Browse Source
Merge pull request #1 from Neilpang/master
Merge pull request #1 from Neilpang/master
Merge Neilpang/le into raunsbaekdk/lepull/102/head
9 years ago
7 changed files with 1109 additions and 88 deletions
@ -0,0 +1,86 @@ |
# How to use dns api |
## Use CloudFlare domain api to automatically issue cert |
For now, we support clourflare integeration. |
First you need to login to your clourflare account to get your api key. |
``` |
export CF_Key="sdfsdfsdfljlbjkljlkjsdfoiwje" |
export CF_Email="" |
``` |
Ok, let's issue cert now: |
``` |
||| issue dns-cf |
``` |
The `CF_Key` and `CF_Email` will be saved in `~/.le/account.conf`, when next time you use cloudflare api, it will reuse this key. |
## Use domain api to automatically issue cert |
For now, we support integeration. |
First you need to login to your account to get your api key and key id. |
``` |
export DP_Id="1234" |
export DP_Key="sADDsdasdgdsf" |
``` |
Ok, let's issue cert now: |
``` |
||| issue dns-dp |
``` |
The `DP_Id` and `DP_Key` will be saved in `~/.le/account.conf`, when next time you use api, it will reuse this key. |
## Use domain api to automatically issue cert |
For now, we support integeration. |
First you need to login to your account to get your api key and key secret. |
``` |
export CX_Key="1234" |
export CX_Secret="sADDsdasdgdsf" |
``` |
Ok, let's issue cert now: |
``` |
||| issue dns-cx |
``` |
The `CX_Key` and `CX_Secret` will be saved in `~/.le/account.conf`, when next time you use api, it will reuse this key. |
# Use custom api |
If your api is not supported yet, you can write your own dns api. |
Let's assume you want to name it 'myapi', |
1. Create a bash script named `~/.le/`, |
2. In the scrypt, you must have a function named `dns-myapi-add()`. Which will be called by to add dns records. |
3. Then you can use your api to issue cert like: |
``` |
||| issue dns-myapi |
``` |
For more details, please check our sample script: []( |
@ -0,0 +1,168 @@ |
#!/bin/bash |
# |
#CF_Key="sdfsdfsdfljlbjkljlkjsdfoiwje" |
# |
#CF_Email="" |
CF_Api="" |
######## Public functions ##################### |
#Usage: add "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs" |
dns-cf-add() { |
fulldomain=$1 |
txtvalue=$2 |
if [ -z "$CF_Key" ] || [ -z "$CF_Email" ] ; then |
_err "You don't specify cloudflare api key and email yet." |
_err "Please create you key and try again." |
return 1 |
fi |
#save the api key and email to the account conf file. |
_saveaccountconf CF_Key "$CF_Key" |
_saveaccountconf CF_Email "$CF_Email" |
_debug "First detect the root zone" |
if ! _get_root $fulldomain ; then |
_err "invalid domain" |
return 1 |
fi |
_debug "Getting txt records" |
_cf_rest GET "/zones/$_domain_id/dns_records?type=TXT&name=$fulldomain" |
if [ "$?" != "0" ] || ! printf $response | grep \"success\":true > /dev/null ; then |
_err "Error" |
return 1 |
fi |
count=$(printf $response | grep -o \"count\":[^,]* | cut -d : -f 2) |
if [ "$count" == "0" ] ; then |
_info "Adding record" |
if _cf_rest POST "/zones/$_domain_id/dns_records" "{\"type\":\"TXT\",\"name\":\"$fulldomain\",\"content\":\"$txtvalue\",\"ttl\":120}"; then |
if printf $response | grep $fulldomain > /dev/null ; then |
_info "Added, sleeping 10 seconds" |
sleep 10 |
#todo: check if the record takes effect |
return 0 |
else |
_err "Add txt record error." |
return 1 |
fi |
fi |
_err "Add txt record error." |
else |
_info "Updating record" |
record_id=$(printf $response | grep -o \"id\":\"[^\"]*\" | cut -d : -f 2 | tr -d \") |
_debug "record_id" $record_id |
_cf_rest PUT "/zones/$_domain_id/dns_records/$record_id" "{\"id\":\"$record_id\",\"type\":\"TXT\",\"name\":\"$fulldomain\",\"content\":\"$txtvalue\",\"zone_id\":\"$_domain_id\",\"zone_name\":\"$_domain\"}" |
