-
Notifications
You must be signed in to change notification settings - Fork 0
/
acme_actual.ps1
178 lines (126 loc) · 7.22 KB
/
acme_actual.ps1
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
Import-Module ACMESharp
Enable-ACMEExtensionModule ACMESharp.Providers.IIS
$domain = "bunker011.com"
$email = "[email protected]"
$vault = "C:\letsencrypt"
Initialize-ACMEVault
#-BaseURI https://acme-v01.api.letsencrypt.org/
New-ACMERegistration -Contacts mailto:$email
Update-ACMERegistration -AcceptTOS
New-ACMEIdentifier -Dns $domain -Alias dns01
New-ACMEProviderConfig -WebServerProvider Manual -Alias manualHttpProvider -FilePath $vault\answer.txt
Get-ACMEIdentifier -Ref dns01
Complete-ACMEChallenge dns01 -ChallengeType dns-01 -Handler manual
#go to DNS and make the TXT Record
#check status
(Update-ACMEIdentifier dns01 -ChallengeType dns-01).Challenges
#after DNS propigates
Submit-ACMEChallenge dns01 -ChallengeType dns-01
(Update-ACMEIdentifier dns01 -ChallengeType dns-01).Challenges | where {$_.Type -eq "dns-01"} | Select-object -ExpandProperty submitResponse | Out-Host -Paging
(Update-ACMEIdentifier dns01 -ChallengeType dns-01).Challenges | Where-Object {$_.Type -eq "dns-01"}
New-ACMECertificate dns01 -Generate -Alias cert1
New-ACMEIdentifier -DNS u.bunker011.com -Alias util01
New-ACMEIdentifier -DNS v.bunker011.com -Alias vsphere01
Complete-ACMEChallenge util01 -ChallengeType dns-01 -Handler manual
Complete-ACMEChallenge vsphere01 -ChallengeType dns-01 -Handler manual
(Update-ACMEIdentifier util01 -ChallengeType dns-01).Challenges
(Update-ACMEIdentifier vsphere01 -ChallengeType dns-01).Challenges
Submit-ACMEChallenge util01 -ChallengeType dns-01
Submit-ACMEChallenge vsphere01 -ChallengeType dns-01
Update-ACMEIdentifier util01
Update-ACMEIdentifier vsphere01
New-ACMECertificate dns01 -Generate -AlternativeIdentifierRefs util01,vsphere01 -alias mastercert
Submit-ACMECertificate mastercert
Update-ACMECertificate mastercert
Get-ACMECertificate mastercert -ExportPkcs12 C:\Users\guacadmin\Documents\2017-bunker011-master.pfx
import-module pkitools
# still no "import-pfxcertificate" cmdlet?
function Import-PfxCertificate {
param([String]$certPath,[String]$certRootStore = “localmachine”,[String]$certStore = “My”)
$pfx = new-object System.Security.Cryptography.X509Certificates.X509Certificate2
$pfx.import($certPath,"","Exportable,PersistKeySet")
$store = new-object System.Security.Cryptography.X509Certificates.X509Store($certStore,$certRootStore)
$store.open("MaxAllowed")
$store.add($pfx)
$store.close()
}
Import-PfxCertificate C:\Users\guacadmin\Documents\2017-bunker011-master.pfx "LocalMachine" "My"
dir Cert:\LocalMachine\my | format-list *
#for transfering to apache
Get-ACMECertificate mastercert -ExportKeyPEM C:\Users\guacadmin\Documents\2017-bunker011-master.pem
Get-ACMECertificate mastercert -ExportCertificatePEM C:\Users\guacadmin\Documents\2017-bunker011-certificate.pem
#realize I forgot www and dev, so log back in and
Import-Module ACMESharp
$domain = "bunker011.com"
$email = "[email protected]"
$vault = "C:\letsencrypt"
New-ACMERegistration -Contacts mailto:$email -AcceptTos
New-ACMEIdentifier -Dns $domain -Alias bunker01
New-ACMEIdentifier -DNS www.bunker011.com -Alias www01
New-ACMEIdentifier -DNS dev.bunker011.com -Alias dev01
New-ACMEIdentifier -DNS admin.bunker011.com -Alias admin01
New-ACMEIdentifier -DNS guac.bunker011.com -Alias guac01
New-ACMEIdentifier -DNS util.bunker011.com -Alias util01
New-ACMEIdentifier -DNS u.bunker011.com -Alias u01
New-ACMEIdentifier -DNS v.bunker011.com -Alias v01
. C:\scripts\acme_selectdnstxt.ps1
$completedChallenge = Complete-ACMEChallenge bunker01 -ChallengeType dns-01 -Handler manual
