You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

247 lines
9.2 KiB

5 years ago
  1. #!/usr/bin/env sh
  2. # This is the OpenProvider API wrapper for acme.sh
  3. #
  4. # Author: Sylvia van Os
  5. # Report Bugs here: https://github.com/acmesh-official/acme.sh/issues/2104
  6. #
  7. # export OPENPROVIDER_USER="username"
  8. # export OPENPROVIDER_PASSWORDHASH="hashed_password"
  9. #
  10. # Usage:
  11. # acme.sh --issue --dns dns_openprovider -d example.com
  12. OPENPROVIDER_API="https://api.openprovider.eu/"
  13. #OPENPROVIDER_API="https://api.cte.openprovider.eu/" # Test API
  14. ######## Public functions #####################
  15. #Usage: dns_openprovider_add _acme-challenge.www.domain.com "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
  16. dns_openprovider_add() {
  17. fulldomain="$1"
  18. txtvalue="$2"
  19. OPENPROVIDER_USER="${OPENPROVIDER_USER:-$(_readaccountconf_mutable OPENPROVIDER_USER)}"
  20. OPENPROVIDER_PASSWORDHASH="${OPENPROVIDER_PASSWORDHASH:-$(_readaccountconf_mutable OPENPROVIDER_PASSWORDHASH)}"
  21. if [ -z "$OPENPROVIDER_USER" ] || [ -z "$OPENPROVIDER_PASSWORDHASH" ]; then
  22. _err "You didn't specify the openprovider user and/or password hash."
  23. return 1
  24. fi
  25. # save the username and password to the account conf file.
  26. _saveaccountconf_mutable OPENPROVIDER_USER "$OPENPROVIDER_USER"
  27. _saveaccountconf_mutable OPENPROVIDER_PASSWORDHASH "$OPENPROVIDER_PASSWORDHASH"
  28. _debug "First detect the root zone"
  29. if ! _get_root "$fulldomain"; then
  30. _err "invalid domain"
  31. return 1
  32. fi
  33. _debug _domain_name "$_domain_name"
  34. _debug _domain_extension "$_domain_extension"
  35. _debug "Getting current records"
  36. existing_items=""
  37. results_retrieved=0
  38. while true; do
  39. _openprovider_request "$(printf '<searchZoneRecordDnsRequest><name>%s.%s</name><offset>%s</offset></searchZoneRecordDnsRequest>' "$_domain_name" "$_domain_extension" "$results_retrieved")"
  40. items="$response"
  41. while true; do
  42. item="$(echo "$items" | _egrep_o '<openXML>.*<\/openXML>' | sed -n 's/.*\(<item>.*<\/item>\).*/\1/p')"
  43. _debug existing_items "$existing_items"
  44. _debug results_retrieved "$results_retrieved"
  45. _debug item "$item"
  46. if [ -z "$item" ]; then
  47. break
  48. fi
  49. tmpitem="$(echo "$item" | sed 's/\*/\\*/g')"
  50. items="$(echo "$items" | sed "s|${tmpitem}||")"
  51. results_retrieved="$(_math "$results_retrieved" + 1)"
  52. new_item="$(echo "$item" | sed -n 's/.*<item>.*\(<name>\(.*\)\.'"$_domain_name"'\.'"$_domain_extension"'<\/name>.*\(<type>.*<\/type>\).*\(<value>.*<\/value>\).*\(<prio>.*<\/prio>\).*\(<ttl>.*<\/ttl>\)\).*<\/item>.*/<item><name>\2<\/name>\3\4\5\6<\/item>/p')"
  53. if [ -z "$new_item" ]; then
  54. # Domain apex
  55. new_item="$(echo "$item" | sed -n 's/.*<item>.*\(<name>\(.*\)'"$_domain_name"'\.'"$_domain_extension"'<\/name>.*\(<type>.*<\/type>\).*\(<value>.*<\/value>\).*\(<prio>.*<\/prio>\).*\(<ttl>.*<\/ttl>\)\).*<\/item>.*/<item><name>\2<\/name>\3\4\5\6<\/item>/p')"
  56. fi
  57. if [ -z "$(echo "$new_item" | _egrep_o ".*<type>(A|AAAA|CNAME|MX|SPF|SRV|TXT|TLSA|SSHFP|CAA|NS)<\/type>.*")" ]; then
  58. _debug "not an allowed record type, skipping" "$new_item"
  59. continue
  60. fi
  61. existing_items="$existing_items$new_item"
  62. done
  63. total="$(echo "$response" | _egrep_o '<total>.*?<\/total>' | sed -n 's/.*<total>\(.*\)<\/total>.*/\1/p')"
  64. _debug total "$total"
  65. if [ "$results_retrieved" -eq "$total" ]; then
  66. break
  67. fi
  68. done
  69. _debug "Creating acme record"
  70. acme_record="$(echo "$fulldomain" | sed -e "s/.$_domain_name.$_domain_extension$//")"
  71. _openprovider_request "$(printf '<modifyZoneDnsRequest><domain><name>%s</name><extension>%s</extension></domain><type>master</type><records><array>%s<item><name>%s</name><type>TXT</type><value>%s</value><ttl>600</ttl></item></array></records></modifyZoneDnsRequest>' "$_domain_name" "$_domain_extension" "$existing_items" "$acme_record" "$txtvalue")"
  72. return 0
  73. }
  74. #Usage: fulldomain txtvalue
  75. #Remove the txt record after validation.
