||
    _debug dyn_url "$dyn_url"
 | 
			
		||||
    _debug response "$response"
 | 
			
		||||
    _debug sessionstatus "$sessionstatus"
 | 
			
		||||
 | 
			
		||||
    if [ "$sessionstatus" = "success" ]; then
 | 
			
		||||
      _dyn_zone="$domain"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  _dyn_zone=""
 | 
			
		||||
  _err "get zone failed"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#add TXT record
 | 
			
		||||
_dyn_add_record() {
 | 
			
		||||
 | 
			
		||||
  _info "Adding TXT record"
 | 
			
		||||
 | 
			
		||||
  data="{\"rdata\":{\"txtdata\":\"$txtvalue\"},\"ttl\":\"300\"}"
 | 
			
		||||
  dyn_url="$DYN_API/TXTRecord/$_dyn_zone/$fulldomain/"
 | 
			
		||||
  method="POST"
 | 
			
		||||
 | 
			
		||||
  export _H1="Auth-Token: $_dyn_authtoken"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$data" "$dyn_url" "" "$method")"
 | 
			
		||||
  sessionstatus="$(printf "%s\n" "$response" | _egrep_o '"status" *: *"[^"]*' | _head_n 1 | sed 's#^"status" *: *"##')"
 | 
			
		||||
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
  _debug sessionstatus "$sessionstatus"
 | 
			
		||||
 | 
			
		||||
  if [ "$sessionstatus" = "success" ]; then
 | 
			
		||||
    _info "TXT Record successfully added"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _err "add TXT record failed"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#publish the zone
 | 
			
		||||
_dyn_publish_zone() {
 | 
			
		||||
 | 
			
		||||
  _info "Publishing zone"
 | 
			
		||||
 | 
			
		||||
  data="{\"publish\":\"true\"}"
 | 
			
		||||
  dyn_url="$DYN_API/Zone/$_dyn_zone/"
 | 
			
		||||
  method="PUT"
 | 
			
		||||
 | 
			
		||||
  export _H1="Auth-Token: $_dyn_authtoken"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$data" "$dyn_url" "" "$method")"
 | 
			
		||||
  sessionstatus="$(printf "%s\n" "$response" | _egrep_o '"status" *: *"[^"]*' | _head_n 1 | sed 's#^"status" *: *"##')"
 | 
			
		||||
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
  _debug sessionstatus "$sessionstatus"
 | 
			
		||||
 | 
			
		||||
  if [ "$sessionstatus" = "success" ]; then
 | 
			
		||||
    _info "Zone published"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _err "publish zone failed"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#get record_id of TXT record so we can delete the record
 | 
			
		||||
_dyn_get_record_id() {
 | 
			
		||||
 | 
			
		||||
  _info "Getting record_id of TXT record"
 | 
			
		||||
 | 
			
		||||
  dyn_url="$DYN_API/TXTRecord/$_dyn_zone/$fulldomain/"
 | 
			
		||||
 | 
			
		||||
  export _H1="Auth-Token: $_dyn_authtoken"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  response="$(_get "$dyn_url" "" "")"
 | 
			
		||||
  sessionstatus="$(printf "%s\n" "$response" | _egrep_o '"status" *: *"[^"]*' | _head_n 1 | sed 's#^"status" *: *"##')"
 | 
			
		||||
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
  _debug sessionstatus "$sessionstatus"
 | 
			
		||||
 | 
			
		||||
  if [ "$sessionstatus" = "success" ]; then
 | 
			
		||||
    _dyn_record_id="$(printf "%s\n" "$response" | _egrep_o "\"data\" *: *\[\"/REST/TXTRecord/$_dyn_zone/$fulldomain/[^\"]*" | _head_n 1 | sed "s#^\"data\" *: *\[\"/REST/TXTRecord/$_dyn_zone/$fulldomain/##")"
 | 
			
		||||
    _debug _dyn_record_id "$_dyn_record_id"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _dyn_record_id=""
 | 
			
		||||
  _err "getting record_id failed"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#delete TXT record
 | 
			
		||||
_dyn_rm_record() {
 | 
			
		||||
 | 
			
		||||
  _info "Deleting TXT record"
 | 
			
		||||
 | 
			
		||||
  dyn_url="$DYN_API/TXTRecord/$_dyn_zone/$fulldomain/$_dyn_record_id/"
 | 
			
		||||
  method="DELETE"
 | 
			
		||||
 | 
			
		||||
  _debug dyn_url "$dyn_url"
 | 
			
		||||
 | 
			
		||||
  export _H1="Auth-Token: $_dyn_authtoken"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  response="$(_post "" "$dyn_url" "" "$method")"
 | 
			
		||||
  sessionstatus="$(printf "%s\n" "$response" | _egrep_o '"status" *: *"[^"]*' | _head_n 1 | sed 's#^"status" *: *"##')"
 | 
			
		||||
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
  _debug sessionstatus "$sessionstatus"
 | 
			
		||||
 | 
			
		||||
  if [ "$sessionstatus" = "success" ]; then
 | 
			
		||||
    _info "TXT record successfully deleted"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _err "delete TXT record failed"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#logout
 | 
			
		||||
_dyn_end_session() {
 | 
			
		||||
 | 
			
		||||
  _info "End Dyn API Session"
 | 
			
		||||
 | 
			
		||||
  dyn_url="$DYN_API/Session/"
 | 
			
		||||
  method="DELETE"
 | 
			
		||||
 | 
			
		||||
  _debug dyn_url "$dyn_url"
 | 
			
		||||
 | 
			
		||||
  export _H1="Auth-Token: $_dyn_authtoken"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  response="$(_post "" "$dyn_url" "" "$method")"
 | 
			
		||||
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
 | 
			
		||||
  _dyn_authtoken=""
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										228
									
								
								dnsapi/dns_dynu.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										228
									
								
								dnsapi/dns_dynu.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,228 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Client ID
 | 
			
		||||
#Dynu_ClientId="0b71cae7-a099-4f6b-8ddf-94571cdb760d"
 | 
			
		||||
#
 | 
			
		||||
#Secret
 | 
			
		||||
#Dynu_Secret="aCUEY4BDCV45KI8CSIC3sp2LKQ9"
 | 
			
		||||
#
 | 
			
		||||
#Token
 | 
			
		||||
Dynu_Token=""
 | 
			
		||||
#
 | 
			
		||||
#Endpoint
 | 
			
		||||
Dynu_EndPoint="https://api.dynu.com/v2"
 | 
			
		||||
#
 | 
			
		||||
#Author: Dynu Systems, Inc.
 | 
			
		||||
#Report Bugs here: https://github.com/shar0119/acme.sh
 | 
			
		||||
#
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add _acme-challenge.www.domain.com "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_dynu_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if [ -z "$Dynu_ClientId" ] || [ -z "$Dynu_Secret" ]; then
 | 
			
		||||
    Dynu_ClientId=""
 | 
			
		||||
    Dynu_Secret=""
 | 
			
		||||
    _err "Dynu client id and secret is not specified."
 | 
			
		||||
    _err "Please create you API client id and secret and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the client id and secret to the account conf file.
 | 
			
		||||
  _saveaccountconf Dynu_ClientId "$Dynu_ClientId"
 | 
			
		||||
  _saveaccountconf Dynu_Secret "$Dynu_Secret"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$Dynu_Token" ]; then
 | 
			
		||||
    _info "Getting Dynu token."
 | 
			
		||||
    if ! _dynu_authentication; then
 | 
			
		||||
      _err "Can not get token."
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "Detect root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "Invalid domain."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _node "$_node"
 | 
			
		||||
  _debug _domain_name "$_domain_name"
 | 
			
		||||
 | 
			
		||||
  _info "Creating TXT record."
 | 
			
		||||
  if ! _dynu_rest POST "dns/$dnsId/record" "{\"domainId\":\"$dnsId\",\"nodeName\":\"$_node\",\"recordType\":\"TXT\",\"textData\":\"$txtvalue\",\"state\":true,\"ttl\":90}"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "200"; then
 | 
			
		||||
    _err "Could not add TXT record."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: rm _acme-challenge.www.domain.com "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_dynu_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if [ -z "$Dynu_ClientId" ] || [ -z "$Dynu_Secret" ]; then
 | 
			
		||||
    Dynu_ClientId=""
 | 
			
		||||
    Dynu_Secret=""
 | 
			
		||||
    _err "Dynu client id and secret is not specified."
 | 
			
		||||
    _err "Please create you API client id and secret and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the client id and secret to the account conf file.
 | 
			
		||||
  _saveaccountconf Dynu_ClientId "$Dynu_ClientId"
 | 
			
		||||
  _saveaccountconf Dynu_Secret "$Dynu_Secret"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$Dynu_Token" ]; then
 | 
			
		||||
    _info "Getting Dynu token."
 | 
			
		||||
    if ! _dynu_authentication; then
 | 
			
		||||
      _err "Can not get token."
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "Detect root zone."
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "Invalid domain."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _node "$_node"
 | 
			
		||||
  _debug _domain_name "$_domain_name"
 | 
			
		||||
 | 
			
		||||
  _info "Checking for TXT record."
 | 
			
		||||
  if ! _get_recordid "$fulldomain" "$txtvalue"; then
 | 
			
		||||
    _err "Could not get TXT record id."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$_dns_record_id" = "" ]; then
 | 
			
		||||
    _err "TXT record not found."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Removing TXT record."
 | 
			
		||||
  if ! _delete_txt_record "$_dns_record_id"; then
 | 
			
		||||
    _err "Could not remove TXT record $_dns_record_id."
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
########  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _node=_acme-challenge.www
 | 
			
		||||
# _domain_name=domain.com
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _dynu_rest GET "dns/getroot/$h"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"domainName\":\"$h\"" >/dev/null; then
 | 
			
		||||
      dnsId=$(printf "%s" "$response" | tr -d "{}" | cut -d , -f 2 | cut -d : -f 2)
 | 
			
		||||
      _domain_name=$h
 | 
			
		||||
      _node=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_get_recordid() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if ! _dynu_rest GET "dns/$dnsId/record"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "$txtvalue"; then
 | 
			
		||||
    _dns_record_id=0
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _dns_record_id=$(printf "%s" "$response" | sed -e 's/[^{]*\({[^}]*}\)[^{]*/\1\n/g' | grep "\"textData\":\"$txtvalue\"" | sed -e 's/.*"id":\([^,]*\).*/\1/')
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_delete_txt_record() {
 | 
			
		||||
  _dns_record_id=$1
 | 
			
		||||
 | 
			
		||||
  if ! _dynu_rest DELETE "dns/$dnsId/record/$_dns_record_id"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "200"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_dynu_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="Authorization: Bearer $Dynu_Token"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  if [ "$data" ] || [ "$m" = "DELETE" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$Dynu_EndPoint/$ep" "" "$m")"
 | 
			
		||||
  else
 | 
			
		||||
    _info "Getting $Dynu_EndPoint/$ep"
 | 
			
		||||
    response="$(_get "$Dynu_EndPoint/$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_dynu_authentication() {
 | 
			
		||||
  realm="$(printf "%s" "$Dynu_ClientId:$Dynu_Secret" | _base64)"
 | 
			
		||||
 | 
			
		||||
  export _H1="Authorization: Basic $realm"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  response="$(_get "$Dynu_EndPoint/oauth2/token")"
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "Authentication failed."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  if _contains "$response" "access_token"; then
 | 
			
		||||
    Dynu_Token=$(printf "%s" "$response" | tr -d "{}" | cut -d , -f 1 | cut -d : -f 2 | cut -d '"' -f 2)
 | 
			
		||||
  fi
 | 
			
		||||
  if _contains "$Dynu_Token" "null"; then
 | 
			
		||||
    Dynu_Token=""
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										358
									
								
								dnsapi/dns_euserv.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										358
									
								
								dnsapi/dns_euserv.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,358 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#This is the euserv.eu api wrapper for acme.sh
 | 
			
		||||
#
 | 
			
		||||
#Author: Michael Brueckner
 | 
			
		||||
#Report Bugs: https://www.github.com/initit/acme.sh  or  mbr@initit.de
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
#EUSERV_Username="username"
 | 
			
		||||
#
 | 
			
		||||
#EUSERV_Password="password"
 | 
			
		||||
#
 | 
			
		||||
# Dependencies:
 | 
			
		||||
# -------------
 | 
			
		||||
# - none -
 | 
			
		||||
 | 
			
		||||
EUSERV_Api="https://api.euserv.net"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_euserv_add() {
 | 
			
		||||
  fulldomain="$(echo "$1" | _lower_case)"
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  EUSERV_Username="${EUSERV_Username:-$(_readaccountconf_mutable EUSERV_Username)}"
 | 
			
		||||
  EUSERV_Password="${EUSERV_Password:-$(_readaccountconf_mutable EUSERV_Password)}"
 | 
			
		||||
  if [ -z "$EUSERV_Username" ] || [ -z "$EUSERV_Password" ]; then
 | 
			
		||||
    EUSERV_Username=""
 | 
			
		||||
    EUSERV_Password=""
 | 
			
		||||
    _err "You don't specify euserv user and password yet."
 | 
			
		||||
    _err "Please create your key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the user and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable EUSERV_Username "$EUSERV_Username"
 | 
			
		||||
  _saveaccountconf_mutable EUSERV_Password "$EUSERV_Password"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug "_sub_domain" "$_sub_domain"
 | 
			
		||||
  _debug "_domain" "$_domain"
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  if ! _euserv_add_record "$_domain" "$_sub_domain" "$txtvalue"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_euserv_rm() {
 | 
			
		||||
 | 
			
		||||
  fulldomain="$(echo "$1" | _lower_case)"
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  EUSERV_Username="${EUSERV_Username:-$(_readaccountconf_mutable EUSERV_Username)}"
 | 
			
		||||
  EUSERV_Password="${EUSERV_Password:-$(_readaccountconf_mutable EUSERV_Password)}"
 | 
			
		||||
  if [ -z "$EUSERV_Username" ] || [ -z "$EUSERV_Password" ]; then
 | 
			
		||||
    EUSERV_Username=""
 | 
			
		||||
    EUSERV_Password=""
 | 
			
		||||
    _err "You don't specify euserv user and password yet."
 | 
			
		||||
    _err "Please create your key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the user and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable EUSERV_Username "$EUSERV_Username"
 | 
			
		||||
  _saveaccountconf_mutable EUSERV_Password "$EUSERV_Password"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug "_sub_domain" "$_sub_domain"
 | 
			
		||||
  _debug "_domain" "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
    <methodName>domain.dns_get_active_records</methodName>
 | 
			
		||||
    <params>
 | 
			
		||||
      <param>
 | 
			
		||||
       <value>
 | 
			
		||||
         <struct>
 | 
			
		||||
           <member>
 | 
			
		||||
             <name>login</name>
 | 
			
		||||
             <value>
 | 
			
		||||
               <string>%s</string>
 | 
			
		||||
             </value>
 | 
			
		||||
            </member>
 | 
			
		||||
            <member>
 | 
			
		||||
              <name>password</name>
 | 
			
		||||
              <value>
 | 
			
		||||
                <string>%s</string>
 | 
			
		||||
              </value>
 | 
			
		||||
            </member>
 | 
			
		||||
            <member>
 | 
			
		||||
              <name>domain_id</name>
 | 
			
		||||
              <value>
 | 
			
		||||
                <int>%s</int>
 | 
			
		||||
              </value>
 | 
			
		||||
            </member>
 | 
			
		||||
          </struct>
 | 
			
		||||
        </value>
 | 
			
		||||
      </param>
 | 
			
		||||
    </params>
 | 
			
		||||
  </methodCall>' "$EUSERV_Username" "$EUSERV_Password" "$_euserv_domain_id")
 | 
			
		||||
 | 
			
		||||
  export _H1="Content-Type: text/xml"
 | 
			
		||||
  response="$(_post "$xml_content" "$EUSERV_Api" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "<member><name>status</name><value><i4>100</i4></value></member>"; then
 | 
			
		||||
    _err "Error could not get txt records"
 | 
			
		||||
    _debug "xml_content" "$xml_content"
 | 
			
		||||
    _debug "response" "$response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! echo "$response" | grep '>dns_record_content<.*>'"$txtvalue"'<' >/dev/null; then
 | 
			
		||||
    _info "Do not need to delete record"
 | 
			
		||||
  else
 | 
			
		||||
    # find XML block where txtvalue is in. The record_id is allways prior this line!
 | 
			
		||||
    _endLine=$(echo "$response" | grep -n '>dns_record_content<.*>'"$txtvalue"'<' | cut -d ':' -f 1)
 | 
			
		||||
    # record_id is the last <name> Tag with a number before the row _endLine, identified by </name><value><struct> 
 | 
			
		||||
    _record_id=$(echo "$response" | sed -n '1,'"$_endLine"'p' | grep '</name><value><struct>' | _tail_n 1 | sed 's/.*<name>\([0-9]*\)<\/name>.*/\1/')
 | 
			
		||||
    _info "Deleting record"
 | 
			
		||||
    _euserv_delete_record "$_record_id"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  _debug "get root"
 | 
			
		||||
 | 
			
		||||
  # Just to read the domain_orders once
 | 
			
		||||
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  if ! _euserv_get_domain_orders; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Get saved response with domain_orders
 | 
			
		||||
  response="$_euserv_domain_orders"
 | 
			
		||||
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(echo "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "$h"; then
 | 
			
		||||
      _sub_domain=$(echo "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain="$h"
 | 
			
		||||
      if ! _euserv_get_domain_id "$_domain"; then
 | 
			
		||||
        _err "invalid domain"
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_euserv_get_domain_orders() {
 | 
			
		||||
  # returns: _euserv_domain_orders
 | 
			
		||||
 | 
			
		||||
  _debug "get domain_orders"
 | 
			
		||||
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
    <methodName>domain.get_domain_orders</methodName>
 | 
			
		||||
    <params>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value>
 | 
			
		||||
          <struct>
 | 
			
		||||
            <member>
 | 
			
		||||
              <name>login</name>
 | 
			
		||||
              <value><string>%s</string></value>
 | 
			
		||||
            </member>
 | 
			
		||||
            <member>
 | 
			
		||||
              <name>password</name>
 | 
			
		||||
              <value><string>%s</string></value>
 | 
			
		||||
            </member>
 | 
			
		||||
          </struct>
 | 
			
		||||
        </value>
 | 
			
		||||
      </param>
 | 
			
		||||
    </params>
 | 
			
		||||
  </methodCall>' "$EUSERV_Username" "$EUSERV_Password")
 | 
			
		||||
 | 
			
		||||
  export _H1="Content-Type: text/xml"
 | 
			
		||||
  response="$(_post "$xml_content" "$EUSERV_Api" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "<member><name>status</name><value><i4>100</i4></value></member>"; then
 | 
			
		||||
    _err "Error could not get domain orders"
 | 
			
		||||
    _debug "xml_content" "$xml_content"
 | 
			
		||||
    _debug "response" "$response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # save response to reduce API calls
 | 
			
		||||
  _euserv_domain_orders="$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_euserv_get_domain_id() {
 | 
			
		||||
  # returns: _euserv_domain_id
 | 
			
		||||
  domain=$1
 | 
			
		||||
  _debug "get domain_id"
 | 
			
		||||
 | 
			
		||||
  # find line where the domain name is within the $response
 | 
			
		||||
  _startLine=$(echo "$_euserv_domain_orders" | grep -n '>domain_name<.*>'"$domain"'<' | cut -d ':' -f 1)
 | 
			
		||||
  # next occurency of domain_id after the domain_name is the correct one
 | 
			
		||||
  _euserv_domain_id=$(echo "$_euserv_domain_orders" | sed -n "$_startLine"',$p' | grep '>domain_id<' | _head_n 1 | sed 's/.*<i4>\([0-9]*\)<\/i4>.*/\1/')
 | 
			
		||||
 | 
			
		||||
  if [ -z "$_euserv_domain_id" ]; then
 | 
			
		||||
    _err "Could not find domain_id for domain $domain"
 | 
			
		||||
    _debug "_euserv_domain_orders" "$_euserv_domain_orders"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_euserv_delete_record() {
 | 
			
		||||
  record_id=$1
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
    <methodName>domain.dns_delete_record</methodName>
 | 
			
		||||
    <params>
 | 
			
		||||
      <param>
 | 
			
		||||
       <value>
 | 
			
		||||
         <struct>
 | 
			
		||||
           <member>
 | 
			
		||||
             <name>login</name>
 | 
			
		||||
             <value>
 | 
			
		||||
               <string>%s</string>
 | 
			
		||||
             </value>
 | 
			
		||||
            </member>
 | 
			
		||||
            <member>
 | 
			
		||||
              <name>password</name>
 | 
			
		||||
              <value>
 | 
			
		||||
                <string>%s</string>
 | 
			
		||||
              </value>
 | 
			
		||||
            </member>
 | 
			
		||||
            <member>
 | 
			
		||||
              <name>dns_record_id</name>
 | 
			
		||||
              <value>
 | 
			
		||||
                <int>%s</int>
 | 
			
		||||
              </value>
 | 
			
		||||
            </member>
 | 
			
		||||
          </struct>
 | 
			
		||||
        </value>
 | 
			
		||||
      </param>
 | 
			
		||||
    </params>
 | 
			
		||||
  </methodCall>' "$EUSERV_Username" "$EUSERV_Password" "$record_id")
 | 
			
		||||
 | 
			
		||||
  export _H1="Content-Type: text/xml"
 | 
			
		||||
  response="$(_post "$xml_content" "$EUSERV_Api" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "<member><name>status</name><value><i4>100</i4></value></member>"; then
 | 
			
		||||
    _err "Error deleting record"
 | 
			
		||||
    _debug "xml_content" "$xml_content"
 | 
			
		||||
    _debug "response" "$response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_euserv_add_record() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  sub_domain=$2
 | 
			
		||||
  txtval=$3
 | 
			
		||||
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
  <methodName>domain.dns_create_record</methodName>
 | 
			
		||||
  <params>
 | 
			
		||||
   <param>
 | 
			
		||||
    <value>
 | 
			
		||||
     <struct>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>login</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>%s</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>password</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>%s</string></value>
 | 
			
		||||
      </member>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>domain_id</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <int>%s</int>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>dns_record_subdomain</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>%s</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>dns_record_type</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>TXT</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>dns_record_value</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>%s</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>dns_record_ttl</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <int>300</int>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
     </struct>
 | 
			
		||||
    </value>
 | 
			
		||||
   </param>
 | 
			
		||||
  </params>
 | 
			
		||||
  </methodCall>' "$EUSERV_Username" "$EUSERV_Password" "$_euserv_domain_id" "$sub_domain" "$txtval")
 | 
			
		||||
 | 
			
		||||
  export _H1="Content-Type: text/xml"
 | 
			
		||||
  response="$(_post "$xml_content" "$EUSERV_Api" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "<member><name>status</name><value><i4>100</i4></value></member>"; then
 | 
			
		||||
    _err "Error could not create record"
 | 
			
		||||
    _debug "xml_content" "$xml_content"
 | 
			
		||||
    _debug "response" "$response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										168
									
								
								dnsapi/dns_exoscale.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										168
									
								
								dnsapi/dns_exoscale.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,168 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
EXOSCALE_API=https://api.exoscale.com/dns/v1
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
# Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
# Used to add txt record
 | 
			
		||||
dns_exoscale_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if ! _checkAuth; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  if _exoscale_rest POST "domains/$_domain_id/records" "{\"record\":{\"name\":\"$_sub_domain\",\"record_type\":\"TXT\",\"content\":\"$txtvalue\",\"ttl\":120}}" "$_domain_token"; then
 | 
			
		||||
    if _contains "$response" "$txtvalue"; then
 | 
			
		||||
      _info "Added, OK"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  _err "Add txt record error."
 | 
			
		||||
  return 1
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Usage: fulldomain txtvalue
 | 
			
		||||
# Used to remove the txt record after validation
 | 
			
		||||
dns_exoscale_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if ! _checkAuth; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _exoscale_rest GET "domains/${_domain_id}/records?type=TXT&name=$_sub_domain" "" "$_domain_token"
 | 
			
		||||
  if _contains "$response" "\"name\":\"$_sub_domain\"" >/dev/null; then
 | 
			
		||||
    _record_id=$(echo "$response" | tr '{' "\n" | grep "\"content\":\"$txtvalue\"" | _egrep_o "\"id\":[^,]+" | _head_n 1 | cut -d : -f 2 | tr -d \")
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$_record_id" ]; then
 | 
			
		||||
    _err "Can not get record id to remove."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "Deleting record $_record_id"
 | 
			
		||||
 | 
			
		||||
  if ! _exoscale_rest DELETE "domains/$_domain_id/records/$_record_id" "" "$_domain_token"; then
 | 
			
		||||
    _err "Delete record error."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_checkAuth() {
 | 
			
		||||
  EXOSCALE_API_KEY="${EXOSCALE_API_KEY:-$(_readaccountconf_mutable EXOSCALE_API_KEY)}"
 | 
			
		||||
  EXOSCALE_SECRET_KEY="${EXOSCALE_SECRET_KEY:-$(_readaccountconf_mutable EXOSCALE_SECRET_KEY)}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$EXOSCALE_API_KEY" ] || [ -z "$EXOSCALE_SECRET_KEY" ]; then
 | 
			
		||||
    EXOSCALE_API_KEY=""
 | 
			
		||||
    EXOSCALE_SECRET_KEY=""
 | 
			
		||||
    _err "You don't specify Exoscale application key and application secret yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf_mutable EXOSCALE_API_KEY "$EXOSCALE_API_KEY"
 | 
			
		||||
  _saveaccountconf_mutable EXOSCALE_SECRET_KEY "$EXOSCALE_SECRET_KEY"
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
# _domain_token=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
 | 
			
		||||
  if ! _exoscale_rest GET "domains"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"name\":\"$h\"" >/dev/null; then
 | 
			
		||||
      _domain_id=$(echo "$response" | tr '{' "\n" | grep "\"name\":\"$h\"" | _egrep_o "\"id\":[^,]+" | _head_n 1 | cut -d : -f 2 | tr -d \")
 | 
			
		||||
      _domain_token=$(echo "$response" | tr '{' "\n" | grep "\"name\":\"$h\"" | _egrep_o "\"token\":\"[^\"]*\"" | _head_n 1 | cut -d : -f 2 | tr -d \")
 | 
			
		||||
      if [ "$_domain_token" ] && [ "$_domain_id" ]; then
 | 
			
		||||
        _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
        _domain=$h
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# returns response
 | 
			
		||||
_exoscale_rest() {
 | 
			
		||||
  method=$1
 | 
			
		||||
  path="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  token="$4"
 | 
			
		||||
  request_url="$EXOSCALE_API/$path"
 | 
			
		||||
  _debug "$path"
 | 
			
		||||
 | 
			
		||||
  export _H1="Accept: application/json"
 | 
			
		||||
 | 
			
		||||
  if [ "$token" ]; then
 | 
			
		||||
    export _H2="X-DNS-Domain-Token: $token"
 | 
			
		||||
  else
 | 
			
		||||
    export _H2="X-DNS-Token: $EXOSCALE_API_KEY:$EXOSCALE_SECRET_KEY"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$data" ] || [ "$method" = "DELETE" ]; then
 | 
			
		||||
    export _H3="Content-Type: application/json"
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$request_url" "" "$method")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$request_url" "" "" "$method")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $request_url"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										326
									
								
								dnsapi/dns_freedns.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										326
									
								
								dnsapi/dns_freedns.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,326 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#This file name is "dns_freedns.sh"
 | 
			
		||||
#So, here must be a method dns_freedns_add()
 | 
			
		||||
#Which will be called by acme.sh to add the txt record to your api system.
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
#
 | 
			
		||||
#Author: David Kerr
 | 
			
		||||
#Report Bugs here: https://github.com/dkerr64/acme.sh
 | 
			
		||||
#
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
# Export FreeDNS userid and password in following variables...
 | 
			
		||||
#  FREEDNS_User=username
 | 
			
		||||
#  FREEDNS_Password=password
 | 
			
		||||
# login cookie is saved in acme account config file so userid / pw
 | 
			
		||||
# need to be set only when changed.
 | 
			
		||||
 | 
			
		||||
#Usage: dns_freedns_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_freedns_add() {
 | 
			
		||||
  fulldomain="$1"
 | 
			
		||||
  txtvalue="$2"
 | 
			
		||||
 | 
			
		||||
  _info "Add TXT record using FreeDNS"
 | 
			
		||||
  _debug "fulldomain: $fulldomain"
 | 
			
		||||
  _debug "txtvalue: $txtvalue"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$FREEDNS_User" ] || [ -z "$FREEDNS_Password" ]; then
 | 
			
		||||
    FREEDNS_User=""
 | 
			
		||||
    FREEDNS_Password=""
 | 
			
		||||
    if [ -z "$FREEDNS_COOKIE" ]; then
 | 
			
		||||
      _err "You did not specify the FreeDNS username and password yet."
 | 
			
		||||
      _err "Please export as FREEDNS_User / FREEDNS_Password and try again."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    using_cached_cookies="true"
 | 
			
		||||
  else
 | 
			
		||||
    FREEDNS_COOKIE="$(_freedns_login "$FREEDNS_User" "$FREEDNS_Password")"
 | 
			
		||||
    if [ -z "$FREEDNS_COOKIE" ]; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    using_cached_cookies="false"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "FreeDNS login cookies: $FREEDNS_COOKIE (cached = $using_cached_cookies)"
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf FREEDNS_COOKIE "$FREEDNS_COOKIE"
 | 
			
		||||
 | 
			
		||||
  # split our full domain name into two parts...
 | 
			
		||||
  i="$(echo "$fulldomain" | tr '.' ' ' | wc -w)"
 | 
			
		||||
  i="$(_math "$i" - 1)"
 | 
			
		||||
  top_domain="$(echo "$fulldomain" | cut -d. -f "$i"-100)"
 | 
			
		||||
  i="$(_math "$i" - 1)"
 | 
			
		||||
  sub_domain="$(echo "$fulldomain" | cut -d. -f -"$i")"
 | 
			
		||||
 | 
			
		||||
  _debug "top_domain: $top_domain"
 | 
			
		||||
  _debug "sub_domain: $sub_domain"
 | 
			
		||||
 | 
			
		||||
  # Sometimes FreeDNS does not return the subdomain page but rather
 | 
			
		||||
  # returns a page regarding becoming a premium member.  This usually
 | 
			
		||||
  # happens after a period of inactivity.  Immediately trying again
 | 
			
		||||
  # returns the correct subdomain page.  So, we will try twice to
 | 
			
		||||
  # load the page and obtain our domain ID
 | 
			
		||||
  attempts=2
 | 
			
		||||
  while [ "$attempts" -gt "0" ]; do
 | 
			
		||||
    attempts="$(_math "$attempts" - 1)"
 | 
			
		||||
 | 
			
		||||
    htmlpage="$(_freedns_retrieve_subdomain_page "$FREEDNS_COOKIE")"
 | 
			
		||||
    if [ "$?" != "0" ]; then
 | 
			
		||||
      if [ "$using_cached_cookies" = "true" ]; then
 | 
			
		||||
        _err "Has your FreeDNS username and password changed?  If so..."
 | 
			
		||||
        _err "Please export as FREEDNS_User / FREEDNS_Password and try again."
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    subdomain_csv="$(echo "$htmlpage" | tr -d "\n\r" | _egrep_o '<form .*</form>' | sed 's/<tr>/@<tr>/g' | tr '@' '\n' | grep edit.php | grep "$top_domain")"
 | 
			
		||||
    _debug3 "subdomain_csv: $subdomain_csv"
 | 
			
		||||
 | 
			
		||||
    # The above beauty ends with striping out rows that do not have an
 | 
			
		||||
    # href to edit.php and do not have the top domain we are looking for.
 | 
			
		||||
    # So all we should be left with is CSV of table of subdomains we are
 | 
			
		||||
    # interested in.
 | 
			
		||||
 | 
			
		||||
    # Now we have to read through this table and extract the data we need
 | 
			
		||||
    lines="$(echo "$subdomain_csv" | wc -l)"
 | 
			
		||||
    i=0
 | 
			
		||||
    found=0
 | 
			
		||||
    DNSdomainid=""
 | 
			
		||||
    while [ "$i" -lt "$lines" ]; do
 | 
			
		||||
      i="$(_math "$i" + 1)"
 | 
			
		||||
      line="$(echo "$subdomain_csv" | sed -n "${i}p")"
 | 
			
		||||
      _debug2 "line: $line"
 | 
			
		||||
      if [ $found = 0 ] && _contains "$line" "<td>$top_domain</td>"; then
 | 
			
