2021-02-22 14:46:22 +01:00
|
|
|
#!/bin/sh
|
|
|
|
|
|
|
|
set -eo pipefail
|
|
|
|
|
2023-03-01 10:10:55 +01:00
|
|
|
declare -a DESTDIR_PATHS=(
|
|
|
|
"/usr/local/share/ca-certificates"
|
|
|
|
"/etc/ca-certificates/trust-source/anchors"
|
|
|
|
"/etc/pki/ca-trust/source/anchors"
|
|
|
|
)
|
|
|
|
|
|
|
|
for path in "${DESTDIR_PATHS[@]}"; do
|
|
|
|
if [ -d "$path" ]; then
|
|
|
|
DESTDIR=$path
|
|
|
|
break
|
|
|
|
fi
|
|
|
|
done
|
2022-10-25 19:37:38 +02:00
|
|
|
|
2021-02-22 14:46:22 +01:00
|
|
|
UPDATE_CERTS_CMD=update-ca-certificates
|
2022-10-25 19:37:38 +02:00
|
|
|
if [ -z "$(which $UPDATE_CERTS_CMD)" ]; then
|
|
|
|
UPDATE_CERTS_CMD="update-ca-trust extract"
|
|
|
|
fi
|
|
|
|
|
2021-02-22 14:46:22 +01:00
|
|
|
CERTS="$(cat <<EOF
|
|
|
|
https://letsencrypt.org/certs/isrgrootx1.pem
|
|
|
|
https://letsencrypt.org/certs/isrg-root-x2.pem
|
|
|
|
https://letsencrypt.org/certs/lets-encrypt-r3.pem
|
|
|
|
https://letsencrypt.org/certs/lets-encrypt-e1.pem
|
|
|
|
https://letsencrypt.org/certs/lets-encrypt-r4.pem
|
|
|
|
https://letsencrypt.org/certs/lets-encrypt-e2.pem
|
|
|
|
EOF
|
|
|
|
)"
|
|
|
|
|
|
|
|
cd "$DESTDIR"
|
|
|
|
|
|
|
|
for cert in $CERTS; do
|
|
|
|
echo "Downloading '$cert'..."
|
|
|
|
filename=$(basename "$cert")
|
2021-05-31 16:42:05 +02:00
|
|
|
wget --tries=10 --timeout=30 -O "$filename" "$cert"
|
2021-02-22 14:46:22 +01:00
|
|
|
openssl x509 -in "$filename" -inform PEM -out "$filename.crt"
|
|
|
|
done
|
|
|
|
|
|
|
|
$UPDATE_CERTS_CMD
|