#!/bin/bash # update-letsencrypt-certs # Pull SSL certificates form a certificate host and restart # servers as necessary. # 7/21/2026 Rod Wright # Set the host from which certificates will be pulled cert_host="portal.thermionic.net" # Set which http server to restart http_server="nginx" #http_server="apache2" #http_server="pveproxy" #http_server="unifi" # Pull certs from the certifiate host if rsync -aL --info=stats2 root@$cert_host:/etc/letsencrypt/live/thermionic.net/ /etc/ssl/thermionic.net/ |grep -q "Number of regular files transferred: 0"; then http_server_restart=false; else http_server_restart=true; fi #Certs go in a non-standard place for a proxmox server if [[ "$http_server" = "pveproxy" ]] then cp -f /etc/ssl/thermionic.net/fullchain.pem /etc/pve/local/pveproxy-ssl.pem cp -f /etc/ssl/thermionic.net/privkey.pem /etc/pve/local/pveproxy-ssl.key fi # Populate additional TLS cers for iRedMail server if [[ -e "/etc/ssl/private/iRedMail.key" ]] then cp -f /etc/ssl/thermionic.net/fullchain.pem /etc/ssl/certs/iRedMail.crt cp -f /etc/ssl/thermionic.net/privkey.pem /etc/ssl/private/iRedMail.key fi # Restart if required if $http_server_restart then if [[ $http_server == "unifi" ]] then # Stop unifi, recreate keystore, start unifi unifi_ssl_import.sh else # Restart normal http servers echo "New certs downloaded. Restarting $http_server." systemctl restart $http_server fi else echo "Certs are up to date. $http_server restart not required." fi