|
| 1 | +package cli |
| 2 | + |
| 3 | +import ( |
| 4 | +"crypto/rand" |
| 5 | +"crypto/rsa" |
| 6 | +"fmt" |
| 7 | +"io/ioutil" |
| 8 | +"log" |
| 9 | +"os" |
| 10 | +"path" |
| 11 | + |
| 12 | +"github.com/Castcloud/castcloud-go-server/Godeps/_workspace/src/github.com/spf13/cobra" |
| 13 | +"github.com/xenolf/lego/acme" |
| 14 | +) |
| 15 | + |
| 16 | +constcaURL="https://acme-v01.api.letsencrypt.org/directory" |
| 17 | +constrsaKeySize=2048 |
| 18 | + |
| 19 | +varsslCmd=&cobra.Command{ |
| 20 | +Use:"ssl <domain>", |
| 21 | +Short:"Enable SSL", |
| 22 | +Run:func(cmd*cobra.Command,args []string) { |
| 23 | +iflen(args)==0 { |
| 24 | +fmt.Println("Usage: ssl <domain>") |
| 25 | +return |
| 26 | +} |
| 27 | + |
| 28 | +sslDir:=path.Join(dir,"ssl") |
| 29 | +err:=os.Mkdir(sslDir,0777) |
| 30 | +iferr!=nil&&!os.IsExist(err) { |
| 31 | +log.Fatal(err) |
| 32 | +} |
| 33 | + |
| 34 | +letsEncrypt(args[0],sslDir) |
| 35 | +}, |
| 36 | +} |
| 37 | + |
| 38 | +typeacmeUserstruct { |
| 39 | +Registration*acme.RegistrationResource |
| 40 | +key*rsa.PrivateKey |
| 41 | +} |
| 42 | + |
| 43 | +func (uacmeUser)GetEmail()string { |
| 44 | +return"" |
| 45 | +} |
| 46 | + |
| 47 | +func (uacmeUser)GetRegistration()*acme.RegistrationResource { |
| 48 | +returnu.Registration |
| 49 | +} |
| 50 | + |
| 51 | +func (uacmeUser)GetPrivateKey()*rsa.PrivateKey { |
| 52 | +returnu.key |
| 53 | +} |
| 54 | + |
| 55 | +funcletsEncrypt(domain,outputDirstring) { |
| 56 | +privateKey,err:=rsa.GenerateKey(rand.Reader,rsaKeySize) |
| 57 | +iferr!=nil { |
| 58 | +log.Fatal(err) |
| 59 | +} |
| 60 | + |
| 61 | +user:=acmeUser{ |
| 62 | +key:privateKey, |
| 63 | +} |
| 64 | + |
| 65 | +client,err:=acme.NewClient(caURL,&user,rsaKeySize,"443") |
| 66 | +iferr!=nil { |
| 67 | +log.Fatal(err) |
| 68 | +} |
| 69 | + |
| 70 | +reg,err:=client.Register() |
| 71 | +iferr!=nil { |
| 72 | +log.Fatal(err) |
| 73 | +} |
| 74 | +user.Registration=reg |
| 75 | + |
| 76 | +err=client.AgreeToTOS() |
| 77 | +iferr!=nil { |
| 78 | +log.Fatal(err) |
| 79 | +} |
| 80 | + |
| 81 | +certs,errors:=client.ObtainCertificates([]string{domain},false) |
| 82 | +iflen(errors)>0 { |
| 83 | +fork,err:=rangeerrors { |
| 84 | +log.Println(k,err) |
| 85 | +} |
| 86 | + |
| 87 | +os.Exit(1) |
| 88 | +} |
| 89 | + |
| 90 | +ioutil.WriteFile(path.Join(outputDir,"cert"),certs[0].Certificate,0777) |
| 91 | +ioutil.WriteFile(path.Join(outputDir,"key"),certs[0].PrivateKey,0777) |
| 92 | +} |