You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

247 lines
9.2 KiB

4 months ago
6 years ago
  1. #!/usr/bin/env sh
  2. # shellcheck disable=SC2034
  3. dns_openprovider_info='OpenProvider.eu
  4. Site: OpenProvider.eu
  5. Domains: OpenProvider.com
  6. Docs: github.com/acmesh-official/acme.sh/wiki/dnsapi#dns_openprovider
  7. Options:
  8. OPENPROVIDER_USER Username
  9. OPENPROVIDER_PASSWORDHASH Password hash
  10. Issues: github.com/acmesh-official/acme.sh/issues/2104
  11. Author: Sylvia van Os
  12. '
  13. OPENPROVIDER_API="https://api.openprovider.eu/"
  14. #OPENPROVIDER_API="https://api.cte.openprovider.eu/" # Test API
  15. ######## Public functions #####################
  16. #Usage: dns_openprovider_add _acme-challenge.www.domain.com "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
  17. dns_openprovider_add() {
  18. fulldomain="$1"
  19. txtvalue="$2"
  20. OPENPROVIDER_USER="${OPENPROVIDER_USER:-$(_readaccountconf_mutable OPENPROVIDER_USER)}"
  21. OPENPROVIDER_PASSWORDHASH="${OPENPROVIDER_PASSWORDHASH:-$(_readaccountconf_mutable OPENPROVIDER_PASSWORDHASH)}"
  22. if [ -z "$OPENPROVIDER_USER" ] || [ -z "$OPENPROVIDER_PASSWORDHASH" ]; then
  23. _err "You didn't specify the openprovider user and/or password hash."
  24. return 1
  25. fi
  26. # save the username and password to the account conf file.
  27. _saveaccountconf_mutable OPENPROVIDER_USER "$OPENPROVIDER_USER"
  28. _saveaccountconf_mutable OPENPROVIDER_PASSWORDHASH "$OPENPROVIDER_PASSWORDHASH"
  29. _debug "First detect the root zone"
  30. if ! _get_root "$fulldomain"; then
  31. _err "invalid domain"
  32. return 1
  33. fi
  34. _debug _domain_name "$_domain_name"
  35. _debug _domain_extension "$_domain_extension"
  36. _debug "Getting current records"
  37. existing_items=""
  38. results_retrieved=0
  39. while true; do
  40. _openprovider_request "$(printf '<searchZoneRecordDnsRequest><name>%s.%s</name><offset>%s</offset></searchZoneRecordDnsRequest>' "$_domain_name" "$_domain_extension" "$results_retrieved")"
  41. items="$response"
  42. while true; do
  43. item="$(echo "$items" | _egrep_o '<openXML>.*<\/openXML>' | sed -n 's/.*\(<item>.*<\/item>\).*/\1/p')"
  44. _debug existing_items "$existing_items"
  45. _debug results_retrieved "$results_retrieved"
  46. _debug item "$item"
  47. if [ -z "$item" ]; then
  48. break
  49. fi
  50. tmpitem="$(echo "$item" | sed 's/\*/\\*/g')"
  51. items="$(echo "$items" | sed "s|${tmpitem}||")"
  52. results_retrieved="$(_math "$results_retrieved" + 1)"
  53. new_item="$(echo "$item" | sed -n 's/.*<item>.*\(<name>\(.*\)\.'"$_domain_name"'\.'"$_domain_extension"'<\/name>.*\(<type>.*<\/type>\).*\(<value>.*<\/value>\).*\(<prio>.*<\/prio>\).*\(<ttl>.*<\/ttl>\)\).*<\/item>.*/<item><name>\2<\/name>\3\4\5\6<\/item>/p')"
  54. if [ -z "$new_item" ]; then
  55. # Domain apex
  56. new_item="$(echo "$item" | sed -n 's/.*<item>.*\(<name>\(.*\)'"$_domain_name"'\.'"$_domain_extension"'<\/name>.*\(<type>.*<\/type>\).*\(<value>.*<\/value>\).*\(<prio>.*<\/prio>\).*\(<ttl>.*<\/ttl>\)\).*<\/item>.*/<item><name>\2<\/name>\3\4\5\6<\/item>/p')"
  57. fi
  58. if [ -z "$(echo "$new_item" | _egrep_o ".*<type>(A|AAAA|CNAME|MX|SPF|SRV|TXT|TLSA|SSHFP|CAA)<\/type>.*")" ]; then
  59. _debug "not an allowed record type, skipping" "$new_item"
  60. continue
  61. fi
  62. existing_items="$existing_items$new_item"
  63. done
  64. total="$(echo "$response" | _egrep_o '<total>.*?<\/total>' | sed -n 's/.*<total>\(.*\)<\/total>.*/\1/p')"
  65. _debug total "$total"
  66. if [ "$results_retrieved" -eq "$total" ]; then
  67. break
  68. fi
  69. done
  70. _debug "Creating acme record"
  71. acme_record="$(echo "$fulldomain" | sed -e "s/.$_domain_name.$_domain_extension$//")"
  72. _openprovider_request "$(printf '<modifyZoneDnsRequest><domain><name>%s</name><extension>%s</extension></domain><type>master</type><records><array>%s<item><name>%s</name><type>TXT</type><value>%s</value><ttl>600</ttl></item></array></records></modifyZoneDnsRequest>' "$_domain_name" "$_domain_extension" "$existing_items" "$acme_record" "$txtvalue")"
  73. return 0
  74. }
  75. #Usage: fulldomain txtvalue
  76. #Remove the txt record after validation.
