|
| 1 | +#!/bin/sh |
| 2 | +SAVE=0 |
| 3 | + |
| 4 | +usage() { |
| 5 | + echo "Usage: $0 [-s]" |
| 6 | + echo "Generates a valid ASP.NET Core self-signed certificate for the local machine." |
| 7 | + echo "The certificate will be imported into the system's certificate store and into various other places." |
| 8 | + echo " -s: Also saves the generated crtfile to the home directory" |
| 9 | + exit 1 |
| 10 | +} |
| 11 | + |
| 12 | +while getopts "sh" opt |
| 13 | +do |
| 14 | + case "$opt" in |
| 15 | + s) |
| 16 | + SAVE=1 |
| 17 | + ;; |
| 18 | + h) |
| 19 | + usage |
| 20 | + exit 1 |
| 21 | + ;; |
| 22 | + *) |
| 23 | + ;; |
| 24 | + esac |
| 25 | +done |
| 26 | + |
| 27 | +TMP_PATH=/var/tmp/localhost-dev-cert |
| 28 | +if [ ! -d $TMP_PATH ]; then |
| 29 | + mkdir $TMP_PATH |
| 30 | +fi |
| 31 | + |
| 32 | +cleanup() { |
| 33 | + rm -R $TMP_PATH |
| 34 | +} |
| 35 | + |
| 36 | +KEYFILE=$TMP_PATH/dotnet-devcert.key |
| 37 | +CRTFILE=$TMP_PATH/dotnet-devcert.crt |
| 38 | +PFXFILE=$TMP_PATH/dotnet-devcert.pfx |
| 39 | + |
| 40 | +NSSDB_PATHS="$HOME/.pki/nssdb \ |
| 41 | + $HOME/snap/chromium/current/.pki/nssdb \ |
| 42 | + $HOME/snap/postman/current/.pki/nssdb" |
| 43 | + |
| 44 | +CONF_PATH=$TMP_PATH/localhost.conf |
| 45 | +cat >> $CONF_PATH <<EOF |
| 46 | +[req] |
| 47 | +prompt = no |
| 48 | +default_bits = 2048 |
| 49 | +distinguished_name = subject |
| 50 | +req_extensions = req_ext |
| 51 | +x509_extensions = x509_ext |
| 52 | +
|
| 53 | +[ subject ] |
| 54 | +commonName = localhost |
| 55 | +
|
| 56 | +[req_ext] |
| 57 | +basicConstraints = critical, CA:true |
| 58 | +subjectAltName = @alt_names |
| 59 | +
|
| 60 | +[x509_ext] |
| 61 | +basicConstraints = critical, CA:true |
| 62 | +keyUsage = critical, keyCertSign, cRLSign, digitalSignature,keyEncipherment |
| 63 | +extendedKeyUsage = critical, serverAuth |
| 64 | +subjectAltName = critical, @alt_names |
| 65 | +1.3.6.1.4.1.311.84.1.1 = ASN1:UTF8String:ASP.NET Core HTTPS development certificate # Needed to get it imported by dotnet dev-certs |
| 66 | +
|
| 67 | +[alt_names] |
| 68 | +DNS.1 = localhost |
| 69 | +EOF |
| 70 | + |
| 71 | +configure_nssdb() { |
| 72 | + echo "Configuring nssdb for $1" |
| 73 | + certutil -d sql:"$1" -D -n dotnet-devcert |
| 74 | + certutil -d sql:"$1" -A -t "CP,," -n dotnet-devcert -i $CRTFILE |
| 75 | +} |
| 76 | + |
| 77 | +openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout $KEYFILE -out $CRTFILE -config $CONF_PATH --passout pass: |
| 78 | +openssl pkcs12 -export -out $PFXFILE -inkey $KEYFILE -in $CRTFILE --passout pass: |
| 79 | + |
| 80 | +for NSSDB in $NSSDB_PATHS; do |
| 81 | + if [ -d "$NSSDB" ]; then |
| 82 | + configure_nssdb "$NSSDB" |
| 83 | + fi |
| 84 | +done |
| 85 | + |
| 86 | +if [ "$(id -u)" -ne 0 ]; then |
| 87 | + # shellcheck disable=SC2034 # SUDO will be used in parent scripts. |
| 88 | + SUDO='sudo' |
| 89 | +fi |
| 90 | + |
| 91 | +dotnet dev-certs https --clean --import $PFXFILE -p "" |
| 92 | + |
| 93 | +if [ "$SAVE" = 1 ]; then |
| 94 | + cp $CRTFILE $HOME |
| 95 | + echo "Saved certificate to $HOME/$(basename $CRTFILE)" |
| 96 | + cp $PFXFILE $HOME |
| 97 | + echo "Saved certificate to $HOME/$(basename $PFXFILE)" |
| 98 | +fi |
0 commit comments