if [ "$?" == "0" ]; then |
_info "Updated, sleeping 10 seconds" |
sleep 10 |
#todo: check if the record takes effect |
return 0; |
fi |
_err "Update error" |
return 1 |
fi |
} |
#################### Private functions bellow ################################## |
||| |
#returns |
# _sub_domain=_acme-challenge.www |
# |
# _domain_id=sdjkglgdfewsdfg |
_get_root() { |
domain=$1 |
i=2 |
p=1 |
while [ '1' ] ; do |
h=$(printf $domain | cut -d . -f $i-100) |
if [ -z "$h" ] ; then |
#not valid |
return 1; |
fi |
if ! _cf_rest GET "zones?name=$h" ; then |
return 1 |
fi |
if printf $response | grep \"name\":\"$h\" ; then |
_domain_id=$(printf $response | grep -o \"id\":\"[^\"]*\" | cut -d : -f 2 | tr -d \") |
if [ "$_domain_id" ] ; then |
_sub_domain=$(printf $domain | cut -d . -f 1-$p) |
_domain=$h |
return 0 |
fi |
return 1 |
fi |
p=$i |
let "i+=1" |
done |
return 1 |
} |
_cf_rest() { |
m=$1 |
ep="$2" |
_debug $ep |
if [ "$3" ] ; then |
data="$3" |
_debug data "$data" |
response="$(curl --silent -X $m "$CF_Api/$ep" -H "X-Auth-Email: $CF_Email" -H "X-Auth-Key: $CF_Key" -H "Content-Type: application/json" --data $data)" |
else |
response="$(curl --silent -X $m "$CF_Api/$ep" -H "X-Auth-Email: $CF_Email" -H "X-Auth-Key: $CF_Key" -H "Content-Type: application/json")" |
fi |
if [ "$?" != "0" ] ; then |
_err "error $ep" |
return 1 |
fi |
_debug response "$response" |
return 0 |
} |
_debug() { |
if [ -z "$DEBUG" ] ; then |
return |
fi |
if [ -z "$2" ] ; then |
echo $1 |
else |
echo "$1"="$2" |
fi |
} |
_info() { |
if [ -z "$2" ] ; then |
echo "$1" |
else |
echo "$1"="$2" |
fi |
} |
_err() { |
if [ -z "$2" ] ; then |
echo "$1" >&2 |
else |
echo "$1"="$2" >&2 |
fi |
} |
@ -0,0 +1,234 @@ |
#!/bin/bash |
# Domain api |
# |
#CX_Key="1234" |
# |
#CX_Secret="sADDsdasdgdsf" |
CX_Api="" |
######## Public functions ##################### |
#Usage: add "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs" |
dns-cx-add() { |
fulldomain=$1 |
txtvalue=$2 |
if [ -z "$CX_Key" ] || [ -z "$CX_Secret" ] ; then |
_err "You don't specify api key or secret yet." |
_err "Please create you key and try again." |
return 1 |
fi |
#save the api key and email to the account conf file. |
_saveaccountconf CX_Key "$CX_Key" |
_saveaccountconf CX_Secret "$CX_Secret" |
_debug "First detect the root zone" |
if ! _get_root $fulldomain ; then |
_err "invalid domain" |
return 1 |
fi |
existing_records $_domain $_sub_domain |
_debug count "$count" |
if [ "$?" != "0" ] ; then |
_err "Error get existing records." |
return 1 |
fi |
if [ "$count" == "0" ] ; then |
add_record $_domain $_sub_domain $txtvalue |
else |
update_record $_domain $_sub_domain $txtvalue |
fi |
if [ "$?" == "0" ] ; then |
return 0 |
fi |
return 1 |
} |
#usage: root sub |
#return if the sub record already exists. |
#echos the existing records count. |
# '0' means doesn't exist |
existing_records() { |
_debug "Getting txt records" |
root=$1 |
sub=$2 |
if ! _rest GET "record/$_domain_id?:domain_id?host_id=0&offset=0&row_num=100" ; then |
return 1 |
fi |
count=0 |
seg=$(printf "$response" | grep -o "{[^{]*host\":\"$_sub_domain[^}]*}") |
_debug seg "$seg" |
if [ -z "$seg" ] ; then |
return 0 |
fi |
if printf "$response" | grep '"type":"TXT"' > /dev/null ; then |
count=1 |
record_id=$(printf "$seg" | grep -o \"record_id\":\"[^\"]*\" | cut -d : -f 2 | tr -d \") |
_debug record_id "$record_id" |
return 0 |
fi |
} |
#add the txt record. |
#usage: root sub txtvalue |
add_record() { |
root=$1 |
sub=$2 |
txtvalue=$3 |
fulldomain=$sub.$root |
_info "Adding record" |
if ! _rest POST "record" "{\"domain_id\": $_domain_id, \"host\":\"$_sub_domain\", \"value\":\"$txtvalue\", \"type\":\"TXT\",\"ttl\":600, \"line_id\":1}"; then |
