JFIF$        dd7 

Viewing File: /usr/local/cpanel/scripts/ssl_crt_status

#!/usr/local/cpanel/3rdparty/bin/perl

# cpanel - scripts/ssl_crt_status                  Copyright 2022 cPanel, L.L.C.
#                                                           All rights reserved.
# copyright@cpanel.net                                         http://cpanel.net
# This code is subject to the cPanel license. Unauthorized copying is prohibited

package scripts::ssl_crt_status;

use strict;
use warnings;

use Cpanel::SSLPath                 ();
use Cpanel::SSLInfo                 ();
use Getopt::Param                   ();
use Cpanel::StringFunc              ();
use Cpanel::ArrayFunc               ();
use Term::ANSIColor                 ();
use Cpanel::Config::LoadUserDomains ();
use Cpanel::Hostname                ();

__PACKAGE__->run() unless caller();

sub run {
    my $param = Getopt::Param->new(
        {
            'quiet'        => 0,
            'help_coderef' => sub {
                print <<"END_HELP";
$0 - give a status report of the server's SSL certificates

    --help          this screen
    --verbose       show more than just errors
    --verbose=long  include verification result of valid crts

By default it will check every domain, you can specify one or more specific
domains to check by passing one or more --domain flags:

    --domain=your.domain.here --domain=other.domain.here

END_HELP
                exit;
            },
        }
    );

    my $debug   = $param->get_param('debug');
    my $verbose = $param->get_param('verbose');

    my @domains = Cpanel::ArrayFunc::uniq_from_arrayrefs( [ $param->exists_param('domain') ? $param->get_param('domain') : ( Cpanel::Hostname::gethostname(), grep( !/^\*/, sort keys %{ Cpanel::Config::LoadUserDomains::loaduserdomains( undef, 1 ) } ) ) ] );

    if ( grep /^--domain$/, @domains ) {
        print "Domain must be unambiguously specified in this format --domain=fqdn.tld\n\n";
        $param->help();
    }

    my $sslroot = Cpanel::SSLPath::getsslroot();

    print "[info] SSL root: $sslroot\n" if $verbose;

    if ($debug) {
        require Data::Dumper;
    }

    # fetchinfo() is and verifysslcert() may still be "loud"
    close STDERR;                     # just to be on the safe side
    open STDERR, '>', '/dev/null';    ## no critic qw(InputOutput::RequireCheckedOpen)

    for my $domain (@domains) {
        my $ssl_info_hr = Cpanel::SSLInfo::fetchinfo($domain);

        if ($debug) {
            print Data::Dumper::Dumper($ssl_info_hr);
        }
        if ( $ssl_info_hr->{'statusmsg'} =~ /^No certificate for the domain \S+ could be found[.]$/ ) {
            if ($verbose) {
                print Term::ANSIColor::color 'bold blue';
                print "Ok: $domain does not have an SSL crt\n";
                print Term::ANSIColor::color 'reset';
            }
        }
        else {
            my ( $rc, $msg ) = Cpanel::SSLInfo::verifysslcert(
                $sslroot,
                $ssl_info_hr->{'crt'},
                $ssl_info_hr->{'key'},
                $ssl_info_hr->{'cab'},
                1,    # makes verifysslcert() not do any print()s
                1,    # makes verifysslcert() return plain text instead of HTML
            );

            if ($rc) {
                if ($verbose) {
                    print Term::ANSIColor::color 'bold green';
                    print "Ok: $domain SSL crt verified\n";
                    print Term::ANSIColor::color 'reset';
                    if ( $verbose eq 'long' ) {
                        print Cpanel::StringFunc::indent_string($msg) . "\n";
                    }
                }
            }
            else {
                print Term::ANSIColor::color 'bold red';
                print "Error: $domain SSL crt verification failed:\n";
                print Term::ANSIColor::color 'reset';
                print Cpanel::StringFunc::indent_string($msg) . "\n";
            }
        }
    }
    return 1;
}
1;
Back to Directory  nL+D550H?Mx ,D"v]qv;6*Zqn)ZP0!1 A "#a$2Qr D8 a Ri[f\mIykIw0cuFcRı?lO7к_f˓[C$殷WF<_W ԣsKcëIzyQy/_LKℂ;C",pFA:/]=H  ~,ls/9ć:[=/#f;)x{ٛEQ )~ =𘙲r*2~ a _V=' kumFD}KYYC)({ *g&f`툪ry`=^cJ.I](*`wq1dđ#̩͑0;H]u搂@:~וKL Nsh}OIR*8:2 !lDJVo(3=M(zȰ+i*NAr6KnSl)!JJӁ* %݉?|D}d5:eP0R;{$X'xF@.ÊB {,WJuQɲRI;9QE琯62fT.DUJ;*cP A\ILNj!J۱+O\͔]ޒS߼Jȧc%ANolՎprULZԛerE2=XDXgVQeӓk yP7U*omQIs,K`)6\G3t?pgjrmۛجwluGtfh9uyP0D;Uڽ"OXlif$)&|ML0Zrm1[HXPlPR0'G=i2N+0e2]]9VTPO׮7h(F*癈'=QVZDF,d߬~TX G[`le69CR(!S2!P <0x<!1AQ "Raq02Br#SCTb ?Ζ"]mH5WR7k.ۛ!}Q~+yԏz|@T20S~Kek *zFf^2X*(@8r?CIuI|֓>^ExLgNUY+{.RѪ τV׸YTD I62'8Y27'\TP.6d&˦@Vqi|8-OΕ]ʔ U=TL8=;6c| !qfF3aů&~$l}'NWUs$Uk^SV:U# 6w++s&r+nڐ{@29 gL u"TÙM=6(^"7r}=6YݾlCuhquympǦ GjhsǜNlɻ}o7#S6aw4!OSrD57%|?x>L |/nD6?/8w#[)L7+6〼T ATg!%5MmZ/c-{1_Je"|^$'O&ޱմTrb$w)R$& N1EtdU3Uȉ1pM"N*(DNyd96.(jQ)X 5cQɎMyW?Q*!R>6=7)Xj5`J]e8%t!+'!1Q5 !1 AQaqё#2"0BRb?Gt^## .llQT $v,,m㵜5ubV =sY+@d{N! dnO<.-B;_wJt6;QJd.Qc%p{ 1,sNDdFHI0ГoXшe黅XۢF:)[FGXƹ/w_cMeD,ʡcc.WDtA$j@:) -# u c1<@ۗ9F)KJ-hpP]_x[qBlbpʖw q"LFGdƶ*s+ډ_Zc"?%t[IP 6J]#=ɺVvvCGsGh1 >)6|ey?Lӣm,4GWUi`]uJVoVDG< SB6ϏQ@ TiUlyOU0kfV~~}SZ@*WUUi##; s/[=!7}"WN]'(L! ~y5g9T̅JkbM' +s:S +B)v@Mj e Cf jE 0Y\QnzG1д~Wo{T9?`Rmyhsy3!HAD]mc1~2LSu7xT;j$`}4->L#vzŏILS ֭T{rjGKC;bpU=-`BsK.SFw4Mq]ZdHS0)tLg