From 51ae1e03d4cf50cea02dfc94c0973389a3c46c77 Mon Sep 17 00:00:00 2001 From: Sam Chow Date: Wed, 18 Jul 2018 14:01:07 -0400 Subject: [PATCH] Change cert install script to read from config dir Temporarily breaks the config app certs install, which will be fixed later. --- conf/init/certs_install.sh | 29 +++++++++++++++-------------- 1 file changed, 15 insertions(+), 14 deletions(-) diff --git a/conf/init/certs_install.sh b/conf/init/certs_install.sh index 981064f70..4f43c42dc 100755 --- a/conf/init/certs_install.sh +++ b/conf/init/certs_install.sh @@ -2,35 +2,36 @@ set -e QUAYPATH=${QUAYPATH:-"."} QUAYCONF=${QUAYCONF:-"$QUAYPATH/conf/stack"} +QUAYCONFIG="$QUAYCONF/stack" cd ${QUAYDIR:-"/quay-registry"} # Add the custom LDAP certificate -if [ -e $QUAYCONF/ldap.crt ] +if [ -e $QUAYCONFIG/ldap.crt ] then - cp $QUAYCONF/ldap.crt /usr/local/share/ca-certificates/ldap.crt + cp $QUAYCONFIG/ldap.crt /usr/local/share/ca-certificates/ldap.crt fi # Add extra trusted certificates (as a directory) -if [ -d $QUAYCONF/extra_ca_certs ]; then - if test "$(ls -A "$QUAYCONF/extra_ca_certs")"; then - echo "Installing extra certificates found in $QUAYCONF/extra_ca_certs directory" - cp $QUAYCONF/extra_ca_certs/* /usr/local/share/ca-certificates/ - cat $QUAYCONF/extra_ca_certs/* >> venv/lib/python2.7/site-packages/requests/cacert.pem - cat $QUAYCONF/extra_ca_certs/* >> venv/lib/python2.7/site-packages/certifi/cacert.pem +if [ -d $QUAYCONFIG/extra_ca_certs ]; then + if test "$(ls -A "$QUAYCONFIG/extra_ca_certs")"; then + echo "Installing extra certificates found in $QUAYCONFIG/extra_ca_certs directory" + cp $QUAYCONFIG/extra_ca_certs/* /usr/local/share/ca-certificates/ + cat $QUAYCONFIG/extra_ca_certs/* >> venv/lib/python2.7/site-packages/requests/cacert.pem + cat $QUAYCONFIG/extra_ca_certs/* >> venv/lib/python2.7/site-packages/certifi/cacert.pem fi fi # Add extra trusted certificates (as a file) -if [ -f $QUAYCONF/extra_ca_certs ]; then - echo "Installing extra certificates found in $QUAYCONF/extra_ca_certs file" - csplit -z -f /usr/local/share/ca-certificates/extra-ca- $QUAYCONF/extra_ca_certs '/-----BEGIN CERTIFICATE-----/' '{*}' - cat $QUAYCONF/extra_ca_certs >> venv/lib/python2.7/site-packages/requests/cacert.pem - cat $QUAYCONF/extra_ca_certs >> venv/lib/python2.7/site-packages/certifi/cacert.pem +if [ -f $QUAYCONFIG/extra_ca_certs ]; then + echo "Installing extra certificates found in $QUAYCONFIG/extra_ca_certs file" + csplit -z -f /usr/local/share/ca-certificates/extra-ca- $QUAYCONFIG/extra_ca_certs '/-----BEGIN CERTIFICATE-----/' '{*}' + cat $QUAYCONFIG/extra_ca_certs >> venv/lib/python2.7/site-packages/requests/cacert.pem + cat $QUAYCONFIG/extra_ca_certs >> venv/lib/python2.7/site-packages/certifi/cacert.pem fi # Add extra trusted certificates (prefixed) -for f in $(find $QUAYCONF/ -maxdepth 1 -type f -name "extra_ca*") +for f in $(find $QUAYCONFIG/ -maxdepth 1 -type f -name "extra_ca*") do echo "Installing extra cert $f" cp "$f" /usr/local/share/ca-certificates/