You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

406 lines
16 KiB

5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
  1. #!/usr/bin/env sh
  2. ## Name: dns_pleskxml.sh
  3. ## Created by Stilez.
  4. ## Also uses some code from PR#1832 by @romanlum (https://github.com/Neilpang/acme.sh/pull/1832/files)
  5. ## This DNS-01 method uses the Plesk XML API described at:
  6. ## https://docs.plesk.com/en-US/12.5/api-rpc/about-xml-api.28709
  7. ## and more specifically: https://docs.plesk.com/en-US/12.5/api-rpc/reference.28784
  8. ## Note: a DNS ID with host = empty string is OK for this API, see
  9. ## https://docs.plesk.com/en-US/obsidian/api-rpc/about-xml-api/reference/managing-dns/managing-dns-records/adding-dns-record.34798
  10. ## For example, to add a TXT record to DNS alias domain "acme-alias.com" would be a valid Plesk action.
  11. ## So this API module can handle such a request, if needed.
  12. ## For ACME v2 purposes, new TXT records are appended when added, and removing one TXT record will not affect any other TXT records.
  13. ## The user credentials (username+password) and URL/URI for the Plesk XML API must be set by the user
  14. ## before this module is called (case sensitive):
  15. ##
  16. ## ```
  17. ## export pleskxml_uri="https://address-of-my-plesk-server.net:8443/enterprise/control/agent.php"
  18. ## (or probably something similar)
  19. ## export pleskxml_user="my plesk username"
  20. ## export pleskxml_pass="my plesk password"
  21. ## ```
  22. ## Ok, let's issue a cert now:
  23. ## ```
  24. ## acme.sh --issue --dns dns_pleskxml -d example.com -d www.example.com
  25. ## ```
  26. ##
  27. ## The `pleskxml_uri`, `pleskxml_user` and `pleskxml_pass` will be saved in `~/.acme.sh/account.conf` and reused when needed.
  28. #################### INTERNAL VARIABLES + NEWLINE + API TEMPLATES ##################################
  29. pleskxml_init_checks_done=0
  30. # Variable containing bare newline - not a style issue
  31. # shellcheck disable=SC1004
  32. NEWLINE='\
  33. '
  34. pleskxml_tplt_get_domains="<packet><customer><get-domain-list><filter/></get-domain-list></customer></packet>"
  35. # Get a list of domains that PLESK can manage, so we can check root domain + host for acme.sh
  36. # Also used to test credentials and URI.
  37. # No params.
  38. pleskxml_tplt_get_dns_records="<packet><dns><get_rec><filter><site-id>%s</site-id></filter></get_rec></dns></packet>"
  39. # Get all DNS records for a Plesk domain ID.
  40. # PARAM = Plesk domain id to query
  41. pleskxml_tplt_add_txt_record="<packet><dns><add_rec><site-id>%s</site-id><type>TXT</type><host>%s</host><value>%s</value></add_rec></dns></packet>"
  42. # Add a TXT record to a domain.
  43. # PARAMS = (1) Plesk internal domain ID, (2) "hostname" for the new record, eg '_acme_challenge', (3) TXT record value
  44. pleskxml_tplt_rmv_dns_record="<packet><dns><del_rec><filter><id>%s</id></filter></del_rec></dns></packet>"
  45. # Delete a specific TXT record from a domain.
  46. # PARAM = the Plesk internal ID for the DNS record to be deleted
  47. #################### Public functions ##################################
  48. #Usage: dns_pleskxml_add _acme-challenge.www.domain.com "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
  49. dns_pleskxml_add() {
  50. fulldomain=$1
  51. txtvalue=$2
  52. _info "Entering dns_pleskxml_add() to add TXT record '$txtvalue' to domain '$fulldomain'..."