		||||
        # this line will contain DNSdomainid for the top_domain
 | 
			
		||||
        DNSdomainid="$(echo "$line" | _egrep_o "edit_domain_id *= *.*>" | cut -d = -f 2 | cut -d '>' -f 1)"
 | 
			
		||||
        _debug2 "DNSdomainid: $DNSdomainid"
 | 
			
		||||
        found=1
 | 
			
		||||
        break
 | 
			
		||||
      fi
 | 
			
		||||
    done
 | 
			
		||||
 | 
			
		||||
    if [ -z "$DNSdomainid" ]; then
 | 
			
		||||
      # If domain ID is empty then something went wrong (top level
 | 
			
		||||
      # domain not found at FreeDNS).
 | 
			
		||||
      if [ "$attempts" = "0" ]; then
 | 
			
		||||
        # exhausted maximum retry attempts
 | 
			
		||||
        _err "Domain $top_domain not found at FreeDNS"
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
    else
 | 
			
		||||
      # break out of the 'retry' loop... we have found our domain ID
 | 
			
		||||
      break
 | 
			
		||||
    fi
 | 
			
		||||
    _info "Domain $top_domain not found at FreeDNS"
 | 
			
		||||
    _info "Retry loading subdomain page ($attempts attempts remaining)"
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  # Add in new TXT record with the value provided
 | 
			
		||||
  _debug "Adding TXT record for $fulldomain, $txtvalue"
 | 
			
		||||
  _freedns_add_txt_record "$FREEDNS_COOKIE" "$DNSdomainid" "$sub_domain" "$txtvalue"
 | 
			
		||||
  return $?
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: fulldomain txtvalue
 | 
			
		||||
#Remove the txt record after validation.
 | 
			
		||||
dns_freedns_rm() {
 | 
			
		||||
  fulldomain="$1"
 | 
			
		||||
  txtvalue="$2"
 | 
			
		||||
 | 
			
		||||
  _info "Delete TXT record using FreeDNS"
 | 
			
		||||
  _debug "fulldomain: $fulldomain"
 | 
			
		||||
  _debug "txtvalue: $txtvalue"
 | 
			
		||||
 | 
			
		||||
  # Need to read cookie from conf file again in case new value set
 | 
			
		||||
  # during login to FreeDNS when TXT record was created.
 | 
			
		||||
  # acme.sh does not have a _readaccountconf() function
 | 
			
		||||
  FREEDNS_COOKIE="$(_read_conf "$ACCOUNT_CONF_PATH" "FREEDNS_COOKIE")"
 | 
			
		||||
  _debug "FreeDNS login cookies: $FREEDNS_COOKIE"
 | 
			
		||||
 | 
			
		||||
  # Sometimes FreeDNS does not return the subdomain page but rather
 | 
			
		||||
  # returns a page regarding becoming a premium member.  This usually
 | 
			
		||||
  # happens after a period of inactivity.  Immediately trying again
 | 
			
		||||
  # returns the correct subdomain page.  So, we will try twice to
 | 
			
		||||
  # load the page and obtain our TXT record.
 | 
			
		||||
  attempts=2
 | 
			
		||||
  while [ "$attempts" -gt "0" ]; do
 | 
			
		||||
    attempts="$(_math "$attempts" - 1)"
 | 
			
		||||
 | 
			
		||||
    htmlpage="$(_freedns_retrieve_subdomain_page "$FREEDNS_COOKIE")"
 | 
			
		||||
    if [ "$?" != "0" ]; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    subdomain_csv="$(echo "$htmlpage" | tr -d "\n\r" | _egrep_o '<form .*</form>' | sed 's/<tr>/@<tr>/g' | tr '@' '\n' | grep edit.php | grep "$fulldomain")"
 | 
			
		||||
    _debug3 "subdomain_csv: $subdomain_csv"
 | 
			
		||||
 | 
			
		||||
    # The above beauty ends with striping out rows that do not have an
 | 
			
		||||
    # href to edit.php and do not have the domain name we are looking for.
 | 
			
		||||
    # So all we should be left with is CSV of table of subdomains we are
 | 
			
		||||
    # interested in.
 | 
			
		||||
 | 
			
		||||
    # Now we have to read through this table and extract the data we need
 | 
			
		||||
    lines="$(echo "$subdomain_csv" | wc -l)"
 | 
			
		||||
    i=0
 | 
			
		||||
    found=0
 | 
			
		||||
    DNSdataid=""
 | 
			
		||||
    while [ "$i" -lt "$lines" ]; do
 | 
			
		||||
      i="$(_math "$i" + 1)"
 | 
			
		||||
      line="$(echo "$subdomain_csv" | sed -n "${i}p")"
 | 
			
		||||
      _debug3 "line: $line"
 | 
			
		||||
      DNSname="$(echo "$line" | _egrep_o 'edit.php.*</a>' | cut -d '>' -f 2 | cut -d '<' -f 1)"
 | 
			
		||||
      _debug2 "DNSname: $DNSname"
 | 
			
		||||
      if [ "$DNSname" = "$fulldomain" ]; then
 | 
			
		||||
        DNStype="$(echo "$line" | sed 's/<td/@<td/g' | tr '@' '\n' | sed -n '4p' | cut -d '>' -f 2 | cut -d '<' -f 1)"
 | 
			
		||||
        _debug2 "DNStype: $DNStype"
 | 
			
		||||
        if [ "$DNStype" = "TXT" ]; then
 | 
			
		||||
          DNSdataid="$(echo "$line" | _egrep_o 'data_id=.*' | cut -d = -f 2 | cut -d '>' -f 1)"
 | 
			
		||||
          _debug2 "DNSdataid: $DNSdataid"
 | 
			
		||||
          DNSvalue="$(echo "$line" | sed 's/<td/@<td/g' | tr '@' '\n' | sed -n '5p' | cut -d '>' -f 2 | cut -d '<' -f 1)"
 | 
			
		||||
          if _startswith "$DNSvalue" """; then
 | 
			
		||||
            # remove the quotation from the start
 | 
			
		||||
            DNSvalue="$(echo "$DNSvalue" | cut -c 7-)"
 | 
			
		||||
          fi
 | 
			
		||||
          if _endswith "$DNSvalue" "..."; then
 | 
			
		||||
            # value was truncated, remove the dot dot dot from the end
 | 
			
		||||
            DNSvalue="$(echo "$DNSvalue" | sed 's/...$//')"
 | 
			
		||||
          elif _endswith "$DNSvalue" """; then
 | 
			
		||||
            # else remove the closing quotation from the end
 | 
			
		||||
            DNSvalue="$(echo "$DNSvalue" | sed 's/......$//')"
 | 
			
		||||
          fi
 | 
			
		||||
          _debug2 "DNSvalue: $DNSvalue"
 | 
			
		||||
 | 
			
		||||
          if [ -n "$DNSdataid" ] && _startswith "$txtvalue" "$DNSvalue"; then
 | 
			
		||||
            # Found a match. But note... Website is truncating the
 | 
			
		||||
            # value field so we are only testing that part that is not 
 | 
			
		||||
            # truncated.  This should be accurate enough.
 | 
			
		||||
            _debug "Deleting TXT record for $fulldomain, $txtvalue"
 | 
			
		||||
            _freedns_delete_txt_record "$FREEDNS_COOKIE" "$DNSdataid"
 | 
			
		||||
            return $?
 | 
			
		||||
          fi
 | 
			
		||||
 | 
			
		||||
        fi
 | 
			
		||||
      fi
 | 
			
		||||
    done
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  # If we get this far we did not find a match (after two attempts)
 | 
			
		||||
  # Not necessarily an error, but log anyway.
 | 
			
		||||
  _debug3 "$subdomain_csv"
 | 
			
		||||
  _info "Cannot delete TXT record for $fulldomain, $txtvalue. Does not exist at FreeDNS"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
# usage: _freedns_login username password
 | 
			
		||||
# print string "cookie=value" etc.
 | 
			
		||||
# returns 0 success
 | 
			
		||||
_freedns_login() {
 | 
			
		||||
  export _H1="Accept-Language:en-US"
 | 
			
		||||
  username="$1"
 | 
			
		||||
  password="$2"
 | 
			
		||||
  url="https://freedns.afraid.org/zc.php?step=2"
 | 
			
		||||
 | 
			
		||||
  _debug "Login to FreeDNS as user $username"
 | 
			
		||||
 | 
			
		||||
  htmlpage="$(_post "username=$(printf '%s' "$username" | _url_encode)&password=$(printf '%s' "$password" | _url_encode)&submit=Login&action=auth" "$url")"
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "FreeDNS login failed for user $username bad RC from _post"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  cookies="$(grep -i '^Set-Cookie.*dns_cookie.*$' "$HTTP_HEADER" | _head_n 1 | tr -d "\r\n" | cut -d " " -f 2)"
 | 
			
		||||
 | 
			
		||||
  # if cookies is not empty then logon successful
 | 
			
		||||
  if [ -z "$cookies" ]; then
 | 
			
		||||
    _debug3 "htmlpage: $htmlpage"
 | 
			
		||||
    _err "FreeDNS login failed for user $username. Check $HTTP_HEADER file"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  printf "%s" "$cookies"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# usage _freedns_retrieve_subdomain_page login_cookies
 | 
			
		||||
# echo page retrieved (html)
 | 
			
		||||
# returns 0 success
 | 
			
		||||
_freedns_retrieve_subdomain_page() {
 | 
			
		||||
  export _H1="Cookie:$1"
 | 
			
		||||
  export _H2="Accept-Language:en-US"
 | 
			
		||||
  url="https://freedns.afraid.org/subdomain/"
 | 
			
		||||
 | 
			
		||||
  _debug "Retrieve subdomain page from FreeDNS"
 | 
			
		||||
 | 
			
		||||
  htmlpage="$(_get "$url")"
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "FreeDNS retrieve subdomains failed bad RC from _get"
 | 
			
		||||
    return 1
 | 
			
		||||
  elif [ -z "$htmlpage" ]; then
 | 
			
		||||
    _err "FreeDNS returned empty subdomain page"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug3 "htmlpage: $htmlpage"
 | 
			
		||||
 | 
			
		||||
  printf "%s" "$htmlpage"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# usage _freedns_add_txt_record login_cookies domain_id subdomain value
 | 
			
		||||
# returns 0 success
 | 
			
		||||
_freedns_add_txt_record() {
 | 
			
		||||
  export _H1="Cookie:$1"
 | 
			
		||||
  export _H2="Accept-Language:en-US"
 | 
			
		||||
  domain_id="$2"
 | 
			
		||||
  subdomain="$3"
 | 
			
		||||
  value="$(printf '%s' "$4" | _url_encode)"
 | 
			
		||||
  url="https://freedns.afraid.org/subdomain/save.php?step=2"
 | 
			
		||||
 | 
			
		||||
  htmlpage="$(_post "type=TXT&domain_id=$domain_id&subdomain=$subdomain&address=%22$value%22&send=Save%21" "$url")"
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "FreeDNS failed to add TXT record for $subdomain bad RC from _post"
 | 
			
		||||
    return 1
 | 
			
		||||
  elif ! grep "200 OK" "$HTTP_HEADER" >/dev/null; then
 | 
			
		||||
    _debug3 "htmlpage: $htmlpage"
 | 
			
		||||
    _err "FreeDNS failed to add TXT record for $subdomain. Check $HTTP_HEADER file"
 | 
			
		||||
    return 1
 | 
			
		||||
  elif _contains "$htmlpage" "security code was incorrect"; then
 | 
			
		||||
    _debug3 "htmlpage: $htmlpage"
 | 
			
		||||
    _err "FreeDNS failed to add TXT record for $subdomain as FreeDNS requested security code"
 | 
			
		||||
    _err "Note that you cannot use automatic DNS validation for FreeDNS public domains"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug3 "htmlpage: $htmlpage"
 | 
			
		||||
  _info "Added acme challenge TXT record for $fulldomain at FreeDNS"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# usage _freedns_delete_txt_record login_cookies data_id
 | 
			
		||||
# returns 0 success
 | 
			
		||||
_freedns_delete_txt_record() {
 | 
			
		||||
  export _H1="Cookie:$1"
 | 
			
		||||
  export _H2="Accept-Language:en-US"
 | 
			
		||||
  data_id="$2"
 | 
			
		||||
  url="https://freedns.afraid.org/subdomain/delete2.php"
 | 
			
		||||
 | 
			
		||||
  htmlheader="$(_get "$url?data_id%5B%5D=$data_id&submit=delete+selected" "onlyheader")"
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "FreeDNS failed to delete TXT record for $data_id bad RC from _get"
 | 
			
		||||
    return 1
 | 
			
		||||
  elif ! _contains "$htmlheader" "200 OK"; then
 | 
			
		||||
    _debug2 "htmlheader: $htmlheader"
 | 
			
		||||
    _err "FreeDNS failed to delete TXT record $data_id"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Deleted acme challenge TXT record for $fulldomain at FreeDNS"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										175
									
								
								dnsapi/dns_gandi_livedns.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										175
									
								
								dnsapi/dns_gandi_livedns.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,175 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# Gandi LiveDNS v5 API
 | 
			
		||||
# http://doc.livedns.gandi.net/
 | 
			
		||||
# currently under beta
 | 
			
		||||
#
 | 
			
		||||
# Requires GANDI API KEY set in GANDI_LIVEDNS_KEY set as environment variable
 | 
			
		||||
#
 | 
			
		||||
#Author: Frédéric Crozat <fcrozat@suse.com>
 | 
			
		||||
#        Dominik Röttsches <drott@google.com>
 | 
			
		||||
#Report Bugs here: https://github.com/fcrozat/acme.sh
 | 
			
		||||
#
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
GANDI_LIVEDNS_API="https://dns.api.gandi.net/api/v5"
 | 
			
		||||
 | 
			
		||||
#Usage: dns_gandi_livedns_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_gandi_livedns_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if [ -z "$GANDI_LIVEDNS_KEY" ]; then
 | 
			
		||||
    _err "No API key specified for Gandi LiveDNS."
 | 
			
		||||
    _err "Create your key and export it as GANDI_LIVEDNS_KEY"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf GANDI_LIVEDNS_KEY "$GANDI_LIVEDNS_KEY"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
  _debug domain "$_domain"
 | 
			
		||||
  _debug sub_domain "$_sub_domain"
 | 
			
		||||
 | 
			
		||||
  _dns_gandi_append_record "$_domain" "$_sub_domain" "$txtvalue"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: fulldomain txtvalue
 | 
			
		||||
#Remove the txt record after validation.
 | 
			
		||||
dns_gandi_livedns_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug domain "$_domain"
 | 
			
		||||
  _debug sub_domain "$_sub_domain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  if ! _dns_gandi_existing_rrset_values "$_domain" "$_sub_domain"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _new_rrset_values=$(echo "$_rrset_values" | sed "s/...$txtvalue...//g")
 | 
			
		||||
  # Cleanup dangling commata.
 | 
			
		||||
  _new_rrset_values=$(echo "$_new_rrset_values" | sed "s/, ,/ ,/g")
 | 
			
		||||
  _new_rrset_values=$(echo "$_new_rrset_values" | sed "s/, *\]/\]/g")
 | 
			
		||||
  _new_rrset_values=$(echo "$_new_rrset_values" | sed "s/\[ *,/\[/g")
 | 
			
		||||
  _debug "New rrset_values" "$_new_rrset_values"
 | 
			
		||||
 | 
			
		||||
  _gandi_livedns_rest PUT \
 | 
			
		||||
    "domains/$_domain/records/$_sub_domain/TXT" \
 | 
			
		||||
    "{\"rrset_ttl\": 300, \"rrset_values\": $_new_rrset_values}" \
 | 
			
		||||
    && _contains "$response" '{"message": "DNS Record Created"}' \
 | 
			
		||||
    && _info "Removing record $(__green "success")"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _gandi_livedns_rest GET "domains/$h"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" '"code": 401'; then
 | 
			
		||||
      _err "$response"
 | 
			
		||||
      return 1
 | 
			
		||||
    elif _contains "$response" '"code": 404'; then
 | 
			
		||||
      _debug "$h not found"
 | 
			
		||||
    else
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain="$h"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p="$i"
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_dns_gandi_append_record() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  sub_domain=$2
 | 
			
		||||
  txtvalue=$3
 | 
			
		||||
 | 
			
		||||
  if _dns_gandi_existing_rrset_values "$domain" "$sub_domain"; then
 | 
			
		||||
    _debug "Appending new value"
 | 
			
		||||
    _rrset_values=$(echo "$_rrset_values" | sed "s/\"]/\",\"$txtvalue\"]/")
 | 
			
		||||
  else
 | 
			
		||||
    _debug "Creating new record" "$_rrset_values"
 | 
			
		||||
    _rrset_values="[\"$txtvalue\"]"
 | 
			
		||||
  fi
 | 
			
		||||
  _debug new_rrset_values "$_rrset_values"
 | 
			
		||||
  _gandi_livedns_rest PUT "domains/$_domain/records/$sub_domain/TXT" \
 | 
			
		||||
    "{\"rrset_ttl\": 300, \"rrset_values\": $_rrset_values}" \
 | 
			
		||||
    && _contains "$response" '{"message": "DNS Record Created"}' \
 | 
			
		||||
    && _info "Adding record $(__green "success")"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_dns_gandi_existing_rrset_values() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  sub_domain=$2
 | 
			
		||||
  if ! _gandi_livedns_rest GET "domains/$domain/records/$sub_domain"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  if ! _contains "$response" '"rrset_type": "TXT"'; then
 | 
			
		||||
    _debug "Does not have a _acme-challenge TXT record yet."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  if _contains "$response" '"rrset_values": \[\]'; then
 | 
			
		||||
    _debug "Empty rrset_values for TXT record, no previous TXT record."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug "Already has TXT record."
 | 
			
		||||
  _rrset_values=$(echo "$response" | _egrep_o 'rrset_values.*\[.*\]' \
 | 
			
		||||
    | _egrep_o '\[".*\"]')
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_gandi_livedns_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="Content-Type: application/json"
 | 
			
		||||
  export _H2="X-Api-Key: $GANDI_LIVEDNS_KEY"
 | 
			
		||||
 | 
			
		||||
  if [ "$m" = "GET" ]; then
 | 
			
		||||
    response="$(_get "$GANDI_LIVEDNS_API/$ep")"
 | 
			
		||||
  else
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$GANDI_LIVEDNS_API/$ep" "" "$m")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										167
									
								
								dnsapi/dns_gcloud.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										167
									
								
								dnsapi/dns_gcloud.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,167 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# Author: Janos Lenart <janos@lenart.io>
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
# Usage: dns_gcloud_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_gcloud_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _info "Using gcloud"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  _dns_gcloud_find_zone || return $?
 | 
			
		||||
 | 
			
		||||
  # Add an extra RR
 | 
			
		||||
  _dns_gcloud_start_tr || return $?
 | 
			
		||||
  _dns_gcloud_get_rrdatas || return $?
 | 
			
		||||
  echo "$rrdatas" | _dns_gcloud_remove_rrs || return $?
 | 
			
		||||
  printf "%s\n%s\n" "$rrdatas" "\"$txtvalue\"" | grep -v '^$' | _dns_gcloud_add_rrs || return $?
 | 
			
		||||
  _dns_gcloud_execute_tr || return $?
 | 
			
		||||
 | 
			
		||||
  _info "$fulldomain record added"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Usage: dns_gcloud_rm   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
# Remove the txt record after validation.
 | 
			
		||||
dns_gcloud_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _info "Using gcloud"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  _dns_gcloud_find_zone || return $?
 | 
			
		||||
 | 
			
		||||
  # Remove one RR
 | 
			
		||||
  _dns_gcloud_start_tr || return $?
 | 
			
		||||
  _dns_gcloud_get_rrdatas || return $?
 | 
			
		||||
  echo "$rrdatas" | _dns_gcloud_remove_rrs || return $?
 | 
			
		||||
  echo "$rrdatas" | grep -F -v "\"$txtvalue\"" | _dns_gcloud_add_rrs || return $?
 | 
			
		||||
  _dns_gcloud_execute_tr || return $?
 | 
			
		||||
 | 
			
		||||
  _info "$fulldomain record added"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_dns_gcloud_start_tr() {
 | 
			
		||||
  if ! trd=$(mktemp -d); then
 | 
			
		||||
    _err "_dns_gcloud_start_tr: failed to create temporary directory"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  tr="$trd/tr.yaml"
 | 
			
		||||
  _debug tr "$tr"
 | 
			
		||||
 | 
			
		||||
  if ! gcloud dns record-sets transaction start \
 | 
			
		||||
    --transaction-file="$tr" \
 | 
			
		||||
    --zone="$managedZone"; then
 | 
			
		||||
    rm -r "$trd"
 | 
			
		||||
    _err "_dns_gcloud_start_tr: failed to execute transaction"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_dns_gcloud_execute_tr() {
 | 
			
		||||
  if ! gcloud dns record-sets transaction execute \
 | 
			
		||||
    --transaction-file="$tr" \
 | 
			
		||||
    --zone="$managedZone"; then
 | 
			
		||||
    _debug tr "$(cat "$tr")"
 | 
			
		||||
    rm -r "$trd"
 | 
			
		||||
    _err "_dns_gcloud_execute_tr: failed to execute transaction"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  rm -r "$trd"
 | 
			
		||||
 | 
			
		||||
  for i in $(seq 1 120); do
 | 
			
		||||
    if gcloud dns record-sets changes list \
 | 
			
		||||
      --zone="$managedZone" \
 | 
			
		||||
      --filter='status != done' \
 | 
			
		||||
      | grep -q '^.*'; then
 | 
			
		||||
      _info "_dns_gcloud_execute_tr: waiting for transaction to be comitted ($i/120)..."
 | 
			
		||||
      sleep 5
 | 
			
		||||
    else
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  _err "_dns_gcloud_execute_tr: transaction is still pending after 10 minutes"
 | 
			
		||||
  rm -r "$trd"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_dns_gcloud_remove_rrs() {
 | 
			
		||||
  if ! xargs --no-run-if-empty gcloud dns record-sets transaction remove \
 | 
			
		||||
    --name="$fulldomain." \
 | 
			
		||||
    --ttl="$ttl" \
 | 
			
		||||
    --type=TXT \
 | 
			
		||||
    --zone="$managedZone" \
 | 
			
		||||
    --transaction-file="$tr"; then
 | 
			
		||||
    _debug tr "$(cat "$tr")"
 | 
			
		||||
    rm -r "$trd"
 | 
			
		||||
    _err "_dns_gcloud_remove_rrs: failed to remove RRs"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_dns_gcloud_add_rrs() {
 | 
			
		||||
  ttl=60
 | 
			
		||||
  if ! xargs --no-run-if-empty gcloud dns record-sets transaction add \
 | 
			
		||||
    --name="$fulldomain." \
 | 
			
		||||
    --ttl="$ttl" \
 | 
			
		||||
    --type=TXT \
 | 
			
		||||
    --zone="$managedZone" \
 | 
			
		||||
    --transaction-file="$tr"; then
 | 
			
		||||
    _debug tr "$(cat "$tr")"
 | 
			
		||||
    rm -r "$trd"
 | 
			
		||||
    _err "_dns_gcloud_add_rrs: failed to add RRs"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_dns_gcloud_find_zone() {
 | 
			
		||||
  # Prepare a filter that matches zones that are suiteable for this entry.
 | 
			
		||||
  # For example, _acme-challenge.something.domain.com might need to go into something.domain.com or domain.com;
 | 
			
		||||
  # this function finds the longest postfix that has a managed zone.
 | 
			
		||||
  part="$fulldomain"
 | 
			
		||||
  filter="dnsName=( "
 | 
			
		||||
  while [ "$part" != "" ]; do
 | 
			
		||||
    filter="$filter$part. "
 | 
			
		||||
    part="$(echo "$part" | sed 's/[^.]*\.*//')"
 | 
			
		||||
  done
 | 
			
		||||
  filter="$filter)"
 | 
			
		||||
  _debug filter "$filter"
 | 
			
		||||
 | 
			
		||||
  # List domains and find the longest match (in case of some levels of delegation)
 | 
			
		||||
  if ! match=$(gcloud dns managed-zones list \
 | 
			
		||||
    --format="value(name, dnsName)" \
 | 
			
		||||
    --filter="$filter" \
 | 
			
		||||
    | while read -r dnsName name; do
 | 
			
		||||
      printf "%s\t%s\t%s\n" "${#dnsName}" "$dnsName" "$name"
 | 
			
		||||
    done \
 | 
			
		||||
    | sort -n -r | _head_n 1 | cut -f2,3 | grep '^.*'); then
 | 
			
		||||
    _err "_dns_gcloud_find_zone: Can't find a matching managed zone! Perhaps wrong project or gcloud credentials?"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  dnsName=$(echo "$match" | cut -f2)
 | 
			
		||||
  _debug dnsName "$dnsName"
 | 
			
		||||
  managedZone=$(echo "$match" | cut -f1)
 | 
			
		||||
  _debug managedZone "$managedZone"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_dns_gcloud_get_rrdatas() {
 | 
			
		||||
  if ! rrdatas=$(gcloud dns record-sets list \
 | 
			
		||||
    --zone="$managedZone" \
 | 
			
		||||
    --name="$fulldomain." \
 | 
			
		||||
    --type=TXT \
 | 
			
		||||
    --format="value(ttl,rrdatas)"); then
 | 
			
		||||
    _err "_dns_gcloud_get_rrdatas: Failed to list record-sets"
 | 
			
		||||
    rm -r "$trd"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  ttl=$(echo "$rrdatas" | cut -f1)
 | 
			
		||||
  rrdatas=$(echo "$rrdatas" | cut -f2 | sed 's/","/"\n"/g')
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										176
									
								
								dnsapi/dns_gd.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										176
									
								
								dnsapi/dns_gd.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,176 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Godaddy domain api
 | 
			
		||||
#
 | 
			
		||||
#GD_Key="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
#
 | 
			
		||||
#GD_Secret="asdfsdfsfsdfsdfdfsdf"
 | 
			
		||||
 | 
			
		||||
GD_Api="https://api.godaddy.com/v1"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_gd_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  GD_Key="${GD_Key:-$(_readaccountconf_mutable GD_Key)}"
 | 
			
		||||
  GD_Secret="${GD_Secret:-$(_readaccountconf_mutable GD_Secret)}"
 | 
			
		||||
  if [ -z "$GD_Key" ] || [ -z "$GD_Secret" ]; then
 | 
			
		||||
    GD_Key=""
 | 
			
		||||
    GD_Secret=""
 | 
			
		||||
    _err "You don't specify godaddy api key and secret yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable GD_Key "$GD_Key"
 | 
			
		||||
  _saveaccountconf_mutable GD_Secret "$GD_Secret"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting existing records"
 | 
			
		||||
  if ! _gd_rest GET "domains/$_domain/records/TXT/$_sub_domain"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if _contains "$response" "$txtvalue"; then
 | 
			
		||||
    _info "The record is existing, skip"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _add_data="{\"data\":\"$txtvalue\"}"
 | 
			
		||||
  for t in $(echo "$response" | tr '{' "\n" | grep "\"name\":\"$_sub_domain\"" | tr ',' "\n" | grep '"data"' | cut -d : -f 2); do
 | 
			
		||||
    _debug2 t "$t"
 | 
			
		||||
    if [ "$t" ]; then
 | 
			
		||||
      _add_data="$_add_data,{\"data\":$t}"
 | 
			
		||||
    fi
 | 
			
		||||
  done
 | 
			
		||||
  _debug2 _add_data "$_add_data"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  if _gd_rest PUT "domains/$_domain/records/TXT/$_sub_domain" "[$_add_data]"; then
 | 
			
		||||
    _info "Added, sleeping 10 seconds"
 | 
			
		||||
    _sleep 10
 | 
			
		||||
    #todo: check if the record takes effect
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
  _err "Add txt record error."
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain
 | 
			
		||||
dns_gd_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  GD_Key="${GD_Key:-$(_readaccountconf_mutable GD_Key)}"
 | 
			
		||||
  GD_Secret="${GD_Secret:-$(_readaccountconf_mutable GD_Secret)}"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting existing records"
 | 
			
		||||
  if ! _gd_rest GET "domains/$_domain/records/TXT/$_sub_domain"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "$txtvalue"; then
 | 
			
		||||
    _info "The record is not existing, skip"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _add_data=""
 | 
			
		||||
  for t in $(echo "$response" | tr '{' "\n" | grep "\"name\":\"$_sub_domain\"" | tr ',' "\n" | grep '"data"' | cut -d : -f 2); do
 | 
			
		||||
    _debug2 t "$t"
 | 
			
		||||
    if [ "$t" ] && [ "$t" != "\"$txtvalue\"" ]; then
 | 
			
		||||
      if [ "$_add_data" ]; then
 | 
			
		||||
        _add_data="$_add_data,{\"data\":$t}"
 | 
			
		||||
      else
 | 
			
		||||
        _add_data="{\"data\":$t}"
 | 
			
		||||
      fi
 | 
			
		||||
    fi
 | 
			
		||||
  done
 | 
			
		||||
  if [ -z "$_add_data" ]; then
 | 
			
		||||
    _add_data="{\"data\":\"\"}"
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 _add_data "$_add_data"
 | 
			
		||||
 | 
			
		||||
  _gd_rest PUT "domains/$_domain/records/TXT/$_sub_domain" "[$_add_data]"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _gd_rest GET "domains/$h"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" '"code":"NOT_FOUND"'; then
 | 
			
		||||
      _debug "$h not found"
 | 
			
		||||
    else
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain="$h"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p="$i"
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_gd_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="Authorization: sso-key $GD_Key:$GD_Secret"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  if [ "$data" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$GD_Api/$ep" "" "$m")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$GD_Api/$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  if _contains "$response" "UNABLE_TO_AUTHENTICATE"; then
 | 
			
		||||
    _err "It seems that your api key or secret is not correct."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										168
									
								
								dnsapi/dns_gdnsdk.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										168
									
								
								dnsapi/dns_gdnsdk.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,168 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
#Author: Herman Sletteng
 | 
			
		||||
#Report Bugs here: https://github.com/loial/acme.sh
 | 
			
		||||
#
 | 
			
		||||
#
 | 
			
		||||
# Note, gratisdns requires a login first, so the script needs to handle
 | 
			
		||||
# temporary cookies. Since acme.sh _get/_post currently don't directly support
 | 
			
		||||
# cookies, I've defined wrapper functions _myget/_mypost to set the headers
 | 
			
		||||
 | 
			
		||||
GDNSDK_API="https://admin.gratisdns.com"
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
#Usage: dns_gdnsdk_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_gdnsdk_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _info "Using gratisdns.dk"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
  if ! _gratisdns_login; then
 | 
			
		||||
    _err "Login failed!"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  #finding domain zone
 | 
			
		||||
  if ! _get_domain; then
 | 
			
		||||
    _err "No matching root domain for $fulldomain found"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  # adding entry
 | 
			
		||||
  _info "Adding the entry"
 | 
			
		||||
  _mypost "action=dns_primary_record_added_txt&user_domain=$_domain&name=$fulldomain&txtdata=$txtvalue&ttl=1"
 | 
			
		||||
  if _successful_update; then return 0; fi
 | 
			
		||||
  _err "Couldn't create entry!"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: fulldomain txtvalue
 | 
			
		||||
#Remove the txt record after validation.
 | 
			
		||||
dns_gdnsdk_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _info "Using gratisdns.dk"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
  if ! _gratisdns_login; then
 | 
			
		||||
    _err "Login failed!"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  if ! _get_domain; then
 | 
			
		||||
    _err "No matching root domain for $fulldomain found"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _findentry "$fulldomain" "$txtvalue"
 | 
			
		||||
  if [ -z "$_id" ]; then
 | 
			
		||||
    _info "Entry doesn't exist, nothing to delete"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
  _debug "Deleting record..."
 | 
			
		||||
  _mypost "action=dns_primary_delete_txt&user_domain=$_domain&id=$_id"
 | 
			
		||||
  # removing entry
 | 
			
		||||
 | 
			
		||||
  if _successful_update; then return 0; fi
 | 
			
		||||
  _err "Couldn't delete entry!"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_checkcredentials() {
 | 
			
		||||
  GDNSDK_Username="${GDNSDK_Username:-$(_readaccountconf_mutable GDNSDK_Username)}"
 | 
			
		||||
  GDNSDK_Password="${GDNSDK_Password:-$(_readaccountconf_mutable GDNSDK_Password)}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$GDNSDK_Username" ] || [ -z "$GDNSDK_Password" ]; then
 | 
			
		||||
    GDNSDK_Username=""
 | 
			
		||||
    GDNSDK_Password=""
 | 
			
		||||
    _err "You haven't specified gratisdns.dk username and password yet."
 | 
			
		||||
    _err "Please add credentials and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  #save the credentials to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable GDNSDK_Username "$GDNSDK_Username"
 | 
			