  76. dns_openprovider_rm() {
  77. fulldomain="$1"
  78. txtvalue="$2"
  79. OPENPROVIDER_USER="${OPENPROVIDER_USER:-$(_readaccountconf_mutable OPENPROVIDER_USER)}"
  80. OPENPROVIDER_PASSWORDHASH="${OPENPROVIDER_PASSWORDHASH:-$(_readaccountconf_mutable OPENPROVIDER_PASSWORDHASH)}"
  81. if [ -z "$OPENPROVIDER_USER" ] || [ -z "$OPENPROVIDER_PASSWORDHASH" ]; then
  82. _err "You didn't specify the openprovider user and/or password hash."
  83. return 1
  84. fi
  85. # save the username and password to the account conf file.
  86. _saveaccountconf_mutable OPENPROVIDER_USER "$OPENPROVIDER_USER"
  87. _saveaccountconf_mutable OPENPROVIDER_PASSWORDHASH "$OPENPROVIDER_PASSWORDHASH"
  88. _debug "First detect the root zone"
  89. if ! _get_root "$fulldomain"; then
  90. _err "invalid domain"
  91. return 1
  92. fi
  93. _debug _domain_name "$_domain_name"
  94. _debug _domain_extension "$_domain_extension"
  95. _debug "Getting current records"
  96. existing_items=""
  97. results_retrieved=0
  98. while true; do
  99. _openprovider_request "$(printf '<searchZoneRecordDnsRequest><name>%s.%s</name><offset>%s</offset></searchZoneRecordDnsRequest>' "$_domain_name" "$_domain_extension" "$results_retrieved")"
  100. # Remove acme records from items
  101. items="$response"
  102. while true; do
  103. item="$(echo "$items" | _egrep_o '<openXML>.*<\/openXML>' | sed -n 's/.*\(<item>.*<\/item>\).*/\1/p')"
  104. _debug existing_items "$existing_items"
  105. _debug results_retrieved "$results_retrieved"
  106. _debug item "$item"
  107. if [ -z "$item" ]; then
  108. break
  109. fi
  110. tmpitem="$(echo "$item" | sed 's/\*/\\*/g')"
  111. items="$(echo "$items" | sed "s|${tmpitem}||")"
  112. results_retrieved="$(_math "$results_retrieved" + 1)"
  113. if ! echo "$item" | grep -v "$fulldomain"; then
  114. _debug "acme record, skipping" "$item"
  115. continue
  116. fi
  117. new_item="$(echo "$item" | sed -n 's/.*<item>.*\(<name>\(.*\)\.'"$_domain_name"'\.'"$_domain_extension"'<\/name>.*\(<type>.*<\/type>\).*\(<value>.*<\/value>\).*\(<prio>.*<\/prio>\).*\(<ttl>.*<\/ttl>\)\).*<\/item>.*/<item><name>\2<\/name>\3\4\5\6<\/item>/p')"
  118. if [ -z "$new_item" ]; then
  119. # domain apex
  120. new_item="$(echo "$item" | sed -n 's/.*<item>.*\(<name>\(.*\)'"$_domain_name"'\.'"$_domain_extension"'<\/name>.*\(<type>.*<\/type>\).*\(<value>.*<\/value>\).*\(<prio>.*<\/prio>\).*\(<ttl>.*<\/ttl>\)\).*<\/item>.*/<item><name>\2<\/name>\3\4\5\6<\/item>/p')"
  121. fi
  122. if [ -z "$(echo "$new_item" | _egrep_o ".*<type>(A|AAAA|CNAME|MX|SPF|SRV|TXT|TLSA|SSHFP|CAA|NS)<\/type>.*")" ]; then
  123. _debug "not an allowed record type, skipping" "$new_item"
  124. continue
  125. fi
  126. existing_items="$existing_items$new_item"
  127. done
  128. total="$(echo "$response" | _egrep_o '<total>.*?<\/total>' | sed -n 's/.*<total>\(.*\)<\/total>.*/\1/p')"
  129. _debug total "$total"
