5 ms·
I've been using the following script in my build process to avoid certificate expiration surprises: currentDateEpoch=$(date +%s) expirationDate=$(openssl x
by moonboots 14y ago
I've been using the following script in my build process to avoid certificate expiration surprises:
currentDateEpoch=$(date +%s)
expirationDate=$(openssl x509 -in $my_cert -enddate -noout | sed 's/notAfter=//' | date -f -)
expirationDateEpoch=$(date -d "$expirationDate" +%s)
diff=$((expirationDateEpoch - currentDateEpoch))
oneMonthInSeconds=$((30 * 24 * 3600))
oneWeekInSeconds=$((7 * 24 * 3600))
if [ "$diff" -lt $oneWeekInSeconds ]; then
printf "Certificate $my_cert needs to be renewed! Expires on $(date -d "$expirationDate" +"%B %_d, %Y")\n" >&2
exit 3
fi
if [ "$diff" -lt $oneMonthInSeconds ]; then
printf "Certificate $my_cert expires in less than a month! Expires on $(date -d "$expirationDate" +"%B %_d, %Y")\n" >&2
else
printf "Note: certificate $my_cert expires on $(date -d "$expirationDate" +"%B %_d, %Y")\n" >&2
fi