		||||
  _saveaccountconf_mutable GDNSDK_Password "$GDNSDK_Password"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_checkcookie() {
 | 
			
		||||
  GDNSDK_Cookie="${GDNSDK_Cookie:-$(_readaccountconf_mutable GDNSDK_Cookie)}"
 | 
			
		||||
  if [ -z "$GDNSDK_Cookie" ]; then
 | 
			
		||||
    _debug "No cached cookie found"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _myget "action="
 | 
			
		||||
  if (echo "$_result" | grep -q "logmeout"); then
 | 
			
		||||
    _debug "Cached cookie still valid"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
  _debug "Cached cookie no longer valid"
 | 
			
		||||
  GDNSDK_Cookie=""
 | 
			
		||||
  _saveaccountconf_mutable GDNSDK_Cookie "$GDNSDK_Cookie"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_gratisdns_login() {
 | 
			
		||||
  if ! _checkcredentials; then return 1; fi
 | 
			
		||||
 | 
			
		||||
  if _checkcookie; then
 | 
			
		||||
    _debug "Already logged in"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
  _debug "Logging into GratisDNS with user $GDNSDK_Username"
 | 
			
		||||
 | 
			
		||||
  if ! _mypost "login=$GDNSDK_Username&password=$GDNSDK_Password&action=logmein"; then
 | 
			
		||||
    _err "GratisDNS login failed for user $GDNSDK_Username bad RC from _post"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  GDNSDK_Cookie="$(grep -A 15 '302 Found' "$HTTP_HEADER" | _egrep_o 'Cookie: [^;]*' | _head_n 1 | cut -d ' ' -f2)"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$GDNSDK_Cookie" ]; then
 | 
			
		||||
    _err "GratisDNS login failed for user $GDNSDK_Username. Check $HTTP_HEADER file"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  export GDNSDK_Cookie
 | 
			
		||||
  _saveaccountconf_mutable GDNSDK_Cookie "$GDNSDK_Cookie"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_myget() {
 | 
			
		||||
  #Adds cookie to request
 | 
			
		||||
  export _H1="Cookie: $GDNSDK_Cookie"
 | 
			
		||||
  _result=$(_get "$GDNSDK_API?$1")
 | 
			
		||||
}
 | 
			
		||||
_mypost() {
 | 
			
		||||
  #Adds cookie to request
 | 
			
		||||
  export _H1="Cookie: $GDNSDK_Cookie"
 | 
			
		||||
  _result=$(_post "$1" "$GDNSDK_API")
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_get_domain() {
 | 
			
		||||
  _myget 'action=dns_primarydns'
 | 
			
		||||
  _domains=$(echo "$_result" | _egrep_o ' domain="[[:alnum:].-_]+' | sed 's/^.*"//')
 | 
			
		||||
  if [ -z "$_domains" ]; then
 | 
			
		||||
    _err "Primary domain list not found!"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  for _domain in $_domains; do
 | 
			
		||||
    if (_endswith "$fulldomain" "$_domain"); then
 | 
			
		||||
      _debug "Root domain: $_domain"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_successful_update() {
 | 
			
		||||
  if (echo "$_result" | grep -q 'table-success'); then return 0; fi
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_findentry() {
 | 
			
		||||
  #returns id of dns entry, if it exists
 | 
			
		||||
  _myget "action=dns_primary_changeDNSsetup&user_domain=$_domain"
 | 
			
		||||
  _id=$(echo "$_result" | _egrep_o "<td>$1</td>\s*<td>$2</td>[^?]*[^&]*&id=[^&]*" | sed 's/^.*=//')
 | 
			
		||||
  if [ -n "$_id" ]; then
 | 
			
		||||
    _debug "Entry found with _id=$_id"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										169
									
								
								dnsapi/dns_he.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										169
									
								
								dnsapi/dns_he.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,169 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
########################################################################
 | 
			
		||||
# Hurricane Electric hook script for acme.sh
 | 
			
		||||
#
 | 
			
		||||
# Environment variables:
 | 
			
		||||
#
 | 
			
		||||
#  - $HE_Username  (your dns.he.net username)
 | 
			
		||||
#  - $HE_Password  (your dns.he.net password)
 | 
			
		||||
#
 | 
			
		||||
# Author: Ondrej Simek <me@ondrejsimek.com>
 | 
			
		||||
# Git repo: https://github.com/angel333/acme.sh
 | 
			
		||||
 | 
			
		||||
#-- dns_he_add() - Add TXT record --------------------------------------
 | 
			
		||||
# Usage: dns_he_add _acme-challenge.subdomain.domain.com "XyZ123..."
 | 
			
		||||
 | 
			
		||||
dns_he_add() {
 | 
			
		||||
  _full_domain=$1
 | 
			
		||||
  _txt_value=$2
 | 
			
		||||
  _info "Using DNS-01 Hurricane Electric hook"
 | 
			
		||||
 | 
			
		||||
  HE_Username="${HE_Username:-$(_readaccountconf_mutable HE_Username)}"
 | 
			
		||||
  HE_Password="${HE_Password:-$(_readaccountconf_mutable HE_Password)}"
 | 
			
		||||
  if [ -z "$HE_Username" ] || [ -z "$HE_Password" ]; then
 | 
			
		||||
    HE_Username=
 | 
			
		||||
    HE_Password=
 | 
			
		||||
    _err "No auth details provided. Please set user credentials using the \$HE_Username and \$HE_Password envoronment variables."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _saveaccountconf_mutable HE_Username "$HE_Username"
 | 
			
		||||
  _saveaccountconf_mutable HE_Password "$HE_Password"
 | 
			
		||||
 | 
			
		||||
  # Fills in the $_zone_id
 | 
			
		||||
  _find_zone "$_full_domain" || return 1
 | 
			
		||||
  _debug "Zone id \"$_zone_id\" will be used."
 | 
			
		||||
  username_encoded="$(printf "%s" "${HE_Username}" | _url_encode)"
 | 
			
		||||
  password_encoded="$(printf "%s" "${HE_Password}" | _url_encode)"
 | 
			
		||||
  body="email=${username_encoded}&pass=${password_encoded}"
 | 
			
		||||
  body="$body&account="
 | 
			
		||||
  body="$body&menu=edit_zone"
 | 
			
		||||
  body="$body&Type=TXT"
 | 
			
		||||
  body="$body&hosted_dns_zoneid=$_zone_id"
 | 
			
		||||
  body="$body&hosted_dns_recordid="
 | 
			
		||||
  body="$body&hosted_dns_editzone=1"
 | 
			
		||||
  body="$body&Priority="
 | 
			
		||||
  body="$body&Name=$_full_domain"
 | 
			
		||||
  body="$body&Content=$_txt_value"
 | 
			
		||||
  body="$body&TTL=300"
 | 
			
		||||
  body="$body&hosted_dns_editrecord=Submit"
 | 
			
		||||
  response="$(_post "$body" "https://dns.he.net/")"
 | 
			
		||||
  exit_code="$?"
 | 
			
		||||
  if [ "$exit_code" -eq 0 ]; then
 | 
			
		||||
    _info "TXT record added successfully."
 | 
			
		||||
  else
 | 
			
		||||
    _err "Couldn't add the TXT record."
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return "$exit_code"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#-- dns_he_rm() - Remove TXT record ------------------------------------
 | 
			
		||||
# Usage: dns_he_rm _acme-challenge.subdomain.domain.com "XyZ123..."
 | 
			
		||||
 | 
			
		||||
dns_he_rm() {
 | 
			
		||||
  _full_domain=$1
 | 
			
		||||
  _txt_value=$2
 | 
			
		||||
  _info "Cleaning up after DNS-01 Hurricane Electric hook"
 | 
			
		||||
  HE_Username="${HE_Username:-$(_readaccountconf_mutable HE_Username)}"
 | 
			
		||||
  HE_Password="${HE_Password:-$(_readaccountconf_mutable HE_Password)}"
 | 
			
		||||
  # fills in the $_zone_id
 | 
			
		||||
  _find_zone "$_full_domain" || return 1
 | 
			
		||||
  _debug "Zone id \"$_zone_id\" will be used."
 | 
			
		||||
 | 
			
		||||
  # Find the record id to clean
 | 
			
		||||
  username_encoded="$(printf "%s" "${HE_Username}" | _url_encode)"
 | 
			
		||||
  password_encoded="$(printf "%s" "${HE_Password}" | _url_encode)"
 | 
			
		||||
  body="email=${username_encoded}&pass=${password_encoded}"
 | 
			
		||||
  body="$body&hosted_dns_zoneid=$_zone_id"
 | 
			
		||||
  body="$body&menu=edit_zone"
 | 
			
		||||
  body="$body&hosted_dns_editzone="
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$body" "https://dns.he.net/")"
 | 
			
		||||
  _debug2 "response" "$response"
 | 
			
		||||
  if ! _contains "$response" "$_txt_value"; then
 | 
			
		||||
    _debug "The txt record is not found, just skip"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
  _record_id="$(echo "$response" | tr -d "#" | sed "s/<tr/#<tr/g" | tr -d "\n" | tr "#" "\n" | grep "$_full_domain" | grep '"dns_tr"' | grep "$_txt_value" | cut -d '"' -f 4)"
 | 
			
		||||
  _debug2 _record_id "$_record_id"
 | 
			
		||||
  if [ -z "$_record_id" ]; then
 | 
			
		||||
    _err "Can not find record id"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  # Remove the record
 | 
			
		||||
  username_encoded="$(printf "%s" "${HE_Username}" | _url_encode)"
 | 
			
		||||
  password_encoded="$(printf "%s" "${HE_Password}" | _url_encode)"
 | 
			
		||||
  body="email=${username_encoded}&pass=${password_encoded}"
 | 
			
		||||
  body="$body&menu=edit_zone"
 | 
			
		||||
  body="$body&hosted_dns_zoneid=$_zone_id"
 | 
			
		||||
  body="$body&hosted_dns_recordid=$_record_id"
 | 
			
		||||
  body="$body&hosted_dns_editzone=1"
 | 
			
		||||
  body="$body&hosted_dns_delrecord=1"
 | 
			
		||||
  body="$body&hosted_dns_delconfirm=delete"
 | 
			
		||||
  _post "$body" "https://dns.he.net/" \
 | 
			
		||||
    | grep '<div id="dns_status" onClick="hideThis(this);">Successfully removed record.</div>' \
 | 
			
		||||
      >/dev/null
 | 
			
		||||
  exit_code="$?"
 | 
			
		||||
  if [ "$exit_code" -eq 0 ]; then
 | 
			
		||||
    _info "Record removed successfully."
 | 
			
		||||
  else
 | 
			
		||||
    _err "Could not clean (remove) up the record. Please go to HE administration interface and clean it by hand."
 | 
			
		||||
    return "$exit_code"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
########################## PRIVATE FUNCTIONS ###########################
 | 
			
		||||
 | 
			
		||||
_find_zone() {
 | 
			
		||||
  _domain="$1"
 | 
			
		||||
  username_encoded="$(printf "%s" "${HE_Username}" | _url_encode)"
 | 
			
		||||
  password_encoded="$(printf "%s" "${HE_Password}" | _url_encode)"
 | 
			
		||||
  body="email=${username_encoded}&pass=${password_encoded}"
 | 
			
		||||
  response="$(_post "$body" "https://dns.he.net/")"
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  if _contains "$response" '>Incorrect<'; then
 | 
			
		||||
    _err "Unable to login to dns.he.net please check username and password"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _table="$(echo "$response" | tr -d "#" | sed "s/<table/#<table/g" | tr -d "\n" | tr "#" "\n" | grep 'id="domains_table"')"
 | 
			
		||||
  _debug2 _table "$_table"
 | 
			
		||||
  _matches="$(echo "$_table" | sed "s/<tr/#<tr/g" | tr "#" "\n" | grep 'alt="edit"' | tr -d " " | sed "s/<td/#<td/g" | tr "#" "\n" | grep 'hosted_dns_zoneid')"
 | 
			
		||||
  _debug2 _matches "$_matches"
 | 
			
		||||
  # Zone names and zone IDs are in same order
 | 
			
		||||
  _zone_ids=$(echo "$_matches" | _egrep_o "hosted_dns_zoneid=[0-9]*&" | cut -d = -f 2 | tr -d '&')
 | 
			
		||||
  _zone_names=$(echo "$_matches" | _egrep_o "name=.*onclick" | cut -d '"' -f 2)
 | 
			
		||||
  _debug2 "These are the zones on this HE account:"
 | 
			
		||||
  _debug2 "$_zone_names"
 | 
			
		||||
  _debug2 "And these are their respective IDs:"
 | 
			
		||||
  _debug2 "$_zone_ids"
 | 
			
		||||
  if [ -z "$_zone_names" ] || [ -z "$_zone_ids" ]; then
 | 
			
		||||
    _err "Can not get zone names."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  # Walk through all possible zone names
 | 
			
		||||
  _strip_counter=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    _attempted_zone=$(echo "$_domain" | cut -d . -f ${_strip_counter}-)
 | 
			
		||||
 | 
			
		||||
    # All possible zone names have been tried
 | 
			
		||||
    if [ -z "$_attempted_zone" ]; then
 | 
			
		||||
      _err "No zone for domain \"$_domain\" found."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    _debug "Looking for zone \"${_attempted_zone}\""
 | 
			
		||||
 | 
			
		||||
    line_num="$(echo "$_zone_names" | grep -n "^$_attempted_zone" | cut -d : -f 1)"
 | 
			
		||||
 | 
			
		||||
    if [ "$line_num" ]; then
 | 
			
		||||
      _zone_id=$(echo "$_zone_ids" | sed -n "${line_num}p")
 | 
			
		||||
      _debug "Found relevant zone \"$_attempted_zone\" with id \"$_zone_id\" - will be used for domain \"$_domain\"."
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    _debug "Zone \"$_attempted_zone\" doesn't exist, let's try a less specific zone."
 | 
			
		||||
    _strip_counter=$(_math "$_strip_counter" + 1)
 | 
			
		||||
  done
 | 
			
		||||
}
 | 
			
		||||
# vim: et:ts=2:sw=2:
 | 
			
		||||
							
								
								
									
										147
									
								
								dnsapi/dns_hostingde.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										147
									
								
								dnsapi/dns_hostingde.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,147 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# hosting.de API
 | 
			
		||||
 | 
			
		||||
# Values to export:
 | 
			
		||||
# export HOSTINGDE_ENDPOINT='https://secure.hosting.de'
 | 
			
		||||
# export HOSTINGDE_APIKEY='xxxxx'
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
dns_hostingde_add() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
  txtvalue="${2}"
 | 
			
		||||
  _debug "Calling: _hostingde_addRecord() '${fulldomain}' '${txtvalue}'"
 | 
			
		||||
  _hostingde_apiKey && _hostingde_getZoneConfig && _hostingde_addRecord
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
dns_hostingde_rm() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
  txtvalue="${2}"
 | 
			
		||||
  _debug "Calling: _hostingde_removeRecord() '${fulldomain}' '${txtvalue}'"
 | 
			
		||||
  _hostingde_apiKey && _hostingde_getZoneConfig && _hostingde_removeRecord
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#################### own Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_hostingde_apiKey() {
 | 
			
		||||
  HOSTINGDE_APIKEY="${HOSTINGDE_APIKEY:-$(_readaccountconf_mutable HOSTINGDE_APIKEY)}"
 | 
			
		||||
  if [ -z "$HOSTINGDE_APIKEY" ] || [ -z "$HOSTINGDE_ENDPOINT" ]; then
 | 
			
		||||
    HOSTINGDE_APIKEY=""
 | 
			
		||||
    HOSTINGDE_ENDPOINT=""
 | 
			
		||||
    _err "You haven't specified hosting.de API key or endpoint yet."
 | 
			
		||||
    _err "Please create your key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf_mutable HOSTINGDE_APIKEY "$HOSTINGDE_APIKEY"
 | 
			
		||||
  _saveaccountconf_mutable HOSTINGDE_ENDPOINT "$HOSTINGDE_ENDPOINT"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_hostingde_getZoneConfig() {
 | 
			
		||||
  _info "Getting ZoneConfig"
 | 
			
		||||
  curZone="${fulldomain#*.}"
 | 
			
		||||
  returnCode=1
 | 
			
		||||
  while _contains "${curZone}" "\\."; do
 | 
			
		||||
    curData="{\"filter\":{\"field\":\"zoneName\",\"value\":\"${curZone}\"},\"limit\":1,\"authToken\":\"${HOSTINGDE_APIKEY}\"}"
 | 
			
		||||
    curResult="$(_post "${curData}" "${HOSTINGDE_ENDPOINT}/api/dns/v1/json/zoneConfigsFind")"
 | 
			
		||||
    _debug "Calling zoneConfigsFind: '${curData}' '${HOSTINGDE_ENDPOINT}/api/dns/v1/json/zoneConfigsFind'"
 | 
			
		||||
    _debug "Result of zoneConfigsFind: '$curResult'"
 | 
			
		||||
    if _contains "${curResult}" '"status": "error"'; then
 | 
			
		||||
      if _contains "${curResult}" '"code": 10109'; then
 | 
			
		||||
        _err "The API-Key is invalid or could not be found"
 | 
			
		||||
      else
 | 
			
		||||
        _err "UNKNOWN API ERROR"
 | 
			
		||||
      fi
 | 
			
		||||
      returnCode=1
 | 
			
		||||
      break
 | 
			
		||||
    fi
 | 
			
		||||
    if _contains "${curResult}" '"totalEntries": 1'; then
 | 
			
		||||
      _info "Retrieved zone data."
 | 
			
		||||
      _debug "Zone data: '${curResult}'"
 | 
			
		||||
      zoneConfigId=$(echo "${curResult}" | _egrep_o '"id":.*' | cut -d ':' -f 2 | cut -d '"' -f 2)
 | 
			
		||||
      zoneConfigName=$(echo "${curResult}" | _egrep_o '"name":.*' | cut -d ':' -f 2 | cut -d '"' -f 2)
 | 
			
		||||
      zoneConfigType=$(echo "${curResult}" | grep -v "FindZoneConfigsResult" | _egrep_o '"type":.*' | cut -d ':' -f 2 | cut -d '"' -f 2)
 | 
			
		||||
      zoneConfigExpire=$(echo "${curResult}" | _egrep_o '"expire":.*' | cut -d ':' -f 2 | cut -d '"' -f 2 | cut -d ',' -f 1)
 | 
			
		||||
      zoneConfigNegativeTtl=$(echo "${curResult}" | _egrep_o '"negativeTtl":.*' | cut -d ':' -f 2 | cut -d '"' -f 2 | cut -d ',' -f 1)
 | 
			
		||||
      zoneConfigRefresh=$(echo "${curResult}" | _egrep_o '"refresh":.*' | cut -d ':' -f 2 | cut -d '"' -f 2 | cut -d ',' -f 1)
 | 
			
		||||
      zoneConfigRetry=$(echo "${curResult}" | _egrep_o '"retry":.*' | cut -d ':' -f 2 | cut -d '"' -f 2 | cut -d ',' -f 1)
 | 
			
		||||
      zoneConfigTtl=$(echo "${curResult}" | _egrep_o '"ttl":.*' | cut -d ':' -f 2 | cut -d '"' -f 2 | cut -d ',' -f 1)
 | 
			
		||||
      zoneConfigDnsServerGroupId=$(echo "${curResult}" | _egrep_o '"dnsServerGroupId":.*' | cut -d ':' -f 2 | cut -d '"' -f 2)
 | 
			
		||||
      zoneConfigEmailAddress=$(echo "${curResult}" | _egrep_o '"emailAddress":.*' | cut -d ':' -f 2 | cut -d '"' -f 2)
 | 
			
		||||
      zoneConfigDnsSecMode=$(echo "${curResult}" | _egrep_o '"dnsSecMode":.*' | cut -d ':' -f 2 | cut -d '"' -f 2)
 | 
			
		||||
      if [ "${zoneConfigType}" != "NATIVE" ]; then
 | 
			
		||||
        _err "Zone is not native"
 | 
			
		||||
        returnCode=1
 | 
			
		||||
        break
 | 
			
		||||
      fi
 | 
			
		||||
      _debug "zoneConfigId '${zoneConfigId}'"
 | 
			
		||||
      returnCode=0
 | 
			
		||||
      break
 | 
			
		||||
    fi
 | 
			
		||||
    curZone="${curZone#*.}"
 | 
			
		||||
  done
 | 
			
		||||
  if [ $returnCode -ne 0 ]; then
 | 
			
		||||
    _info "ZoneEnd reached, Zone ${curZone} not found in hosting.de API"
 | 
			
		||||
  fi
 | 
			
		||||
  return $returnCode
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_hostingde_getZoneStatus() {
 | 
			
		||||
  _debug "Checking Zone status"
 | 
			
		||||
  curData="{\"filter\":{\"field\":\"zoneConfigId\",\"value\":\"${zoneConfigId}\"},\"limit\":1,\"authToken\":\"${HOSTINGDE_APIKEY}\"}"
 | 
			
		||||
  curResult="$(_post "${curData}" "${HOSTINGDE_ENDPOINT}/api/dns/v1/json/zonesFind")"
 | 
			
		||||
  _debug "Calling zonesFind '${curData}' '${HOSTINGDE_ENDPOINT}/api/dns/v1/json/zonesFind'"
 | 
			
		||||
  _debug "Result of zonesFind '$curResult'"
 | 
			
		||||
  zoneStatus=$(echo "${curResult}" | grep -v success | _egrep_o '"status":.*' | cut -d ':' -f 2 | cut -d '"' -f 2)
 | 
			
		||||
  _debug "zoneStatus '${zoneStatus}'"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_hostingde_addRecord() {
 | 
			
		||||
  _info "Adding record to zone"
 | 
			
		||||
  _hostingde_getZoneStatus
 | 
			
		||||
  _debug "Result of zoneStatus: '${zoneStatus}'"
 | 
			
		||||
  while [ "${zoneStatus}" != "active" ]; do
 | 
			
		||||
    _sleep 5
 | 
			
		||||
    _hostingde_getZoneStatus
 | 
			
		||||
    _debug "Result of zoneStatus: '${zoneStatus}'"
 | 
			
		||||
  done
 | 
			
		||||
  curData="{\"authToken\":\"${HOSTINGDE_APIKEY}\",\"zoneConfig\":{\"id\":\"${zoneConfigId}\",\"name\":\"${zoneConfigName}\",\"type\":\"${zoneConfigType}\",\"dnsServerGroupId\":\"${zoneConfigDnsServerGroupId}\",\"dnsSecMode\":\"${zoneConfigDnsSecMode}\",\"emailAddress\":\"${zoneConfigEmailAddress}\",\"soaValues\":{\"expire\":${zoneConfigExpire},\"negativeTtl\":${zoneConfigNegativeTtl},\"refresh\":${zoneConfigRefresh},\"retry\":${zoneConfigRetry},\"ttl\":${zoneConfigTtl}}},\"recordsToAdd\":[{\"name\":\"${fulldomain}\",\"type\":\"TXT\",\"content\":\"\\\"${txtvalue}\\\"\",\"ttl\":3600}]}"
 | 
			
		||||
  curResult="$(_post "${curData}" "${HOSTINGDE_ENDPOINT}/api/dns/v1/json/zoneUpdate")"
 | 
			
		||||
  _debug "Calling zoneUpdate: '${curData}' '${HOSTINGDE_ENDPOINT}/api/dns/v1/json/zoneUpdate'"
 | 
			
		||||
  _debug "Result of zoneUpdate: '$curResult'"
 | 
			
		||||
  if _contains "${curResult}" '"status": "error"'; then
 | 
			
		||||
    if _contains "${curResult}" '"code": 10109'; then
 | 
			
		||||
      _err "The API-Key is invalid or could not be found"
 | 
			
		||||
    else
 | 
			
		||||
      _err "UNKNOWN API ERROR"
 | 
			
		||||
    fi
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_hostingde_removeRecord() {
 | 
			
		||||
  _info "Removing record from zone"
 | 
			
		||||
  _hostingde_getZoneStatus
 | 
			
		||||
  _debug "Result of zoneStatus: '$zoneStatus'"
 | 
			
		||||
  while [ "$zoneStatus" != "active" ]; do
 | 
			
		||||
    _sleep 5
 | 
			
		||||
    _hostingde_getZoneStatus
 | 
			
		||||
    _debug "Result of zoneStatus: '$zoneStatus'"
 | 
			
		||||
  done
 | 
			
		||||
  curData="{\"authToken\":\"${HOSTINGDE_APIKEY}\",\"zoneConfig\":{\"id\":\"${zoneConfigId}\",\"name\":\"${zoneConfigName}\",\"type\":\"${zoneConfigType}\",\"dnsServerGroupId\":\"${zoneConfigDnsServerGroupId}\",\"dnsSecMode\":\"${zoneConfigDnsSecMode}\",\"emailAddress\":\"${zoneConfigEmailAddress}\",\"soaValues\":{\"expire\":${zoneConfigExpire},\"negativeTtl\":${zoneConfigNegativeTtl},\"refresh\":${zoneConfigRefresh},\"retry\":${zoneConfigRetry},\"ttl\":${zoneConfigTtl}}},\"recordsToDelete\":[{\"name\":\"${fulldomain}\",\"type\":\"TXT\",\"content\":\"\\\"${txtvalue}\\\"\"}]}"
 | 
			
		||||
  curResult="$(_post "${curData}" "${HOSTINGDE_ENDPOINT}/api/dns/v1/json/zoneUpdate")"
 | 
			
		||||
  _debug "Calling zoneUpdate: '${curData}' '${HOSTINGDE_ENDPOINT}/api/dns/v1/json/zoneUpdate'"
 | 
			
		||||
  _debug "Result of zoneUpdate: '$curResult'"
 | 
			
		||||
  if _contains "${curResult}" '"status": "error"'; then
 | 
			
		||||
    if _contains "${curResult}" '"code": 10109'; then
 | 
			
		||||
      _err "The API-Key is invalid or could not be found"
 | 
			
		||||
    else
 | 
			
		||||
      _err "UNKNOWN API ERROR"
 | 
			
		||||
    fi
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										102
									
								
								dnsapi/dns_infoblox.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										102
									
								
								dnsapi/dns_infoblox.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,102 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
## Infoblox API integration by Jason Keller and Elijah Tenai
 | 
			
		||||
##
 | 
			
		||||
## Report any bugs via https://github.com/jasonkeller/acme.sh
 | 
			
		||||
 | 
			
		||||
dns_infoblox_add() {
 | 
			
		||||
 | 
			
		||||
  ## Nothing to see here, just some housekeeping
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  baseurlnObject="https://$Infoblox_Server/wapi/v2.2.2/record:txt?name=$fulldomain&text=$txtvalue&view=$Infoblox_View"
 | 
			
		||||
 | 
			
		||||
  _info "Using Infoblox API"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  ## Check for the credentials
 | 
			
		||||
  if [ -z "$Infoblox_Creds" ] || [ -z "$Infoblox_Server" ]; then
 | 
			
		||||
    Infoblox_Creds=""
 | 
			
		||||
    Infoblox_Server=""
 | 
			
		||||
    _err "You didn't specify the credentials, server or infoblox view yet (Infoblox_Creds, Infoblox_Server and Infoblox_View)."
 | 
			
		||||
    _err "Please set them via EXPORT ([username:password], [ip or hostname]) and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$Infoblox_View" ]; then
 | 
			
		||||
    Infoblox_View="default"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  ## Save the credentials to the account file
 | 
			
		||||
  _saveaccountconf Infoblox_Creds "$Infoblox_Creds"
 | 
			
		||||
  _saveaccountconf Infoblox_Server "$Infoblox_Server"
 | 
			
		||||
  _saveaccountconf Infoblox_View "$Infoblox_View"
 | 
			
		||||
 | 
			
		||||
  ## Base64 encode the credentials
 | 
			
		||||
  Infoblox_CredsEncoded=$(printf "%b" "$Infoblox_Creds" | _base64)
 | 
			
		||||
 | 
			
		||||
  ## Construct the HTTP Authorization header
 | 
			
		||||
  export _H1="Accept-Language:en-US"
 | 
			
		||||
  export _H2="Authorization: Basic $Infoblox_CredsEncoded"
 | 
			
		||||
 | 
			
		||||
  ## Add the challenge record to the Infoblox grid member
 | 
			
		||||
  result="$(_post "" "$baseurlnObject" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  ## Let's see if we get something intelligible back from the unit
 | 
			
		||||
  if [ "$(echo "$result" | _egrep_o "record:txt/.*:.*/$Infoblox_View")" ]; then
 | 
			
		||||
    _info "Successfully created the txt record"
 | 
			
		||||
    return 0
 | 
			
		||||
  else
 | 
			
		||||
    _err "Error encountered during record addition"
 | 
			
		||||
    _err "$result"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
dns_infoblox_rm() {
 | 
			
		||||
 | 
			
		||||
  ## Nothing to see here, just some housekeeping
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  _info "Using Infoblox API"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  ## Base64 encode the credentials
 | 
			
		||||
  Infoblox_CredsEncoded="$(printf "%b" "$Infoblox_Creds" | _base64)"
 | 
			
		||||
 | 
			
		||||
  ## Construct the HTTP Authorization header
 | 
			
		||||
  export _H1="Accept-Language:en-US"
 | 
			
		||||
  export _H2="Authorization: Basic $Infoblox_CredsEncoded"
 | 
			
		||||
 | 
			
		||||
  ## Does the record exist?  Let's check.
 | 
			
		||||
  baseurlnObject="https://$Infoblox_Server/wapi/v2.2.2/record:txt?name=$fulldomain&text=$txtvalue&view=$Infoblox_View&_return_type=xml-pretty"
 | 
			
		||||
  result="$(_get "$baseurlnObject")"
 | 
			
		||||
 | 
			
		||||
  ## Let's see if we get something intelligible back from the grid
 | 
			
		||||
  if [ "$(echo "$result" | _egrep_o "record:txt/.*:.*/$Infoblox_View")" ]; then
 | 
			
		||||
    ## Extract the object reference
 | 
			
		||||
    objRef="$(printf "%b" "$result" | _egrep_o "record:txt/.*:.*/$Infoblox_View")"
 | 
			
		||||
    objRmUrl="https://$Infoblox_Server/wapi/v2.2.2/$objRef"
 | 
			
		||||
    ## Delete them! All the stale records!
 | 
			
		||||
    rmResult="$(_post "" "$objRmUrl" "" "DELETE")"
 | 
			
		||||
    ## Let's see if that worked
 | 
			
		||||
    if [ "$(echo "$rmResult" | _egrep_o "record:txt/.*:.*/$Infoblox_View")" ]; then
 | 
			
		||||
      _info "Successfully deleted $objRef"
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Error occurred during txt record delete"
 | 
			
		||||
      _err "$rmResult"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  else
 | 
			
		||||
    _err "Record to delete didn't match an existing record"
 | 
			
		||||
    _err "$result"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
							
								
								