  130. if [ "$results_retrieved" -eq "$total" ]; then
  131. break
  132. fi
  133. done
  134. _debug "Removing acme record"
  135. _openprovider_request "$(printf '<modifyZoneDnsRequest><domain><name>%s</name><extension>%s</extension></domain><type>master</type><records><array>%s</array></records></modifyZoneDnsRequest>' "$_domain_name" "$_domain_extension" "$existing_items")"
  136. return 0
  137. }
  138. #################### Private functions below ##################################
  139. #_acme-challenge.www.domain.com
  140. #returns
  141. # _domain_name=domain
  142. # _domain_extension=com
  143. _get_root() {
  144. domain=$1
  145. i=2
  146. results_retrieved=0
  147. while true; do
  148. h=$(echo "$domain" | cut -d . -f $i-100)
  149. _debug h "$h"
  150. if [ -z "$h" ]; then
  151. #not valid
  152. return 1
  153. fi
  154. _openprovider_request "$(printf '<searchDomainRequest><domainNamePattern>%s</domainNamePattern><offset>%s</offset></searchDomainRequest>' "$(echo "$h" | cut -d . -f 1)" "$results_retrieved")"
  155. items="$response"
  156. while true; do
  157. item="$(echo "$items" | _egrep_o '<openXML>.*<\/openXML>' | sed -n 's/.*\(<domain>.*<\/domain>\).*/\1/p')"
  158. _debug existing_items "$existing_items"
  159. _debug results_retrieved "$results_retrieved"
  160. _debug item "$item"
  161. if [ -z "$item" ]; then
  162. break
  163. fi
  164. tmpitem="$(echo "$item" | sed 's/\*/\\*/g')"
  165. items="$(echo "$items" | sed "s|${tmpitem}||")"
  166. results_retrieved="$(_math "$results_retrieved" + 1)"
  167. _domain_name="$(echo "$item" | sed -n 's/.*<domain>.*<name>\(.*\)<\/name>.*<\/domain>.*/\1/p')"
  168. _domain_extension="$(echo "$item" | sed -n 's/.*<domain>.*<extension>\(.*\)<\/extension>.*<\/domain>.*/\1/p')"
  169. _debug _domain_name "$_domain_name"
  170. _debug _domain_extension "$_domain_extension"
  171. if [ "$_domain_name.$_domain_extension" = "$h" ]; then
  172. return 0
  173. fi
  174. done
  175. total="$(echo "$response" | _egrep_o '<total>.*?<\/total>' | sed -n 's/.*<total>\(.*\)<\/total>.*/\1/p')"
  176. _debug total "$total"
  177. if [ "$results_retrieved" -eq "$total" ]; then
  178. results_retrieved=0
  179. i="$(_math "$i" + 1)"
  180. fi
  181. done
  182. return 1
  183. }
  184. _openprovider_request() {
  185. request_xml=$1
  186. xml_prefix='<?xml version="1.0" encoding="UTF-8"?>'
  187. xml_content=$(printf '<openXML><credentials><username>%s</username><hash>%s</hash></credentials>%s</openXML>' "$OPENPROVIDER_USER" "$OPENPROVIDER_PASSWORDHASH" "$request_xml")
  188. response="$(_post "$(echo "$xml_prefix$xml_content" | tr -d '\n')" "$OPENPROVIDER_API" "" "POST" "application/xml")"
  189. _debug response "$response"
  190. if ! _contains "$response" "<openXML><reply><code>0</code>.*</reply></openXML>"; then
  191. _err "API request failed."
  192. return 1
  193. fi
  194. }