From d6f0c2b52b4bb0438d05bb26bed8825a15fbd923 Mon Sep 17 00:00:00 2001 From: Maxim Zalysin Date: Sun, 9 Oct 2016 16:56:04 +0300 Subject: [PATCH 1/8] Add support PowerDNS API (#322) * Add support PowerDNS API * Small fixes --- README.md | 3 +- acme.sh | 7 +++ dnsapi/README.md | 27 ++++++++-- dnsapi/dns_pdns.sh | 127 +++++++++++++++++++++++++++++++++++++++++++++ 4 files changed, 160 insertions(+), 4 deletions(-) create mode 100755 dnsapi/dns_pdns.sh diff --git a/README.md b/README.md index 1e3623e8..c207704b 100644 --- a/README.md +++ b/README.md @@ -241,7 +241,8 @@ You don't have do anything manually! 4. Godaddy.com API 5. OVH, kimsufi, soyoustart and runabove API 6. AWS Route 53, see: https://github.com/Neilpang/acme.sh/issues/65 -7. lexicon dns api: https://github.com/Neilpang/acme.sh/wiki/How-to-use-lexicon-dns-api +7. PowerDNS API, see: https://doc.powerdns.com/md/httpapi/README/ +8. lexicon dns api: https://github.com/Neilpang/acme.sh/wiki/How-to-use-lexicon-dns-api (DigitalOcean, DNSimple, DnsMadeEasy, DNSPark, EasyDNS, Namesilo, NS1, PointHQ, Rage4 and Vultr etc.) ##### More APIs are coming soon... diff --git a/acme.sh b/acme.sh index c385beb3..9387dcec 100755 --- a/acme.sh +++ b/acme.sh @@ -3173,6 +3173,13 @@ _initconf() { # #GD_Secret=\"sADDsdasdfsdfdssdgdsf\" +####################### +#PowerDNS: +#PDNS_Url=\"http://ns.example.com:8081\" +#PDNS_ServerId=\"localhost\" +#PDNS_Token=\"0123456789ABCDEF\" +#PDNS_Ttl=60 + " > $ACCOUNT_CONF_PATH fi } diff --git a/dnsapi/README.md b/dnsapi/README.md index 5aa52cdf..e17406e3 100644 --- a/dnsapi/README.md +++ b/dnsapi/README.md @@ -66,7 +66,7 @@ The `CX_Key` and `CX_Secret` will be saved in `~/.acme.sh/account.conf`, when n ## Use Godaddy.com domain api to automatically issue cert -We support Godaddy integeration. +We support Godaddy integration. First you need to login to your Godaddy account to get your api key and api secret. @@ -89,6 +89,29 @@ acme.sh --issue --dns dns_gd -d aa.com -d www.aa.com The `GD_Key` and `GD_Secret` will be saved in `~/.acme.sh/account.conf`, when next time you use cloudflare api, it will reuse this key. +## Use PowerDNS embedded api to automatically issue cert + +We support PowerDNS embedded API integration. + +First you need to enable api and set your api-token in PowerDNS configuration. + +https://doc.powerdns.com/md/httpapi/README/ + +``` +export PDNS_Url="http://ns.example.com:8081" +export PDNS_ServerId="localhost" +export PDNS_Token="0123456789ABCDEF" +export PDNS_Ttl=60 + +``` + +Ok, let's issue cert now: +``` +acme.sh --issue --dns dns_pdns -d aa.com -d www.aa.com +``` + +The `PDNS_Url`, `PDNS_ServerId`, `PDNS_Token` and `PDNS_Ttl` will be saved in `~/.acme.sh/account.conf`. + ## Use OVH/kimsufi/soyoustart/runabove API https://github.com/Neilpang/acme.sh/wiki/How-to-use-OVH-domain-api @@ -109,8 +132,6 @@ acme.sh --issue --dns dns_myapi -d aa.com -d www.aa.com For more details, please check our sample script: [dns_myapi.sh](dns_myapi.sh) - - # Use lexicon dns api https://github.com/Neilpang/acme.sh/wiki/How-to-use-lexicon-dns-api diff --git a/dnsapi/dns_pdns.sh b/dnsapi/dns_pdns.sh new file mode 100755 index 00000000..842a5b82 --- /dev/null +++ b/dnsapi/dns_pdns.sh @@ -0,0 +1,127 @@ +#!