									
										356
									
								
								dnsapi/dns_inwx.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										356
									
								
								dnsapi/dns_inwx.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,356 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
#INWX_User="username"
 | 
			
		||||
#
 | 
			
		||||
#INWX_Password="password"
 | 
			
		||||
#
 | 
			
		||||
# Dependencies:
 | 
			
		||||
# -------------
 | 
			
		||||
# - oathtool (When using 2 Factor Authentication)
 | 
			
		||||
 | 
			
		||||
INWX_Api="https://api.domrobot.com/xmlrpc/"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_inwx_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  INWX_User="${INWX_User:-$(_readaccountconf_mutable INWX_User)}"
 | 
			
		||||
  INWX_Password="${INWX_Password:-$(_readaccountconf_mutable INWX_Password)}"
 | 
			
		||||
  INWX_Shared_Secret="${INWX_Shared_Secret:-$(_readaccountconf_mutable INWX_Shared_Secret)}"
 | 
			
		||||
  if [ -z "$INWX_User" ] || [ -z "$INWX_Password" ]; then
 | 
			
		||||
    INWX_User=""
 | 
			
		||||
    INWX_Password=""
 | 
			
		||||
    _err "You don't specify inwx user and password yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable INWX_User "$INWX_User"
 | 
			
		||||
  _saveaccountconf_mutable INWX_Password "$INWX_Password"
 | 
			
		||||
  _saveaccountconf_mutable INWX_Shared_Secret "$INWX_Shared_Secret"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  _inwx_add_record "$_domain" "$_sub_domain" "$txtvalue"
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_inwx_rm() {
 | 
			
		||||
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  INWX_User="${INWX_User:-$(_readaccountconf_mutable INWX_User)}"
 | 
			
		||||
  INWX_Password="${INWX_Password:-$(_readaccountconf_mutable INWX_Password)}"
 | 
			
		||||
  if [ -z "$INWX_User" ] || [ -z "$INWX_Password" ]; then
 | 
			
		||||
    INWX_User=""
 | 
			
		||||
    INWX_Password=""
 | 
			
		||||
    _err "You don't specify inwx user and password yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable INWX_User "$INWX_User"
 | 
			
		||||
  _saveaccountconf_mutable INWX_Password "$INWX_Password"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
  <methodName>nameserver.info</methodName>
 | 
			
		||||
  <params>
 | 
			
		||||
   <param>
 | 
			
		||||
    <value>
 | 
			
		||||
     <struct>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>domain</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>%s</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>type</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>TXT</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>name</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>%s</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
     </struct>
 | 
			
		||||
    </value>
 | 
			
		||||
   </param>
 | 
			
		||||
  </params>
 | 
			
		||||
  </methodCall>' "$_domain" "$_sub_domain")
 | 
			
		||||
  response="$(_post "$xml_content" "$INWX_Api" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "Command completed successfully"; then
 | 
			
		||||
    _err "Error could not get txt records"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! printf "%s" "$response" | grep "count" >/dev/null; then
 | 
			
		||||
    _info "Do not need to delete record"
 | 
			
		||||
  else
 | 
			
		||||
    _record_id=$(printf '%s' "$response" | _egrep_o '.*(<member><name>record){1}(.*)([0-9]+){1}' | _egrep_o '<name>id<\/name><value><int>[0-9]+' | _egrep_o '[0-9]+')
 | 
			
		||||
    _info "Deleting record"
 | 
			
		||||
    _inwx_delete_record "$_record_id"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_inwx_login() {
 | 
			
		||||
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
  <methodName>account.login</methodName>
 | 
			
		||||
  <params>
 | 
			
		||||
   <param>
 | 
			
		||||
    <value>
 | 
			
		||||
     <struct>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>user</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>%s</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>pass</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>%s</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
     </struct>
 | 
			
		||||
    </value>
 | 
			
		||||
   </param>
 | 
			
		||||
  </params>
 | 
			
		||||
  </methodCall>' $INWX_User $INWX_Password)
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$xml_content" "$INWX_Api" "" "POST")"
 | 
			
		||||
  _H1=$(printf "Cookie: %s" "$(grep "domrobot=" "$HTTP_HEADER" | grep "^Set-Cookie:" | _tail_n 1 | _egrep_o 'domrobot=[^;]*;' | tr -d ';')")
 | 
			
		||||
  export _H1
 | 
			
		||||
 | 
			
		||||
  #https://github.com/inwx/php-client/blob/master/INWX/Domrobot.php#L71
 | 
			
		||||
  if _contains "$response" "<member><name>code</name><value><int>1000</int></value></member>" \
 | 
			
		||||
    && _contains "$response" "<member><name>tfa</name><value><string>GOOGLE-AUTH</string></value></member>"; then
 | 
			
		||||
    if [ -z "$INWX_Shared_Secret" ]; then
 | 
			
		||||
      _err "Mobile TAN detected."
 | 
			
		||||
      _err "Please define a shared secret."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _exists oathtool; then
 | 
			
		||||
      _err "Please install oathtool to use 2 Factor Authentication."
 | 
			
		||||
      _err ""
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    tan="$(oathtool --base32 --totp "${INWX_Shared_Secret}" 2>/dev/null)"
 | 
			
		||||
 | 
			
		||||
    xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
    <methodCall>
 | 
			
		||||
    <methodName>account.unlock</methodName>
 | 
			
		||||
    <params>
 | 
			
		||||
     <param>
 | 
			
		||||
      <value>
 | 
			
		||||
       <struct>
 | 
			
		||||
        <member>
 | 
			
		||||
         <name>tan</name>
 | 
			
		||||
         <value>
 | 
			
		||||
          <string>%s</string>
 | 
			
		||||
         </value>
 | 
			
		||||
        </member>
 | 
			
		||||
       </struct>
 | 
			
		||||
      </value>
 | 
			
		||||
     </param>
 | 
			
		||||
    </params>
 | 
			
		||||
    </methodCall>' "$tan")
 | 
			
		||||
 | 
			
		||||
    response="$(_post "$xml_content" "$INWX_Api" "" "POST")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  _debug "get root"
 | 
			
		||||
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  _inwx_login
 | 
			
		||||
 | 
			
		||||
  xml_content='<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
  <methodName>nameserver.list</methodName>
 | 
			
		||||
  </methodCall>'
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$xml_content" "$INWX_Api" "" "POST")"
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "$h"; then
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain="$h"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_inwx_delete_record() {
 | 
			
		||||
  record_id=$1
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
  <methodName>nameserver.deleteRecord</methodName>
 | 
			
		||||
  <params>
 | 
			
		||||
   <param>
 | 
			
		||||
    <value>
 | 
			
		||||
     <struct>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>id</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <int>%s</int>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
     </struct>
 | 
			
		||||
    </value>
 | 
			
		||||
   </param>
 | 
			
		||||
  </params>
 | 
			
		||||
  </methodCall>' "$record_id")
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$xml_content" "$INWX_Api" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  if ! printf "%s" "$response" | grep "Command completed successfully" >/dev/null; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_inwx_update_record() {
 | 
			
		||||
  record_id=$1
 | 
			
		||||
  txtval=$2
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
  <methodName>nameserver.updateRecord</methodName>
 | 
			
		||||
  <params>
 | 
			
		||||
   <param>
 | 
			
		||||
    <value>
 | 
			
		||||
     <struct>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>content</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>%s</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>id</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <int>%s</int>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
     </struct>
 | 
			
		||||
    </value>
 | 
			
		||||
   </param>
 | 
			
		||||
  </params>
 | 
			
		||||
  </methodCall>' "$txtval" "$record_id")
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$xml_content" "$INWX_Api" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  if ! printf "%s" "$response" | grep "Command completed successfully" >/dev/null; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_inwx_add_record() {
 | 
			
		||||
 | 
			
		||||
  domain=$1
 | 
			
		||||
  sub_domain=$2
 | 
			
		||||
  txtval=$3
 | 
			
		||||
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
  <methodName>nameserver.createRecord</methodName>
 | 
			
		||||
  <params>
 | 
			
		||||
   <param>
 | 
			
		||||
    <value>
 | 
			
		||||
     <struct>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>domain</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>%s</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>type</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>TXT</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>content</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>%s</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
      <member>
 | 
			
		||||
       <name>name</name>
 | 
			
		||||
       <value>
 | 
			
		||||
        <string>%s</string>
 | 
			
		||||
       </value>
 | 
			
		||||
      </member>
 | 
			
		||||
     </struct>
 | 
			
		||||
    </value>
 | 
			
		||||
   </param>
 | 
			
		||||
  </params>
 | 
			
		||||
  </methodCall>' "$domain" "$txtval" "$sub_domain")
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$xml_content" "$INWX_Api" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  if ! printf "%s" "$response" | grep "Command completed successfully" >/dev/null; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										176
									
								
								dnsapi/dns_ispconfig.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										176
									
								
								dnsapi/dns_ispconfig.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,176 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# ISPConfig 3.1 API
 | 
			
		||||
# User must provide login data and URL to the ISPConfig installation incl. port. The remote user in ISPConfig must have access to:
 | 
			
		||||
# - DNS txt Functions
 | 
			
		||||
 | 
			
		||||
# Report bugs to https://github.com/sjau/acme.sh
 | 
			
		||||
 | 
			
		||||
# Values to export:
 | 
			
		||||
# export ISPC_User="remoteUser"
 | 
			
		||||
# export ISPC_Password="remotePassword"
 | 
			
		||||
# export ISPC_Api="https://ispc.domain.tld:8080/remote/json.php"
 | 
			
		||||
# export ISPC_Api_Insecure=1     # Set 1 for insecure and 0 for secure -> difference is whether ssl cert is checked for validity (0) or whether it is just accepted (1)
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_myapi_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_ispconfig_add() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
  txtvalue="${2}"
 | 
			
		||||
  _debug "Calling: dns_ispconfig_add() '${fulldomain}' '${txtvalue}'"
 | 
			
		||||
  _ISPC_credentials && _ISPC_login && _ISPC_getZoneInfo && _ISPC_addTxt
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: dns_myapi_rm   _acme-challenge.www.domain.com
 | 
			
		||||
dns_ispconfig_rm() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
  _debug "Calling: dns_ispconfig_rm() '${fulldomain}'"
 | 
			
		||||
  _ISPC_credentials && _ISPC_login && _ISPC_rmTxt
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_ISPC_credentials() {
 | 
			
		||||
  if [ -z "${ISPC_User}" ] || [ -z "$ISPC_Password" ] || [ -z "${ISPC_Api}" ] || [ -z "${ISPC_Api_Insecure}" ]; then
 | 
			
		||||
    ISPC_User=""
 | 
			
		||||
    ISPC_Password=""
 | 
			
		||||
    ISPC_Api=""
 | 
			
		||||
    ISPC_Api_Insecure=""
 | 
			
		||||
    _err "You haven't specified the ISPConfig Login data, URL and whether you want check the ISPC SSL cert. Please try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  else
 | 
			
		||||
    _saveaccountconf ISPC_User "${ISPC_User}"
 | 
			
		||||
    _saveaccountconf ISPC_Password "${ISPC_Password}"
 | 
			
		||||
    _saveaccountconf ISPC_Api "${ISPC_Api}"
 | 
			
		||||
    _saveaccountconf ISPC_Api_Insecure "${ISPC_Api_Insecure}"
 | 
			
		||||
    # Set whether curl should use secure or insecure mode
 | 
			
		||||
    export HTTPS_INSECURE="${ISPC_Api_Insecure}"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_ISPC_login() {
 | 
			
		||||
  _info "Getting Session ID"
 | 
			
		||||
  curData="{\"username\":\"${ISPC_User}\",\"password\":\"${ISPC_Password}\",\"client_login\":false}"
 | 
			
		||||
  curResult="$(_post "${curData}" "${ISPC_Api}?login")"
 | 
			
		||||
  _debug "Calling _ISPC_login: '${curData}' '${ISPC_Api}?login'"
 | 
			
		||||
  _debug "Result of _ISPC_login: '$curResult'"
 | 
			
		||||
  if _contains "${curResult}" '"code":"ok"'; then
 | 
			
		||||
    sessionID=$(echo "${curResult}" | _egrep_o "response.*" | cut -d ':' -f 2 | cut -d '"' -f 2)
 | 
			
		||||
    _info "Retrieved Session ID."
 | 
			
		||||
    _debug "Session ID: '${sessionID}'"
 | 
			
		||||
  else
 | 
			
		||||
    _err "Couldn't retrieve the Session ID."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_ISPC_getZoneInfo() {
 | 
			
		||||
  _info "Getting Zoneinfo"
 | 
			
		||||
  zoneEnd=false
 | 
			
		||||
  curZone="${fulldomain}"
 | 
			
		||||
  while [ "${zoneEnd}" = false ]; do
 | 
			
		||||
    # we can strip the first part of the fulldomain, since it's just the _acme-challenge string
 | 
			
		||||
    curZone="${curZone#*.}"
 | 
			
		||||
    # suffix . needed for zone -> domain.tld.
 | 
			
		||||
    curData="{\"session_id\":\"${sessionID}\",\"primary_id\":{\"origin\":\"${curZone}.\"}}"
 | 
			
		||||
    curResult="$(_post "${curData}" "${ISPC_Api}?dns_zone_get")"
 | 
			
		||||
    _debug "Calling _ISPC_getZoneInfo: '${curData}' '${ISPC_Api}?login'"
 | 
			
		||||
    _debug "Result of _ISPC_getZoneInfo: '$curResult'"
 | 
			
		||||
    if _contains "${curResult}" '"id":"'; then
 | 
			
		||||
      zoneFound=true
 | 
			
		||||
      zoneEnd=true
 | 
			
		||||
      _info "Retrieved zone data."
 | 
			
		||||
      _debug "Zone data: '${curResult}'"
 | 
			
		||||
    fi
 | 
			
		||||
    if [ "${curZone#*.}" != "$curZone" ]; then
 | 
			
		||||
      _debug2 "$curZone still contains a '.' - so we can check next higher level"
 | 
			
		||||
    else
 | 
			
		||||
      zoneEnd=true
 | 
			
		||||
      _err "Couldn't retrieve zone data."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  done
 | 
			
		||||
  if [ "${zoneFound}" ]; then
 | 
			
		||||
    server_id=$(echo "${curResult}" | _egrep_o "server_id.*" | cut -d ':' -f 2 | cut -d '"' -f 2)
 | 
			
		||||
    _debug "Server ID: '${server_id}'"
 | 
			
		||||
    case "${server_id}" in
 | 
			
		||||
      '' | *[!0-9]*)
 | 
			
		||||
        _err "Server ID is not numeric."
 | 
			
		||||
        return 1
 | 
			
		||||
        ;;
 | 
			
		||||
      *) _info "Retrieved Server ID" ;;
 | 
			
		||||
    esac
 | 
			
		||||
    zone=$(echo "${curResult}" | _egrep_o "\"id.*" | cut -d ':' -f 2 | cut -d '"' -f 2)
 | 
			
		||||
    _debug "Zone: '${zone}'"
 | 
			
		||||
    case "${zone}" in
 | 
			
		||||
      '' | *[!0-9]*)
 | 
			
		||||
        _err "Zone ID is not numeric."
 | 
			
		||||
        return 1
 | 
			
		||||
        ;;
 | 
			
		||||
      *) _info "Retrieved Zone ID" ;;
 | 
			
		||||
    esac
 | 
			
		||||
    client_id=$(echo "${curResult}" | _egrep_o "sys_userid.*" | cut -d ':' -f 2 | cut -d '"' -f 2)
 | 
			
		||||
    _debug "Client ID: '${client_id}'"
 | 
			
		||||
    case "${client_id}" in
 | 
			
		||||
      '' | *[!0-9]*)
 | 
			
		||||
        _err "Client ID is not numeric."
 | 
			
		||||
        return 1
 | 
			
		||||
        ;;
 | 
			
		||||
      *) _info "Retrieved Client ID." ;;
 | 
			
		||||
    esac
 | 
			
		||||
    zoneFound=""
 | 
			
		||||
    zoneEnd=""
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_ISPC_addTxt() {
 | 
			
		||||
  curSerial="$(date +%s)"
 | 
			
		||||
  curStamp="$(date +'%F %T')"
 | 
			
		||||
  params="\"server_id\":\"${server_id}\",\"zone\":\"${zone}\",\"name\":\"${fulldomain}.\",\"type\":\"txt\",\"data\":\"${txtvalue}\",\"aux\":\"0\",\"ttl\":\"3600\",\"active\":\"y\",\"stamp\":\"${curStamp}\",\"serial\":\"${curSerial}\""
 | 
			
		||||
  curData="{\"session_id\":\"${sessionID}\",\"client_id\":\"${client_id}\",\"params\":{${params}},\"update_serial\":true}"
 | 
			
		||||
  curResult="$(_post "${curData}" "${ISPC_Api}?dns_txt_add")"
 | 
			
		||||
  _debug "Calling _ISPC_addTxt: '${curData}' '${ISPC_Api}?dns_txt_add'"
 | 
			
		||||
  _debug "Result of _ISPC_addTxt: '$curResult'"
 | 
			
		||||
  record_id=$(echo "${curResult}" | _egrep_o "\"response.*" | cut -d ':' -f 2 | cut -d '"' -f 2)
 | 
			
		||||
  _debug "Record ID: '${record_id}'"
 | 
			
		||||
  case "${record_id}" in
 | 
			
		||||
    '' | *[!0-9]*)
 | 
			
		||||
      _err "Couldn't add ACME Challenge TXT record to zone."
 | 
			
		||||
      return 1
 | 
			
		||||
      ;;
 | 
			
		||||
    *) _info "Added ACME Challenge TXT record to zone." ;;
 | 
			
		||||
  esac
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_ISPC_rmTxt() {
 | 
			
		||||
  # Need to get the record ID.
 | 
			
		||||
  curData="{\"session_id\":\"${sessionID}\",\"primary_id\":{\"name\":\"${fulldomain}.\",\"type\":\"TXT\"}}"
 | 
			
		||||
  curResult="$(_post "${curData}" "${ISPC_Api}?dns_txt_get")"
 | 
			
		||||
  _debug "Calling _ISPC_rmTxt: '${curData}' '${ISPC_Api}?dns_txt_get'"
 | 
			
		||||
  _debug "Result of _ISPC_rmTxt: '$curResult'"
 | 
			
		||||
  if _contains "${curResult}" '"code":"ok"'; then
 | 
			
		||||
    record_id=$(echo "${curResult}" | _egrep_o "\"id.*" | cut -d ':' -f 2 | cut -d '"' -f 2)
 | 
			
		||||
    _debug "Record ID: '${record_id}'"
 | 
			
		||||
    case "${record_id}" in
 | 
			
		||||
      '' | *[!0-9]*)
 | 
			
		||||
        _err "Record ID is not numeric."
 | 
			
		||||
        return 1
 | 
			
		||||
        ;;
 | 
			
		||||
      *)
 | 
			
		||||
        unset IFS
 | 
			
		||||
        _info "Retrieved Record ID."
 | 
			
		||||
        curData="{\"session_id\":\"${sessionID}\",\"primary_id\":\"${record_id}\",\"update_serial\":true}"
 | 
			
		||||
        curResult="$(_post "${curData}" "${ISPC_Api}?dns_txt_delete")"
 | 
			
		||||
        _debug "Calling _ISPC_rmTxt: '${curData}' '${ISPC_Api}?dns_txt_delete'"
 | 
			
		||||
        _debug "Result of _ISPC_rmTxt: '$curResult'"
 | 
			
		||||
        if _contains "${curResult}" '"code":"ok"'; then
 | 
			
		||||
          _info "Removed ACME Challenge TXT record from zone."
 | 
			
		||||
        else
 | 
			
		||||
          _err "Couldn't remove ACME Challenge TXT record from zone."
 | 
			
		||||
          return 1
 | 
			
		||||
        fi
 | 
			
		||||
        ;;
 | 
			
		||||
    esac
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										107
									
								
								dnsapi/dns_kinghost.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										107
									
								
								dnsapi/dns_kinghost.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,107 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
############################################################
 | 
			
		||||
# KingHost API support                                     #
 | 
			
		||||
# http://api.kinghost.net/doc/                             #
 | 
			
		||||
#                                                          #
 | 
			
		||||
# Author: Felipe Keller Braz <felipebraz@kinghost.com.br>  #
 | 
			
		||||
# Report Bugs here: https://github.com/kinghost/acme.sh    #
 | 
			
		||||
#                                                          #
 | 
			
		||||
# Values to export:                                        #
 | 
			
		||||
# export KINGHOST_Username="email@provider.com"            #
 | 
			
		||||
# export KINGHOST_Password="xxxxxxxxxx"                    #
 | 
			
		||||
############################################################
 | 
			
		||||
 | 
			
		||||
KING_Api="https://api.kinghost.net/acme"
 | 
			
		||||
 | 
			
		||||
# Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
# Used to add txt record
 | 
			
		||||
dns_kinghost_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  KINGHOST_Username="${KINGHOST_Username:-$(_readaccountconf_mutable KINGHOST_Username)}"
 | 
			
		||||
  KINGHOST_Password="${KINGHOST_Password:-$(_readaccountconf_mutable KINGHOST_Password)}"
 | 
			
		||||
  if [ -z "$KINGHOST_Username" ] || [ -z "$KINGHOST_Password" ]; then
 | 
			
		||||
    KINGHOST_Username=""
 | 
			
		||||
    KINGHOST_Password=""
 | 
			
		||||
    _err "You don't specify KingHost api password and email yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the credentials to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable KINGHOST_Username "$KINGHOST_Username"
 | 
			
		||||
  _saveaccountconf_mutable KINGHOST_Password "$KINGHOST_Password"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _kinghost_rest GET "dns" "name=$fulldomain&content=$txtvalue"
 | 
			
		||||
 | 
			
		||||
  #This API call returns "status":"ok" if dns record does not exists
 | 
			
		||||
  #We are creating a new txt record here, so we expect the "ok" status
 | 
			
		||||
  if ! echo "$response" | grep '"status":"ok"' >/dev/null; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    _err "$response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _kinghost_rest POST "dns" "name=$fulldomain&content=$txtvalue"
 | 
			
		||||
  if ! echo "$response" | grep '"status":"ok"' >/dev/null; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    _err "$response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Usage: fulldomain txtvalue
 | 
			
		||||
# Used to remove the txt record after validation
 | 
			
		||||
dns_kinghost_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  KINGHOST_Password="${KINGHOST_Password:-$(_readaccountconf_mutable KINGHOST_Password)}"
 | 
			
		||||
  KINGHOST_Username="${KINGHOST_Username:-$(_readaccountconf_mutable KINGHOST_Username)}"
 | 
			
		||||
  if [ -z "$KINGHOST_Password" ] || [ -z "$KINGHOST_Username" ]; then
 | 
			
		||||
    KINGHOST_Password=""
 | 
			
		||||
    KINGHOST_Username=""
 | 
			
		||||
    _err "You don't specify KingHost api key and email yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _kinghost_rest DELETE "dns" "name=$fulldomain&content=$txtvalue"
 | 
			
		||||
  if ! echo "$response" | grep '"status":"ok"' >/dev/null; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    _err "$response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
_kinghost_rest() {
 | 
			
		||||
  method=$1
 | 
			
		||||
  uri="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$uri"
 | 
			
		||||
 | 
			
		||||
  export _H1="X-Auth-Email: $KINGHOST_Username"
 | 
			
		||||
  export _H2="X-Auth-Key: $KINGHOST_Password"
 | 
			
		||||
 | 
			
		||||
  if [ "$method" != "GET" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$KING_Api/$uri.json" "" "$method")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$KING_Api/$uri.json?$data")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $uri"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										95
									
								
								dnsapi/dns_knot.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										95
									
								
								dnsapi/dns_knot.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,95 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_knot_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_knot_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _checkKey || return 1
 | 
			
		||||
  [ -n "${KNOT_SERVER}" ] || KNOT_SERVER="localhost"
 | 
			
		||||
  # save the dns server and key to the account.conf file.
 | 
			
		||||
  _saveaccountconf KNOT_SERVER "${KNOT_SERVER}"
 | 
			
		||||
  _saveaccountconf KNOT_KEY "${KNOT_KEY}"
 | 
			
		||||
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "Domain does not exist."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Adding ${fulldomain}. 60 TXT \"${txtvalue}\""
 | 
			
		||||
 | 
			
		||||
  knsupdate -y "${KNOT_KEY}" <<EOF
 | 
			
		||||
server ${KNOT_SERVER}
 | 
			
		||||
zone ${_domain}.
 | 
			
		||||
update add ${fulldomain}. 60 TXT "${txtvalue}"
 | 
			
		||||
send
 | 
			
		||||
quit
 | 
			
		||||
EOF
 | 
			
		||||
 | 
			
		||||
  if [ $? -ne 0 ]; then
 | 
			
		||||
    _err "Error updating domain."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Domain TXT record successfully added."
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: dns_knot_rm   _acme-challenge.www.domain.com
 | 
			
		||||
dns_knot_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  _checkKey || return 1
 | 
			
		||||
  [ -n "${KNOT_SERVER}" ] || KNOT_SERVER="localhost"
 | 
			
		||||
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "Domain does not exist."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Removing ${fulldomain}. TXT"
 | 
			
		||||
 | 
			
		||||
  knsupdate -y "${KNOT_KEY}" <<EOF
 | 
			
		||||
server ${KNOT_SERVER}
 | 
			
		||||
zone ${_domain}.
 | 
			
		||||
update del ${fulldomain}. TXT
 | 
			
		||||
send
 | 
			
		||||
quit
 | 
			
		||||
EOF
 | 
			
		||||
 | 
			
		||||
  if [ $? -ne 0 ]; then
 | 
			
		||||
    _err "error updating domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Domain TXT record successfully deleted."
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
# _acme-challenge.www.domain.com
 | 
			
		||||
# returns
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i="$(echo "$fulldomain" | tr '.' ' ' | wc -w)"
 | 
			
		||||
  i=$(_math "$i" - 1)
 | 
			
		||||
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f "$i"-100)
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    _domain="$h"
 | 
			
		||||
    return 0
 | 
			
		||||
  done
 | 
			
		||||
  _debug "$domain not found"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_checkKey() {
 | 
			
		||||
  if [ -z "${KNOT_KEY}" ]; then
 | 
			
		||||
    _err "You must specify a TSIG key to authenticate the request."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										103
									
								
								dnsapi/dns_lexicon.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										103
									
								
								dnsapi/dns_lexicon.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,103 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# dns api wrapper of lexicon for acme.sh
 | 
			
		||||
 | 
			
		||||
# https://github.com/AnalogJ/lexicon
 | 
			
		||||
lexicon_cmd="lexicon"
 | 
			
		||||
 | 
			
		||||
wiki="https://github.com/Neilpang/acme.sh/wiki/How-to-use-lexicon-dns-api"
 | 
			
		||||
 | 
			
		||||
_lexicon_init() {
 | 
			
		||||
  if ! _exists "$lexicon_cmd"; then
 | 
			
		||||
    _err "Please install $lexicon_cmd first: $wiki"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  PROVIDER="${PROVIDER:-$(_readdomainconf PROVIDER)}"
 | 
			
		||||
  if [ -z "$PROVIDER" ]; then
 | 
			
		||||
    PROVIDER=""
 | 
			
		||||
    _err "Please define env PROVIDER first: $wiki"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _savedomainconf PROVIDER "$PROVIDER"
 | 
			
		||||
  export PROVIDER
 | 
			
		||||
 | 
			
		||||
  # e.g. busybox-ash does not know [:upper:]
 | 
			
		||||
  # shellcheck disable=SC2018,SC2019
 | 
			
		||||
  Lx_name=$(echo LEXICON_"${PROVIDER}"_USERNAME | tr 'a-z' 'A-Z')
 | 
			
		||||
  eval "$Lx_name=\${$Lx_name:-$(_readaccountconf_mutable "$Lx_name")}"
 | 
			
		||||
  Lx_name_v=$(eval echo \$"$Lx_name")
 | 
			
		||||
  _secure_debug "$Lx_name" "$Lx_name_v"
 | 
			
		||||
  if [ "$Lx_name_v" ]; then
 | 
			
		||||
    _saveaccountconf_mutable "$Lx_name" "$Lx_name_v"
 | 
			
		||||
    eval export "$Lx_name"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # shellcheck disable=SC2018,SC2019
 | 
			
		||||
  Lx_token=$(echo LEXICON_"${PROVIDER}"_TOKEN | tr 'a-z' 'A-Z')
 | 
			
		||||
  eval "$Lx_token=\${$Lx_token:-$(_readaccountconf_mutable "$Lx_token")}"
 | 
			
		||||
  Lx_token_v=$(eval echo \$"$Lx_token")
 | 
			
		||||
  _secure_debug "$Lx_token" "$Lx_token_v"
 | 
			
		||||
  if [ "$Lx_token_v" ]; then
 | 
			
		||||
    _saveaccountconf_mutable "$Lx_token" "$Lx_token_v"
 | 
			
		||||
    eval export "$Lx_token"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # shellcheck disable=SC2018,SC2019
 | 
			
		||||
  Lx_password=$(echo LEXICON_"${PROVIDER}"_PASSWORD | tr 'a-z' 'A-Z')
 | 
			
		||||
  eval "$Lx_password=\${$Lx_password:-$(_readaccountconf_mutable "$Lx_password")}"
 | 
			
		||||
  Lx_password_v=$(eval echo \$"$Lx_password")
 | 
			
		||||
  _secure_debug "$Lx_password" "$Lx_password_v"
 | 
			
		||||
  if [ "$Lx_password_v" ]; then
 | 
			
		||||
    _saveaccountconf_mutable "$Lx_password" "$Lx_password_v"
 | 
			
		||||
    eval export "$Lx_password"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # shellcheck disable=SC2018,SC2019
 | 
			
		||||
  Lx_domaintoken=$(echo LEXICON_"${PROVIDER}"_DOMAINTOKEN | tr 'a-z' 'A-Z')
 | 
			
		||||
  eval "$Lx_domaintoken=\${$Lx_domaintoken:-$(_readaccountconf_mutable "$Lx_domaintoken")}"
 | 
			
		||||
  Lx_domaintoken_v=$(eval echo \$"$Lx_domaintoken")
 | 
			
		||||
  _secure_debug "$Lx_domaintoken" "$Lx_domaintoken_v"
 | 
			
		||||
  if [ "$Lx_domaintoken_v" ]; then
 | 
			
		||||
    _saveaccountconf_mutable "$Lx_domaintoken" "$Lx_domaintoken_v"
 | 
			
		||||
    eval export "$Lx_domaintoken"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_lexicon_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_lexicon_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if ! _lexicon_init; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  domain=$(printf "%s" "$fulldomain" | cut -d . -f 2-999)
 | 
			
		||||
 | 
			
		||||
  _secure_debug LEXICON_OPTS "$LEXICON_OPTS"
 | 
			
		||||
  _savedomainconf LEXICON_OPTS "$LEXICON_OPTS"
 | 
			
		||||
 | 
			
		||||
  # shellcheck disable=SC2086
 | 
			
		||||
  $lexicon_cmd "$PROVIDER" $LEXICON_OPTS create "${domain}" TXT --name="_acme-challenge.${domain}." --content="${txtvalue}"
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: dns_lexicon_rm   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_lexicon_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if ! _lexicon_init; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  domain=$(printf "%s" "$fulldomain" | cut -d . -f 2-999)
 | 
			
		||||
 | 
			
		||||
  # shellcheck disable=SC2086
 | 
			
		||||
  $lexicon_cmd "$PROVIDER" $LEXICON_OPTS delete "${domain}" TXT --name="_acme-challenge.${domain}." --content="${txtvalue}"
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										183
									
								
								dnsapi/dns_linode.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										183
									
								
								dnsapi/dns_linode.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,183 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Author: Philipp Grosswiler <philipp.grosswiler@swiss-design.net>
 | 
			
		||||
 | 
			
		||||
LINODE_API_URL="https://api.linode.com/?api_key=$LINODE_API_KEY&api_action="
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_linode_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_linode_add() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
  txtvalue="${2}"
 | 
			
		||||
 | 
			
		||||
  if ! _Linode_API; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Using Linode"
 | 
			
		||||
  _debug "Calling: dns_linode_add() '${fulldomain}' '${txtvalue}'"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "Domain does not exist."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _parameters="&DomainID=$_domain_id&Type=TXT&Name=$_sub_domain&Target=$txtvalue"
 | 
			
		||||
 | 
			
		||||
  if _rest GET "domain.resource.create" "$_parameters" && [ -n "$response" ]; then
 | 
			
		||||
    _resource_id=$(printf "%s\n" "$response" | _egrep_o "\"ResourceID\":\s*[0-9]+" | cut -d : -f 2 | tr -d " " | _head_n 1)
 | 
			
		||||
    _debug _resource_id "$_resource_id"
 | 
			
		||||
 | 
			
		||||
    if [ -z "$_resource_id" ]; then
 | 
			
		||||
      _err "Error adding the domain resource."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    _info "Domain resource successfully added."
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: dns_linode_rm   _acme-challenge.www.domain.com
 | 
			
		||||
dns_linode_rm() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
 | 
			
		||||
  if ! _Linode_API; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Using Linode"
 | 
			
		||||
  _debug "Calling: dns_linode_rm() '${fulldomain}'"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "Domain does not exist."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _parameters="&DomainID=$_domain_id"
 | 
			
		||||
 | 
			
		||||
  if _rest GET "domain.resource.list" "$_parameters" && [ -n "$response" ]; then
 | 
			
		||||
    response="$(echo "$response" | tr -d "\n" | tr '{' "|" | sed 's/|/&{/g' | tr "|" "\n")"
 | 
			
		||||
 | 
			
		||||
    resource="$(echo "$response" | _egrep_o "{.*\"NAME\":\s*\"$_sub_domain\".*}")"
 | 
			
		||||
    if [ "$resource" ]; then
 | 
			
		||||
      _resource_id=$(printf "%s\n" "$resource" | _egrep_o "\"RESOURCEID\":\s*[0-9]+" | _head_n 1 | cut -d : -f 2 | tr -d \ )
 | 
			
		||||
      if [ "$_resource_id" ]; then
 | 
			
		||||
        _debug _resource_id "$_resource_id"
 | 
			
		||||
 | 
			
		||||
        _parameters="&DomainID=$_domain_id&ResourceID=$_resource_id"
 | 
			
		||||
 | 
			
		||||
        if _rest GET "domain.resource.delete" "$_parameters" && [ -n "$response" ]; then
 | 
			
