Marius Burkard
2016-02-29 96f31df08510cf7be9c28224e91215953dc94e5a
server/plugins-available/apache2_plugin.inc.php
@@ -275,10 +275,10 @@
        [ req_distinguished_name ]
        C                      = ".trim($data['new']['ssl_country'])."
        ST                     = ".trim($data['new']['ssl_state'])."
        L                      = ".trim($data['new']['ssl_locality'])."
        O                      = ".trim($data['new']['ssl_organisation'])."
        OU                     = ".trim($data['new']['ssl_organisation_unit'])."
        " . (trim($data['new']['ssl_state']) == '' ? '' : "ST                     = ".trim($data['new']['ssl_state'])) . "
        " . (trim($data['new']['ssl_locality']) == '' ? '' : "L                      = ".trim($data['new']['ssl_locality']))."
        " . (trim($data['new']['ssl_organisation']) == '' ? '' : "O                      = ".trim($data['new']['ssl_organisation']))."
        " . (trim($data['new']['ssl_organisation_unit']) == '' ? '' : "OU                     = ".trim($data['new']['ssl_organisation_unit']))."
        CN                     = $domain
        emailAddress           = webmaster@".$data['new']['domain']."
@@ -1052,6 +1052,10 @@
                        }
                     }
                  }
                  foreach($sub_prefixes as $s) {
                     $temp_domains[] = $s . $aliasdomain['domain'];
                  }
               }
            }
         }
@@ -1121,6 +1125,7 @@
         || ($data['old']['domain'] != $data['new']['domain']) // we have domain update
         || ($data['old']['subdomain'] != $data['new']['subdomain']) // we have new or update on "auto" subdomain
         || ($data['new']['type'] == 'subdomain') // we have new or update on subdomain
         || ($data['old']['type'] == 'alias' || $data['new']['type'] == 'alias') // we have new or update on aliasdomain
      )) {
         if(substr($domain, 0, 2) === '*.') {
            // wildcard domain not yet supported by letsencrypt!
@@ -1135,6 +1140,8 @@
         $temp_domains = array();
         $lddomain = $domain;
         $subdomains = null;
         $aliasdomains = null;
         $sub_prefixes = array();
         //* be sure to have good domain
         if($data['new']['subdomain'] == "www" OR $data['new']['subdomain'] == "*") {
@@ -1146,6 +1153,18 @@
         if(is_array($subdomains)) {
            foreach($subdomains as $subdomain) {
               $temp_domains[] = $subdomain['domain'];
               $sub_prefixes[] = str_replace($domain, "", $subdomain['domain']);
            }
         }
         //* then, add alias domain if we have
         $aliasdomains = $app->db->queryAllRecords('SELECT domain,subdomain FROM web_domain WHERE parent_domain_id = '.intval($data['new']['domain_id'])." AND active = 'y' AND type = 'alias'");
         if(is_array($aliasdomains)) {
            foreach($aliasdomains as $aliasdomain) {
               $temp_domains[] = $aliasdomain['domain'];
               if(isset($aliasdomain['subdomain']) && ! empty($aliasdomain['subdomain'])) {
                  $temp_domains[] = $aliasdomain['subdomain'] . "." . $aliasdomain['domain'];
               }
            }
         }
@@ -1166,35 +1185,14 @@
         $bundle_tmp_file = "/etc/letsencrypt/live/".$domain."/chain.pem";
         $webroot = $data['new']['document_root']."/web";
         $wk_dir_existed = false;
         if(is_dir($webroot . '/.well-known')) $wk_dir_existed = true;
         //* check if we have already a Let's Encrypt cert
         if(!file_exists($crt_tmp_file) && !file_exists($key_tmp_file)) {
            $app->log("Create Let's Encrypt SSL Cert for: $domain", LOGLEVEL_DEBUG);
            if(is_dir($webroot . "/.well-known/acme-challenge/")) {
               $app->log("Remove old challenge directory", LOGLEVEL_DEBUG);
               $this->_exec("rm -rf " . $webroot . "/.well-known/acme-challenge/");
            }
            $app->log("Create challenge directory", LOGLEVEL_DEBUG);
            $app->system->mkdirpath($webroot . "/.well-known/");
            $app->system->chown($webroot . "/.well-known/", $data['new']['system_user']);
            $app->system->chgrp($webroot . "/.well-known/", $data['new']['system_group']);
            $app->system->mkdirpath($webroot . "/.well-known/acme-challenge");
            $app->system->chown($webroot . "/.well-known/acme-challenge/", $data['new']['system_user']);
            $app->system->chgrp($webroot . "/.well-known/acme-challenge/", $data['new']['system_group']);
            $app->system->chmod($webroot . "/.well-known/acme-challenge", "g+s");
            if(file_exists("/root/.local/share/letsencrypt/bin/letsencrypt")) {
               $this->_exec("/root/.local/share/letsencrypt/bin/letsencrypt auth --text --agree-tos --authenticator webroot --server https://acme-v01.api.letsencrypt.org/directory --rsa-key-size 4096 --email postmaster@$domain --domains $lddomain --webroot-path " . escapeshellarg($webroot));
               $this->_exec("/root/.local/share/letsencrypt/bin/letsencrypt auth --text --agree-tos --authenticator webroot --server https://acme-v01.api.letsencrypt.org/directory --rsa-key-size 4096 --email postmaster@$domain --domains $lddomain --webroot-path /usr/local/ispconfig/interface/acme");
            }
         }
         if($wk_dir_existed == false && is_dir($webroot . '/.well-known')) {
            $this->_exec("rm -rf " . $webroot . "/.well-known");
         } elseif(is_dir($webroot . "/.well-known/acme-challenge/")) {
            $this->_exec("rm -rf " . $webroot . "/.well-known/acme-challenge/");
         }
         };
         //* check is been correctly created
         if(file_exists($crt_tmp_file) OR file_exists($key_tmp_file)) {
@@ -1711,7 +1709,7 @@
               $data['new']['ipv6_address'] = implode(':', $explode_v6);
            }
         }
         if($data['new']['ipv6_address'] == '*') $data['new']['ipv6_address'] = '::';
         $tmp_vhost_arr = array('ip_address' => '['.$data['new']['ipv6_address'].']', 'ssl_enabled' => 0, 'port' => 80);
         if(count($rewrite_rules) > 0)  $tmp_vhost_arr = $tmp_vhost_arr + array('redirects' => $rewrite_rules);
         if(count($alias_seo_redirects) > 0) $tmp_vhost_arr = $tmp_vhost_arr + array('alias_seo_redirects' => $alias_seo_redirects);