  53. # Get credentials if not already checked, and confirm we can log in to Plesk XML API
  54. if ! _credential_check; then
  55. return 1
  56. fi
  57. # Get root and subdomain details, and Plesk domain ID
  58. if ! _pleskxml_get_root_domain "$fulldomain"; then
  59. return 1
  60. fi
  61. _debug 'Credentials OK, and domain identified. Calling Plesk XML API to add TXT record'
  62. # printf using template in a variable - not a style issue
  63. # shellcheck disable=SC2059
  64. request="$(printf "$pleskxml_tplt_add_txt_record" "$root_domain_id" "$sub_domain_name" "$txtvalue")"
  65. if ! _call_api "$request"; then
  66. return 1
  67. fi
  68. # OK, we should have added a TXT record. Let's check and return success if so.
  69. # All that should be left in the result, is one section, containing <result><status>ok</status><id>NEW_DNS_RECORD_ID</id></result>
  70. results="$(_api_response_split "$pleskxml_prettyprint_result" 'result' '<status>')"
  71. if ! _value "$results" | grep '<status>ok</status>' | grep '<id>[0-9]\{1,\}</id>' >/dev/null; then
  72. # Error - doesn't contain expected string. Something's wrong.
  73. _err 'Error when calling Plesk XML API.'
  74. _err 'The result did not contain the expected <id>XXXXX</id> section, or contained other values as well.'
  75. _err 'This is unexpected: something has gone wrong.'
  76. _err 'The full response was:\n' "$pleskxml_prettyprint_result"
  77. return 1
  78. fi
  79. recid="$(_value "$results" | grep '<id>[0-9]\{1,\}</id>' | sed 's/^.*<id>\([0-9]\{1,\}\)<\/id>.*$/\1/')"
  80. _info "Success. TXT record appears to be correctly added (Plesk record ID=$recid). Exiting dns_pleskxml_add()."
  81. return 0
  82. }
  83. #Usage: dns_pleskxml_rm _acme-challenge.www.domain.com "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
  84. dns_pleskxml_rm() {
  85. fulldomain=$1
  86. txtvalue=$2
  87. _info "Entering dns_pleskxml_rm() to remove TXT record '$txtvalue' from domain '$fulldomain'..."
  88. # Get credentials if not already checked, and confirm we can log in to Plesk XML API
  89. if ! _credential_check; then
  90. return 1
  91. fi
  92. # Get root and subdomain details, and Plesk domain ID
  93. if ! _pleskxml_get_root_domain "$fulldomain"; then
  94. return 1
  95. fi
  96. _debug 'Credentials OK, and domain identified. Calling Plesk XML API to get list of TXT records and their IDs'
  97. # printf using template in a variable - not a style issue
  98. # shellcheck disable=SC2059
  99. request="$(printf "$pleskxml_tplt_get_dns_records" "$root_domain_id")"
  100. if ! _call_api "$request"; then
  101. return 1
  102. fi
  103. # Reduce output to one line per DNS record, filtered for TXT records with a record ID only (which they should all have)
  104. reclist="$(_api_response_split "$pleskxml_prettyprint_result" 'result' '<status>ok</status>' \
  105. | grep "<site-id>${root_domain_id}</site-id>" \
  106. | grep '<id>[0-9]\{1,\}</id>' \
  107. | grep '<type>TXT</type>'
  108. )"
  109. if [ -z "$reclist" ]; then
  110. _err "No TXT records found for root domain ${root_domain_name} (Plesk domain ID ${root_domain_id}). Exiting."
  111. return 1
  112. fi
  113. _debug "Got list of DNS TXT records for root domain '$root_domain_name'. Full list is:"'\n'"$reclist"
  114. _debug "DNS TXT records for host '$fulldomain':"'\n'"$(_value "$reclist" | grep "<host>${fulldomain}.</host>")"
  115. recid="$(_value "$reclist" \
  116. | grep "<host>${fulldomain}.</host>" \
  117. | grep "<value>${txtvalue}</value>" \
  118. | sed 's/^.*<id>\([0-9]\{1,\}\)<\/id>.*$/\1/'
  119. )"
  120. if ! _value "$recid" | grep '^[0-9]\{1,\}$' >/dev/null; then
  121. _err "DNS records for root domain '${root_domain_name}' (Plesk ID ${root_domain_id}) + host '${sub_domain_name}' do not contain the TXT record '${txtvalue}'"
  122. _err "Cannot delete TXT record. Exiting."
