summaryrefslogtreecommitdiffstats
path: root/httpd-ssl-gencerts
blob: 67b6d9a19f6ed608e2ac3b52b0bf1047532b17c5 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
#!/usr/bin/bash

set -e

FQDN=`hostname`

if test -f /etc/pki/tls/certs/localhost.crt -o \
        -f /etc/pki/tls/private/localhost.key -o \
        -f /etc/pki/tls/certs/localhost-ca.crt; then
    exit 1
fi

sscg -q                                                             \
     --cert-file           /etc/pki/tls/certs/localhost.crt         \
     --cert-key-file       /etc/pki/tls/private/localhost.key       \
     --ca-file             /etc/pki/tls/certs/localhost-ca.crt      \
     --lifetime            365                                      \
     --hostname            $FQDN                                    \
     --email               root@$FQDN

# mod_ssl will send the CA cert if it's appended to the server cert.
cat /etc/pki/tls/certs/localhost-ca.crt >> /etc/pki/tls/certs/localhost.crt