/usr/bin/env sh + +#PowerDNS Emdedded API +#https://doc.powerdns.com/md/httpapi/api_spec/ +# +#PDNS_Url="http://ns.example.com:8081" +#PDNS_ServerId="localhost" +#PDNS_Token="0123456789ABCDEF" +#PDNS_Ttl=60 + +######## Public functions ##################### +#Usage: add _acme-challenge.www.domain.com "123456789ABCDEF0000000000000000000000000000000000000" +dns_pdns_add() { + fulldomain=$1 + txtvalue=$2 + + if [ -z "$PDNS_Url" ] ; then + _err "You don't specify PowerDNS address." + _err "Please set PDNS_Url and try again." + return 1 + fi + + if [ -z "$PDNS_ServerId" ] ; then + _err "You don't specify PowerDNS server id." + _err "Please set you PDNS_ServerId and try again." + return 1 + fi + + if [ -z "$PDNS_Token" ] ; then + _err "You don't specify PowerDNS token." + _err "Please create you PDNS_Token and try again." + return 1 + fi + + if [ -z "$PDNS_Ttl" ] ; then + PDNS_Ttl=60 + fi + + #save the api addr and key to the account conf file. + _saveaccountconf PDNS_Url "$PDNS_Url" + _saveaccountconf PDNS_ServerId "$PDNS_ServerId" + _saveaccountconf PDNS_Token "$PDNS_Token" + + _debug "First detect the root zone" + if ! _get_root $fulldomain ; then + _err "invalid domain" + return 1 + fi + _debug _domain "$_domain" + + if ! set_record "$_domain" "$fulldomain" "$txtvalue" ; then + return 1 + fi + + return 0 +} + +set_record() { + _info "Adding record" + root=$1 + full=$2 + txtvalue=$3 + + if ! _pdns_rest "PATCH" "/api/v1/servers/$PDNS_ServerId/zones/$root." "{\"rrsets\": [{\"name\": \"$full.\", \"changetype\": \"REPLACE\", \"type\": \"TXT\", \"ttl\": $PDNS_Ttl, \"records\": [{\"name\": \"$full.\", \"type\": \"TXT\", \"content\": \"\\\"$txtvalue\\\"\", \"disabled\": false, \"ttl\": $PDNS_Ttl}]}]}" ; then + _err "Set txt record error." + return 1 + fi + if ! _pdns_rest "PUT" "/api/v1/servers/$PDNS_ServerId/zones/$root./notify" ; then + _err "Notify servers error." + return 1 + fi + return 0 +} + +#################### Private functions bellow ################################## +#_acme-challenge.www.domain.com +#returns +# _domain=domain.com +_get_root() { + domain=$1 + i=1 + p=1 + + if _pdns_rest "GET" "/api/v1/servers/$PDNS_ServerId/zones" ; then + _zones_response=$response + fi + + while [ '1' ] ; do + h=$(printf $domain | cut -d . -f $i-100) + if [ -z "$h" ] ; then + return 1 + fi + + if printf "$_zones_response" | grep "\"name\": \"$h.\"" >/dev/null ; then + _domain=$h + return 0 + fi + + p=$i + i=$(expr $i + 1) + done + _debug "$domain not found" + return 1 +} + +_pdns_rest() { + method=$1 + ep=$2 + data=$3 + + _H1="X-API-Key: $PDNS_Token" + + if [ ! "$method" = "GET" ] ; then + _debug data "$data" + response="$(_post "$data" "$PDNS_Url$ep" "" "$method")" + else + response="$(_get "$PDNS_Url$ep")" + fi + + if [ "$?" != "0" ] ; then + _err "error $ep" + return 1 + fi + _debug2 response "$response" + + return 0 +} \ No newline at end of file From b9311282eb6ecf381dc4c2c0acbdb2085fdfe8f2 Mon Sep 17 00:00:00 2001 From: neilpang Date: Sun, 9 Oct 2016 22:15:15 +0800 Subject: [PATCH 2/8] minor fix pdns api --- dnsapi/dns_pdns.sh | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/dnsapi/dns_pdns.sh b/dnsapi/dns_pdns.sh index 842a5b82..30c6d658 100755 --- a/dnsapi/dns_pdns.sh +++ b/dnsapi/dns_pdns.sh @@ -8,6 +8,8 @@ #PDNS_Token="0123456789ABCDEF" #PDNS_Ttl=60 +DEFAULT_PDNS_TTL=60 + ######## Public functions ##################### #Usage: add _acme-challenge.www.domain.com "123456789ABCDEF0000000000000000000000000000000000000" dns_pdns_add() { @@ -33,13 +35,17 @@ dns_pdns_add() { fi if [ -z "$PDNS_Ttl" ] ; then - PDNS_Ttl=60 + PDNS_Ttl=$DEFAULT_PDNS_TTL fi #save the api addr and key to the account conf file. _saveaccountconf PDNS_Url "$PDNS_Url" _saveaccountconf PDNS_ServerId "$PDNS_ServerId" _saveaccountconf PDNS_Token "$PDNS_Token" + + if [ "$PDNS_Ttl" != "$DEFAULT_PDNS_TTL" ] ; then + _saveaccountconf PDNS_Ttl "$PDNS_Ttl" + fi _debug "First detect the root zone" if ! _get_root $fulldomain ; then From 483ebc81410a87fbbe4f30343606d2e29aa55758 Mon Sep 17 00:00:00 2001 From: neil Date: Sun, 9 Oct 2016 22:17:45 +0800 Subject: [PATCH 3/8] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index c207704b..609de73c 100644 --- a/README.md +++ b/README.md @@ -241,7 +241,7 @@ You don't have do anything manually! 4. Godaddy.com API 5. OVH, kimsufi, soyoustart and runabove API 6. AWS Route 53, see: https://github.com/Neilpang/acme.sh/issues/65 -7. PowerDNS API, see: https://doc.powerdns.com/md/httpapi/README/ +7. PowerDNS API 8. lexicon dns api: https://github.com/Neilpang/acme.sh/wiki/How-to-use-lexicon-dns-api (DigitalOcean, DNSimple, DnsMadeEasy, DNSPark, EasyDNS, Namesilo, NS1, PointHQ, Rage4 and Vultr etc.) From 095fe2ed1b1e338e012174a6244d7e34ab9035ee Mon Sep 17 00:00:00 2001 From: root Date: Sun, 9 Oct 2016 22:19:35 +0800 Subject: [PATCH 4/8] minor --- dnsapi/dns_ovh.sh | 0 1 file changed, 0 insertions(+), 0 deletions(-) mode change 100644 => 100755 dnsapi/dns_ovh.sh diff --git a/dnsapi/dns_ovh.sh b/dnsapi/dns_ovh.sh old mode 100644 new mode 100755 From 66990cf872e1c9c7878b11be8a03854ca62bb128 Mon Sep 17 00:00:00 2001 From: neilpang Date: Sun, 9 Oct 2016 22:27:25 +0800 Subject: [PATCH 5/8] minor --- acme.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/acme.sh b/acme.sh index 9387dcec..19a8296c 100755 --- a/acme.sh +++ b/acme.sh @@ -1368,7 +1368,7 @@ _readlink() { __initHome() { if [ -z "$_SCRIPT_HOME" ] ; then if _exists readlink && _exists dirname ; then - _debug "Lets guess script dir." + _debug "Lets find script dir." _debug "_SCRIPT_" "$_SCRIPT_" _script="$(_readlink "$_SCRIPT_")" _debug "_script" "$_script" @@ -3362,7 +3362,7 @@ install() { if [ -z "$NO_DETECT_SH" ] ; then #Modify shebang if _exists bash ; then - _info "Good, bash is installed, change the shebang to use bash as prefered." + _info "Good, bash is found, so change the shebang to use bash as prefered." _shebang='#!