summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSeth Vidal <skvidal@fedoraproject.org>2007-09-25 16:16:49 -0400
committerSeth Vidal <skvidal@fedoraproject.org>2007-09-25 16:16:49 -0400
commit0cab664634d76d771eb88b33b1d94238c2c9a9df (patch)
tree7f5ff6ac7c9cfdc8c5b2a4c79138ae5bf4161862
parent4d36563e61ab0d0b6617aae18c9a6962701c6c59 (diff)
downloadthird_party-func-0cab664634d76d771eb88b33b1d94238c2c9a9df.tar.gz
third_party-func-0cab664634d76d771eb88b33b1d94238c2c9a9df.tar.xz
third_party-func-0cab664634d76d771eb88b33b1d94238c2c9a9df.zip
make certmaster auto-create the ca key and cert on startup, if they are not present
-rwxr-xr-xfunc/certmaster.py18
-rwxr-xr-xscripts/certmaster7
2 files changed, 15 insertions, 10 deletions
diff --git a/func/certmaster.py b/func/certmaster.py
index 59bfd36..b12ecdb 100755
--- a/func/certmaster.py
+++ b/func/certmaster.py
@@ -61,12 +61,22 @@ class CertMaster(object):
else:
self.cfg.autosign = False
self.cfg.listen_port = int(self.cfg.listen_port)
+ self.ca_key_file = '%s/funcmaster.key' % self.cfg.cadir
+ self.ca_cert_file = '%s/funcmaster.crt' % self.cfg.cadir
+ try:
+ if not os.path.exists(self.cfg.cadir):
+ os.makedirs(self.cfg.cadir)
+ # fixme - should we creating these separately?
+ if not os.path.exists(self.ca_key_file) and not os.path.exists(self.ca_cert_file):
+ func.certs.create_ca(ca_key_file=self.ca_key_file, ca_cert_file=self.ca_cert_file)
+ except (IOError, OsError), e:
+ print 'Cannot make certmaster certificate authority keys/certs, aborting: %s' % e
+ sys.exit(1)
+
# open up the cakey and cacert so we have them available
- ca_key_file = '%s/funcmaster.key' % self.cfg.cadir
- ca_cert_file = '%s/funcmaster.crt' % self.cfg.cadir
- self.cakey = func.certs.retrieve_key_from_file(ca_key_file)
- self.cacert = func.certs.retrieve_cert_from_file(ca_cert_file)
+ self.cakey = func.certs.retrieve_key_from_file(self.ca_key_file)
+ self.cacert = func.certs.retrieve_cert_from_file(self.ca_cert_file)
for dirpath in [self.cfg.cadir, self.cfg.certroot, self.cfg.csrroot]:
if not os.path.exists(dirpath):
diff --git a/scripts/certmaster b/scripts/certmaster
index 1be4c58..f4bcf53 100755
--- a/scripts/certmaster
+++ b/scripts/certmaster
@@ -1,11 +1,6 @@
#!/usr/bin/python
-import sys
-import distutils.sysconfig
-
-sys.path.append("%s/func" % distutils.sysconfig.get_python_lib())
-
-import certmaster
+from func import certmaster
defaults = { 'listen_addr': 'localhost',
'listen_port': '51235',