		||||
          _resource_id=$(printf "%s\n" "$response" | _egrep_o "\"ResourceID\":\s*[0-9]+" | cut -d : -f 2 | tr -d " " | _head_n 1)
 | 
			
		||||
          _debug _resource_id "$_resource_id"
 | 
			
		||||
 | 
			
		||||
          if [ -z "$_resource_id" ]; then
 | 
			
		||||
            _err "Error deleting the domain resource."
 | 
			
		||||
            return 1
 | 
			
		||||
          fi
 | 
			
		||||
 | 
			
		||||
          _info "Domain resource successfully deleted."
 | 
			
		||||
          return 0
 | 
			
		||||
        fi
 | 
			
		||||
      fi
 | 
			
		||||
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_Linode_API() {
 | 
			
		||||
  if [ -z "$LINODE_API_KEY" ]; then
 | 
			
		||||
    LINODE_API_KEY=""
 | 
			
		||||
 | 
			
		||||
    _err "You didn't specify the Linode API key yet."
 | 
			
		||||
    _err "Please create your key and try again."
 | 
			
		||||
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf LINODE_API_KEY "$LINODE_API_KEY"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=12345
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  if _rest GET "domain.list"; then
 | 
			
		||||
    response="$(echo "$response" | tr -d "\n" | tr '{' "|" | sed 's/|/&{/g' | tr "|" "\n")"
 | 
			
		||||
    while true; do
 | 
			
		||||
      h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
      _debug h "$h"
 | 
			
		||||
      if [ -z "$h" ]; then
 | 
			
		||||
        #not valid
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
 | 
			
		||||
      hostedzone="$(echo "$response" | _egrep_o "{.*\"DOMAIN\":\s*\"$h\".*}")"
 | 
			
		||||
      if [ "$hostedzone" ]; then
 | 
			
		||||
        _domain_id=$(printf "%s\n" "$hostedzone" | _egrep_o "\"DOMAINID\":\s*[0-9]+" | _head_n 1 | cut -d : -f 2 | tr -d \ )
 | 
			
		||||
        if [ "$_domain_id" ]; then
 | 
			
		||||
          _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
          _domain=$h
 | 
			
		||||
          return 0
 | 
			
		||||
        fi
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
      p=$i
 | 
			
		||||
      i=$(_math "$i" + 1)
 | 
			
		||||
    done
 | 
			
		||||
  fi
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#method method action data
 | 
			
		||||
_rest() {
 | 
			
		||||
  mtd="$1"
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
 | 
			
		||||
  _debug mtd "$mtd"
 | 
			
		||||
  _debug ep "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="Accept: application/json"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  if [ "$mtd" != "GET" ]; then
 | 
			
		||||
    # both POST and DELETE.
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$LINODE_API_URL$ep" "" "$mtd")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$LINODE_API_URL$ep$data")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										185
									
								
								dnsapi/dns_linode_v4.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										185
									
								
								dnsapi/dns_linode_v4.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,185 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Original Author: Philipp Grosswiler <philipp.grosswiler@swiss-design.net>
 | 
			
		||||
#v4 Update Author: Aaron W. Swenson <aaron@grandmasfridge.org>
 | 
			
		||||
 | 
			
		||||
LINODE_V4_API_URL="https://api.linode.com/v4/domains"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_linode_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_linode_add() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
  txtvalue="${2}"
 | 
			
		||||
 | 
			
		||||
  if ! _Linode_API; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Using Linode"
 | 
			
		||||
  _debug "Calling: dns_linode_add() '${fulldomain}' '${txtvalue}'"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "Domain does not exist."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _payload="{
 | 
			
		||||
              \"type\": \"TXT\",
 | 
			
		||||
              \"name\": \"$_sub_domain\",
 | 
			
		||||
              \"target\": \"$txtvalue\"
 | 
			
		||||
            }"
 | 
			
		||||
 | 
			
		||||
  if _rest POST "/$_domain_id/records" "$_payload" && [ -n "$response" ]; then
 | 
			
		||||
    _resource_id=$(printf "%s\n" "$response" | _egrep_o "\"id\":\s*[0-9]+" | cut -d : -f 2 | tr -d " " | _head_n 1)
 | 
			
		||||
    _debug _resource_id "$_resource_id"
 | 
			
		||||
 | 
			
		||||
    if [ -z "$_resource_id" ]; then
 | 
			
		||||
      _err "Error adding the domain resource."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    _info "Domain resource successfully added."
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: dns_linode_rm   _acme-challenge.www.domain.com
 | 
			
		||||
dns_linode_rm() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
 | 
			
		||||
  if ! _Linode_API; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Using Linode"
 | 
			
		||||
  _debug "Calling: dns_linode_rm() '${fulldomain}'"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "Domain does not exist."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  if _rest GET "/$_domain_id/records" && [ -n "$response" ]; then
 | 
			
		||||
    response="$(echo "$response" | tr -d "\n" | tr '{' "|" | sed 's/|/&{/g' | tr "|" "\n")"
 | 
			
		||||
 | 
			
		||||
    resource="$(echo "$response" | _egrep_o "{.*\"name\":\s*\"$_sub_domain\".*}")"
 | 
			
		||||
    if [ "$resource" ]; then
 | 
			
		||||
      _resource_id=$(printf "%s\n" "$resource" | _egrep_o "\"id\":\s*[0-9]+" | _head_n 1 | cut -d : -f 2 | tr -d \ )
 | 
			
		||||
      if [ "$_resource_id" ]; then
 | 
			
		||||
        _debug _resource_id "$_resource_id"
 | 
			
		||||
 | 
			
		||||
        if _rest DELETE "/$_domain_id/records/$_resource_id" && [ -n "$response" ]; then
 | 
			
		||||
          # On 200/OK, empty set is returned. Check for error, if any.
 | 
			
		||||
          _error_response=$(printf "%s\n" "$response" | _egrep_o "\"errors\"" | cut -d : -f 2 | tr -d " " | _head_n 1)
 | 
			
		||||
 | 
			
		||||
          if [ -n "$_error_response" ]; then
 | 
			
		||||
            _err "Error deleting the domain resource: $_error_response"
 | 
			
		||||
            return 1
 | 
			
		||||
          fi
 | 
			
		||||
 | 
			
		||||
          _info "Domain resource successfully deleted."
 | 
			
		||||
          return 0
 | 
			
		||||
        fi
 | 
			
		||||
      fi
 | 
			
		||||
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_Linode_API() {
 | 
			
		||||
  if [ -z "$LINODE_V4_API_KEY" ]; then
 | 
			
		||||
    LINODE_V4_API_KEY=""
 | 
			
		||||
 | 
			
		||||
    _err "You didn't specify the Linode v4 API key yet."
 | 
			
		||||
    _err "Please create your key and try again."
 | 
			
		||||
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf LINODE_V4_API_KEY "$LINODE_V4_API_KEY"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=12345
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  if _rest GET; then
 | 
			
		||||
    response="$(echo "$response" | tr -d "\n" | tr '{' "|" | sed 's/|/&{/g' | tr "|" "\n")"
 | 
			
		||||
    while true; do
 | 
			
		||||
      h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
      _debug h "$h"
 | 
			
		||||
      if [ -z "$h" ]; then
 | 
			
		||||
        #not valid
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
 | 
			
		||||
      hostedzone="$(echo "$response" | _egrep_o "{.*\"domain\":\s*\"$h\".*}")"
 | 
			
		||||
      if [ "$hostedzone" ]; then
 | 
			
		||||
        _domain_id=$(printf "%s\n" "$hostedzone" | _egrep_o "\"id\":\s*[0-9]+" | _head_n 1 | cut -d : -f 2 | tr -d \ )
 | 
			
		||||
        if [ "$_domain_id" ]; then
 | 
			
		||||
          _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
          _domain=$h
 | 
			
		||||
          return 0
 | 
			
		||||
        fi
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
      p=$i
 | 
			
		||||
      i=$(_math "$i" + 1)
 | 
			
		||||
    done
 | 
			
		||||
  fi
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#method method action data
 | 
			
		||||
_rest() {
 | 
			
		||||
  mtd="$1"
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
 | 
			
		||||
  _debug mtd "$mtd"
 | 
			
		||||
  _debug ep "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="Accept: application/json"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
  export _H3="Authorization: Bearer $LINODE_V4_API_KEY"
 | 
			
		||||
 | 
			
		||||
  if [ "$mtd" != "GET" ]; then
 | 
			
		||||
    # both POST and DELETE.
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$LINODE_V4_API_URL$ep" "" "$mtd")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$LINODE_V4_API_URL$ep$data")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										286
									
								
								dnsapi/dns_loopia.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										286
									
								
								dnsapi/dns_loopia.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,286 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
#LOOPIA_User="username"
 | 
			
		||||
#
 | 
			
		||||
#LOOPIA_Password="password"
 | 
			
		||||
 | 
			
		||||
LOOPIA_Api="https://api.loopia.se/RPCSERV"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_loopia_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  LOOPIA_User="${LOOPIA_User:-$(_readaccountconf_mutable LOOPIA_User)}"
 | 
			
		||||
  LOOPIA_Password="${LOOPIA_Password:-$(_readaccountconf_mutable LOOPIA_Password)}"
 | 
			
		||||
  if [ -z "$LOOPIA_User" ] || [ -z "$LOOPIA_Password" ]; then
 | 
			
		||||
    LOOPIA_User=""
 | 
			
		||||
    LOOPIA_Password=""
 | 
			
		||||
    _err "You don't specify loopia user and password yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable LOOPIA_User "$LOOPIA_User"
 | 
			
		||||
  _saveaccountconf_mutable LOOPIA_Password "$LOOPIA_Password"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
 | 
			
		||||
  _loopia_add_sub_domain "$_domain" "$_sub_domain"
 | 
			
		||||
  _loopia_add_record "$_domain" "$_sub_domain" "$txtvalue"
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
dns_loopia_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  LOOPIA_User="${LOOPIA_User:-$(_readaccountconf_mutable LOOPIA_User)}"
 | 
			
		||||
  LOOPIA_Password="${LOOPIA_Password:-$(_readaccountconf_mutable LOOPIA_Password)}"
 | 
			
		||||
  if [ -z "$LOOPIA_User" ] || [ -z "$LOOPIA_Password" ]; then
 | 
			
		||||
    LOOPIA_User=""
 | 
			
		||||
    LOOPIA_Password=""
 | 
			
		||||
    _err "You don't specify LOOPIA user and password yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable LOOPIA_User "$LOOPIA_User"
 | 
			
		||||
  _saveaccountconf_mutable LOOPIA_Password "$LOOPIA_Password"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
    <methodName>removeSubdomain</methodName>
 | 
			
		||||
    <params>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
    </params>
 | 
			
		||||
  </methodCall>' $LOOPIA_User $LOOPIA_Password "$_domain" "$_sub_domain")
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$xml_content" "$LOOPIA_Api" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "OK"; then
 | 
			
		||||
    _err "Error could not get txt records"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_loopia_get_records() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  sub_domain=$2
 | 
			
		||||
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
    <methodName>getZoneRecords</methodName>
 | 
			
		||||
    <params>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
    </params>
 | 
			
		||||
  </methodCall>' $LOOPIA_User $LOOPIA_Password "$domain" "$sub_domain")
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$xml_content" "$LOOPIA_Api" "" "POST")"
 | 
			
		||||
  if ! _contains "$response" "<array>"; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  _debug "get root"
 | 
			
		||||
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
  <methodName>getDomains</methodName>
 | 
			
		||||
  <params>
 | 
			
		||||
   <param>
 | 
			
		||||
    <value><string>%s</string></value>
 | 
			
		||||
   </param>
 | 
			
		||||
   <param>
 | 
			
		||||
    <value><string>%s</string></value>
 | 
			
		||||
   </param>
 | 
			
		||||
  </params>
 | 
			
		||||
  </methodCall>' $LOOPIA_User $LOOPIA_Password)
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$xml_content" "$LOOPIA_Api" "" "POST")"
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(echo "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "$h"; then
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain="$h"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_loopia_add_record() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  sub_domain=$2
 | 
			
		||||
  txtval=$3
 | 
			
		||||
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
    <methodName>addZoneRecord</methodName>
 | 
			
		||||
    <params>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <struct>
 | 
			
		||||
          <member>
 | 
			
		||||
            <name>type</name>
 | 
			
		||||
            <value><string>TXT</string></value>
 | 
			
		||||
          </member>
 | 
			
		||||
          <member>
 | 
			
		||||
            <name>priority</name>
 | 
			
		||||
            <value><int>0</int></value>
 | 
			
		||||
          </member>
 | 
			
		||||
          <member>
 | 
			
		||||
            <name>ttl</name>
 | 
			
		||||
            <value><int>60</int></value>
 | 
			
		||||
          </member>
 | 
			
		||||
          <member>
 | 
			
		||||
            <name>rdata</name>
 | 
			
		||||
            <value><string>%s</string></value>
 | 
			
		||||
          </member>
 | 
			
		||||
        </struct>
 | 
			
		||||
      </param>
 | 
			
		||||
    </params>
 | 
			
		||||
  </methodCall>' $LOOPIA_User $LOOPIA_Password "$domain" "$sub_domain" "$txtval")
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$xml_content" "$LOOPIA_Api" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "OK"; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_sub_domain_exists() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  sub_domain=$2
 | 
			
		||||
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
    <methodName>getSubdomains</methodName>
 | 
			
		||||
    <params>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
    </params>
 | 
			
		||||
  </methodCall>' $LOOPIA_User $LOOPIA_Password "$domain")
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$xml_content" "$LOOPIA_Api" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  if _contains "$response" "$sub_domain"; then
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_loopia_add_sub_domain() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  sub_domain=$2
 | 
			
		||||
 | 
			
		||||
  if _sub_domain_exists "$domain" "$sub_domain"; then
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  xml_content=$(printf '<?xml version="1.0" encoding="UTF-8"?>
 | 
			
		||||
  <methodCall>
 | 
			
		||||
    <methodName>addSubdomain</methodName>
 | 
			
		||||
    <params>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
      <param>
 | 
			
		||||
        <value><string>%s</string></value>
 | 
			
		||||
      </param>
 | 
			
		||||
    </params>
 | 
			
		||||
  </methodCall>' $LOOPIA_User $LOOPIA_Password "$domain" "$sub_domain")
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$xml_content" "$LOOPIA_Api" "" "POST")"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "OK"; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										154
									
								
								dnsapi/dns_lua.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										154
									
								
								dnsapi/dns_lua.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,154 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# bug reports to dev@1e.ca
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
#LUA_Key="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
#
 | 
			
		||||
#LUA_Email="user@luadns.net"
 | 
			
		||||
 | 
			
		||||
LUA_Api="https://api.luadns.com/v1"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_lua_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  LUA_Key="${LUA_Key:-$(_readaccountconf_mutable LUA_Key)}"
 | 
			
		||||
  LUA_Email="${LUA_Email:-$(_readaccountconf_mutable LUA_Email)}"
 | 
			
		||||
  LUA_auth=$(printf "%s" "$LUA_Email:$LUA_Key" | _base64)
 | 
			
		||||
 | 
			
		||||
  if [ -z "$LUA_Key" ] || [ -z "$LUA_Email" ]; then
 | 
			
		||||
    LUA_Key=""
 | 
			
		||||
    LUA_Email=""
 | 
			
		||||
    _err "You don't specify luadns api key and email yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable LUA_Key "$LUA_Key"
 | 
			
		||||
  _saveaccountconf_mutable LUA_Email "$LUA_Email"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  if _LUA_rest POST "zones/$_domain_id/records" "{\"type\":\"TXT\",\"name\":\"$fulldomain.\",\"content\":\"$txtvalue\",\"ttl\":120}"; then
 | 
			
		||||
    if _contains "$response" "$fulldomain"; then
 | 
			
		||||
      _info "Added"
 | 
			
		||||
      #todo: check if the record takes effect
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Add txt record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain
 | 
			
		||||
dns_lua_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  LUA_Key="${LUA_Key:-$(_readaccountconf_mutable LUA_Key)}"
 | 
			
		||||
  LUA_Email="${LUA_Email:-$(_readaccountconf_mutable LUA_Email)}"
 | 
			
		||||
  LUA_auth=$(printf "%s" "$LUA_Email:$LUA_Key" | _base64)
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _LUA_rest GET "zones/${_domain_id}/records"
 | 
			
		||||
 | 
			
		||||
  count=$(printf "%s\n" "$response" | _egrep_o "\"name\":\"$fulldomain.\",\"type\":\"TXT\"" | wc -l | tr -d " ")
 | 
			
		||||
  _debug count "$count"
 | 
			
		||||
  if [ "$count" = "0" ]; then
 | 
			
		||||
    _info "Don't need to remove."
 | 
			
		||||
  else
 | 
			
		||||
    record_id=$(printf "%s\n" "$response" | _egrep_o "\"id\":[^,]*,\"name\":\"$fulldomain.\",\"type\":\"TXT\"" | _head_n 1 | cut -d: -f2 | cut -d, -f1)
 | 
			
		||||
    _debug "record_id" "$record_id"
 | 
			
		||||
    if [ -z "$record_id" ]; then
 | 
			
		||||
      _err "Can not get record id to remove."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    if ! _LUA_rest DELETE "/zones/$_domain_id/records/$record_id"; then
 | 
			
		||||
      _err "Delete record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    _contains "$response" "$record_id"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  if ! _LUA_rest GET "zones"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"name\":\"$h\""; then
 | 
			
		||||
      _domain_id=$(printf "%s\n" "$response" | _egrep_o "\"id\":[^,]*,\"name\":\"$h\"" | cut -d : -f 2 | cut -d , -f 1)
 | 
			
		||||
      _debug _domain_id "$_domain_id"
 | 
			
		||||
      if [ "$_domain_id" ]; then
 | 
			
		||||
        _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
        _domain="$h"
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_LUA_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="Accept: application/json"
 | 
			
		||||
  export _H2="Authorization: Basic $LUA_auth"
 | 
			
		||||
  if [ "$m" != "GET" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$LUA_Api/$ep" "" "$m")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$LUA_Api/$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										157
									
								
								dnsapi/dns_me.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										157
									
								
								dnsapi/dns_me.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,157 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# bug reports to dev@1e.ca
 | 
			
		||||
 | 
			
		||||
# ME_Key=qmlkdjflmkqdjf	
 | 
			
		||||
# ME_Secret=qmsdlkqmlksdvnnpae
 | 
			
		||||
 | 
			
		||||
ME_Api=https://api.dnsmadeeasy.com/V2.0/dns/managed
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_me_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if [ -z "$ME_Key" ] || [ -z "$ME_Secret" ]; then
 | 
			
		||||
    ME_Key=""
 | 
			
		||||
    ME_Secret=""
 | 
			
		||||
    _err "You didn't specify DNSMadeEasy api key and secret yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf ME_Key "$ME_Key"
 | 
			
		||||
  _saveaccountconf ME_Secret "$ME_Secret"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _me_rest GET "${_domain_id}/records?recordName=$_sub_domain&type=TXT"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "\"totalRecords\":"; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  if _me_rest POST "$_domain_id/records/" "{\"type\":\"TXT\",\"name\":\"$_sub_domain\",\"value\":\"$txtvalue\",\"gtdLocation\":\"DEFAULT\",\"ttl\":120}"; then
 | 
			
		||||
    if printf -- "%s" "$response" | grep \"id\": >/dev/null; then
 | 
			
		||||
      _info "Added"
 | 
			
		||||
      #todo: check if the record takes effect
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Add txt record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain
 | 
			
		||||
dns_me_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _me_rest GET "${_domain_id}/records?recordName=$_sub_domain&type=TXT"
 | 
			
		||||
 | 
			
		||||
  count=$(printf "%s\n" "$response" | _egrep_o "\"totalRecords\":[^,]*" | cut -d : -f 2)
 | 
			
		||||
  _debug count "$count"
 | 
			
		||||
  if [ "$count" = "0" ]; then
 | 
			
		||||
    _info "Don't need to remove."
 | 
			
		||||
  else
 | 
			
		||||
    record_id=$(printf "%s\n" "$response" | _egrep_o ",\"value\":\"..$txtvalue..\",\"id\":[^,]*" | cut -d : -f 3 | head -n 1)
 | 
			
		||||
    _debug "record_id" "$record_id"
 | 
			
		||||
    if [ -z "$record_id" ]; then
 | 
			
		||||
      _err "Can not get record id to remove."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    if ! _me_rest DELETE "$_domain_id/records/$record_id"; then
 | 
			
		||||
      _err "Delete record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    _contains "$response" ''
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _me_rest GET "name?domainname=$h"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"name\":\"$h\""; then
 | 
			
		||||
      _domain_id=$(printf "%s\n" "$response" | _egrep_o "\"id\":[^,]*" | head -n 1 | cut -d : -f 2 | tr -d '}')
 | 
			
		||||
      if [ "$_domain_id" ]; then
 | 
			
		||||
        _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
        _domain="$h"
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_me_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
 | 
			
		||||
  cdate=$(LANG=C date -u +"%a, %d %b %Y %T %Z")
 | 
			
		||||
  hmac=$(printf "%s" "$cdate" | _hmac sha1 "$(printf "%s" "$ME_Secret" | _hex_dump | tr -d " ")" hex)
 | 
			
		||||
 | 
			
		||||
  export _H1="x-dnsme-apiKey: $ME_Key"
 | 
			
		||||
  export _H2="x-dnsme-requestDate: $cdate"
 | 
			
		||||
  export _H3="x-dnsme-hmac: $hmac"
 | 
			
		||||
 | 
			
		||||
  if [ "$m" != "GET" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$ME_Api/$ep" "" "$m")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$ME_Api/$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										35
									
								
								dnsapi/dns_myapi.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										35
									
								
								dnsapi/dns_myapi.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,35 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a sample custom api script.
 | 
			
		||||
#This file name is "dns_myapi.sh"
 | 
			
		||||
#So, here must be a method   dns_myapi_add()
 | 
			
		||||
#Which will be called by acme.sh to add the txt record to your api system.
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
#
 | 
			
		||||
#Author: Neilpang
 | 
			
		||||
#Report Bugs here: https://github.com/Neilpang/acme.sh
 | 
			
		||||
#
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_myapi_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_myapi_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _info "Using myapi"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
  _err "Not implemented!"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: fulldomain txtvalue
 | 
			
		||||
#Remove the txt record after validation.
 | 
			
		||||
dns_myapi_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _info "Using myapi"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
							
								
								
									
										210
									
								
								dnsapi/dns_mydnsjp.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										210
									
								
								dnsapi/dns_mydnsjp.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,210 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Here is a api script for MyDNS.JP.
 | 
			
		||||
#This file name is "dns_mydnsjp.sh"
 | 
			
		||||
#So, here must be a method   dns_mydnsjp_add()
 | 
			
		||||
#Which will be called by acme.sh to add the txt record to your api system.
 | 
			
		||||
#returns 0 means success, otherwise error.
 | 
			
		||||
#
 | 
			
		||||
#Author: epgdatacapbon
 | 
			
		||||
#Report Bugs here: https://github.com/epgdatacapbon/acme.sh
 | 
			
		||||
#
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
# Export MyDNS.JP MasterID and Password in following variables...
 | 
			
		||||
#  MYDNSJP_MasterID=MasterID
 | 
			
		||||
#  MYDNSJP_Password=Password
 | 
			
		||||
 | 
			
		||||
MYDNSJP_API="https://www.mydns.jp"
 | 
			
		||||
 | 
			
		||||
#Usage: dns_mydnsjp_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_mydnsjp_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  _info "Using mydnsjp"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  # Load the credentials from the account conf file
 | 
			
		||||
  MYDNSJP_MasterID="${MYDNSJP_MasterID:-$(_readaccountconf_mutable MYDNSJP_MasterID)}"
 | 
			
		||||
  MYDNSJP_Password="${MYDNSJP_Password:-$(_readaccountconf_mutable MYDNSJP_Password)}"
 | 
			
		||||
  if [ -z "$MYDNSJP_MasterID" ] || [ -z "$MYDNSJP_Password" ]; then
 | 
			
		||||
    MYDNSJP_MasterID=""
 | 
			
		||||
    MYDNSJP_Password=""
 | 
			
		||||
    _err "You don't specify mydnsjp api MasterID and Password yet."
 | 
			
		||||
    _err "Please export as MYDNSJP_MasterID / MYDNSJP_Password and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Save the credentials to the account conf file
 | 
			
		||||
  _saveaccountconf_mutable MYDNSJP_MasterID "$MYDNSJP_MasterID"
 | 
			
		||||
  _saveaccountconf_mutable MYDNSJP_Password "$MYDNSJP_Password"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone."
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  if _mydnsjp_api "REGIST" "$_domain" "$txtvalue"; then
 | 
			
		||||
    if printf -- "%s" "$response" | grep "OK." >/dev/null; then
 | 
			
		||||
      _info "Added, OK"
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Add txt record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  _err "Add txt record error."
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: fulldomain txtvalue
 | 
			
		||||
#Remove the txt record after validation.
 | 
			
		||||
dns_mydnsjp_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  _info "Removing TXT record"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  # Load the credentials from the account conf file
 | 
			
		||||
  MYDNSJP_MasterID="${MYDNSJP_MasterID:-$(_readaccountconf_mutable MYDNSJP_MasterID)}"
 | 
			
		||||
  MYDNSJP_Password="${MYDNSJP_Password:-$(_readaccountconf_mutable MYDNSJP_Password)}"
 | 
			
		||||
  if [ -z "$MYDNSJP_MasterID" ] || [ -z "$MYDNSJP_Password" ]; then
 | 
			
		||||
    MYDNSJP_MasterID=""
 | 
			
		||||
    MYDNSJP_Password=""
 | 
			
		||||
    _err "You don't specify mydnsjp api MasterID and Password yet."
 | 
			
		||||
    _err "Please export as MYDNSJP_MasterID / MYDNSJP_Password and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  if _mydnsjp_api "DELETE" "$_domain" "$txtvalue"; then
 | 
			
		||||
    if printf -- "%s" "$response" | grep "OK." >/dev/null; then
 | 
			
		||||
      _info "Deleted, OK"
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Delete txt record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  _err "Delete txt record error."
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
# _acme-challenge.www.domain.com
 | 
			
		||||
# returns
 | 
			
		||||
#  _sub_domain=_acme-challenge.www
 | 
			
		||||
#  _domain=domain.com
 | 
			
		||||
_get_root() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  # Get the root domain
 | 
			
		||||
  _mydnsjp_retrieve_domain
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    # not valid
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  while true; do
 | 
			
		||||
    _domain=$(printf "%s" "$fulldomain" | cut -d . -f $i-100)
 | 
			
		||||
 | 
			
		||||
    if [ -z "$_domain" ]; then
 | 
			
		||||
      # not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if [ "$_domain" = "$_root_domain" ]; then
 | 
			
		||||
      _sub_domain=$(printf "%s" "$fulldomain" | cut -d . -f 1-$p)
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Retrieve the root domain
 | 
			
		||||
# returns 0 success
 | 
			
		||||
_mydnsjp_retrieve_domain() {
 | 
			
		||||
  _debug "Login to MyDNS.JP"
 | 
			
		||||
 | 
			
		||||
  response="$(_post "masterid=$MYDNSJP_MasterID&masterpwd=$MYDNSJP_Password" "$MYDNSJP_API/?MENU=100")"
 | 
			
		||||
  cookie="$(grep -i '^set-cookie:' "$HTTP_HEADER" | _head_n 1 | cut -d " " -f 2)"
 | 
			
		||||
 | 
			
		||||
  # If cookies is not empty then logon successful
 | 
			
		||||
  if [ -z "$cookie" ]; then
 | 
			
		||||
    _err "Fail to get a cookie."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "Retrieve DOMAIN INFO page"
 | 
			
		||||
 | 
			
		||||
  export _H1="Cookie:${cookie}"
 | 
			
		||||
 | 
			
		||||
  response="$(_get "$MYDNSJP_API/?MENU=300")"
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "Fail to retrieve DOMAIN INFO."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _root_domain=$(echo "$response" | grep "DNSINFO\[domainname\]" | sed 's/^.*value="\([^"]*\)".*/\1/')
 | 
			
		||||
 | 
			
		||||
  # Logout
 | 
			
		||||
  response="$(_get "$MYDNSJP_API/?MENU=090")"
 | 
			
		||||
 | 
			
		||||
  _debug _root_domain "$_root_domain"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$_root_domain" ]; then
 | 
			
		||||
    _err "Fail to get the root domain."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_mydnsjp_api() {
 | 
			
		||||
  cmd=$1
 | 
			
		||||
  domain=$2
 | 
			
		||||
  txtvalue=$3
 | 
			
		||||
 | 
			
		||||
  # Base64 encode the credentials
 | 
			
		||||
  credentials=$(printf "%s:%s" "$MYDNSJP_MasterID" "$MYDNSJP_Password" | _base64)
 | 
			
		||||
 | 
			
		||||
  # Construct the HTTP Authorization header
 | 
			
		||||
  export _H1="Content-Type: application/x-www-form-urlencoded"
 | 
			
		||||
  export _H2="Authorization: Basic ${credentials}"
 | 
			
		||||
 | 
			
		||||
  response="$(_post "CERTBOT_DOMAIN=$domain&CERTBOT_VALIDATION=$txtvalue&EDIT_CMD=$cmd" "$MYDNSJP_API/directedit.html")"
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										356
									
								
								dnsapi/dns_namecheap.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										356
									
								
								dnsapi/dns_namecheap.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,356 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# Namecheap API
 | 
			
		||||
# https://www.namecheap.com/support/api/intro.aspx
 | 
			
		||||
#
 | 
			
		||||
# Requires Namecheap API key set in NAMECHEAP_API_KEY, NAMECHEAP_SOURCEIP and NAMECHEAP_USERNAME set as environment variable
 | 
			
		||||
# Due to Namecheap's API limitation all the records of your domain will be read and re applied, make sure to have a backup of your records you could apply if any issue would arise.
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
if [ "$STAGE" -eq 1 ]; then
 | 
			
		||||
  NAMECHEAP_API="https://api.sandbox.namecheap.com/xml.response"
 | 
			
		||||
else
 | 
			
		||||
  NAMECHEAP_API="https://api.namecheap.com/xml.response"
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
#Usage: dns_namecheap_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_namecheap_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if ! _namecheap_check_config; then
 | 
			
		||||
    _err "$error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _namecheap_set_publicip; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
  _debug domain "$_domain"
 | 
			
		||||
  _debug sub_domain "$_sub_domain"
 | 
			
		||||
 | 
			
		||||
  _set_namecheap_TXT "$_domain" "$_sub_domain" "$txtvalue"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: fulldomain txtvalue
 | 
			
		||||
#Remove the txt record after validation.
 | 
			
		||||
dns_namecheap_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if ! _namecheap_set_publicip; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _namecheap_check_config; then
 | 
			
		||||
    _err "$error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
  _debug domain "$_domain"
 | 
			
		||||
  _debug sub_domain "$_sub_domain"
 | 
			
		||||
 | 
			
		||||
  _del_namecheap_TXT "$_domain" "$_sub_domain" "$txtvalue"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
 | 
			
		||||
  if ! _namecheap_post "namecheap.domains.getList"; then
 | 
			
		||||
    _err "$error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  while true; do
 | 
			
		||||
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _contains "$response" "$h"; then
 | 
			
		||||
      _debug "$h not found"
 | 
			
		||||
    else
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain="$h"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p="$i"
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_namecheap_set_publicip() {
 | 
			
		||||
 | 
			
		||||
  if [ -z "$NAMECHEAP_SOURCEIP" ]; then
 | 
			
		||||
    _err "No Source IP specified for Namecheap API."
 | 
			
		||||
    _err "Use your public ip address or an url to retrieve it (e.g. https://ipconfig.co/ip) and export it as NAMECHEAP_SOURCEIP"
 | 
			
		||||
    return 1
 | 
			
		||||
  else
 | 
			
		||||
    _saveaccountconf NAMECHEAP_SOURCEIP "$NAMECHEAP_SOURCEIP"
 | 
			
		||||
    _debug sourceip "$NAMECHEAP_SOURCEIP"
 | 
			
		||||
 | 
			
		||||
    ip=$(echo "$NAMECHEAP_SOURCEIP" | _egrep_o '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}')
 | 
			