return 1 |
fi |
return 0 |
} |
#update the txt record |
#Usage: root sub txtvalue |
update_record() { |
root=$1 |
sub=$2 |
txtvalue=$3 |
fulldomain=$sub.$root |
_info "Updating record" |
if _rest PUT "record/$record_id" "{\"domain_id\": $_domain_id, \"host\":\"$_sub_domain\", \"value\":\"$txtvalue\", \"type\":\"TXT\",\"ttl\":600, \"line_id\":1}" ; then |
return 0 |
fi |
return 1 |
} |
#################### Private functions bellow ################################## |
||| |
#returns |
# _sub_domain=_acme-challenge.www |
# |
# _domain_id=sdjkglgdfewsdfg |
_get_root() { |
domain=$1 |
i=2 |
p=1 |
if ! _rest GET "domain" ; then |
return 1 |
fi |
while [ '1' ] ; do |
h=$(printf $domain | cut -d . -f $i-100) |
_debug h "$h" |
if [ -z "$h" ] ; then |
#not valid |
return 1; |
fi |
if printf "$response" | grep "$h." ; then |
seg=$(printf "$response" | grep -o "{[^{]*$h\.[^}]*\}" ) |
_debug seg "$seg" |
_domain_id=$(printf "$seg" | grep -o \"id\":\"[^\"]*\" | cut -d : -f 2 | tr -d \") |
_debug _domain_id "$_domain_id" |
if [ "$_domain_id" ] ; then |
_sub_domain=$(printf $domain | cut -d . -f 1-$p) |
_debug _sub_domain $_sub_domain |
_domain=$h |
_debug _domain $_domain |
return 0 |
fi |
return 1 |
fi |
p=$i |
let "i+=1" |
done |
return 1 |
} |
#Usage: method URI data |
_rest() { |
m=$1 |
ep="$2" |
_debug $ep |
url="$REST_API/$ep" |
_debug url "$url" |
cdate=$(date -u "+%Y-%m-%d %H:%M:%S UTC") |
_debug cdate "$cdate" |
data="$3" |
_debug data "$data" |
sec="$CX_Key$url$data$cdate$CX_Secret" |
_debug sec "$sec" |
hmac=$(printf "$sec"| openssl md5 |cut -d " " -f 2) |
_debug hmac "$hmac" |
if [ "$3" ] ; then |
response="$(curl --silent -X $m "$url" -H "API-KEY: $CX_Key" -H "API-REQUEST-DATE: $cdate" -H "API-HMAC: $hmac" -H 'Content-Type: application/json' -d "$data")" |
else |
response="$(curl --silent -X $m "$url" -H "API-KEY: $CX_Key" -H "API-REQUEST-DATE: $cdate" -H "API-HMAC: $hmac" -H 'Content-Type: application/json')" |
fi |
if [ "$?" != "0" ] ; then |
_err "error $ep" |
return 1 |
fi |
_debug response "$response" |
if ! printf "$response" | grep '"message":"success"' > /dev/null ; then |
return 1 |
fi |
return 0 |
} |
_debug() { |
if [ -z "$DEBUG" ] ; then |
return |
fi |
if [ -z "$2" ] ; then |
echo $1 |
else |
echo "$1"="$2" |
fi |
} |
_info() { |
if [ -z "$2" ] ; then |
echo "$1" |
else |
echo "$1"="$2" |
fi |
} |
_err() { |
if [ -z "$2" ] ; then |
echo "$1" >&2 |
else |
echo "$1"="$2" >&2 |
fi |
} |
@ -0,0 +1,229 @@ |
#!/bin/bash |
# Domain api |
# |
#DP_Id="1234" |
# |
#DP_Key="sADDsdasdgdsf" |
DP_Api="" |
######## Public functions ##################### |
#Usage: add "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs" |
dns-dp-add() { |
fulldomain=$1 |
txtvalue=$2 |
if [ -z "$DP_Id" ] || [ -z "$DP_Key" ] ; then |
_err "You don't specify dnspod api key and key id yet." |
_err "Please create you key and try again." |
return 1 |
fi |
#save the api key and email to the account conf file. |
_saveaccountconf DP_Id "$DP_Id" |
_saveaccountconf DP_Key "$DP_Key" |
_debug "First detect the root zone" |
if ! _get_root $fulldomain ; then |
_err "invalid domain" |
return 1 |
fi |
existing_records $_domain $_sub_domain |
_debug count "$count" |
if [ "$?" != "0" ] ; then |
_err "Error get existing records." |
return 1 |
fi |
if [ "$count" == "0" ] ; then |
add_record $_domain $_sub_domain $txtvalue |
else |
update_record $_domain $_sub_domain $txtvalue |
fi |
} |
#usage: root sub |
#return if the sub record already exists. |
#echos the existing records count. |
# '0' means doesn't exist |
existing_records() { |
_debug "Getting txt records" |
root=$1 |
sub=$2 |
if ! _rest POST "Record.List" "login_token=$DP_Id,$DP_Key&domain_id=$_domain_id&sub_domain=$_sub_domain"; then |
