X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/3e091ef3d515a094fd4493faacbc5c3ba266c2ad..3c7a077610049f811e11b295e69772f69f30bdba:/cookbooks/letsencrypt/files/default/bin/check-certificate?ds=inline diff --git a/cookbooks/letsencrypt/files/default/bin/check-certificate b/cookbooks/letsencrypt/files/default/bin/check-certificate index 46ca8e848..303314fca 100755 --- a/cookbooks/letsencrypt/files/default/bin/check-certificate +++ b/cookbooks/letsencrypt/files/default/bin/check-certificate @@ -10,27 +10,27 @@ begin if Time.now < certificate.not_before puts "Certificate #{domain} not valid until #{certificate.not_before}" - elsif certificate.not_after - Time.now < 14 * 86400 + elsif certificate.not_after - Time.now < 21 * 86400 puts "Certificate #{domain} expires at #{certificate.not_after}" else subject_alt_name = certificate.extensions.find { |e| e.oid == "subjectAltName" } if subject_alt_name.nil? - puts "Certificate #{domain} has no subject_alt_name" + puts "Certificate #{domain} has no subjectAltName" else alt_names = subject_alt_name.value.split(/\s*,\s*/).sort ARGV.sort.each do |expected| - puts "Certificate #{domain} is missing subject_alt_name #{expected}" unless alt_names.shift == "DNS:#{expected}" + puts "Certificate #{domain} is missing subjectAltName #{expected}" unless alt_names.shift == "DNS:#{expected}" end alt_names.each do |name| - puts "Certificate #{domain} has unexpected altName #{name}" + puts "Certificate #{domain} has unexpected subjectAltName #{name}" end end end connection.finish -rescue OpenSSL::SSL::SSLError => error +rescue StandardError => error puts "Error connecting to #{domain}: #{error.message}" end