  77. dns_openprovider_rm() {
  78. fulldomain="$1"
  79. txtvalue="$2"
  80. OPENPROVIDER_USER="${OPENPROVIDER_USER:-$(_readaccountconf_mutable OPENPROVIDER_USER)}"
  81. OPENPROVIDER_PASSWORDHASH="${OPENPROVIDER_PASSWORDHASH:-$(_readaccountconf_mutable OPENPROVIDER_PASSWORDHASH)}"
  82. if [ -z "$OPENPROVIDER_USER" ] || [ -z "$OPENPROVIDER_PASSWORDHASH" ]; then
  83. _err "You didn't specify the openprovider user and/or password hash."
  84. return 1
  85. fi
  86. # save the username and password to the account conf file.
  87. _saveaccountconf_mutable OPENPROVIDER_USER "$OPENPROVIDER_USER"
  88. _saveaccountconf_mutable OPENPROVIDER_PASSWORDHASH "$OPENPROVIDER_PASSWORDHASH"
  89. _debug "First detect the root zone"
  90. if ! _get_root "$fulldomain"; then
  91. _err "invalid domain"
  92. return 1
  93. fi
  94. _debug _domain_name "$_domain_name"
  95. _debug _domain_extension "$_domain_extension"
  96. _debug "Getting current records"
  97. existing_items=""
  98. results_retrieved=0
  99. while true; do
  100. _openprovider_request "$(printf '<searchZoneRecordDnsRequest><name>%s.%s</name><offset>%s</offset></searchZoneRecordDnsRequest>' "$_domain_name" "$_domain_extension" "$results_retrieved")"
  101. # Remove acme records from items
  102. items="$response"
  103. while true; do
  104. item="$(echo "$items" | _egrep_o '<openXML>.*<\/openXML>' | sed -n 's/.*\(<item>.*<\/item>\).*/\1/p')"
  105. _debug existing_items "$existing_items"
  106. _debug results_retrieved "$results_retrieved"
  107. _debug item "$item"
  108. if [ -z "$item" ]; then
  109. break
  110. fi
  111. tmpitem="$(echo "$item" | sed 's/\*/\\*/g')"
  112. items="$(echo "$items" | sed "s|${tmpitem}||")"
  113. results_retrieved="$(_math "$results_retrieved" + 1)"
  114. if ! echo "$item" | grep -v "$fulldomain"; then
  115. _debug "acme record, skipping" "$item"
  116. continue
  117. fi
  118. new_item="$(echo "$item" | sed -n 's/.*<item>.*\(<name>\(.*\)\.'"$_domain_name"'\.'"$_domain_extension"'<\/name>.*\(<type>.*<\/type>\).*\(<value>.*<\/value>\).*\(<prio>.*<\/prio>\).*\(<ttl>.*<\/ttl>\)\).*<\/item>.*/<item><name>\2<\/name>\3\4\5\6<\/item>/p')"
  119. if [ -z "$new_item" ]; then
  120. # domain apex
  121. new_item="$(echo "$item" | sed -n 's/.*<item>.*\(<name>\(.*\)'"$_domain_name"'\.'"$_domain_extension"'<\/name>.*\(<type>.*<\/type>\).*\(<value>.*<\/value>\).*\(<prio>.*<\/prio>\).*\(<ttl>.*<\/ttl>\)\).*<\/item>.*/<item><name>\2<\/name>\3\4\5\6<\/item>/p')"
  122. fi
  123. if [ -z "$(echo "$new_item" | _egrep_o ".*<type>(A|AAAA|CNAME|MX|SPF|SRV|TXT|TLSA|SSHFP|CAA)<\/type>.*")" ]; then
  124. _debug "not an allowed record type, skipping" "$new_item"
  125. continue
  126. fi
  127. existing_items="$existing_items$new_item"
  128. done
  129. total="$(echo "$response" | _egrep_o '<total>.*?<\/total>' | sed -n 's/.*<total>\(.*\)<\/total>.*/\1/p')"
  130. _debug total "$total"