return 1 |
fi |
if printf "$response" | grep 'No records' ; then |
count=0; |
return 0 |
fi |
if printf "$response" | grep "Action completed successful" >/dev/null ; then |
count=$(printf "$response" | grep '<type>TXT</type>' | wc -l) |
record_id=$(printf "$response" | grep '^<id>' | tail -1 | cut -d '>' -f 2 | cut -d '<' -f 1) |
return 0 |
else |
_err "get existing records error." |
return 1 |
fi |
count=0 |
} |
#add the txt record. |
#usage: root sub txtvalue |
add_record() { |
root=$1 |
sub=$2 |
txtvalue=$3 |
fulldomain=$sub.$root |
_info "Adding record" |
if ! _rest POST "Record.Create" "login_token=$DP_Id,$DP_Key&format=json&domain_id=$_domain_id&sub_domain=$_sub_domain&record_type=TXT&value=$txtvalue&record_line=默认"; then |
return 1 |
fi |
if printf "$response" | grep "Action completed successful" ; then |
return 0 |
fi |
return 1 #error |
} |
#update the txt record |
#Usage: root sub txtvalue |
update_record() { |
root=$1 |
sub=$2 |
txtvalue=$3 |
fulldomain=$sub.$root |
_info "Updating record" |
if ! _rest POST "Record.Modify" "login_token=$DP_Id,$DP_Key&format=json&domain_id=$_domain_id&sub_domain=$_sub_domain&record_type=TXT&value=$txtvalue&record_line=默认&record_id=$record_id"; then |
return 1 |
fi |
if printf "$response" | grep "Action completed successful" ; then |
return 0 |
fi |
return 1 #error |
} |
#################### Private functions bellow ################################## |
||| |
#returns |
# _sub_domain=_acme-challenge.www |
# |
# _domain_id=sdjkglgdfewsdfg |
_get_root() { |
domain=$1 |
i=2 |
p=1 |
while [ '1' ] ; do |
h=$(printf $domain | cut -d . -f $i-100) |
if [ -z "$h" ] ; then |
#not valid |
return 1; |
fi |
if ! _rest POST "Domain.Info" "login_token=$DP_Id,$DP_Key&format=json&domain=$h"; then |
return 1 |
fi |
if printf "$response" | grep "Action completed successful" ; then |
_domain_id=$(printf "$response" | grep -o \"id\":\"[^\"]*\" | cut -d : -f 2 | tr -d \") |
_debug _domain_id "$_domain_id" |
if [ "$_domain_id" ] ; then |
_sub_domain=$(printf $domain | cut -d . -f 1-$p) |
_debug _sub_domain $_sub_domain |
_domain=$h |
_debug _domain $_domain |
return 0 |
fi |
return 1 |
fi |
p=$i |
let "i+=1" |
done |
return 1 |
} |
#Usage: method URI data |
_rest() { |
m=$1 |
ep="$2" |
_debug $ep |
url="$REST_API/$ep" |
_debug url "$url" |
if [ "$3" ] ; then |
data="$3" |
_debug data "$data" |
response="$(curl --silent -X $m "$url" -d $data)" |
else |
response="$(curl --silent -X $m "$url" )" |
fi |
if [ "$?" != "0" ] ; then |
_err "error $ep" |
return 1 |
fi |
_debug response "$response" |
return 0 |
} |
_debug() { |
if [ -z "$DEBUG" ] ; then |
return |
fi |
if [ -z "$2" ] ; then |
echo $1 |
else |
echo "$1"="$2" |
fi |
} |
_info() { |
if [ -z "$2" ] ; then |
echo "$1" |
else |
echo "$1"="$2" |
fi |
} |
_err() { |
if [ -z "$2" ] ; then |
echo "$1" >&2 |
else |
echo "$1"="$2" >&2 |
fi |
} |
@ -0,0 +1,61 @@ |
#!/bin/bash |
#Here is a sample custom api script. |
#This file name is "" |
#So, here must be a method dns-myapi-add() |
#Which will be called by to add the txt record to your api system. |
#returns 0 meanst success, otherwise error. |
######## Public functions ##################### |
#Usage: add "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs" |
dns-myapi-add() { |
fulldomain=$1 |
txtvalue=$2 |
_err "Not implemented!" |
return 1; |
} |
#################### Private functions bellow ################################## |
_debug() { |
if [ -z "$DEBUG" ] ; then |
return |
fi |
if [ -z "$2" ] ; then |
echo $1 |
else |
echo "$1"="$2" |
fi |
} |
_info() { |
if [ -z "$2" ] ; then |
echo "$1" |
else |
echo "$1"="$2" |
fi |
} |
_err() { |
if [ -z "$2" ] ; then |
echo "$1" >&2 |
else |
echo "$1"="$2" >&2 |
fi |
} |
Reference in new issue