From 53c1600d3c3a71aaca096789d0159470d58c7a69 Mon Sep 17 00:00:00 2001 From: Christoph Date: Tue, 16 Jul 2019 16:56:06 +0200 Subject: [PATCH] get_all_keys.sh: fix error in case og old easyrsa layout (revert to previos version). --- .get_all_keys.sh.swo | Bin 32768 -> 0 bytes get_all_keys.sh | 38 ++++++++++++++++++++++++++------------ 2 files changed, 26 insertions(+), 12 deletions(-) delete mode 100644 .get_all_keys.sh.swo diff --git a/.get_all_keys.sh.swo b/.get_all_keys.sh.swo deleted file mode 100644 index a2d555a4de526f3325782f3460e4df0647aa9de6..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 32768 zcmeI43y@@0d4MnIqARe=BVa*k_DoN+GqY2i=w7fYVMzvQR)d6kS?C}gI+L*>r$)RLmI zfvg0q1dc}n)yiaQ{prrSp6)JrTWg|4oPE|+#}k7MYb9VMU?pHBU?pHBU?pHBU?pHB z@GCBXO6e5m8p^ONEXS?k?@0~6uL=L39{%3kaQ#)`|1-niPc>XWIsD%r{{Cab^;5$C z$_~Nt_ZzOiI{bfH_}dz0(Bv~bZGWr;tOTqCtOTqCtOTqCtOTqCtOTqCtOTqCtOS}! zz|A?%X(-wU?;pDPKFm(IL?>g&)|3Aeem1xc6b}C zf-hn)xF2qX9JsI-w!m6A6aE{e{@d^fJPe+mQXfm`4pycRz7I>-4S zyaO_jhGp>Na>uy?J`R5hH^L2YCai$d;XAJ-P51)*4g59q!b$KoWN{bV1|@haNcp^o zoF0HVXn}L#2!@jf;R|pd9EN+~kKuYK!+&AC_yK$rJ`BGH9;}C7hr<|8?uLUi8Qm{ zEvOi~h*5}519d06$LExQ9afUM>>bB_daJh|h?Z!$?N@+>pNG z1U9ZkQ!tW>H{wu~C#rQd%E>k_)iJ~d8c6d`)NHt1>zix)+GT5`=ICN`y~*}Uke?Ar z9mRaNG*6)ZY;^CUX=Sp0N20^wcDhrG$QJ#IoA=B81#ialD|8kDBxIj4b)NN2_ejJB zpjv`>%;_MiaAApRsgRI#s$*c9r|`9)i)2Vf(>ybr?n@-wr6XUtTo4B@>bh8nlwT}X zD+uL7kDKxT%CA_m#y@g|EXfXNNgGyE3fH;(LHY(Uz^~Xdth3$ z&6a|^UrDZ;YwJijQgmSrlBlW73p&^60j74TeZnn!a)wbtCFz8``@mGb;Hd#C9IXP8 z%89l%p>wB3pm3zl`;*LY14RO=VM<8P#ApU#eu-v|q5d6%Tl+Uhb5}SVG@JYu7(Kj$ z`EsS)nQ+W_KF?GU)jg8n6R+N|^ij*MRjv*zhw%Q5!@GxuH)ghN+&y^JNM@jaXRKZ6 zVD)Wp-iAeB6VkM=1v6mEr4#XjfXRS%lXYdgFBJD>CaD`)OF96VWpYiG;}>glst&_< z*q~B*QPyqBoY^#Bj#5RDs&8KDuzh7^6V0{twTaYZPn7Z!8}z*OpN`t)TxW82Xh&vK z|IkRLf7i&I=($uxMHOSRq-sjkLsI>$sLz?+PbD!qYMHR$FoJIg)G#xIEqT(dFy%HC z^}<4yEs#-mL)5pkK|ywA@;oE9_g`tcci7iuFW)q@EhDe=TpBN_sU&J)&scfwuo{8I zKy_xq3woP%bSar*%cz=S*v1$|b!XPA4%QW+5Op8UdD(&+cyc*X8(2 z4LQ5|Y7u5s4%iKM&!uTnoh5IEv03Lm)?NA%>HOp3>e`w3bZOtN7!-omq zFfum}Z^os%l(S42vJsk?mXLBQ!1!W~zXy^iuy{fu8Pz)c?)%`>&$ke;NJ?#zE@+BQOlB;Z!&UzRP{j z!ZYwR{5{+RGQPF&Z|L`rg4F;20=@(Hf)CTM6;6Ry!O8FxI{yQ3Kim%2!