  123. return 1
  124. fi
  125. _debug "Found Plesk record ID for target text string '${txtvalue}': ID=${recid}"
  126. _debug 'Calling Plesk XML API to remove TXT record'
  127. # printf using template in a variable - not a style issue
  128. # shellcheck disable=SC2059
  129. request="$(printf "$pleskxml_tplt_rmv_dns_record" "$recid")"
  130. if ! _call_api "$request"; then
  131. return 1
  132. fi
  133. # OK, we should have removed a TXT record. Let's check and return success if so.
  134. # All that should be left in the result, is one section, containing <result><status>ok</status><id>PLESK_DELETED_DNS_RECORD_ID</id></result>
  135. results="$(_api_response_split "$pleskxml_prettyprint_result" 'result' '<status>')"
  136. if ! _value "$results" | grep '<status>ok</status>' | grep '<id>[0-9]\{1,\}</id>' >/dev/null; then
  137. # Error - doesn't contain expected string. Something's wrong.
  138. _err 'Error when calling Plesk XML API.'
  139. _err 'The result did not contain the expected <id>XXXXX</id> section, or contained other values as well.'
  140. _err 'This is unexpected: something has gone wrong.'
  141. _err 'The full response was:\n' "$pleskxml_prettyprint_result"
  142. return 1
  143. fi
  144. _info "Success. TXT record appears to be correctly removed. Exiting dns_pleskxml_rm()."
  145. return 0
  146. }
  147. #################### Private functions below (utility functions) ##################################
  148. # Outputs value of a variable without additional newlines etc
  149. _value() {
  150. printf '%s' "$1"
  151. }
  152. # Outputs value of a variable (FQDN) and cuts it at 2 specified '.' delimiters, returning the text in between
  153. # $1, $2 = where to cut
  154. # $3 = FQDN
  155. _valuecut() {
  156. printf '%s' "$3" | cut -d . -f "${1}-${2}"
  157. }
  158. # Counts '.' present in a domain name
  159. # $1 = domain name
  160. _countdots() {
  161. _value "$1" | tr -dc '.' | wc -c
  162. }
  163. # Cleans up an API response, splits it "one line per item in the response" and greps for a string that in the context, identifies "useful" lines
  164. # $1 - result string from API
  165. # $2 - plain text tag to resplit on (usually "result" or "domain"). NOT REGEX
  166. # $3 - basic regex to recognise useful return lines
  167. # note: $3 matches via basic NOT extended regex (BRE), as extended regex capabilities not needed at the moment.
  168. # Last line could change to <sed -n '/.../p'> instead, with suitable escaping of ['"/$],
  169. # if future Plesk XML API changes ever require extended regex
  170. _api_response_split() {
  171. printf '%s' "$1" \
  172. | sed 's/^ +//;s/ +$//' \
  173. | tr -d '\n\r' \
  174. | sed "s/<\/\{0,1\}$2>/${NEWLINE}/g" \
  175. | grep "$3"
  176. }
  177. #################### Private functions below (DNS functions) ##################################
  178. # Calls Plesk XML API, and checks results for obvious issues
  179. _call_api() {
  180. request="$1"
  181. errtext=''
  182. _debug 'Entered _call_api(). Calling Plesk XML API with request:\n' "'${request}'"
  183. export _H1="HTTP_AUTH_LOGIN: $pleskxml_user"
  184. export _H2="HTTP_AUTH_PASSWD: $pleskxml_pass"
  185. export _H3="content-Type: text/xml"
  186. export _H4="HTTP_PRETTY_PRINT: true"
  187. pleskxml_prettyprint_result="$(_post "${request}" "$pleskxml_uri" "" "POST")"
  188. pleskxml_retcode="$?"
  189. _debug 'The responses from the Plesk XML server were:\n' "retcode=$pleskxml_retcode. Literal response:"'\n' "'$pleskxml_prettyprint_result'"
  190. # Detect any <status> that isn't "ok". None of the used calls should fail if the API is working correctly.