/usr/bin/env bash' _setShebang "$LE_WORKING_DIR/$PROJECT_ENTRY" "$_shebang" if [ -d "$LE_WORKING_DIR/dnsapi" ] ; then From f78babfaa0ad334cdb6056bed02562abb1c8749a Mon Sep 17 00:00:00 2001 From: neil Date: Mon, 10 Oct 2016 19:47:16 +0800 Subject: [PATCH 6/8] nc (#324) --- acme.sh | 28 ++++++++++++++++------------ 1 file changed, 16 insertions(+), 12 deletions(-) diff --git a/acme.sh b/acme.sh index 19a8296c..fc7aa7b7 100755 --- a/acme.sh +++ b/acme.sh @@ -1205,26 +1205,30 @@ _startserver() { _debug "startserver: $$" nchelp="$(nc -h 2>&1)" - if echo "$nchelp" | grep "\-q[ ,]" >/dev/null ; then - _NC="nc -q 1 -l $ncaddr" - else - if echo "$nchelp" | grep "GNU netcat" >/dev/null && echo "$nchelp" | grep "\-c, \-\-close" >/dev/null ; then - _NC="nc -c -l $ncaddr" - elif echo "$nchelp" | grep "\-N" |grep "Shutdown the network socket after EOF on stdin" >/dev/null ; then - _NC="nc -N -l $ncaddr" - else - _NC="nc -l $ncaddr" - fi - fi - _debug Le_HTTPPort "$Le_HTTPPort" _debug Le_Listen_V4 "$Le_Listen_V4" _debug Le_Listen_V6 "$Le_Listen_V6" + _NC="nc" + if [ "$Le_Listen_V4" ] ; then _NC="$_NC -4" elif [ "$Le_Listen_V6" ] ; then _NC="$_NC -6" fi + + if echo "$nchelp" | grep "\-q[ ,]" >/dev/null ; then + _NC="$_NC -q 1 -l $ncaddr" + else + if echo "$nchelp" | grep "GNU netcat" >/dev/null && echo "$nchelp" | grep "\-c, \-\-close" >/dev/null ; then + _NC="$_NC -c -l $ncaddr" + elif echo "$nchelp" | grep "\-N" |grep "Shutdown the network socket after EOF on stdin" >/dev/null ; then + _NC="$_NC -N -l $ncaddr" + else + _NC="$_NC -l $ncaddr" + fi + fi + + _debug "_NC" "$_NC" # while true ; do From 81f27e907723079c82789d82ceb14977a2554e4b Mon Sep 17 00:00:00 2001 From: neil Date: Tue, 11 Oct 2016 18:05:32 +0800 Subject: [PATCH 7/8] minor, get the error info, if it contains CRLF --- acme.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/acme.sh b/acme.sh index 19a8296c..98df2e48 100755 --- a/acme.sh +++ b/acme.sh @@ -2435,7 +2435,7 @@ issue() { fi if [ "$status" = "invalid" ] ; then - error="$(echo "$response" | _egrep_o '"error":\{[^\}]*\}')" + error="$(echo "$response" | tr -d "\r\n" | _egrep_o '"error":\{[^\}]*\}')" _debug2 error "$error" errordetail="$(echo $error | _egrep_o '"detail": *"[^"]*"' | cut -d '"' -f 4)" _debug2 errordetail "$errordetail" @@ -2447,7 +2447,7 @@ issue() { if [ "$DEBUG" ] ; then if [ "$vtype" = "$VTYPE_HTTP" ] ; then _debug "Debug: get token url." - _get "http://$d/.well-known/acme-challenge/$token" + _get "http://$d/.well-known/acme-challenge/$token" "" 1 fi fi _clearupwebbroot "$_currentRoot" "$removelevel" "$token" From b15cfc2c5a5f8f7a80ae01d270b91652721e288a Mon Sep 17 00:00:00 2001 From: neil Date: Tue, 11 Oct 2016 18:30:38 +0800 Subject: [PATCH 8/8] minor --- acme.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/acme.sh b/acme.sh index 7536a2d9..9ff54d32 100755 --- a/acme.sh +++ b/acme.sh @@ -2439,9 +2439,9 @@ issue() { fi if [ "$status" = "invalid" ] ; then - error="$(echo "$response" | tr -d "\r\n" | _egrep_o '"error":\{[^\}]*\}')" + error="$(echo "$response" | tr -d "\r\n" | _egrep_o '"error":\{[^\}]*')" _debug2 error "$error" - errordetail="$(echo $error | _egrep_o '"detail": *"[^"]*"' | cut -d '"' -f 4)" + errordetail="$(echo "$error" | _egrep_o '"detail": *"[^"]*' | cut -d '"' -f 4)" _debug2 errordetail "$errordetail" if [ "$errordetail" ] ; then _err "$d:Verify error:$errordetail"