diff --git a/security/acme.sh/Makefile b/security/acme.sh/Makefile index 47af0b99895c..7b383a071e92 100644 --- a/security/acme.sh/Makefile +++ b/security/acme.sh/Makefile @@ -1,81 +1,82 @@ PORTNAME= acme.sh PORTVERSION= 3.0.7 +PORTREVISION= 1 CATEGORIES= security MAINTAINER= dvl@FreeBSD.org COMMENT= ACME protocol client written in shell WWW= https://github.com/Neilpang/acme.sh/ LICENSE= GPLv3+ USES= shebangfix SHEBANG_FILES= deploy/synology_dsm.sh USE_GITHUB= yes GH_ACCOUNT= acmesh-official USERS= acme GROUPS= acme OPTIONS_DEFINE= BINDTOOLS DOCS EXAMPLES IDN STANDALONE OPTIONS_DEFAULT= CURL STANDALONE OPTIONS_SINGLE= HTTP OPTIONS_SINGLE_HTTP= CURL WGET BINDTOOLS_DESC= Depend on bind-tools for nsupdate CURL_DESC= Depend on cURL for HTTP(S) queries STANDALONE_DESC= Standalone mode requires SOCAT WGET_DESC= Depend on Wget for HTTP(S) queries NO_ARCH= yes NO_BUILD= yes BINDTOOLS_RUN_DEPENDS= nsupdate:dns/bind-tools CURL_RUN_DEPENDS= curl:ftp/curl IDN_RUN_DEPENDS= idn2:dns/libidn2 STANDALONE_RUN_DEPENDS= socat>0:net/socat WGET_RUN_DEPENDS= wget:ftp/wget PORTDOCS= README.md SUB_FILES= acme-crontab pkg-message SUB_LIST= ACME_USER=acme post-patch-EXAMPLES-on: ${REINPLACE_CMD} -e 's|sed -i "|sed -i bak "|' ${WRKSRC}/dnsapi/dns_nsd.sh post-patch-IDN-on: ${REINPLACE_CMD} -e 's|^ *idn | idn2 |'\ -e 's|_exists idn|_exists idn2|' ${WRKSRC}/acme.sh do-install: ${INSTALL_SCRIPT} ${WRKSRC}/${PORTNAME} ${STAGEDIR}${PREFIX}/sbin/${PORTNAME} ${MKDIR} ${STAGEDIR}/var/db/acme/.acme.sh \ ${STAGEDIR}/var/db/acme/certs \ ${STAGEDIR}${PREFIX}/etc/newsyslog.conf.d \ ${STAGEDIR}${EXAMPLESDIR} ${INSTALL_DATA} ${FILESDIR}/account.conf.sample ${STAGEDIR}/var/db/acme/.acme.sh ${INSTALL_DATA} ${WRKDIR}/acme-crontab ${STAGEDIR}${EXAMPLESDIR}/acme.sh-cron.d ${INSTALL_DATA} ${FILESDIR}/acme-newsyslog ${STAGEDIR}${PREFIX}/etc/newsyslog.conf.d/acme.sh.conf.sample do-install-DOCS-on: ${MKDIR} ${STAGEDIR}${DOCSDIR} ${INSTALL_DATA} ${WRKSRC}/README.md ${STAGEDIR}${DOCSDIR} do-install-EXAMPLES-on: ${MKDIR} ${STAGEDIR}${EXAMPLESDIR}/deploy ${STAGEDIR}${EXAMPLESDIR}/dnsapi ( cd ${WRKSRC} && ${COPYTREE_BIN} deploy ${STAGEDIR}${EXAMPLESDIR} ) ( cd ${WRKSRC} && ${COPYTREE_BIN} dnsapi ${STAGEDIR}${EXAMPLESDIR} ) ( cd ${WRKSRC} && ${COPYTREE_BIN} notify ${STAGEDIR}${EXAMPLESDIR} ) ${RLN} ${STAGEDIR}/${EXAMPLESDIR}/deploy ${STAGEDIR}/var/db/acme/.acme.sh ${RLN} ${STAGEDIR}/${EXAMPLESDIR}/dnsapi ${STAGEDIR}/var/db/acme/.acme.sh ${RLN} ${STAGEDIR}/${EXAMPLESDIR}/notify ${STAGEDIR}/var/db/acme/.acme.sh .include diff --git a/security/acme.sh/files/acme-crontab.in b/security/acme.sh/files/acme-crontab.in index ffde51de652f..7793b84a8bf9 100644 --- a/security/acme.sh/files/acme-crontab.in +++ b/security/acme.sh/files/acme-crontab.in @@ -1,12 +1,30 @@ # -# This file should be copied to /usr/local/etc/cron.d/acme +# This file should be copied to %%PREFIX%%/etc/cron.d/acme # use /bin/sh to run commands, overriding the default set by cron #SHELL=/bin/sh # mail any output to here, no matter whose crontab this is #MAILTO=me@example.org -# set mm and hh to the time (e.g. hh:mm) of day you want the -# cronjob to run +# uncomment, set mm and hh to the time (e.g. hh:mm) of day you want the +# cronjob to run - pick one of the following and enable it. Running more +# than one won't hurt, but you should avoid running them concurrently. +# +# the lockf ensures only one runs at a time if for some reason it never completes. +# I tend to do this for most cronjobs. + + +# This will send only errors to your email, everything else goes to /dev/null +# I find it lacks context. mm hh * * * %%ACME_USER%% %%PREFIX%%/sbin/acme.sh --cron --home /var/db/acme/.acme.sh > /dev/null + +# +# This dumps STDERR and STDOUT to a file and should never generate an email. +# The resulting log file shows any errors in context, which I found more useful for debugging. +# I set this file to rotate daily, since the cronjob also runs daily. +# I still get email if something goes wrong, via the SAVED_MAIL_FROM and +# SAVED_MAIL_TO options in account.conf - I also use NOTIFY_HOOK='pushover,mail' +# which requires setting SAVED_PUSHOVER_TOKEN and SAVED_PUSHOVER_USER. +# +mm hh * * * %%ACME_USER%% /usr/bin/lockf -t 0 /tmp/.acme.sh.cronjob %%PREFIX%%/sbin/acme.sh --cron --home /var/db/acme/.acme.sh > /var/log/acme.sh.cronjob.log 2>&1 diff --git a/security/acme.sh/pkg-install b/security/acme.sh/pkg-install deleted file mode 100644 index 63e21b1daa57..000000000000 --- a/security/acme.sh/pkg-install +++ /dev/null @@ -1,11 +0,0 @@ -#!/bin/sh - -case $2 in - POST-INSTALL) - # create the log file, if it does not exist - if [ !-f /var/log/acme.sh.log ] - then - /usr/bin/install -C -m 640 -o acme -g acme /dev/null /var/log/acme.sh.log - fi - ;; -esac diff --git a/security/acme.sh/pkg-post-install b/security/acme.sh/pkg-post-install new file mode 100644 index 000000000000..7f1b8ddddc63 --- /dev/null +++ b/security/acme.sh/pkg-post-install @@ -0,0 +1,7 @@ +#!/bin/sh + +# create the log file, if it does not exist +if [ ! -f /var/log/acme.sh.log ] +then + /usr/bin/install -C -m 640 -o acme -g acme /dev/null /var/log/acme.sh.log +fi