  191. # Also detect if there simply aren't any status lines (null result?) and report that, as well.
  192. statuslines_count_total="$(echo "$pleskxml_prettyprint_result" | grep -c '^ *<status>[^<]*</status> *$')"
  193. statuslines_count_okay="$(echo "$pleskxml_prettyprint_result" | grep -c '^ *<status>ok</status> *$')"
  194. if [ -z "$statuslines_count_total" ]; then
  195. # We have no status lines at all. Results are empty
  196. errtext='The Plesk XML API unexpectedly returned an empty set of results for this call.'
  197. elif [ "$statuslines_count_okay" -ne "$statuslines_count_total" ]; then
  198. # We have some status lines that aren't "ok". Any available details are in API response fields "status" "errcode" and "errtext"
  199. # Workaround for basic regex:
  200. # - filter output to keep only lines like this: "SPACES<TAG>text</TAG>SPACES" (shouldn't be necessary with prettyprint but guarantees subsequent code is ok)
  201. # - then edit the 3 "useful" error tokens individually and remove closing tags on all lines
  202. # - then filter again to remove all lines not edited (which will be the lines not starting A-Z)
  203. errtext="$(_value "$pleskxml_prettyprint_result" \
  204. | grep '^ *<[a-z]\{1,\}>[^<]*<\/[a-z]\{1,\}> *$' \
  205. | sed 's/^ *<status>/Status: /;s/^ *<errcode>/Error code: /;s/^ *<errtext>/Error text: /;s/<\/.*$//' \
  206. | grep '^[A-Z]'
  207. )"
  208. fi
  209. if [ "$pleskxml_retcode" -ne 0 ] || [ "$errtext" != "" ]; then
  210. # Call failed, for reasons either in the retcode or the response text...
  211. if [ "$pleskxml_retcode" -eq 0 ]; then
  212. _err "The POST request was successfully sent to the Plesk server."
  213. else
  214. _err "The return code for the POST request was $pleskxml_retcode (non-zero = failure in submitting request to server)."
  215. fi
  216. if [ "$errtext" != "" ]; then
  217. _err 'The error responses received from the Plesk server were:\n' "$errtext"
  218. else
  219. _err "No additional error messages were received back from the Plesk server"
  220. fi
  221. _err "The Plesk XML API call failed."
  222. return 1
  223. fi
  224. _debug "Leaving _call_api(). Successful call."
  225. return 0
  226. }
  227. # Startup checks (credentials, URI)
  228. _credential_check() {
  229. _debug "Checking Plesk XML API login credentials and URI..."
  230. if [ "$pleskxml_init_checks_done" -eq 1 ]; then
  231. _debug "Initial checks already done, no need to repeat. Skipped."
  232. return 0
  233. fi
  234. pleskxml_user="${pleskxml_user:-$(_readaccountconf_mutable pleskxml_user)}"
  235. pleskxml_pass="${pleskxml_pass:-$(_readaccountconf_mutable pleskxml_pass)}"
  236. pleskxml_uri="${pleskxml_uri:-$(_readaccountconf_mutable pleskxml_uri)}"
  237. if [ -z "$pleskxml_user" ] || [ -z "$pleskxml_pass" ] || [ -z "$pleskxml_uri" ]; then
  238. pleskxml_user=""
  239. pleskxml_pass=""
  240. pleskxml_uri=""
  241. _err "You didn't specify one or more of the Plesk XML API username, password, or URI."
  242. _err "Please create these and try again."
  243. _err "Instructions are in the 'dns_pleskxml' plugin source code or in the acme.sh documentation."
  244. return 1
  245. fi
  246. # Test the API is usable, by trying to read the list of managed domains...
  247. _call_api "$pleskxml_tplt_get_domains"
  248. if [ "$pleskxml_retcode" -ne 0 ]; then
  249. _err '\nFailed to access Plesk XML API.'
  250. _err "Please check your login credentials and Plesk URI, and that the URI is reachable, and try again."