  131. if [ "$results_retrieved" -eq "$total" ]; then
  132. break
  133. fi
  134. done
  135. _debug "Removing acme record"
  136. _openprovider_request "$(printf '<modifyZoneDnsRequest><domain><name>%s</name><extension>%s</extension></domain><type>master</type><records><array>%s</array></records></modifyZoneDnsRequest>' "$_domain_name" "$_domain_extension" "$existing_items")"
  137. return 0
  138. }
  139. #################### Private functions below ##################################
  140. #_acme-challenge.www.domain.com
  141. #returns
  142. # _domain_name=domain
  143. # _domain_extension=com
  144. _get_root() {
  145. domain=$1
  146. i=2
  147. results_retrieved=0
  148. while true; do
  149. h=$(echo "$domain" | cut -d . -f "$i"-100)
  150. _debug h "$h"
  151. if [ -z "$h" ]; then
  152. #not valid
  153. return 1
  154. fi
  155. _openprovider_request "$(printf '<searchDomainRequest><domainNamePattern>%s</domainNamePattern><offset>%s</offset></searchDomainRequest>' "$(echo "$h" | cut -d . -f 1)" "$results_retrieved")"
  156. items="$response"
  157. while true; do
  158. item="$(echo "$items" | _egrep_o '<openXML>.*<\/openXML>' | sed -n 's/.*\(<domain>.*<\/domain>\).*/\1/p')"
  159. _debug existing_items "$existing_items"
  160. _debug results_retrieved "$results_retrieved"
  161. _debug item "$item"
  162. if [ -z "$item" ]; then
  163. break
  164. fi
  165. tmpitem="$(echo "$item" | sed 's/\*/\\*/g')"
  166. items="$(echo "$items" | sed "s|${tmpitem}||")"
  167. results_retrieved="$(_math "$results_retrieved" + 1)"
  168. _domain_name="$(echo "$item" | sed -n 's/.*<domain>.*<name>\(.*\)<\/name>.*<\/domain>.*/\1/p')"
  169. _domain_extension="$(echo "$item" | sed -n 's/.*<domain>.*<extension>\(.*\)<\/extension>.*<\/domain>.*/\1/p')"
  170. _debug _domain_name "$_domain_name"
  171. _debug _domain_extension "$_domain_extension"
  172. if [ "$_domain_name.$_domain_extension" = "$h" ]; then
  173. return 0
  174. fi
  175. done
  176. total="$(echo "$response" | _egrep_o '<total>.*?<\/total>' | sed -n 's/.*<total>\(.*\)<\/total>.*/\1/p')"
  177. _debug total "$total"
  178. if [ "$results_retrieved" -eq "$total" ]; then
  179. results_retrieved=0
  180. i="$(_math "$i" + 1)"
  181. fi
  182. done
  183. return 1
  184. }
  185. _openprovider_request() {
  186. request_xml=$1
  187. xml_prefix='<?xml version="1.0" encoding="UTF-8"?>'
  188. xml_content=$(printf '<openXML><credentials><username>%s</username><hash>%s</hash></credentials>%s</openXML>' "$OPENPROVIDER_USER" "$OPENPROVIDER_PASSWORDHASH" "$request_xml")
  189. response="$(_post "$(echo "$xml_prefix$xml_content" | tr -d '\n')" "$OPENPROVIDER_API" "" "POST" "application/xml")"
  190. _debug response "$response"
  191. if ! _contains "$response" "<openXML><reply><code>0</code>.*</reply></openXML>"; then
  192. _err "API request failed."
  193. return 1
  194. fi
  195. }