-
Notifications
You must be signed in to change notification settings - Fork 8
/
setup_certs
executable file
·42 lines (30 loc) · 1.05 KB
/
setup_certs
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
#!/usr/bin/env bash
set -e
addon="$1"
[ -z $addon ] && {
echo "addon is missing" >&2
exit 1
}
client_key="$(echo $addon)_CLIENT_CERT_KEY"
client_cert="$(echo $addon)_CLIENT_CERT"
trusted_cert="$(echo $addon)_TRUSTED_CERT"
[ -z $TRUSTSTORE_PASSWORD ] && {
echo "TRUSTSTORE_PASSWORD is missing" >&2
exit 1
}
[ -z $KEYSTORE_PASSWORD ] && {
echo "KEYSTORE_PASSWORD is missing" >&2
exit 1
}
rm -f .{keystore,truststore}.{pem,pkcs12,jks}
rm -f .cacerts
#cp /etc/ssl/certs/java/cacerts ./.cacerts
echo -n "${!client_key}" >> .keystore.pem
echo -n "${!client_cert}" >> .keystore.pem
echo -n "${!trusted_cert}" > .truststore.pem
keytool -importcert -file .truststore.pem -keystore .truststore.jks -deststorepass $TRUSTSTORE_PASSWORD -noprompt
openssl pkcs12 -export -in .keystore.pem -out .keystore.pkcs12 -password pass:$KEYSTORE_PASSWORD
keytool -importkeystore -srcstoretype PKCS12 \
-destkeystore .keystore.jks -deststorepass $KEYSTORE_PASSWORD \
-srckeystore .keystore.pkcs12 -srcstorepass $KEYSTORE_PASSWORD
rm -f .{keystore,truststore}.{pem,pkcs12}