  251. return 1
  252. fi
  253. _saveaccountconf_mutable pleskxml_uri "$pleskxml_uri"
  254. _saveaccountconf_mutable pleskxml_user "$pleskxml_user"
  255. _saveaccountconf_mutable pleskxml_pass "$pleskxml_pass"
  256. _debug "Test login to Plesk XML API successful. Login credentials and URI successfully saved to the acme.sh configuration file for future use."
  257. pleskxml_init_checks_done=1
  258. return 0
  259. }
  260. # For a FQDN, identify the root domain managed by Plesk, its domain ID in Plesk, and the host if any.
  261. # IMPORTANT NOTE: a result with host = empty string is OK for this API, see
  262. # https://docs.plesk.com/en-US/obsidian/api-rpc/about-xml-api/reference/managing-dns/managing-dns-records/adding-dns-record.34798
  263. # See notes at top of this file
  264. _pleskxml_get_root_domain() {
  265. original_full_domain_name="$1"
  266. _debug "Identifying DNS root domain for '$original_full_domain_name' that is managed by the Plesk account."
  267. # test if the domain as provided is valid for splitting.
  268. if ! _countdots "$original_full_domain_name"; then
  269. _err "Invalid domain. The ACME domain must contain at least two parts (aa.bb) to identify a domain and tld for the TXT record."
  270. return 1
  271. fi
  272. _debug "Querying Plesk server for list of managed domains..."
  273. _call_api "$pleskxml_tplt_get_domains"
  274. if [ "$pleskxml_retcode" -ne 0 ]; then
  275. return 1
  276. fi
  277. # Generate a crude list of domains known to this Plesk account.
  278. # We convert <ascii-name> tags to <name> so it'll flag on a hit with either <name> or <ascii-name> fields,
  279. # for non-Western character sets.
  280. # Output will be one line per known domain, containing 2 <name> tages and a single <id> tag
  281. # We don't actually need to check for type, name, *and* id, but it guarantees only usable lines are returned.
  282. output="$(_api_response_split "$pleskxml_prettyprint_result" 'domain' '<type>domain</type>' | sed 's/<ascii-name>/<name>/g;s/<\/ascii-name>/<\/name>/g' | grep '<name>' | grep '<id>')"
  283. _debug 'Domains managed by Plesk server are (ignore the hacked output):\n' "$output"
  284. # loop and test if domain, or any parent domain, is managed by Plesk
  285. # Loop until we don't have any '.' in the string we're testing as a candidate Plesk-managed domain
  286. root_domain_name="$original_full_domain_name"
  287. while true; do
  288. _debug "Checking if '$root_domain_name' is managed by the Plesk server..."
  289. root_domain_id="$(_value "$output" | grep "<name>$root_domain_name</name>" | _head_n 1 | sed 's/^.*<id>\([0-9]\{1,\}\)<\/id>.*$/\1/')"
  290. if [ -n "$root_domain_id" ]; then
  291. # Found a match
  292. # SEE IMPORTANT NOTE ABOVE - THIS FUNCTION CAN RETURN HOST='', AND THAT'S OK FOR PLESK XML API WHICH ALLOWS IT.
  293. # SO WE HANDLE IT AND DON'T PREVENT IT
  294. sub_domain_name="$(_value "$original_full_domain_name" | sed "s/\.\{0,1\}${root_domain_name}"'$//')"
  295. _info "Success. Matched host '$original_full_domain_name' to: DOMAIN '${root_domain_name}' (Plesk ID '${root_domain_id}'), HOST '${sub_domain_name}'. Returning."
  296. return 0
  297. fi
  298. # No match, try next parent up (if any)...
  299. root_domain_name="$(_valuecut 2 1000 "$root_domain_name")"
  300. if ! _countdots "$root_domain_name"; then
  301. _debug "No match, and next parent would be a TLD..."
  302. _err "Cannot find '$original_full_domain_name' or any parent domain of it, in Plesk."
  303. _err "Are you sure that this domain is managed by this Plesk server?"
  304. return 1
  305. fi
  306. _debug "No match, trying next parent up..."
  307. done
  308. }