最終更新 1 month ago

mk-ssl-cert.sh Raw
1#!/bin/bash
2set -euo pipefail
3
4source .env
5SSL_FQDN=${SSL_DOMAIN:?Insert hostname this certificate is for}
6SSL_CN=${SSL_COMMON_NAME:?Insert common name for this certificate}
7
8printf "Creating self-signed SSL certificate...\n"
9openssl req -x509 -nodes -newkey rsa:2048 -keyout "/usr/local/share/ca-certificates/${SSL_FQDN}.key" -out "/usr/local/share/ca-certificates/${SSL_FQDN}.crt" -days 365 -subj "/CN=${SSL_CN}"
10printf "Updating system's trusted certificates...\n"
11update-ca-certificates