%Fx*`uY7H^30ILlT}u z=YIkog};Sc;YK(YR={28|F^+k!nH6A7sC_i{ExsNg0um=2d;s4!y))hxB}8}H~Rk_ zunUIZZO{TQpzA*l?}jp52y3Ag1gwJd;Ropd--d_bw_pf@d+J@H!&%Py zZ29uqVtQeN!gAIuFVnuUJS@<{2{4Z>QBV6h86K90%R0H93JT6`|70c)!Wv(&=YiLj23wSe|by7C#C zF$6RTPzkDDXnet59J6E8G-{dEm?g$ED5I5!HW~9YR9dH%aYor@q}iutpD}U93^Xl9 z3RqaM{>1GtCbUf4Ja7!32rioDKAzP2#4Yvz>(JBXb9|})qiUt4 zBX#^I;Bj~i9t3%>{Iwq|0V@G30V@G30V@G30V@G30V@G30V@G3fmcQX*@EZ#nQBS! zjw|g{Fpn#heh`XTLp!9@IoST6^}4ND@M}+3r2hX9mGcKYOP2cotzktyhrWLl?t{Z{ z2S|IsP4EFY1O=Fe&5(u`I2V2m&W2aR_pl3m1Ej6s2z(8sz2NU)3eJI(!GV`}{{K^W z4vxYn;Wqda_z>)dG{}7eZSV&8E(Qy^ci>rg96k&0f-x9@_0R)vfb-!zI0Kf!^Y{*Y z7H$I{CgJVS3(Mdo{0CluXW%LL7CZ(I!rgEk9D+Tt3$BE%@EfoZ-VCeYS^NvW0f*sp z@JW#S6K;o3zz5-4*b34o;Vp0xTnK46A6CM{_$2%j+y{r@Uib&N6Fvmj!L{Il3)|ol zcr!?Uh87U83Rc3?_%Qqnd=)+eAB7?4gynD)Uxo)k`Z(MIH^bGi8+O1|FarIs8P0Ux816^moXE3nQ=%E`(KZ27C!$hmS)ACSWIQhBv}#@I3AEX?Ozu6^_8CLAKZ5 zhu?wshsW3RyAn==Q{icRA=Iadm9UBJEF3WoxB-q#14ZegJDJ~C4Ya?ObWs#-@|^Nk zY^&{X7#xtJNYfn-+M#RA*H+lt_qL*&%lrF8&YN_rg-Tgo!Ix}*K03&HYLkStjjA-| zV>;y#$mpajf>BQT!VofpCWJOffX_~#dWd;|N*hdbf*3KgqNzs^l0c0z6~7^_@? z!8AMNiSRz5?US)!3HBd2;s3h*37NsIeaf1uFY>L5Ja0*pnJojgy$%GQzsNeMqa&ua z^W}`MTnsVT5=%m?Uaee8<=%rR79}iwXU%}BqfnlO+$dwzzJ@KhF%NFlzL=bp^G7rJ zDW?&x%d%?IGJj%q(B3ZcYuAbn

_e!-kE~s>{o zXjP5snQrG)K075g)wSsIRIysfi3v{>XpUa)vRHWIZ-~R`v8l*M&E0W>cjR1|7x_M> zUSk2*k5mQ*8xmH%f_9_3W%DEojY)*NXH;&CfV5X=Wu~P1iuSJ0n7{Ok=(u%FYR*9} z(Fu9cxQSmNALgp7=1gC*_Ba>sb<^inrA7aw(8CAS(YZPDpuAZT{+OHN0dv!aD#Oms%Z;IX5-Vt{1>KO0k&xcMfO2NF&uNJsYR z=Dy43%j>2oFFTD30#5v;zze*0R`cb2#Va?-prh(8@G4ct?QU6*vIabv5QFFCy*+aY z=|>{_ewy3(r9)bvrcLJH)KhDvP62)ay%<(>=@# zpXy(@3v0A-&)F6nsKdwh4%aDnSEUW2qX?g2cj{i%}S+~iVy6<@NrFR+BG8U-@s)@`m zLW&mq3}=IUsUi-zWz%NyH0tEjq~^FyN6W#exIztnixyTDYh6^-SbFSy@q%iJ^mNgq zi8hvZlccOu)7YZ8UY6L@gTtEC@b*tLpr*@HB}R%;C7EP6rtq%hp242|(;UkQJ$HV=_1(#kK&6WcOU#UXk+NDJPzW?U=iWQ(W2@fg{Bv zr)UZz!j2PmcD8?cINv9dmnT$|>VOE$@XJuVy1U~NhgAfXp!z*Ua`2XtMPmns8fud5 z`iZQ3_B`9&+PY@6r7LyuINOn!8r4+MxUHdG%1cOk6sm-A{n`a)hGu{wjJoE&4FBe@^gXyQ6(JhEtlM^ z*E`O_jDpHc2Hs4OUB8vU%@^dz!+ME)$xtFYQiN#e}rx}noSg3e>y|vz1Yoc%Bs-pWX5aPGd-A6r-;-ged(a-krS?W|%8CATsql3g9_<#1YC)EoFG@_w2(?