		||||
    addr=$(echo "$NAMECHEAP_SOURCEIP" | _egrep_o '(http|https)://.*')
 | 
			
		||||
 | 
			
		||||
    _debug2 ip "$ip"
 | 
			
		||||
    _debug2 addr "$addr"
 | 
			
		||||
 | 
			
		||||
    if [ -n "$ip" ]; then
 | 
			
		||||
      _publicip="$ip"
 | 
			
		||||
    elif [ -n "$addr" ]; then
 | 
			
		||||
      _publicip=$(_get "$addr")
 | 
			
		||||
    else
 | 
			
		||||
      _err "No Source IP specified for Namecheap API."
 | 
			
		||||
      _err "Use your public ip address or an url to retrieve it (e.g. https://ipconfig.co/ip) and export it as NAMECHEAP_SOURCEIP"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug publicip "$_publicip"
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_namecheap_post() {
 | 
			
		||||
  command=$1
 | 
			
		||||
  data="ApiUser=${NAMECHEAP_USERNAME}&ApiKey=${NAMECHEAP_API_KEY}&ClientIp=${_publicip}&UserName=${NAMECHEAP_USERNAME}&Command=${command}"
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$data" "$NAMECHEAP_API" "" "POST")"
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
 | 
			
		||||
  if _contains "$response" "Status=\"ERROR\"" >/dev/null; then
 | 
			
		||||
    error=$(echo "$response" | _egrep_o ">.*<\\/Error>" | cut -d '<' -f 1 | tr -d '>')
 | 
			
		||||
    _err "error $error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_namecheap_parse_host() {
 | 
			
		||||
  _host=$1
 | 
			
		||||
  _debug _host "$_host"
 | 
			
		||||
 | 
			
		||||
  _hostid=$(echo "$_host" | _egrep_o ' HostId="[^"]*' | cut -d '"' -f 2)
 | 
			
		||||
  _hostname=$(echo "$_host" | _egrep_o ' Name="[^"]*' | cut -d '"' -f 2)
 | 
			
		||||
  _hosttype=$(echo "$_host" | _egrep_o ' Type="[^"]*' | cut -d '"' -f 2)
 | 
			
		||||
  _hostaddress=$(echo "$_host" | _egrep_o ' Address="[^"]*' | cut -d '"' -f 2)
 | 
			
		||||
  _hostmxpref=$(echo "$_host" | _egrep_o ' MXPref="[^"]*' | cut -d '"' -f 2)
 | 
			
		||||
  _hostttl=$(echo "$_host" | _egrep_o ' TTL="[^"]*' | cut -d '"' -f 2)
 | 
			
		||||
 | 
			
		||||
  _debug hostid "$_hostid"
 | 
			
		||||
  _debug hostname "$_hostname"
 | 
			
		||||
  _debug hosttype "$_hosttype"
 | 
			
		||||
  _debug hostaddress "$_hostaddress"
 | 
			
		||||
  _debug hostmxpref "$_hostmxpref"
 | 
			
		||||
  _debug hostttl "$_hostttl"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_namecheap_check_config() {
 | 
			
		||||
 | 
			
		||||
  if [ -z "$NAMECHEAP_API_KEY" ]; then
 | 
			
		||||
    _err "No API key specified for Namecheap API."
 | 
			
		||||
    _err "Create your key and export it as NAMECHEAP_API_KEY"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$NAMECHEAP_USERNAME" ]; then
 | 
			
		||||
    _err "No username key specified for Namecheap API."
 | 
			
		||||
    _err "Create your key and export it as NAMECHEAP_USERNAME"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf NAMECHEAP_API_KEY "$NAMECHEAP_API_KEY"
 | 
			
		||||
  _saveaccountconf NAMECHEAP_USERNAME "$NAMECHEAP_USERNAME"
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_set_namecheap_TXT() {
 | 
			
		||||
  subdomain=$2
 | 
			
		||||
  txt=$3
 | 
			
		||||
 | 
			
		||||
  if ! _namecheap_set_tld_sld "$1"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  request="namecheap.domains.dns.getHosts&SLD=${_sld}&TLD=${_tld}"
 | 
			
		||||
 | 
			
		||||
  if ! _namecheap_post "$request"; then
 | 
			
		||||
    _err "$error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  hosts=$(echo "$response" | _egrep_o '<host[^>]*')
 | 
			
		||||
  _debug hosts "$hosts"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$hosts" ]; then
 | 
			
		||||
    _error "Hosts not found"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _namecheap_reset_hostList
 | 
			
		||||
 | 
			
		||||
  while read -r host; do
 | 
			
		||||
    if _contains "$host" "<host"; then
 | 
			
		||||
      _namecheap_parse_host "$host"
 | 
			
		||||
      _namecheap_add_host "$_hostname" "$_hosttype" "$_hostaddress" "$_hostmxpref" "$_hostttl"
 | 
			
		||||
    fi
 | 
			
		||||
  done <<EOT
 | 
			
		||||
echo "$hosts"
 | 
			
		||||
EOT
 | 
			
		||||
 | 
			
		||||
  _namecheap_add_host "$subdomain" "TXT" "$txt" 10 120
 | 
			
		||||
 | 
			
		||||
  _debug hostrequestfinal "$_hostrequest"
 | 
			
		||||
 | 
			
		||||
  request="namecheap.domains.dns.setHosts&SLD=${_sld}&TLD=${_tld}${_hostrequest}"
 | 
			
		||||
 | 
			
		||||
  if ! _namecheap_post "$request"; then
 | 
			
		||||
    _err "$error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_del_namecheap_TXT() {
 | 
			
		||||
  subdomain=$2
 | 
			
		||||
  txt=$3
 | 
			
		||||
 | 
			
		||||
  if ! _namecheap_set_tld_sld "$1"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  request="namecheap.domains.dns.getHosts&SLD=${_sld}&TLD=${_tld}"
 | 
			
		||||
 | 
			
		||||
  if ! _namecheap_post "$request"; then
 | 
			
		||||
    _err "$error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  hosts=$(echo "$response" | _egrep_o '<host[^>]*')
 | 
			
		||||
  _debug hosts "$hosts"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$hosts" ]; then
 | 
			
		||||
    _error "Hosts not found"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _namecheap_reset_hostList
 | 
			
		||||
 | 
			
		||||
  found=0
 | 
			
		||||
 | 
			
		||||
  while read -r host; do
 | 
			
		||||
    if _contains "$host" "<host"; then
 | 
			
		||||
      _namecheap_parse_host "$host"
 | 
			
		||||
      if [ "$_hosttype" = "TXT" ] && [ "$_hostname" = "$subdomain" ] && [ "$_hostaddress" = "$txt" ]; then
 | 
			
		||||
        _debug "TXT entry found"
 | 
			
		||||
        found=1
 | 
			
		||||
      else
 | 
			
		||||
        _namecheap_add_host "$_hostname" "$_hosttype" "$_hostaddress" "$_hostmxpref" "$_hostttl"
 | 
			
		||||
      fi
 | 
			
		||||
    fi
 | 
			
		||||
  done <<EOT
 | 
			
		||||
echo "$hosts"
 | 
			
		||||
EOT
 | 
			
		||||
 | 
			
		||||
  if [ $found -eq 0 ]; then
 | 
			
		||||
    _debug "TXT entry not found"
 | 
			
		||||
    return 0
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug hostrequestfinal "$_hostrequest"
 | 
			
		||||
 | 
			
		||||
  request="namecheap.domains.dns.setHosts&SLD=${_sld}&TLD=${_tld}${_hostrequest}"
 | 
			
		||||
 | 
			
		||||
  if ! _namecheap_post "$request"; then
 | 
			
		||||
    _err "$error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_namecheap_reset_hostList() {
 | 
			
		||||
  _hostindex=0
 | 
			
		||||
  _hostrequest=""
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: _namecheap_add_host HostName RecordType Address MxPref TTL
 | 
			
		||||
_namecheap_add_host() {
 | 
			
		||||
  _hostindex=$(_math "$_hostindex" + 1)
 | 
			
		||||
  _hostrequest=$(printf '%s&HostName%d=%s&RecordType%d=%s&Address%d=%s&MXPref%d=%d&TTL%d=%d' "$_hostrequest" "$_hostindex" "$1" "$_hostindex" "$2" "$_hostindex" "$3" "$_hostindex" "$4" "$_hostindex" "$5")
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_namecheap_set_tld_sld() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  _tld=""
 | 
			
		||||
  _sld=""
 | 
			
		||||
 | 
			
		||||
  i=2
 | 
			
		||||
 | 
			
		||||
  while true; do
 | 
			
		||||
 | 
			
		||||
    _tld=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug tld "$_tld"
 | 
			
		||||
 | 
			
		||||
    if [ -z "$_tld" ]; then
 | 
			
		||||
      _debug "invalid tld"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    j=$(_math "$i" - 1)
 | 
			
		||||
 | 
			
		||||
    _sld=$(printf "%s" "$domain" | cut -d . -f 1-"$j")
 | 
			
		||||
    _debug sld "$_sld"
 | 
			
		||||
 | 
			
		||||
    if [ -z "$_sld" ]; then
 | 
			
		||||
      _debug "invalid sld"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    request="namecheap.domains.dns.getHosts&SLD=$_sld&TLD=$_tld"
 | 
			
		||||
 | 
			
		||||
    if ! _namecheap_post "$request"; then
 | 
			
		||||
      _debug "sld($_sld)/tld($_tld) not found"
 | 
			
		||||
    else
 | 
			
		||||
      _debug "sld($_sld)/tld($_tld) found"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										166
									
								
								dnsapi/dns_namecom.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										166
									
								
								dnsapi/dns_namecom.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,166 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Author: RaidenII
 | 
			
		||||
#Created 06/28/2017
 | 
			
		||||
#Updated 03/01/2018, rewrote to support name.com API v4
 | 
			
		||||
#Utilize name.com API to finish dns-01 verifications.
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
Namecom_API="https://api.name.com/v4"
 | 
			
		||||
 | 
			
		||||
#Usage: dns_namecom_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_namecom_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  # First we need name.com credentials.
 | 
			
		||||
  if [ -z "$Namecom_Username" ]; then
 | 
			
		||||
    Namecom_Username=""
 | 
			
		||||
    _err "Username for name.com is missing."
 | 
			
		||||
    _err "Please specify that in your environment variable."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$Namecom_Token" ]; then
 | 
			
		||||
    Namecom_Token=""
 | 
			
		||||
    _err "API token for name.com is missing."
 | 
			
		||||
    _err "Please specify that in your environment variable."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Save them in configuration.
 | 
			
		||||
  _saveaccountconf Namecom_Username "$Namecom_Username"
 | 
			
		||||
  _saveaccountconf Namecom_Token "$Namecom_Token"
 | 
			
		||||
 | 
			
		||||
  # Login in using API
 | 
			
		||||
  if ! _namecom_login; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Find domain in domain list.
 | 
			
		||||
  if ! _namecom_get_root "$fulldomain"; then
 | 
			
		||||
    _err "Unable to find domain specified."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Add TXT record.
 | 
			
		||||
  _namecom_addtxt_json="{\"host\":\"$_sub_domain\",\"type\":\"TXT\",\"answer\":\"$txtvalue\",\"ttl\":\"300\"}"
 | 
			
		||||
  if _namecom_rest POST "domains/$_domain/records" "$_namecom_addtxt_json"; then
 | 
			
		||||
    _retvalue=$(printf "%s\n" "$response" | _egrep_o "\"$_sub_domain\"")
 | 
			
		||||
    if [ "$_retvalue" ]; then
 | 
			
		||||
      _info "Successfully added TXT record, ready for validation."
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Unable to add the DNS record."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: fulldomain txtvalue
 | 
			
		||||
#Remove the txt record after validation.
 | 
			
		||||
dns_namecom_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if ! _namecom_login; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Find domain in domain list.
 | 
			
		||||
  if ! _namecom_get_root "$fulldomain"; then
 | 
			
		||||
    _err "Unable to find domain specified."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Get the record id.
 | 
			
		||||
  if _namecom_rest GET "domains/$_domain/records"; then
 | 
			
		||||
    _record_id=$(printf "%s\n" "$response" | _egrep_o "\"id\":[0-9]+,\"domainName\":\"$_domain\",\"host\":\"$_sub_domain\",\"fqdn\":\"$fulldomain.\",\"type\":\"TXT\",\"answer\":\"$txtvalue\"" | cut -d \" -f 3 | _egrep_o [0-9]+)
 | 
			
		||||
    _debug record_id "$_record_id"
 | 
			
		||||
    if [ "$_record_id" ]; then
 | 
			
		||||
      _info "Successfully retrieved the record id for ACME challenge."
 | 
			
		||||
    else
 | 
			
		||||
      _err "Unable to retrieve the record id."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Remove the DNS record using record id.
 | 
			
		||||
  if _namecom_rest DELETE "domains/$_domain/records/$_record_id"; then
 | 
			
		||||
    _info "Successfully removed the TXT record."
 | 
			
		||||
    return 0
 | 
			
		||||
  else
 | 
			
		||||
    _err "Unable to delete record id."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
_namecom_rest() {
 | 
			
		||||
  method=$1
 | 
			
		||||
  param=$2
 | 
			
		||||
  data=$3
 | 
			
		||||
 | 
			
		||||
  export _H1="Authorization: Basic $_namecom_auth"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  if [ "$method" != "GET" ]; then
 | 
			
		||||
    response="$(_post "$data" "$Namecom_API/$param" "" "$method")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$Namecom_API/$param")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $param"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_namecom_login() {
 | 
			
		||||
  # Auth string
 | 
			
		||||
  # Name.com API v4 uses http basic auth to authenticate
 | 
			
		||||
  # need to convert the token for http auth
 | 
			
		||||
  _namecom_auth=$(printf "%s:%s" "$Namecom_Username" "$Namecom_Token" | _base64)
 | 
			
		||||
 | 
			
		||||
  if _namecom_rest GET "hello"; then
 | 
			
		||||
    retcode=$(printf "%s\n" "$response" | _egrep_o "\"username\"\:\"$Namecom_Username\"")
 | 
			
		||||
    if [ "$retcode" ]; then
 | 
			
		||||
      _info "Successfully logged in."
 | 
			
		||||
    else
 | 
			
		||||
      _err "Logging in failed."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_namecom_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  if ! _namecom_rest GET "domains"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Need to exclude the last field (tld)
 | 
			
		||||
  numfields=$(echo "$domain" | _egrep_o "\." | wc -l)
 | 
			
		||||
  while [ $i -le "$numfields" ]; do
 | 
			
		||||
    host=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug host "$host"
 | 
			
		||||
    if [ -z "$host" ]; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "$host"; then
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain="$host"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										137
									
								
								dnsapi/dns_namesilo.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										137
									
								
								dnsapi/dns_namesilo.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,137 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Author: meowthink
 | 
			
		||||
#Created 01/14/2017
 | 
			
		||||
#Utilize namesilo.com API to finish dns-01 verifications.
 | 
			
		||||
 | 
			
		||||
Namesilo_API="https://www.namesilo.com/api"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_myapi_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_namesilo_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if [ -z "$Namesilo_Key" ]; then
 | 
			
		||||
    Namesilo_Key=""
 | 
			
		||||
    _err "API token for namesilo.com is missing."
 | 
			
		||||
    _err "Please specify that in your environment variable."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf Namesilo_Key "$Namesilo_Key"
 | 
			
		||||
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "Unable to find domain specified."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
  if _namesilo_rest GET "dnsAddRecord?version=1&type=xml&key=$Namesilo_Key&domain=$_domain&rrtype=TXT&rrhost=$_sub_domain&rrvalue=$txtvalue"; then
 | 
			
		||||
    retcode=$(printf "%s\n" "$response" | _egrep_o "<code>300")
 | 
			
		||||
    if [ "$retcode" ]; then
 | 
			
		||||
      _info "Successfully added TXT record, ready for validation."
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Unable to add the DNS record."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: fulldomain txtvalue
 | 
			
		||||
#Remove the txt record after validation.
 | 
			
		||||
dns_namesilo_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "Unable to find domain specified."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Get the record id.
 | 
			
		||||
  if _namesilo_rest GET "dnsListRecords?version=1&type=xml&key=$Namesilo_Key&domain=$_domain"; then
 | 
			
		||||
    retcode=$(printf "%s\n" "$response" | _egrep_o "<code>300")
 | 
			
		||||
    if [ "$retcode" ]; then
 | 
			
		||||
      _record_id=$(printf "%s\n" "$response" | _egrep_o "<record_id>([^<]*)</record_id><type>TXT</type><host>$fulldomain</host>" | _egrep_o "<record_id>([^<]*)</record_id>" | sed -r "s/<record_id>([^<]*)<\/record_id>/\1/" | tail -n 1)
 | 
			
		||||
      _debug record_id "$_record_id"
 | 
			
		||||
      _info "Successfully retrieved the record id for ACME challenge."
 | 
			
		||||
    else
 | 
			
		||||
      _err "Unable to retrieve the record id."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Remove the DNS record using record id.
 | 
			
		||||
  if _namesilo_rest GET "dnsDeleteRecord?version=1&type=xml&key=$Namesilo_Key&domain=$_domain&rrid=$_record_id"; then
 | 
			
		||||
    retcode=$(printf "%s\n" "$response" | _egrep_o "<code>300")
 | 
			
		||||
    if [ "$retcode" ]; then
 | 
			
		||||
      _info "Successfully removed the TXT record."
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Unable to remove the DNS record."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
# _acme-challenge.www.domain.com
 | 
			
		||||
# returns
 | 
			
		||||
#  _sub_domain=_acme-challenge.www
 | 
			
		||||
#  _domain=domain.com
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  if ! _namesilo_rest GET "listDomains?version=1&type=xml&key=$Namesilo_Key"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # Need to exclude the last field (tld)
 | 
			
		||||
  numfields=$(echo "$domain" | _egrep_o "\." | wc -l)
 | 
			
		||||
  while [ $i -le "$numfields" ]; do
 | 
			
		||||
    host=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug host "$host"
 | 
			
		||||
    if [ -z "$host" ]; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "$host"; then
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain="$host"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_namesilo_rest() {
 | 
			
		||||
  method=$1
 | 
			
		||||
  param=$2
 | 
			
		||||
  data=$3
 | 
			
		||||
 | 
			
		||||
  if [ "$method" != "GET" ]; then
 | 
			
		||||
    response="$(_post "$data" "$Namesilo_API/$param" "" "$method")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$Namesilo_API/$param")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $param"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										181
									
								
								dnsapi/dns_neodigit.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										181
									
								
								dnsapi/dns_neodigit.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,181 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
# NEODIGIT_API_TOKEN="jasdfhklsjadhflnhsausdfas"
 | 
			
		||||
 | 
			
		||||
# This is Neodigit.net api wrapper for acme.sh
 | 
			
		||||
#
 | 
			
		||||
# Author: Adrian Almenar
 | 
			
		||||
# Report Bugs here: https://github.com/tecnocratica/acme.sh
 | 
			
		||||
#
 | 
			
		||||
NEODIGIT_API_URL="https://api.neodigit.net/v1"
 | 
			
		||||
#
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
# Usage: dns_myapi_add _acme-challenge.www.domain.com "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_neodigit_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  NEODIGIT_API_TOKEN="${NEODIGIT_API_TOKEN:-$(_readaccountconf_mutable NEODIGIT_API_TOKEN)}"
 | 
			
		||||
  if [ -z "$NEODIGIT_API_TOKEN" ]; then
 | 
			
		||||
    NEODIGIT_API_TOKEN=""
 | 
			
		||||
    _err "You haven't specified a Token api key."
 | 
			
		||||
    _err "Please create the key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable NEODIGIT_API_TOKEN "$NEODIGIT_API_TOKEN"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
  _debug domain "$_domain"
 | 
			
		||||
  _debug sub_domain "$_sub_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _neo_rest GET "dns/zones/${_domain_id}/records?type=TXT&name=$fulldomain"
 | 
			
		||||
 | 
			
		||||
  _debug _code "$_code"
 | 
			
		||||
 | 
			
		||||
  if [ "$_code" != "200" ]; then
 | 
			
		||||
    _err "error retrieving data!"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
  _debug domain "$_domain"
 | 
			
		||||
  _debug sub_domain "$_sub_domain"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  if _neo_rest POST "dns/zones/$_domain_id/records" "{\"record\":{\"type\":\"TXT\",\"name\":\"$_sub_domain\",\"content\":\"$txtvalue\",\"ttl\":60}}"; then
 | 
			
		||||
    if printf -- "%s" "$response" | grep "$_sub_domain" >/dev/null; then
 | 
			
		||||
      _info "Added, OK"
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Add txt record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  _err "Add txt record error."
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_neodigit_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  NEODIGIT_API_TOKEN="${NEODIGIT_API_TOKEN:-$(_readaccountconf_mutable NEODIGIT_API_TOKEN)}"
 | 
			
		||||
  if [ -z "$NEODIGIT_API_TOKEN" ]; then
 | 
			
		||||
    NEODIGIT_API_TOKEN=""
 | 
			
		||||
    _err "You haven't specified a Token api key."
 | 
			
		||||
    _err "Please create the key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable NEODIGIT_API_TOKEN "$NEODIGIT_API_TOKEN"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _neo_rest GET "dns/zones/${_domain_id}/records?type=TXT&name=$fulldomain&content=$txtvalue"
 | 
			
		||||
 | 
			
		||||
  if [ "$_code" != "200" ]; then
 | 
			
		||||
    _err "error retrieving data!"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  record_id=$(echo "$response" | _egrep_o "\"id\":\s*[0-9]+" | _head_n 1 | cut -d: -f2 | cut -d, -f1)
 | 
			
		||||
  _debug "record_id" "$record_id"
 | 
			
		||||
  if [ -z "$record_id" ]; then
 | 
			
		||||
    _err "Can not get record id to remove."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  if ! _neo_rest DELETE "dns/zones/$_domain_id/records/$record_id"; then
 | 
			
		||||
    _err "Delete record error."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=dasfdsafsadg5ythd
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _neo_rest GET "dns/zones?name=$h"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    _debug p "$p"
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"name\":\"$h\"" >/dev/null; then
 | 
			
		||||
      _domain_id=$(echo "$response" | _egrep_o "\"id\":\s*[0-9]+" | _head_n 1 | cut -d: -f2 | cut -d, -f1)
 | 
			
		||||
      if [ "$_domain_id" ]; then
 | 
			
		||||
        _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
        _domain=$h
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_neo_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="X-TCPanel-Token: $NEODIGIT_API_TOKEN"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  if [ "$m" != "GET" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$NEODIGIT_API_URL/$ep" "" "$m")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$NEODIGIT_API_URL/$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _code="$(grep "^HTTP" "$HTTP_HEADER" | _tail_n 1 | cut -d " " -f 2 | tr -d "\\r\\n")"
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										133
									
								
								dnsapi/dns_netcup.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										133
									
								
								dnsapi/dns_netcup.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,133 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
#developed by linux-insideDE
 | 
			
		||||
 | 
			
		||||
NC_Apikey="${NC_Apikey:-$(_readaccountconf_mutable NC_Apikey)}"
 | 
			
		||||
NC_Apipw="${NC_Apipw:-$(_readaccountconf_mutable NC_Apipw)}"
 | 
			
		||||
NC_CID="${NC_CID:-$(_readaccountconf_mutable NC_CID)}"
 | 
			
		||||
end="https://ccp.netcup.net/run/webservice/servers/endpoint.php?JSON"
 | 
			
		||||
client=""
 | 
			
		||||
 | 
			
		||||
dns_netcup_add() {
 | 
			
		||||
  login
 | 
			
		||||
  if [ "$NC_Apikey" = "" ] || [ "$NC_Apipw" = "" ] || [ "$NC_CID" = "" ]; then
 | 
			
		||||
    _err "No Credentials given"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _saveaccountconf_mutable NC_Apikey "$NC_Apikey"
 | 
			
		||||
  _saveaccountconf_mutable NC_Apipw "$NC_Apipw"
 | 
			
		||||
  _saveaccountconf_mutable NC_CID "$NC_CID"
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  domain=""
 | 
			
		||||
  exit=$(echo "$fulldomain" | tr -dc '.' | wc -c)
 | 
			
		||||
  exit=$(_math "$exit" + 1)
 | 
			
		||||
  i=$exit
 | 
			
		||||
 | 
			
		||||
  while
 | 
			
		||||
    [ "$exit" -gt 0 ]
 | 
			
		||||
  do
 | 
			
		||||
    tmp=$(echo "$fulldomain" | cut -d'.' -f"$exit")
 | 
			
		||||
    if [ "$(_math "$i" - "$exit")" -eq 0 ]; then
 | 
			
		||||
      domain="$tmp"
 | 
			
		||||
    else
 | 
			
		||||
      domain="$tmp.$domain"
 | 
			
		||||
    fi
 | 
			
		||||
    if [ "$(_math "$i" - "$exit")" -ge 1 ]; then
 | 
			
		||||
      msg=$(_post "{\"action\": \"updateDnsRecords\", \"param\": {\"apikey\": \"$NC_Apikey\", \"apisessionid\": \"$sid\", \"customernumber\": \"$NC_CID\",\"clientrequestid\": \"$client\" , \"domainname\": \"$domain\", \"dnsrecordset\": { \"dnsrecords\": [ {\"id\": \"\", \"hostname\": \"$fulldomain.\", \"type\": \"TXT\", \"priority\": \"\", \"destination\": \"$txtvalue\", \"deleterecord\": \"false\", \"state\": \"yes\"} ]}}}" "$end" "" "POST")
 | 
			
		||||
      _debug "$msg"
 | 
			
		||||
      if [ "$(_getfield "$msg" "5" | sed 's/"statuscode"://g')" != 5028 ]; then
 | 
			
		||||
        if [ "$(_getfield "$msg" "4" | sed s/\"status\":\"//g | sed s/\"//g)" != "success" ]; then
 | 
			
		||||
          _err "$msg"
 | 
			
		||||
          return 1
 | 
			
		||||
        else
 | 
			
		||||
          break
 | 
			
		||||
        fi
 | 
			
		||||
      fi
 | 
			
		||||
    fi
 | 
			
		||||
    exit=$(_math "$exit" - 1)
 | 
			
		||||
  done
 | 
			
		||||
  logout
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
dns_netcup_rm() {
 | 
			
		||||
  login
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  domain=""
 | 
			
		||||
  exit=$(echo "$fulldomain" | tr -dc '.' | wc -c)
 | 
			
		||||
  exit=$(_math "$exit" + 1)
 | 
			
		||||
  i=$exit
 | 
			
		||||
  rec=""
 | 
			
		||||
 | 
			
		||||
  while
 | 
			
		||||
    [ "$exit" -gt 0 ]
 | 
			
		||||
  do
 | 
			
		||||
    tmp=$(echo "$fulldomain" | cut -d'.' -f"$exit")
 | 
			
		||||
    if [ "$(_math "$i" - "$exit")" -eq 0 ]; then
 | 
			
		||||
      domain="$tmp"
 | 
			
		||||
    else
 | 
			
		||||
      domain="$tmp.$domain"
 | 
			
		||||
    fi
 | 
			
		||||
    if [ "$(_math "$i" - "$exit")" -ge 1 ]; then
 | 
			
		||||
      msg=$(_post "{\"action\": \"infoDnsRecords\", \"param\": {\"apikey\": \"$NC_Apikey\", \"apisessionid\": \"$sid\", \"customernumber\": \"$NC_CID\", \"domainname\": \"$domain\"}}" "$end" "" "POST")
 | 
			
		||||
      rec=$(echo "$msg" | sed 's/\[//g' | sed 's/\]//g' | sed 's/{\"serverrequestid\".*\"dnsrecords\"://g' | sed 's/},{/};{/g' | sed 's/{//g' | sed 's/}//g')
 | 
			
		||||
      _debug "$msg"
 | 
			
		||||
      if [ "$(_getfield "$msg" "5" | sed 's/"statuscode"://g')" != 5028 ]; then
 | 
			
		||||
        if [ "$(_getfield "$msg" "4" | sed s/\"status\":\"//g | sed s/\"//g)" != "success" ]; then
 | 
			
		||||
          _err "$msg"
 | 
			
		||||
          return 1
 | 
			
		||||
        else
 | 
			
		||||
          break
 | 
			
		||||
        fi
 | 
			
		||||
      fi
 | 
			
		||||
    fi
 | 
			
		||||
    exit=$(_math "$exit" - 1)
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  ida=0000
 | 
			
		||||
  idv=0001
 | 
			
		||||
  ids=0000000000
 | 
			
		||||
  i=1
 | 
			
		||||
  while
 | 
			
		||||
    [ "$i" -ne 0 ]
 | 
			
		||||
  do
 | 
			
		||||
    specrec=$(_getfield "$rec" "$i" ";")
 | 
			
		||||
    idv="$ida"
 | 
			
		||||
    ida=$(_getfield "$specrec" "1" "," | sed 's/\"id\":\"//g' | sed 's/\"//g')
 | 
			
		||||
    txtv=$(_getfield "$specrec" "5" "," | sed 's/\"destination\":\"//g' | sed 's/\"//g')
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
    if [ "$txtvalue" = "$txtv" ]; then
 | 
			
		||||
      i=0
 | 
			
		||||
      ids="$ida"
 | 
			
		||||
    fi
 | 
			
		||||
    if [ "$ida" = "$idv" ]; then
 | 
			
		||||
      i=0
 | 
			
		||||
    fi
 | 
			
		||||
  done
 | 
			
		||||
  msg=$(_post "{\"action\": \"updateDnsRecords\", \"param\": {\"apikey\": \"$NC_Apikey\", \"apisessionid\": \"$sid\", \"customernumber\": \"$NC_CID\",\"clientrequestid\": \"$client\" , \"domainname\": \"$domain\", \"dnsrecordset\": { \"dnsrecords\": [ {\"id\": \"$ids\", \"hostname\": \"$fulldomain.\", \"type\": \"TXT\", \"priority\": \"\", \"destination\": \"$txtvalue\", \"deleterecord\": \"TRUE\", \"state\": \"yes\"} ]}}}" "$end" "" "POST")
 | 
			
		||||
  _debug "$msg"
 | 
			
		||||
  if [ "$(_getfield "$msg" "4" | sed s/\"status\":\"//g | sed s/\"//g)" != "success" ]; then
 | 
			
		||||
    _err "$msg"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  logout
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
login() {
 | 
			
		||||
  tmp=$(_post "{\"action\": \"login\", \"param\": {\"apikey\": \"$NC_Apikey\", \"apipassword\": \"$NC_Apipw\", \"customernumber\": \"$NC_CID\"}}" "$end" "" "POST")
 | 
			
		||||
  sid=$(_getfield "$tmp" "8" | sed s/\"responsedata\":\{\"apisessionid\":\"//g | sed 's/\"\}\}//g')
 | 
			
		||||
  _debug "$tmp"
 | 
			
		||||
  if [ "$(_getfield "$msg" "4" | sed s/\"status\":\"//g | sed s/\"//g)" != "success" ]; then
 | 
			
		||||
    _err "$msg"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
logout() {
 | 
			
		||||
  tmp=$(_post "{\"action\": \"logout\", \"param\": {\"apikey\": \"$NC_Apikey\", \"apisessionid\": \"$sid\", \"customernumber\": \"$NC_CID\"}}" "$end" "" "POST")
 | 
			
		||||
  _debug "$tmp"
 | 
			
		||||
  if [ "$(_getfield "$msg" "4" | sed s/\"status\":\"//g | sed s/\"//g)" != "success" ]; then
 | 
			
		||||
    _err "$msg"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										158
									
								
								dnsapi/dns_nsone.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										158
									
								
								dnsapi/dns_nsone.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,158 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
# bug reports to dev@1e.ca
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
#NS1_Key="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
#
 | 
			
		||||
 | 
			
		||||
NS1_Api="https://api.nsone.net/v1"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_nsone_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if [ -z "$NS1_Key" ]; then
 | 
			
		||||
    NS1_Key=""
 | 
			
		||||
    _err "You didn't specify nsone dns api key yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf NS1_Key "$NS1_Key"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _nsone_rest GET "zones/${_domain}"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "\"records\":"; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  count=$(printf "%s\n" "$response" | _egrep_o "\"domain\":\"$fulldomain\",[^{]*\"type\":\"TXT\"" | wc -l | tr -d " ")
 | 
			
		||||
  _debug count "$count"
 | 
			
		||||
  if [ "$count" = "0" ]; then
 | 
			
		||||
    _info "Adding record"
 | 
			
		||||
 | 
			
		||||
    if _nsone_rest PUT "zones/$_domain/$fulldomain/TXT" "{\"answers\":[{\"answer\":[\"$txtvalue\"]}],\"type\":\"TXT\",\"domain\":\"$fulldomain\",\"zone\":\"$_domain\"}"; then
 | 
			
