Skip to content

Commit

Permalink
Cronjob for cleaning up expired SSL certificates in order to improve …
Browse files Browse the repository at this point in the history
…page load times with many domains (#2410)

Fixes #2316.
  • Loading branch information
yeah authored Dec 22, 2024
1 parent e0b9371 commit 18721e4
Show file tree
Hide file tree
Showing 2 changed files with 26 additions and 0 deletions.
9 changes: 9 additions & 0 deletions setup/ssl.sh
Original file line number Diff line number Diff line change
Expand Up @@ -96,3 +96,12 @@ fi
if [ ! -f "$STORAGE_ROOT/ssl/dh2048.pem" ]; then
openssl dhparam -out "$STORAGE_ROOT/ssl/dh2048.pem" 2048
fi

# Cleanup expired SSL certificates from $STORAGE_ROOT/ssl daily
cat > /etc/cron.daily/mailinabox-ssl-cleanup << EOF;
#!/bin/bash
# Mail-in-a-Box
# Cleanup expired SSL certificates
$(pwd)/tools/ssl_cleanup
EOF
chmod +x /etc/cron.daily/mailinabox-ssl-cleanup
17 changes: 17 additions & 0 deletions tools/ssl_cleanup
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
#!/bin/bash
# Cleanup SSL certificates which expired more than 7 days ago from $STORAGE_ROOT/ssl and move them to $STORAGE_ROOT/ssl.expired

source /etc/mailinabox.conf
shopt -s extglob

retain_after="$(date --date="7 days ago" +%Y%m%d)"

mkdir -p $STORAGE_ROOT/ssl.expired
for file in $STORAGE_ROOT/ssl/*-+([0-9])-+([0-9a-f]).pem; do
pem="$(basename "$file")"
not_valid_after="$(cut -d- -f1 <<< "${pem: -21}")"

if [ "$not_valid_after" -lt "$retain_after" ]; then
mv "$file" "$STORAGE_ROOT/ssl.expired/${pem}"
fi
done

0 comments on commit 18721e4

Please sign in to comment.