+aEt zQ|kHuH_-*}MZc8#zj^=O&(PhC&VN0}*T57!ho1fvd;s1H2VnAPSU~%GQ zYhR1MyM?fNJ-FaIUKS3tv^aj=?}=GLwsn#VXMXXWaL0XrbVGEY7TJ*=rB%A)*@H(! z(I=)5{x4#*Z{!IDs>R74tortiJZRC)-}ai+Ov`(q_wC153BC153BC153BC153BC153B zC154+3zmTNIN?o&@%IJ%a(Mzv&m!YIQ!Z8myeJYi|2*R}sT>d@uf4jL4;W*x`jvh` V+QX=4CY92DM8qH3^rV~S{{S2-7|j3x diff --git a/get_all_keys.sh b/get_all_keys.sh index 12d874a..4c05e6d 100755 --- a/get_all_keys.sh +++ b/get_all_keys.sh @@ -253,21 +253,35 @@ else info "No revoked keys in \033[1m${OPENVPN_REVOKED_KEY_DIR}\033[m for OpenVPN service \033[1m$service_name\033[m exists." fi -while IFS= read -r -d '' _cert ; do +if $EASYRSA_LAYOUT_NEW ; then + while IFS= read -r -d '' _cert ; do - _serial="$(basename "$_cert")" - _serial="${_serial%.*}" + _serial="$(basename "$_cert")" + _serial="${_serial%.*}" - _cn="$(openssl x509 -noout -text -in $_cert | grep Subject: | grep -oE "CN\s*=\s*[^,]+" | awk '{print$3}')" - if ! containsElement "$_cn" "${all_cn_arr[@]}" ; then + _cn="$(openssl x509 -noout -text -in $_cert | grep Subject: | grep -oE "CN\s*=\s*[^,]+" | awk '{print$3}')" + if ! containsElement "$_cn" "${all_cn_arr[@]}" ; then + all_arr+=("${_serial}:$(trim $_cn)") + all_cn_arr+=("$(trim $_cn)") + fi + if ! containsElement "$_cn" "${revoked_cn_arr[@]}" ; then + active_arr+=("${_serial}:$(trim $_cn)") + fi + + done < <(find ${OPENVPN_CERT_DIR_SERIAL} -name "*\.pem" -print0 | sort -z ) +else + while IFS= read -r -d '' _cert ; do + + _serial="$(basename "$_cert")" + _serial="${_serial%.*}" + + _cn="$(openssl x509 -noout -text -in $_cert | grep Subject: | grep -oE "CN\s*=\s*[^,]+" | awk '{print$3}')" all_arr+=("${_serial}:$(trim $_cn)") - all_cn_arr+=("$(trim $_cn)") - fi - if ! containsElement "$_cn" "${revoked_cn_arr[@]}" ; then - active_arr+=("${_serial}:$(trim $_cn)") - fi - -done < <(find ${OPENVPN_CERT_DIR_SERIAL} -name "*\.pem" -print0 | sort -z ) + if ! containsElement "$_cn" "${revoked_cn_arr[@]}" ; then + active_arr+=("${_serial}:$(trim $_cn)") + fi + done < <(find ${OPENVPN_KEY_DIR} -name "??\.pem" -print0 | sort -z ) +fi if [[ ${#all_arr[@]} -gt 0 ]]; then echo ""