		||||
      if _contains "$response" "$fulldomain"; then
 | 
			
		||||
        _info "Added"
 | 
			
		||||
        #todo: check if the record takes effect
 | 
			
		||||
        return 0
 | 
			
		||||
      else
 | 
			
		||||
        _err "Add txt record error."
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
    fi
 | 
			
		||||
    _err "Add txt record error."
 | 
			
		||||
  else
 | 
			
		||||
    _info "Updating record"
 | 
			
		||||
    prev_txt=$(printf "%s\n" "$response" | _egrep_o "\"domain\":\"$fulldomain\",\"short_answers\":\[\"[^,]*\]" | _head_n 1 | cut -d: -f3 | cut -d, -f1)
 | 
			
		||||
    _debug "prev_txt" "$prev_txt"
 | 
			
		||||
 | 
			
		||||
    _nsone_rest POST "zones/$_domain/$fulldomain/TXT" "{\"answers\": [{\"answer\": [\"$txtvalue\"]},{\"answer\": $prev_txt}],\"type\": \"TXT\",\"domain\":\"$fulldomain\",\"zone\": \"$_domain\"}"
 | 
			
		||||
    if [ "$?" = "0" ] && _contains "$response" "$fulldomain"; then
 | 
			
		||||
      _info "Updated!"
 | 
			
		||||
      #todo: check if the record takes effect
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    _err "Update error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain
 | 
			
		||||
dns_nsone_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _nsone_rest GET "zones/${_domain}/$fulldomain/TXT"
 | 
			
		||||
 | 
			
		||||
  count=$(printf "%s\n" "$response" | _egrep_o "\"domain\":\"$fulldomain\",.*\"type\":\"TXT\"" | wc -l | tr -d " ")
 | 
			
		||||
  _debug count "$count"
 | 
			
		||||
  if [ "$count" = "0" ]; then
 | 
			
		||||
    _info "Don't need to remove."
 | 
			
		||||
  else
 | 
			
		||||
    if ! _nsone_rest DELETE "zones/${_domain}/$fulldomain/TXT"; then
 | 
			
		||||
      _err "Delete record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    _contains "$response" ""
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  if ! _nsone_rest GET "zones"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"zone\":\"$h\""; then
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain="$h"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_nsone_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="Accept: application/json"
 | 
			
		||||
  export _H2="X-NSONE-Key: $NS1_Key"
 | 
			
		||||
  if [ "$m" != "GET" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$NS1_Api/$ep" "" "$m")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$NS1_Api/$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										84
									
								
								dnsapi/dns_nsupdate.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										84
									
								
								dnsapi/dns_nsupdate.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,84 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_nsupdate_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_nsupdate_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
  _checkKeyFile || return 1
 | 
			
		||||
  [ -n "${NSUPDATE_SERVER}" ] || NSUPDATE_SERVER="localhost"
 | 
			
		||||
  [ -n "${NSUPDATE_SERVER_PORT}" ] || NSUPDATE_SERVER_PORT=53
 | 
			
		||||
  # save the dns server and key to the account conf file.
 | 
			
		||||
  _saveaccountconf NSUPDATE_SERVER "${NSUPDATE_SERVER}"
 | 
			
		||||
  _saveaccountconf NSUPDATE_SERVER_PORT "${NSUPDATE_SERVER_PORT}"
 | 
			
		||||
  _saveaccountconf NSUPDATE_KEY "${NSUPDATE_KEY}"
 | 
			
		||||
  _saveaccountconf NSUPDATE_ZONE "${NSUPDATE_ZONE}"
 | 
			
		||||
  _info "adding ${fulldomain}. 60 in txt \"${txtvalue}\""
 | 
			
		||||
  [ -n "$DEBUG" ] && [ "$DEBUG" -ge "$DEBUG_LEVEL_1" ] && nsdebug="-d"
 | 
			
		||||
  [ -n "$DEBUG" ] && [ "$DEBUG" -ge "$DEBUG_LEVEL_2" ] && nsdebug="-D"
 | 
			
		||||
  if [ -z "${NSUPDATE_ZONE}" ]; then
 | 
			
		||||
    nsupdate -k "${NSUPDATE_KEY}" $nsdebug <<EOF
 | 
			
		||||
server ${NSUPDATE_SERVER}  ${NSUPDATE_SERVER_PORT} 
 | 
			
		||||
update add ${fulldomain}. 60 in txt "${txtvalue}"
 | 
			
		||||
send
 | 
			
		||||
EOF
 | 
			
		||||
  else
 | 
			
		||||
    nsupdate -k "${NSUPDATE_KEY}" $nsdebug <<EOF
 | 
			
		||||
server ${NSUPDATE_SERVER}  ${NSUPDATE_SERVER_PORT}
 | 
			
		||||
zone ${NSUPDATE_ZONE}.
 | 
			
		||||
update add ${fulldomain}. 60 in txt "${txtvalue}"
 | 
			
		||||
send
 | 
			
		||||
EOF
 | 
			
		||||
  fi
 | 
			
		||||
  if [ $? -ne 0 ]; then
 | 
			
		||||
    _err "error updating domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: dns_nsupdate_rm   _acme-challenge.www.domain.com
 | 
			
		||||
dns_nsupdate_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  _checkKeyFile || return 1
 | 
			
		||||
  [ -n "${NSUPDATE_SERVER}" ] || NSUPDATE_SERVER="localhost"
 | 
			
		||||
  [ -n "${NSUPDATE_SERVER_PORT}" ] || NSUPDATE_SERVER_PORT=53
 | 
			
		||||
  _info "removing ${fulldomain}. txt"
 | 
			
		||||
  [ -n "$DEBUG" ] && [ "$DEBUG" -ge "$DEBUG_LEVEL_1" ] && nsdebug="-d"
 | 
			
		||||
  [ -n "$DEBUG" ] && [ "$DEBUG" -ge "$DEBUG_LEVEL_2" ] && nsdebug="-D"
 | 
			
		||||
  if [ -z "${NSUPDATE_ZONE}" ]; then
 | 
			
		||||
    nsupdate -k "${NSUPDATE_KEY}" $nsdebug <<EOF
 | 
			
		||||
server ${NSUPDATE_SERVER}  ${NSUPDATE_SERVER_PORT} 
 | 
			
		||||
update delete ${fulldomain}. txt
 | 
			
		||||
send
 | 
			
		||||
EOF
 | 
			
		||||
  else
 | 
			
		||||
    nsupdate -k "${NSUPDATE_KEY}" $nsdebug <<EOF
 | 
			
		||||
server ${NSUPDATE_SERVER}  ${NSUPDATE_SERVER_PORT}
 | 
			
		||||
zone ${NSUPDATE_ZONE}.
 | 
			
		||||
update delete ${fulldomain}. txt
 | 
			
		||||
send
 | 
			
		||||
EOF
 | 
			
		||||
  fi
 | 
			
		||||
  if [ $? -ne 0 ]; then
 | 
			
		||||
    _err "error updating domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_checkKeyFile() {
 | 
			
		||||
  if [ -z "${NSUPDATE_KEY}" ]; then
 | 
			
		||||
    _err "you must specify a path to the nsupdate key file"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  if [ ! -r "${NSUPDATE_KEY}" ]; then
 | 
			
		||||
    _err "key ${NSUPDATE_KEY} is unreadable"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										318
									
								
								dnsapi/dns_ovh.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										318
									
								
								dnsapi/dns_ovh.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,318 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#Application Key
 | 
			
		||||
#OVH_AK="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
#
 | 
			
		||||
#Application Secret
 | 
			
		||||
#OVH_AS="sdfsafsdfsdfdsfsdfsa"
 | 
			
		||||
#
 | 
			
		||||
#Consumer Key
 | 
			
		||||
#OVH_CK="sdfsdfsdfsdfsdfdsf"
 | 
			
		||||
 | 
			
		||||
#OVH_END_POINT=ovh-eu
 | 
			
		||||
 | 
			
		||||
#'ovh-eu'
 | 
			
		||||
OVH_EU='https://eu.api.ovh.com/1.0'
 | 
			
		||||
 | 
			
		||||
#'ovh-ca':
 | 
			
		||||
OVH_CA='https://ca.api.ovh.com/1.0'
 | 
			
		||||
 | 
			
		||||
#'kimsufi-eu'
 | 
			
		||||
KSF_EU='https://eu.api.kimsufi.com/1.0'
 | 
			
		||||
 | 
			
		||||
#'kimsufi-ca'
 | 
			
		||||
KSF_CA='https://ca.api.kimsufi.com/1.0'
 | 
			
		||||
 | 
			
		||||
#'soyoustart-eu'
 | 
			
		||||
SYS_EU='https://eu.api.soyoustart.com/1.0'
 | 
			
		||||
 | 
			
		||||
#'soyoustart-ca'
 | 
			
		||||
SYS_CA='https://ca.api.soyoustart.com/1.0'
 | 
			
		||||
 | 
			
		||||
#'runabove-ca'
 | 
			
		||||
RAV_CA='https://api.runabove.com/1.0'
 | 
			
		||||
 | 
			
		||||
wiki="https://github.com/Neilpang/acme.sh/wiki/How-to-use-OVH-domain-api"
 | 
			
		||||
 | 
			
		||||
ovh_success="https://github.com/Neilpang/acme.sh/wiki/OVH-Success"
 | 
			
		||||
 | 
			
		||||
_ovh_get_api() {
 | 
			
		||||
  _ogaep="$1"
 | 
			
		||||
 | 
			
		||||
  case "${_ogaep}" in
 | 
			
		||||
 | 
			
		||||
    ovh-eu | ovheu)
 | 
			
		||||
      printf "%s" $OVH_EU
 | 
			
		||||
      return
 | 
			
		||||
      ;;
 | 
			
		||||
    ovh-ca | ovhca)
 | 
			
		||||
      printf "%s" $OVH_CA
 | 
			
		||||
      return
 | 
			
		||||
      ;;
 | 
			
		||||
    kimsufi-eu | kimsufieu)
 | 
			
		||||
      printf "%s" $KSF_EU
 | 
			
		||||
      return
 | 
			
		||||
      ;;
 | 
			
		||||
    kimsufi-ca | kimsufica)
 | 
			
		||||
      printf "%s" $KSF_CA
 | 
			
		||||
      return
 | 
			
		||||
      ;;
 | 
			
		||||
    soyoustart-eu | soyoustarteu)
 | 
			
		||||
      printf "%s" $SYS_EU
 | 
			
		||||
      return
 | 
			
		||||
      ;;
 | 
			
		||||
    soyoustart-ca | soyoustartca)
 | 
			
		||||
      printf "%s" $SYS_CA
 | 
			
		||||
      return
 | 
			
		||||
      ;;
 | 
			
		||||
    runabove-ca | runaboveca)
 | 
			
		||||
      printf "%s" $RAV_CA
 | 
			
		||||
      return
 | 
			
		||||
      ;;
 | 
			
		||||
 | 
			
		||||
    *)
 | 
			
		||||
 | 
			
		||||
      _err "Unknown parameter : $1"
 | 
			
		||||
      return 1
 | 
			
		||||
      ;;
 | 
			
		||||
  esac
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_initAuth() {
 | 
			
		||||
  OVH_AK="${OVH_AK:-$(_readaccountconf_mutable OVH_AK)}"
 | 
			
		||||
  OVH_AS="${OVH_AS:-$(_readaccountconf_mutable OVH_AS)}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$OVH_AK" ] || [ -z "$OVH_AS" ]; then
 | 
			
		||||
    OVH_AK=""
 | 
			
		||||
    OVH_AS=""
 | 
			
		||||
    _err "You don't specify OVH application key and application secret yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$OVH_AK" != "$(_readaccountconf OVH_AK)" ]; then
 | 
			
		||||
    _info "It seems that your ovh key is changed, let's clear consumer key first."
 | 
			
		||||
    _clearaccountconf OVH_CK
 | 
			
		||||
  fi
 | 
			
		||||
  _saveaccountconf_mutable OVH_AK "$OVH_AK"
 | 
			
		||||
  _saveaccountconf_mutable OVH_AS "$OVH_AS"
 | 
			
		||||
 | 
			
		||||
  OVH_END_POINT="${OVH_END_POINT:-$(_readaccountconf_mutable OVH_END_POINT)}"
 | 
			
		||||
  if [ -z "$OVH_END_POINT" ]; then
 | 
			
		||||
    OVH_END_POINT="ovh-eu"
 | 
			
		||||
  fi
 | 
			
		||||
  _info "Using OVH endpoint: $OVH_END_POINT"
 | 
			
		||||
  if [ "$OVH_END_POINT" != "ovh-eu" ]; then
 | 
			
		||||
    _saveaccountconf_mutable OVH_END_POINT "$OVH_END_POINT"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  OVH_API="$(_ovh_get_api $OVH_END_POINT)"
 | 
			
		||||
  _debug OVH_API "$OVH_API"
 | 
			
		||||
 | 
			
		||||
  OVH_CK="${OVH_CK:-$(_readaccountconf_mutable OVH_CK)}"
 | 
			
		||||
  if [ -z "$OVH_CK" ]; then
 | 
			
		||||
    _info "OVH consumer key is empty, Let's get one:"
 | 
			
		||||
    if ! _ovh_authentication; then
 | 
			
		||||
      _err "Can not get consumer key."
 | 
			
		||||
    fi
 | 
			
		||||
    #return and wait for retry.
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Checking authentication"
 | 
			
		||||
 | 
			
		||||
  if ! _ovh_rest GET "domain" || _contains "$response" "INVALID_CREDENTIAL"; then
 | 
			
		||||
    _err "The consumer key is invalid: $OVH_CK"
 | 
			
		||||
    _err "Please retry to create a new one."
 | 
			
		||||
    _clearaccountconf OVH_CK
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _info "Consumer key is ok."
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_ovh_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if ! _initAuth; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  if _ovh_rest POST "domain/zone/$_domain/record" "{\"fieldType\":\"TXT\",\"subDomain\":\"$_sub_domain\",\"target\":\"$txtvalue\",\"ttl\":60}"; then
 | 
			
		||||
    if _contains "$response" "$txtvalue"; then
 | 
			
		||||
      _ovh_rest POST "domain/zone/$_domain/refresh"
 | 
			
		||||
      _debug "Refresh:$response"
 | 
			
		||||
      _info "Added, sleep 10 seconds."
 | 
			
		||||
      _sleep 10
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  _err "Add txt record error."
 | 
			
		||||
  return 1
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain
 | 
			
		||||
dns_ovh_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if ! _initAuth; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  if ! _ovh_rest GET "domain/zone/$_domain/record?fieldType=TXT&subDomain=$_sub_domain"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  for rid in $(echo "$response" | tr '][,' '   '); do
 | 
			
		||||
    _debug rid "$rid"
 | 
			
		||||
    if ! _ovh_rest GET "domain/zone/$_domain/record/$rid"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    if _contains "$response" "\"target\":\"$txtvalue\""; then
 | 
			
		||||
      _debug "Found txt id:$rid"
 | 
			
		||||
      if ! _ovh_rest DELETE "domain/zone/$_domain/record/$rid"; then
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_ovh_authentication() {
 | 
			
		||||
 | 
			
		||||
  _H1="X-Ovh-Application: $OVH_AK"
 | 
			
		||||
  _H2="Content-type: application/json"
 | 
			
		||||
  _H3=""
 | 
			
		||||
  _H4=""
 | 
			
		||||
 | 
			
		||||
  _ovhdata='{"accessRules": [{"method": "GET","path": "/auth/time"},{"method": "GET","path": "/domain"},{"method": "GET","path": "/domain/zone/*"},{"method": "GET","path": "/domain/zone/*/record"},{"method": "POST","path": "/domain/zone/*/record"},{"method": "POST","path": "/domain/zone/*/refresh"},{"method": "PUT","path": "/domain/zone/*/record/*"},{"method": "DELETE","path": "/domain/zone/*/record/*"}],"redirection":"'$ovh_success'"}'
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$_ovhdata" "$OVH_API/auth/credential")"
 | 
			
		||||
  _debug3 response "$response"
 | 
			
		||||
  validationUrl="$(echo "$response" | _egrep_o "validationUrl\":\"[^\"]*\"" | _egrep_o "http.*\"" | tr -d '"')"
 | 
			
		||||
  if [ -z "$validationUrl" ]; then
 | 
			
		||||
    _err "Unable to get validationUrl"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug validationUrl "$validationUrl"
 | 
			
		||||
 | 
			
		||||
  consumerKey="$(echo "$response" | _egrep_o "consumerKey\":\"[^\"]*\"" | cut -d : -f 2 | tr -d '"')"
 | 
			
		||||
  if [ -z "$consumerKey" ]; then
 | 
			
		||||
    _err "Unable to get consumerKey"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _secure_debug consumerKey "$consumerKey"
 | 
			
		||||
 | 
			
		||||
  OVH_CK="$consumerKey"
 | 
			
		||||
  _saveaccountconf OVH_CK "$OVH_CK"
 | 
			
		||||
 | 
			
		||||
  _info "Please open this link to do authentication: $(__green "$validationUrl")"
 | 
			
		||||
 | 
			
		||||
  _info "Here is a guide for you: $(__green "$wiki")"
 | 
			
		||||
  _info "Please retry after the authentication is done."
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _ovh_rest GET "domain/zone/$h"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _contains "$response" "This service does not exist" >/dev/null && ! _contains "$response" "NOT_GRANTED_CALL" >/dev/null; then
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain="$h"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_ovh_timestamp() {
 | 
			
		||||
  _H1=""
 | 
			
		||||
  _H2=""
 | 
			
		||||
  _H3=""
 | 
			
		||||
  _H4=""
 | 
			
		||||
  _H5=""
 | 
			
		||||
  _get "$OVH_API/auth/time" "" 30
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_ovh_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
 | 
			
		||||
  _ovh_url="$OVH_API/$ep"
 | 
			
		||||
  _debug2 _ovh_url "$_ovh_url"
 | 
			
		||||
  _ovh_t="$(_ovh_timestamp)"
 | 
			
		||||
  _debug2 _ovh_t "$_ovh_t"
 | 
			
		||||
  _ovh_p="$OVH_AS+$OVH_CK+$m+$_ovh_url+$data+$_ovh_t"
 | 
			
		||||
  _secure_debug _ovh_p "$_ovh_p"
 | 
			
		||||
  _ovh_hex="$(printf "%s" "$_ovh_p" | _digest sha1 hex)"
 | 
			
		||||
  _debug2 _ovh_hex "$_ovh_hex"
 | 
			
		||||
 | 
			
		||||
  export _H1="X-Ovh-Application: $OVH_AK"
 | 
			
		||||
  export _H2="X-Ovh-Signature: \$1\$$_ovh_hex"
 | 
			
		||||
  _debug2 _H2 "$_H2"
 | 
			
		||||
  export _H3="X-Ovh-Timestamp: $_ovh_t"
 | 
			
		||||
  export _H4="X-Ovh-Consumer: $OVH_CK"
 | 
			
		||||
  export _H5="Content-Type: application/json;charset=utf-8"
 | 
			
		||||
  if [ "$data" ] || [ "$m" = "POST" ] || [ "$m" = "PUT" ] || [ "$m" = "DELETE" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$_ovh_url" "" "$m")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$_ovh_url")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ] || _contains "$response" "INVALID_CREDENTIAL"; then
 | 
			
		||||
    _err "error $response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										232
									
								
								dnsapi/dns_pdns.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										232
									
								
								dnsapi/dns_pdns.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,232 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#PowerDNS Embedded API
 | 
			
		||||
#https://doc.powerdns.com/md/httpapi/api_spec/
 | 
			
		||||
#
 | 
			
		||||
#PDNS_Url="http://ns.example.com:8081"
 | 
			
		||||
#PDNS_ServerId="localhost"
 | 
			
		||||
#PDNS_Token="0123456789ABCDEF"
 | 
			
		||||
#PDNS_Ttl=60
 | 
			
		||||
 | 
			
		||||
DEFAULT_PDNS_TTL=60
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
#Usage: add _acme-challenge.www.domain.com "123456789ABCDEF0000000000000000000000000000000000000"
 | 
			
		||||
#fulldomain
 | 
			
		||||
#txtvalue
 | 
			
		||||
dns_pdns_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if [ -z "$PDNS_Url" ]; then
 | 
			
		||||
    PDNS_Url=""
 | 
			
		||||
    _err "You don't specify PowerDNS address."
 | 
			
		||||
    _err "Please set PDNS_Url and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$PDNS_ServerId" ]; then
 | 
			
		||||
    PDNS_ServerId=""
 | 
			
		||||
    _err "You don't specify PowerDNS server id."
 | 
			
		||||
    _err "Please set you PDNS_ServerId and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$PDNS_Token" ]; then
 | 
			
		||||
    PDNS_Token=""
 | 
			
		||||
    _err "You don't specify PowerDNS token."
 | 
			
		||||
    _err "Please create you PDNS_Token and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ -z "$PDNS_Ttl" ]; then
 | 
			
		||||
    PDNS_Ttl="$DEFAULT_PDNS_TTL"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api addr and key to the account conf file.
 | 
			
		||||
  _saveaccountconf PDNS_Url "$PDNS_Url"
 | 
			
		||||
  _saveaccountconf PDNS_ServerId "$PDNS_ServerId"
 | 
			
		||||
  _saveaccountconf PDNS_Token "$PDNS_Token"
 | 
			
		||||
 | 
			
		||||
  if [ "$PDNS_Ttl" != "$DEFAULT_PDNS_TTL" ]; then
 | 
			
		||||
    _saveaccountconf PDNS_Ttl "$PDNS_Ttl"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "Detect root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  if ! set_record "$_domain" "$fulldomain" "$txtvalue"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain
 | 
			
		||||
dns_pdns_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if [ -z "$PDNS_Ttl" ]; then
 | 
			
		||||
    PDNS_Ttl="$DEFAULT_PDNS_TTL"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "Detect root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  if ! rm_record "$_domain" "$fulldomain" "$txtvalue"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
set_record() {
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  root=$1
 | 
			
		||||
  full=$2
 | 
			
		||||
  new_challenge=$3
 | 
			
		||||
 | 
			
		||||
  _record_string=""
 | 
			
		||||
  _build_record_string "$new_challenge"
 | 
			
		||||
  _list_existingchallenges
 | 
			
		||||
  for oldchallenge in $_existing_challenges; do
 | 
			
		||||
    _build_record_string "$oldchallenge"
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  if ! _pdns_rest "PATCH" "/api/v1/servers/$PDNS_ServerId/zones/$root" "{\"rrsets\": [{\"changetype\": \"REPLACE\", \"name\": \"$full.\", \"type\": \"TXT\", \"ttl\": $PDNS_Ttl, \"records\": [$_record_string]}]}"; then
 | 
			
		||||
    _err "Set txt record error."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! notify_slaves "$root"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
rm_record() {
 | 
			
		||||
  _info "Remove record"
 | 
			
		||||
  root=$1
 | 
			
		||||
  full=$2
 | 
			
		||||
  txtvalue=$3
 | 
			
		||||
 | 
			
		||||
  #Enumerate existing acme challenges
 | 
			
		||||
  _list_existingchallenges
 | 
			
		||||
 | 
			
		||||
  if _contains "$_existing_challenges" "$txtvalue"; then
 | 
			
		||||
    #Delete all challenges (PowerDNS API does not allow to delete content)
 | 
			
		||||
    if ! _pdns_rest "PATCH" "/api/v1/servers/$PDNS_ServerId/zones/$root" "{\"rrsets\": [{\"changetype\": \"DELETE\", \"name\": \"$full.\", \"type\": \"TXT\"}]}"; then
 | 
			
		||||
      _err "Delete txt record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    _record_string=""
 | 
			
		||||
    #If the only existing challenge was the challenge to delete: nothing to do
 | 
			
		||||
    if ! [ "$_existing_challenges" = "$txtvalue" ]; then
 | 
			
		||||
      for oldchallenge in $_existing_challenges; do
 | 
			
		||||
        #Build up the challenges to re-add, ommitting the one what should be deleted
 | 
			
		||||
        if ! [ "$oldchallenge" = "$txtvalue" ]; then
 | 
			
		||||
          _build_record_string "$oldchallenge"
 | 
			
		||||
        fi
 | 
			
		||||
      done
 | 
			
		||||
      #Recreate the existing challenges
 | 
			
		||||
      if ! _pdns_rest "PATCH" "/api/v1/servers/$PDNS_ServerId/zones/$root" "{\"rrsets\": [{\"changetype\": \"REPLACE\", \"name\": \"$full.\", \"type\": \"TXT\", \"ttl\": $PDNS_Ttl, \"records\": [$_record_string]}]}"; then
 | 
			
		||||
        _err "Set txt record error."
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
    fi
 | 
			
		||||
    if ! notify_slaves "$root"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  else
 | 
			
		||||
    _info "Record not found, nothing to remove"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
notify_slaves() {
 | 
			
		||||
  root=$1
 | 
			
		||||
 | 
			
		||||
  if ! _pdns_rest "PUT" "/api/v1/servers/$PDNS_ServerId/zones/$root/notify"; then
 | 
			
		||||
    _err "Notify slaves error."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=1
 | 
			
		||||
 | 
			
		||||
  if _pdns_rest "GET" "/api/v1/servers/$PDNS_ServerId/zones"; then
 | 
			
		||||
    _zones_response="$response"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
 | 
			
		||||
    if _contains "$_zones_response" "\"name\": \"$h.\""; then
 | 
			
		||||
      _domain="$h."
 | 
			
		||||
      if [ -z "$h" ]; then
 | 
			
		||||
        _domain="=2E"
 | 
			
		||||
      fi
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    i=$(_math $i + 1)
 | 
			
		||||
  done
 | 
			
		||||
  _debug "$domain not found"
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_pdns_rest() {
 | 
			
		||||
  method=$1
 | 
			
		||||
  ep=$2
 | 
			
		||||
  data=$3
 | 
			
		||||
 | 
			
		||||
  export _H1="X-API-Key: $PDNS_Token"
 | 
			
		||||
 | 
			
		||||
  if [ ! "$method" = "GET" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$PDNS_Url$ep" "" "$method")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$PDNS_Url$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_build_record_string() {
 | 
			
		||||
  _record_string="${_record_string:+${_record_string}, }{\"content\": \"\\\"${1}\\\"\", \"disabled\": false}"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_list_existingchallenges() {
 | 
			
		||||
  _pdns_rest "GET" "/api/v1/servers/$PDNS_ServerId/zones/$root"
 | 
			
		||||
  _existing_challenges=$(echo "$response" | _normalizeJson | _egrep_o "\"name\":\"${fulldomain}[^]]*}" | _egrep_o 'content\":\"\\"[^\\]*' | sed -n 's/^content":"\\"//p')
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										164
									
								
								dnsapi/dns_pointhq.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										164
									
								
								dnsapi/dns_pointhq.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,164 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
#PointHQ_Key="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
#
 | 
			
		||||
#PointHQ_Email="xxxx@sss.com"
 | 
			
		||||
 | 
			
		||||
PointHQ_Api="https://api.pointhq.com"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_pointhq_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  PointHQ_Key="${PointHQ_Key:-$(_readaccountconf_mutable PointHQ_Key)}"
 | 
			
		||||
  PointHQ_Email="${PointHQ_Email:-$(_readaccountconf_mutable PointHQ_Email)}"
 | 
			
		||||
  if [ -z "$PointHQ_Key" ] || [ -z "$PointHQ_Email" ]; then
 | 
			
		||||
    PointHQ_Key=""
 | 
			
		||||
    PointHQ_Email=""
 | 
			
		||||
    _err "You didn't specify a PointHQ API key and email yet."
 | 
			
		||||
    _err "Please create the key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$PointHQ_Email" "@"; then
 | 
			
		||||
    _err "It seems that the PointHQ_Email=$PointHQ_Email is not a valid email address."
 | 
			
		||||
    _err "Please check and retry."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable PointHQ_Key "$PointHQ_Key"
 | 
			
		||||
  _saveaccountconf_mutable PointHQ_Email "$PointHQ_Email"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  if _pointhq_rest POST "zones/$_domain/records" "{\"zone_record\": {\"name\":\"$_sub_domain\",\"record_type\":\"TXT\",\"data\":\"$txtvalue\",\"ttl\":3600}}"; then
 | 
			
		||||
    if printf -- "%s" "$response" | grep "$fulldomain" >/dev/null; then
 | 
			
		||||
      _info "Added, OK"
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Add txt record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  _err "Add txt record error."
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_pointhq_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  PointHQ_Key="${PointHQ_Key:-$(_readaccountconf_mutable PointHQ_Key)}"
 | 
			
		||||
  PointHQ_Email="${PointHQ_Email:-$(_readaccountconf_mutable PointHQ_Email)}"
 | 
			
		||||
  if [ -z "$PointHQ_Key" ] || [ -z "$PointHQ_Email" ]; then
 | 
			
		||||
    PointHQ_Key=""
 | 
			
		||||
    PointHQ_Email=""
 | 
			
		||||
    _err "You didn't specify a PointHQ API key and email yet."
 | 
			
		||||
    _err "Please create the key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _pointhq_rest GET "zones/${_domain}/records?record_type=TXT&name=$_sub_domain"
 | 
			
		||||
 | 
			
		||||
  if ! printf "%s" "$response" | grep "^\[" >/dev/null; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$response" = "[]" ]; then
 | 
			
		||||
    _info "No records to remove."
 | 
			
		||||
  else
 | 
			
		||||
    record_id=$(printf "%s\n" "$response" | _egrep_o "\"id\":[^,]*" | cut -d : -f 2 | tr -d \" | head -n 1)
 | 
			
		||||
    _debug "record_id" "$record_id"
 | 
			
		||||
    if [ -z "$record_id" ]; then
 | 
			
		||||
      _err "Can not get record id to remove."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    if ! _pointhq_rest DELETE "zones/$_domain/records/$record_id"; then
 | 
			
		||||
      _err "Delete record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    _contains "$response" '"status":"OK"'
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _pointhq_rest GET "zones"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"name\":\"$h\"" >/dev/null; then
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain=$h
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_pointhq_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
 | 
			
		||||
  _pointhq_auth=$(printf "%s:%s" "$PointHQ_Email" "$PointHQ_Key" | _base64)
 | 
			
		||||
 | 
			
		||||
  export _H1="Authorization: Basic $_pointhq_auth"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
  export _H3="Accept: application/json"
 | 
			
		||||
 | 
			
		||||
  if [ "$m" != "GET" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$PointHQ_Api/$ep" "" "$m")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$PointHQ_Api/$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										161
									
								
								dnsapi/dns_selectel.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										161
									
								
								dnsapi/dns_selectel.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,161 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
#SL_Key="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
#
 | 
			
		||||
 | 
			
		||||
SL_Api="https://api.selectel.ru/domains/v1"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_selectel_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  SL_Key="${SL_Key:-$(_readaccountconf_mutable SL_Key)}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$SL_Key" ]; then
 | 
			
		||||
    SL_Key=""
 | 
			
		||||
    _err "You don't specify selectel.ru api key yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable SL_Key "$SL_Key"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
  if _sl_rest POST "/$_domain_id/records/" "{\"type\": \"TXT\", \"ttl\": 60, \"name\": \"$fulldomain\", \"content\": \"$txtvalue\"}"; then
 | 
			
		||||
    if _contains "$response" "$txtvalue" || _contains "$response" "record_already_exists"; then
 | 
			
		||||
      _info "Added, OK"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  _err "Add txt record error."
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_selectel_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  SL_Key="${SL_Key:-$(_readaccountconf_mutable SL_Key)}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$SL_Key" ]; then
 | 
			
		||||
    SL_Key=""
 | 
			
		||||
    _err "You don't specify slectel api key yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _sl_rest GET "/${_domain_id}/records/"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "$txtvalue"; then
 | 
			
		||||
    _err "Txt record not found"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _record_seg="$(echo "$response" | _egrep_o "\"content\" *: *\"$txtvalue\"[^}]*}")"
 | 
			
		||||
  _debug2 "_record_seg" "$_record_seg"
 | 
			
		||||
  if [ -z "$_record_seg" ]; then
 | 
			
		||||
    _err "can not find _record_seg"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _record_id="$(echo "$_record_seg" | tr "," "\n" | tr "}" "\n" | tr -d " " | grep "\"id\"" | cut -d : -f 2)"
 | 
			
		||||
  _debug2 "_record_id" "$_record_id"
 | 
			
		||||
  if [ -z "$_record_id" ]; then
 | 
			
		||||
    _err "can not find _record_id"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _sl_rest DELETE "/$_domain_id/records/$_record_id"; then
 | 
			
		||||
    _err "Delete record error."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
 | 
			
		||||
  if ! _sl_rest GET "/"; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"name\": \"$h\","; then
 | 
			