(Update-ACMEIdentifier bunker01 -ChallengeType dns-01).Challenges
$dnstodo = $completedChallenge.Challenges | Where-Object { $_.Type -eq "dns-01" } | select HandlerHandleMessage
Select-DNSTXT $dnstodo
#paste into DNS records
#Complete-ACMEChallenge www01 -ChallengeType dns-01 -Handler manual
$completedChallenge = Complete-ACMEChallenge www01 -ChallengeType dns-01 -Handler manual
$dnstodo = $completedChallenge.Challenges | Where-Object { $_.Type -eq "dns-01" } | select HandlerHandleMessage
Select-DNSTXT $dnstodo
#paste into DNS records
Complete-ACMEChallenge admin01 -ChallengeType dns-01 -Handler manual
$completedChallenge = Complete-ACMEChallenge admin01 -ChallengeType dns-01 -Handler manual
$dnstodo = $completedChallenge.Challenges | Where-Object { $_.Type -eq "dns-01" } | select HandlerHandleMessage
Select-DNSTXT $dnstodo
#paste into DNS records
Complete-ACMEChallenge guac01 -ChallengeType dns-01 -Handler manual
$completedChallenge = Complete-ACMEChallenge guac01 -ChallengeType dns-01 -Handler manual
$dnstodo = $completedChallenge.Challenges | Where-Object { $_.Type -eq "dns-01" } | select HandlerHandleMessage
Select-DNSTXT $dnstodo
#paste into DNS records
Complete-ACMEChallenge util01 -ChallengeType dns-01 -Handler manual
$completedChallenge = Complete-ACMEChallenge util01 -ChallengeType dns-01 -Handler manual
$dnstodo = $completedChallenge.Challenges | Where-Object { $_.Type -eq "dns-01" } | select HandlerHandleMessage
Select-DNSTXT $dnstodo
#paste into DNS records
Complete-ACMEChallenge dev01 -ChallengeType dns-01 -Handler manual
$completedChallenge = Complete-ACMEChallenge dev01 -ChallengeType dns-01 -Handler manual
$dnstodo = $completedChallenge.Challenges | Where-Object { $_.Type -eq "dns-01" } | select HandlerHandleMessage
Select-DNSTXT $dnstodo
#paste into DNS records
Complete-ACMEChallenge u01 -ChallengeType dns-01 -Handler manual
$completedChallenge = Complete-ACMEChallenge u01 -ChallengeType dns-01 -Handler manual
$dnstodo = $completedChallenge.Challenges | Where-Object { $_.Type -eq "dns-01" } | select HandlerHandleMessage
Select-DNSTXT $dnstodo
#paste into DNS records
Complete-ACMEChallenge v01 -ChallengeType dns-01 -Handler manual
$completedChallenge = Complete-ACMEChallenge v01 -ChallengeType dns-01 -Handler manual
$dnstodo = $completedChallenge.Challenges | Where-Object { $_.Type -eq "dns-01" } | select HandlerHandleMessage
Select-DNSTXT $dnstodo
#paste into DNS records
#New-ACMEProviderConfig -WebServerProvider Manual -Alias manualHttpProvider -FilePath $vault\answer2.txt
Submit-ACMEChallenge bunker01 -ChallengeType dns-01
Submit-ACMEChallenge util01 -ChallengeType dns-01
Submit-ACMEChallenge guac01 -ChallengeType dns-01
Submit-ACMEChallenge admin01 -ChallengeType dns-01
Submit-ACMEChallenge dev01 -ChallengeType dns-01
Submit-ACMEChallenge www01 -ChallengeType dns-01
Submit-ACMEChallenge u01 -ChallengeType dns-01
Submit-ACMEChallenge v01 -ChallengeType dns-01
$sites = ('bunker01','www01','dev01','util01','guac01','u01','v01')
$sites | %{ Update-ACMEIdentifier $_ }
New-ACMECertificate bunker01 -Generate -AlternativeIdentifierRefs $sites -alias mastercert
Submit-ACMECertificate mastercert
Update-ACMECertificate mastercert
Get-ACMECertificate mastercert -ExportPkcs12 $HOME\Desktop\2017-bunker011-master.pfx
#for transfering to apache
Get-ACMECertificate mastercert -ExportKeyPEM $HOME\Desktop\2017-bunker011-master.pem
Get-ACMECertificate mastercert -ExportCertificatePEM $HOME\Desktop\2017-bunker011-certificate.pem
#Needed this for VCSA wizard (/usr/lib/vmware-vmca/bin/certificate-manager)
Get-ACMECertificate mastercert -ExportIssuerPEM $HOME\Desktop\2017-bunker011-issuer.pem