		||||
      _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
      _domain=$h
 | 
			
		||||
      _debug "Getting domain id for $h"
 | 
			
		||||
      if ! _sl_rest GET "/$h"; then
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
      _domain_id="$(echo "$response" | tr "," "\n" | tr "}" "\n" | tr -d " " | grep "\"id\":" | cut -d : -f 2)"
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_sl_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="X-Token: $SL_Key"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  if [ "$m" != "GET" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$SL_Api/$ep" "" "$m")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$SL_Api/$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										170
									
								
								dnsapi/dns_servercow.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										170
									
								
								dnsapi/dns_servercow.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,170 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
##########
 | 
			
		||||
# Custom servercow.de DNS API v1 for use with [acme.sh](https://github.com/Neilpang/acme.sh)
 | 
			
		||||
#
 | 
			
		||||
# Usage:
 | 
			
		||||
# export SERVERCOW_API_Username=username
 | 
			
		||||
# export SERVERCOW_API_Password=password
 | 
			
		||||
# acme.sh --issue -d example.com --dns dns_servercow
 | 
			
		||||
#
 | 
			
		||||
# Issues:
 | 
			
		||||
# Any issues / questions / suggestions can be posted here:
 | 
			
		||||
# https://github.com/jhartlep/servercow-dns-api/issues
 | 
			
		||||
#
 | 
			
		||||
# Author: Jens Hartlep
 | 
			
		||||
##########
 | 
			
		||||
 | 
			
		||||
SERVERCOW_API="https://api.servercow.de/dns/v1/domains"
 | 
			
		||||
 | 
			
		||||
# Usage dns_servercow_add _acme-challenge.www.domain.com "abcdefghijklmnopqrstuvwxyz"
 | 
			
		||||
dns_servercow_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  _info "Using servercow"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  SERVERCOW_API_Username="${SERVERCOW_API_Username:-$(_readaccountconf_mutable SERVERCOW_API_Username)}"
 | 
			
		||||
  SERVERCOW_API_Password="${SERVERCOW_API_Password:-$(_readaccountconf_mutable SERVERCOW_API_Password)}"
 | 
			
		||||
  if [ -z "$SERVERCOW_API_Username" ] || [ -z "$SERVERCOW_API_Password" ]; then
 | 
			
		||||
    SERVERCOW_API_Username=""
 | 
			
		||||
    SERVERCOW_API_Password=""
 | 
			
		||||
    _err "You don't specify servercow api username and password yet."
 | 
			
		||||
    _err "Please create your username and password and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  # save the credentials to the account conf file
 | 
			
		||||
  _saveaccountconf_mutable SERVERCOW_API_Username "$SERVERCOW_API_Username"
 | 
			
		||||
  _saveaccountconf_mutable SERVERCOW_API_Password "$SERVERCOW_API_Password"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  if _servercow_api POST "$_domain" "{\"type\":\"TXT\",\"name\":\"$fulldomain\",\"content\":\"$txtvalue\",\"ttl\":20}"; then
 | 
			
		||||
    if printf -- "%s" "$response" | grep "ok" >/dev/null; then
 | 
			
		||||
      _info "Added, OK"
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "add txt record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
  _err "add txt record error."
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Usage fulldomain txtvalue
 | 
			
		||||
# Remove the txt record after validation
 | 
			
		||||
dns_servercow_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  _info "Using servercow"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$fulldomain"
 | 
			
		||||
 | 
			
		||||
  SERVERCOW_API_Username="${SERVERCOW_API_Username:-$(_readaccountconf_mutable SERVERCOW_API_Username)}"
 | 
			
		||||
  SERVERCOW_API_Password="${SERVERCOW_API_Password:-$(_readaccountconf_mutable SERVERCOW_API_Password)}"
 | 
			
		||||
  if [ -z "$SERVERCOW_API_Username" ] || [ -z "$SERVERCOW_API_Password" ]; then
 | 
			
		||||
    SERVERCOW_API_Username=""
 | 
			
		||||
    SERVERCOW_API_Password=""
 | 
			
		||||
    _err "You don't specify servercow api username and password yet."
 | 
			
		||||
    _err "Please create your username and password and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  if _servercow_api DELETE "$_domain" "{\"type\":\"TXT\",\"name\":\"$fulldomain\"}"; then
 | 
			
		||||
    if printf -- "%s" "$response" | grep "ok" >/dev/null; then
 | 
			
		||||
      _info "Deleted, OK"
 | 
			
		||||
      _contains "$response" '"message":"ok"'
 | 
			
		||||
    else
 | 
			
		||||
      _err "delete txt record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
# _acme-challenge.www.domain.com
 | 
			
		||||
# returns
 | 
			
		||||
#  _sub_domain=_acme-challenge.www
 | 
			
		||||
#  _domain=domain.com
 | 
			
		||||
_get_root() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  while true; do
 | 
			
		||||
    _domain=$(printf "%s" "$fulldomain" | cut -d . -f $i-100)
 | 
			
		||||
 | 
			
		||||
    _debug _domain "$_domain"
 | 
			
		||||
    if [ -z "$_domain" ]; then
 | 
			
		||||
      # not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _servercow_api GET "$_domain"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _contains "$response" '"error":"no such domain in user context"' >/dev/null; then
 | 
			
		||||
      _sub_domain=$(printf "%s" "$fulldomain" | cut -d . -f 1-$p)
 | 
			
		||||
      if [ -z "$_sub_domain" ]; then
 | 
			
		||||
        # not valid
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_servercow_api() {
 | 
			
		||||
  method=$1
 | 
			
		||||
  domain=$2
 | 
			
		||||
  data="$3"
 | 
			
		||||
 | 
			
		||||
  export _H1="Content-Type: application/json"
 | 
			
		||||
  export _H2="X-Auth-Username: $SERVERCOW_API_Username"
 | 
			
		||||
  export _H3="X-Auth-Password: $SERVERCOW_API_Password"
 | 
			
		||||
 | 
			
		||||
  if [ "$method" != "GET" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$SERVERCOW_API/$domain" "" "$method")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$SERVERCOW_API/$domain")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										69
									
								
								dnsapi/dns_tele3.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										69
									
								
								dnsapi/dns_tele3.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,69 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
#
 | 
			
		||||
# tele3.cz DNS API
 | 
			
		||||
#
 | 
			
		||||
# Author: Roman Blizik
 | 
			
		||||
# Report Bugs here: https://github.com/par-pa/acme.sh
 | 
			
		||||
#
 | 
			
		||||
# --
 | 
			
		||||
# export TELE3_Key="MS2I4uPPaI..."
 | 
			
		||||
# export TELE3_Secret="kjhOIHGJKHg"
 | 
			
		||||
# --
 | 
			
		||||
 | 
			
		||||
TELE3_API="https://www.tele3.cz/acme/"
 | 
			
		||||
 | 
			
		||||
########  Public functions  #####################
 | 
			
		||||
 | 
			
		||||
dns_tele3_add() {
 | 
			
		||||
  _info "Using TELE3 DNS"
 | 
			
		||||
  data="\"ope\":\"add\", \"domain\":\"$1\", \"value\":\"$2\""
 | 
			
		||||
  if ! _tele3_call; then
 | 
			
		||||
    _err "Publish zone failed"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "Zone published"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
dns_tele3_rm() {
 | 
			
		||||
  _info "Using TELE3 DNS"
 | 
			
		||||
  data="\"ope\":\"rm\", \"domain\":\"$1\", \"value\":\"$2\""
 | 
			
		||||
  if ! _tele3_call; then
 | 
			
		||||
    _err "delete TXT record failed"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _info "TXT record successfully deleted"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below  ##################################
 | 
			
		||||
 | 
			
		||||
_tele3_init() {
 | 
			
		||||
  TELE3_Key="${TELE3_Key:-$(_readaccountconf_mutable TELE3_Key)}"
 | 
			
		||||
  TELE3_Secret="${TELE3_Secret:-$(_readaccountconf_mutable TELE3_Secret)}"
 | 
			
		||||
  if [ -z "$TELE3_Key" ] || [ -z "$TELE3_Secret" ]; then
 | 
			
		||||
    TELE3_Key=""
 | 
			
		||||
    TELE3_Secret=""
 | 
			
		||||
    _err "You must export variables: TELE3_Key and TELE3_Secret"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the config variables to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable TELE3_Key "$TELE3_Key"
 | 
			
		||||
  _saveaccountconf_mutable TELE3_Secret "$TELE3_Secret"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_tele3_call() {
 | 
			
		||||
  _tele3_init
 | 
			
		||||
  data="{\"key\":\"$TELE3_Key\", \"secret\":\"$TELE3_Secret\", $data}"
 | 
			
		||||
 | 
			
		||||
  _debug data "$data"
 | 
			
		||||
 | 
			
		||||
  response="$(_post "$data" "$TELE3_API" "" "POST")"
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
 | 
			
		||||
  if [ "$response" != "success" ]; then
 | 
			
		||||
    _err "$response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										185
									
								
								dnsapi/dns_unoeuro.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										185
									
								
								dnsapi/dns_unoeuro.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,185 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
#UNO_Key="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
#
 | 
			
		||||
#UNO_User="UExxxxxx"
 | 
			
		||||
 | 
			
		||||
Uno_Api="https://api.unoeuro.com/1"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_unoeuro_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  UNO_Key="${UNO_Key:-$(_readaccountconf_mutable UNO_Key)}"
 | 
			
		||||
  UNO_User="${UNO_User:-$(_readaccountconf_mutable UNO_User)}"
 | 
			
		||||
  if [ -z "$UNO_Key" ] || [ -z "$UNO_User" ]; then
 | 
			
		||||
    UNO_Key=""
 | 
			
		||||
    UNO_User=""
 | 
			
		||||
    _err "You haven't specified a UnoEuro api key and account yet."
 | 
			
		||||
    _err "Please create your key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$UNO_User" "UE"; then
 | 
			
		||||
    _err "It seems that the UNO_User=$UNO_User is not a valid username."
 | 
			
		||||
    _err "Please check and retry."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key and email to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable UNO_Key "$UNO_Key"
 | 
			
		||||
  _saveaccountconf_mutable UNO_User "$UNO_User"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _uno_rest GET "my/products/$h/dns/records"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "\"status\": 200" >/dev/null; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _info "Adding record"
 | 
			
		||||
 | 
			
		||||
  if _uno_rest POST "my/products/$h/dns/records" "{\"name\":\"$fulldomain\",\"type\":\"TXT\",\"data\":\"$txtvalue\",\"ttl\":120}"; then
 | 
			
		||||
    if _contains "$response" "\"status\": 200" >/dev/null; then
 | 
			
		||||
      _info "Added, OK"
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _err "Add txt record error."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_unoeuro_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  UNO_Key="${UNO_Key:-$(_readaccountconf_mutable UNO_Key)}"
 | 
			
		||||
  UNO_User="${UNO_User:-$(_readaccountconf_mutable UNO_User)}"
 | 
			
		||||
  if [ -z "$UNO_Key" ] || [ -z "$UNO_User" ]; then
 | 
			
		||||
    UNO_Key=""
 | 
			
		||||
    UNO_User=""
 | 
			
		||||
    _err "You haven't specified a UnoEuro api key and account yet."
 | 
			
		||||
    _err "Please create your key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$UNO_User" "UE"; then
 | 
			
		||||
    _err "It seems that the UNO_User=$UNO_User is not a valid username."
 | 
			
		||||
    _err "Please check and retry."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _uno_rest GET "my/products/$h/dns/records"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "\"status\": 200"; then
 | 
			
		||||
    _err "Error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" "$_sub_domain"; then
 | 
			
		||||
    _info "Don't need to remove."
 | 
			
		||||
  else
 | 
			
		||||
    for record_line_number in $(echo "$response" | grep -n "$_sub_domain" | cut -d : -f 1); do
 | 
			
		||||
      record_line_number=$(_math "$record_line_number" - 1)
 | 
			
		||||
      _debug "record_line_number" "$record_line_number"
 | 
			
		||||
      record_id=$(echo "$response" | _head_n "$record_line_number" | _tail_n 1 1 | _egrep_o "[0-9]{1,}")
 | 
			
		||||
      _debug "record_id" "$record_id"
 | 
			
		||||
 | 
			
		||||
      if [ -z "$record_id" ]; then
 | 
			
		||||
        _err "Can not get record id to remove."
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
 | 
			
		||||
      if ! _uno_rest DELETE "my/products/$h/dns/records/$record_id"; then
 | 
			
		||||
        _err "Delete record error."
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
      _contains "$response" "\"status\": 200"
 | 
			
		||||
    done
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=sdjkglgdfewsdfg
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _uno_rest GET "my/products/$h/dns/records"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"status\": 200"; then
 | 
			
		||||
      _domain_id=$h
 | 
			
		||||
      if [ "$_domain_id" ]; then
 | 
			
		||||
        _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
        _domain=$h
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    p=$i
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_uno_rest() {
 | 
			
		||||
  m=$1
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
  _debug "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="Content-Type: application/json"
 | 
			
		||||
 | 
			
		||||
  if [ "$m" != "GET" ]; then
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$Uno_Api/$UNO_User/$UNO_Key/$ep" "" "$m")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$Uno_Api/$UNO_User/$UNO_Key/$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										149
									
								
								dnsapi/dns_vscale.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										149
									
								
								dnsapi/dns_vscale.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,149 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#This is the vscale.io api wrapper for acme.sh
 | 
			
		||||
#
 | 
			
		||||
#Author: Alex Loban
 | 
			
		||||
#Report Bugs here: https://github.com/LAV45/acme.sh
 | 
			
		||||
 | 
			
		||||
#VSCALE_API_KEY="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
VSCALE_API_URL="https://api.vscale.io/v1"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_myapi_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_vscale_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  if [ -z "$VSCALE_API_KEY" ]; then
 | 
			
		||||
    VSCALE_API_KEY=""
 | 
			
		||||
    _err "You didn't specify the VSCALE api key yet."
 | 
			
		||||
    _err "Please create you key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _saveaccountconf VSCALE_API_KEY "$VSCALE_API_KEY"
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _vscale_tmpl_json="{\"type\":\"TXT\",\"name\":\"$_sub_domain.$_domain\",\"content\":\"$txtvalue\"}"
 | 
			
		||||
 | 
			
		||||
  if _vscale_rest POST "domains/$_domain_id/records/" "$_vscale_tmpl_json"; then
 | 
			
		||||
    response=$(printf "%s\n" "$response" | _egrep_o "{\"error\": \".+\"" | cut -d : -f 2)
 | 
			
		||||
    if [ -z "$response" ]; then
 | 
			
		||||
      _info "txt record updated success."
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_vscale_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  _debug "First detect the root zone"
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "invalid domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug _domain_id "$_domain_id"
 | 
			
		||||
  _debug _sub_domain "$_sub_domain"
 | 
			
		||||
  _debug _domain "$_domain"
 | 
			
		||||
 | 
			
		||||
  _debug "Getting txt records"
 | 
			
		||||
  _vscale_rest GET "domains/$_domain_id/records/"
 | 
			
		||||
 | 
			
		||||
  if [ -n "$response" ]; then
 | 
			
		||||
    record_id=$(printf "%s\n" "$response" | _egrep_o "\"TXT\", \"id\": [0-9]+, \"name\": \"$_sub_domain.$_domain\"" | cut -d : -f 2 | tr -d ", \"name\"")
 | 
			
		||||
    _debug record_id "$record_id"
 | 
			
		||||
    if [ -z "$record_id" ]; then
 | 
			
		||||
      _err "Can not get record id to remove."
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    if _vscale_rest DELETE "domains/$_domain_id/records/$record_id" && [ -z "$response" ]; then
 | 
			
		||||
      _info "txt record deleted success."
 | 
			
		||||
      return 0
 | 
			
		||||
    fi
 | 
			
		||||
    _debug response "$response"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#_acme-challenge.www.domain.com
 | 
			
		||||
#returns
 | 
			
		||||
# _sub_domain=_acme-challenge.www
 | 
			
		||||
# _domain=domain.com
 | 
			
		||||
# _domain_id=12345
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  p=1
 | 
			
		||||
 | 
			
		||||
  if _vscale_rest GET "domains/"; then
 | 
			
		||||
    response="$(echo "$response" | tr -d "\n" | sed 's/{/\n&/g')"
 | 
			
		||||
    while true; do
 | 
			
		||||
      h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
      _debug h "$h"
 | 
			
		||||
      if [ -z "$h" ]; then
 | 
			
		||||
        #not valid
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
 | 
			
		||||
      hostedzone="$(echo "$response" | _egrep_o "{.*\"name\":\s*\"$h\".*}")"
 | 
			
		||||
      if [ "$hostedzone" ]; then
 | 
			
		||||
        _domain_id=$(printf "%s\n" "$hostedzone" | _egrep_o "\"id\":\s*[0-9]+" | _head_n 1 | cut -d : -f 2 | tr -d \ )
 | 
			
		||||
        if [ "$_domain_id" ]; then
 | 
			
		||||
          _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
 | 
			
		||||
          _domain=$h
 | 
			
		||||
          return 0
 | 
			
		||||
        fi
 | 
			
		||||
        return 1
 | 
			
		||||
      fi
 | 
			
		||||
      p=$i
 | 
			
		||||
      i=$(_math "$i" + 1)
 | 
			
		||||
    done
 | 
			
		||||
  fi
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#method uri qstr data
 | 
			
		||||
_vscale_rest() {
 | 
			
		||||
  mtd="$1"
 | 
			
		||||
  ep="$2"
 | 
			
		||||
  data="$3"
 | 
			
		||||
 | 
			
		||||
  _debug mtd "$mtd"
 | 
			
		||||
  _debug ep "$ep"
 | 
			
		||||
 | 
			
		||||
  export _H1="Accept: application/json"
 | 
			
		||||
  export _H2="Content-Type: application/json"
 | 
			
		||||
  export _H3="X-Token: ${VSCALE_API_KEY}"
 | 
			
		||||
 | 
			
		||||
  if [ "$mtd" != "GET" ]; then
 | 
			
		||||
    # both POST and DELETE.
 | 
			
		||||
    _debug data "$data"
 | 
			
		||||
    response="$(_post "$data" "$VSCALE_API_URL/$ep" "" "$mtd")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$VSCALE_API_URL/$ep")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $ep"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										106
									
								
								dnsapi/dns_yandex.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										106
									
								
								dnsapi/dns_yandex.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,106 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
# Author: non7top@gmail.com
 | 
			
		||||
# 07 Jul 2017
 | 
			
		||||
# report bugs at https://github.com/non7top/acme.sh
 | 
			
		||||
 | 
			
		||||
# Values to export:
 | 
			
		||||
# export PDD_Token="xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: dns_myapi_add   _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_yandex_add() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
  txtvalue="${2}"
 | 
			
		||||
  _debug "Calling: dns_yandex_add() '${fulldomain}' '${txtvalue}'"
 | 
			
		||||
  _PDD_credentials || return 1
 | 
			
		||||
  export _H1="PddToken: $PDD_Token"
 | 
			
		||||
 | 
			
		||||
  _PDD_get_domain "$fulldomain"
 | 
			
		||||
  _debug "Found suitable domain in pdd: $curDomain"
 | 
			
		||||
  curData="domain=${curDomain}&type=TXT&subdomain=${curSubdomain}&ttl=360&content=${txtvalue}"
 | 
			
		||||
  curUri="https://pddimp.yandex.ru/api2/admin/dns/add"
 | 
			
		||||
  curResult="$(_post "${curData}" "${curUri}")"
 | 
			
		||||
  _debug "Result: $curResult"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#Usage: dns_myapi_rm   _acme-challenge.www.domain.com
 | 
			
		||||
dns_yandex_rm() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
  _debug "Calling: dns_yandex_rm() '${fulldomain}'"
 | 
			
		||||
  _PDD_credentials || return 1
 | 
			
		||||
  export _H1="PddToken: $PDD_Token"
 | 
			
		||||
  record_id=$(pdd_get_record_id "${fulldomain}")
 | 
			
		||||
  _debug "Result: $record_id"
 | 
			
		||||
 | 
			
		||||
  _PDD_get_domain "$fulldomain"
 | 
			
		||||
  _debug "Found suitable domain in pdd: $curDomain"
 | 
			
		||||
 | 
			
		||||
  curUri="https://pddimp.yandex.ru/api2/admin/dns/del"
 | 
			
		||||
  curData="domain=${curDomain}&record_id=${record_id}"
 | 
			
		||||
  curResult="$(_post "${curData}" "${curUri}")"
 | 
			
		||||
  _debug "Result: $curResult"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_PDD_get_domain() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
  __page=1
 | 
			
		||||
  __last=0
 | 
			
		||||
  while [ $__last -eq 0 ]; do
 | 
			
		||||
    uri1="https://pddimp.yandex.ru/api2/admin/domain/domains?page=${__page}&on_page=20"
 | 
			
		||||
    res1="$(_get "$uri1" | _normalizeJson)"
 | 
			
		||||
    _debug2 "res1" "$res1"
 | 
			
		||||
    __found="$(echo "$res1" | sed -n -e 's#.* "found": \([^,]*\),.*#\1#p')"
 | 
			
		||||
    _debug "found: $__found results on page"
 | 
			
		||||
    if [ "$__found" -lt 20 ]; then
 | 
			
		||||
      _debug "last page: $__page"
 | 
			
		||||
      __last=1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    __all_domains="$__all_domains $(echo "$res1" | tr "," "\n" | grep '"name"' | cut -d: -f2 | sed -e 's@"@@g')"
 | 
			
		||||
 | 
			
		||||
    __page=$(_math $__page + 1)
 | 
			
		||||
  done
 | 
			
		||||
 | 
			
		||||
  k=2
 | 
			
		||||
  while [ $k -lt 10 ]; do
 | 
			
		||||
    __t=$(echo "$fulldomain" | cut -d . -f $k-100)
 | 
			
		||||
    _debug "finding zone for domain $__t"
 | 
			
		||||
    for d in $__all_domains; do
 | 
			
		||||
      if [ "$d" = "$__t" ]; then
 | 
			
		||||
        p=$(_math $k - 1)
 | 
			
		||||
        curSubdomain="$(echo "$fulldomain" | cut -d . -f "1-$p")"
 | 
			
		||||
        curDomain="$__t"
 | 
			
		||||
        return 0
 | 
			
		||||
      fi
 | 
			
		||||
    done
 | 
			
		||||
    k=$(_math $k + 1)
 | 
			
		||||
  done
 | 
			
		||||
  _err "No suitable domain found in your account"
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_PDD_credentials() {
 | 
			
		||||
  if [ -z "${PDD_Token}" ]; then
 | 
			
		||||
    PDD_Token=""
 | 
			
		||||
    _err "You need to export PDD_Token=xxxxxxxxxxxxxxxxx"
 | 
			
		||||
    _err "You can get it at https://pddimp.yandex.ru/api2/admin/get_token"
 | 
			
		||||
    return 1
 | 
			
		||||
  else
 | 
			
		||||
    _saveaccountconf PDD_Token "${PDD_Token}"
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
pdd_get_record_id() {
 | 
			
		||||
  fulldomain="${1}"
 | 
			
		||||
 | 
			
		||||
  _PDD_get_domain "$fulldomain"
 | 
			
		||||
  _debug "Found suitable domain in pdd: $curDomain"
 | 
			
		||||
 | 
			
		||||
  curUri="https://pddimp.yandex.ru/api2/admin/dns/list?domain=${curDomain}"
 | 
			
		||||
  curResult="$(_get "${curUri}" | _normalizeJson)"
 | 
			
		||||
  _debug "Result: $curResult"
 | 
			
		||||
  echo "$curResult" | _egrep_o "{[^{]*\"content\":[^{]*\"subdomain\":\"${curSubdomain}\"" | sed -n -e 's#.* "record_id": \(.*\),[^,]*#\1#p'
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										139
									
								
								dnsapi/dns_zilore.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										139
									
								
								dnsapi/dns_zilore.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,139 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
Zilore_API="https://api.zilore.com/dns/v1"
 | 
			
		||||
# Zilore_Key="YOUR-ZILORE-API-KEY"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
dns_zilore_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  _info "Using Zilore"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  Zilore_Key="${Zilore_Key:-$(_readaccountconf_mutable Zilore_Key)}"
 | 
			
		||||
  if [ -z "$Zilore_Key" ]; then
 | 
			
		||||
    Zilore_Key=""
 | 
			
		||||
    _err "Please define Zilore API key"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _saveaccountconf_mutable Zilore_Key "$Zilore_Key"
 | 
			
		||||
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "Unable to determine root domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  else
 | 
			
		||||
    _debug _domain "$_domain"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if _zilore_rest POST "domains/$_domain/records?record_type=TXT&record_ttl=600&record_name=$fulldomain&record_value=\"$txtvalue\""; then
 | 
			
		||||
    if _contains "$response" '"added"' >/dev/null; then
 | 
			
		||||
      _info "Added TXT record, waiting for validation"
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _debug response "$response"
 | 
			
		||||
      _err "Error while adding DNS records"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
dns_zilore_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  _info "Using Zilore"
 | 
			
		||||
  _debug fulldomain "$fulldomain"
 | 
			
		||||
  _debug txtvalue "$txtvalue"
 | 
			
		||||
 | 
			
		||||
  Zilore_Key="${Zilore_Key:-$(_readaccountconf_mutable Zilore_Key)}"
 | 
			
		||||
  if [ -z "$Zilore_Key" ]; then
 | 
			
		||||
    Zilore_Key=""
 | 
			
		||||
    _err "Please define Zilore API key"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _saveaccountconf_mutable Zilore_Key "$Zilore_Key"
 | 
			
		||||
 | 
			
		||||
  if ! _get_root "$fulldomain"; then
 | 
			
		||||
    _err "Unable to determine root domain"
 | 
			
		||||
    return 1
 | 
			
		||||
  else
 | 
			
		||||
    _debug _domain "$_domain"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug "Getting TXT records"
 | 
			
		||||
  _zilore_rest GET "domains/${_domain}/records?search_text=$txtvalue&search_record_type=TXT"
 | 
			
		||||
  _debug response "$response"
 | 
			
		||||
 | 
			
		||||
  if ! _contains "$response" '"ok"' >/dev/null; then
 | 
			
		||||
    _err "Error while getting records list"
 | 
			
		||||
    return 1
 | 
			
		||||
  else
 | 
			
		||||
    _record_id=$(printf "%s\n" "$response" | _egrep_o "\"record_id\":\"[^\"]+\"" | cut -d : -f 2 | tr -d \" | _head_n 1)
 | 
			
		||||
    if [ -z "$_record_id" ]; then
 | 
			
		||||
      _err "Cannot determine _record_id"
 | 
			
		||||
      return 1
 | 
			
		||||
    else
 | 
			
		||||
      _debug _record_id "$_record_id"
 | 
			
		||||
    fi
 | 
			
		||||
    if ! _zilore_rest DELETE "domains/${_domain}/records?record_id=$_record_id"; then
 | 
			
		||||
      _err "Error while deleting chosen record"
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
    _contains "$response" '"ok"'
 | 
			
		||||
  fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
 | 
			
		||||
_get_root() {
 | 
			
		||||
  domain=$1
 | 
			
		||||
  i=2
 | 
			
		||||
  while true; do
 | 
			
		||||
    h=$(printf "%s" "$domain" | cut -d . -f $i-100)
 | 
			
		||||
    _debug h "$h"
 | 
			
		||||
    if [ -z "$h" ]; then
 | 
			
		||||
      #not valid
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! _zilore_rest GET "domains?search_text=$h"; then
 | 
			
		||||
      return 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if _contains "$response" "\"$h\"" >/dev/null; then
 | 
			
		||||
      _domain=$h
 | 
			
		||||
      return 0
 | 
			
		||||
    else
 | 
			
		||||
      _debug "$h not found"
 | 
			
		||||
    fi
 | 
			
		||||
    i=$(_math "$i" + 1)
 | 
			
		||||
  done
 | 
			
		||||
  return 1
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
_zilore_rest() {
 | 
			
		||||
  method=$1
 | 
			
		||||
  param=$2
 | 
			
		||||
  data=$3
 | 
			
		||||
 | 
			
		||||
  export _H1="X-Auth-Key: $Zilore_Key"
 | 
			
		||||
 | 
			
		||||
  if [ "$method" != "GET" ]; then
 | 
			
		||||
    response="$(_post "$data" "$Zilore_API/$param" "" "$method")"
 | 
			
		||||
  else
 | 
			
		||||
    response="$(_get "$Zilore_API/$param")"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    _err "error $param"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  return 0
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										85
									
								
								dnsapi/dns_zonomi.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										85
									
								
								dnsapi/dns_zonomi.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,85 @@
 | 
			
		||||
#!/usr/bin/env sh
 | 
			
		||||
 | 
			
		||||
#
 | 
			
		||||
#ZM_Key="sdfsdfsdfljlbjkljlkjsdfoiwje"
 | 
			
		||||
#
 | 
			
		||||
#https://zonomi.com dns api
 | 
			
		||||
 | 
			
		||||
ZM_Api="https://zonomi.com/app/dns/dyndns.jsp"
 | 
			
		||||
 | 
			
		||||
########  Public functions #####################
 | 
			
		||||
 | 
			
		||||
#Usage: add  _acme-challenge.www.domain.com   "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
 | 
			
		||||
dns_zonomi_add() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  ZM_Key="${ZM_Key:-$(_readaccountconf_mutable ZM_Key)}"
 | 
			
		||||
 | 
			
		||||
  if [ -z "$ZM_Key" ]; then
 | 
			
		||||
    ZM_Key=""
 | 
			
		||||
    _err "You don't specify zonomi api key yet."
 | 
			
		||||
    _err "Please create your key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  #save the api key to the account conf file.
 | 
			
		||||
  _saveaccountconf_mutable ZM_Key "$ZM_Key"
 | 
			
		||||
 | 
			
		||||
  _info "Get existing txt records for $fulldomain"
 | 
			
		||||
  if ! _zm_request "action=QUERY&name=$fulldomain"; then
 | 
			
		||||
    _err "error"
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  if _contains "$response" "<record"; then
 | 
			
		||||
    _debug "get and update records"
 | 
			
		||||
    _qstr="action[1]=SET&type[1]=TXT&name[1]=$fulldomain&value[1]=$txtvalue"
 | 
			
		||||
    _qindex=2
 | 
			
		||||
    for t in $(echo "$response" | tr -d "\r\n" | _egrep_o '<action.*</action>' | tr "<" "\n" | grep record | grep 'type="TXT"' | cut -d '"' -f 6); do
 | 
			
		||||
      _debug2 t "$t"
 | 
			
		||||
      _qstr="$_qstr&action[$_qindex]=SET&type[$_qindex]=TXT&name[$_qindex]=$fulldomain&value[$_qindex]=$t"
 | 
			
		||||
      _qindex="$(_math "$_qindex" + 1)"
 | 
			
		||||
    done
 | 
			
		||||
    _zm_request "$_qstr"
 | 
			
		||||
  else
 | 
			
		||||
    _debug "Just add record"
 | 
			
		||||
    _zm_request "action=SET&type=TXT&name=$fulldomain&value=$txtvalue"
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#fulldomain txtvalue
 | 
			
		||||
dns_zonomi_rm() {
 | 
			
		||||
  fulldomain=$1
 | 
			
		||||
  txtvalue=$2
 | 
			
		||||
 | 
			
		||||
  ZM_Key="${ZM_Key:-$(_readaccountconf_mutable ZM_Key)}"
 | 
			
		||||
  if [ -z "$ZM_Key" ]; then
 | 
			
		||||
    ZM_Key=""
 | 
			
		||||
    _err "You don't specify zonomi api key yet."
 | 
			
		||||
    _err "Please create your key and try again."
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
  _zm_request "action=DELETE&type=TXT&name=$fulldomain"
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
####################  Private functions below ##################################
 | 
			
		||||
#qstr
 | 
			
		||||
_zm_request() {
 | 
			
		||||
  qstr="$1"
 | 
			
		||||
 | 
			
		||||
  _debug2 "qstr" "$qstr"
 | 
			
		||||
 | 
			
		||||
  _zm_url="$ZM_Api?api_key=$ZM_Key&$qstr"
 | 
			
		||||
  _debug2 "_zm_url" "$_zm_url"
 | 
			
		||||
  response="$(_get "$_zm_url")"
 | 
			
		||||
 | 
			
		||||
  if [ "$?" != "0" ]; then
 | 
			
		||||
    return 1
 | 
			
		||||
  fi
 | 
			
		||||
  _debug2 response "$response"
 | 
			
		||||
  _contains "$response" "<is_ok>OK:"
 | 
			
		||||
}
 | 
			
		||||
		Reference in New Issue
	
	Block a user