Server IP : 103.119.228.120 / Your IP : 18.119.127.13 Web Server : Apache System : Linux v8.techscape8.com 3.10.0-1160.119.1.el7.tuxcare.els2.x86_64 #1 SMP Mon Jul 15 12:09:18 UTC 2024 x86_64 User : nobody ( 99) PHP Version : 5.6.40 Disable Function : shell_exec,symlink,system,exec,proc_get_status,proc_nice,proc_terminate,define_syslog_variables,syslog,openlog,closelog,escapeshellcmd,passthru,ocinum cols,ini_alter,leak,listen,chgrp,apache_note,apache_setenv,debugger_on,debugger_off,ftp_exec,dl,dll,myshellexec,proc_open,socket_bind,proc_close,escapeshellarg,parse_ini_filepopen,fpassthru,exec,passthru,escapeshellarg,escapeshellcmd,proc_close,proc_open,ini_alter,popen,show_source,proc_nice,proc_terminate,proc_get_status,proc_close,pfsockopen,leak,apache_child_terminate,posix_kill,posix_mkfifo,posix_setpgid,posix_setsid,posix_setuid,dl,symlink,shell_exec,system,dl,passthru,escapeshellarg,escapeshellcmd,myshellexec,c99_buff_prepare,c99_sess_put,fpassthru,getdisfunc,fx29exec,fx29exec2,is_windows,disp_freespace,fx29sh_getupdate,fx29_buff_prepare,fx29_sess_put,fx29shexit,fx29fsearch,fx29ftpbrutecheck,fx29sh_tools,fx29sh_about,milw0rm,imagez,sh_name,myshellexec,checkproxyhost,dosyayicek,c99_buff_prepare,c99_sess_put,c99getsource,c99sh_getupdate,c99fsearch,c99shexit,view_perms,posix_getpwuid,posix_getgrgid,posix_kill,parse_perms,parsesort,view_perms_color,set_encoder_input,ls_setcheckboxall,ls_reverse_all,rsg_read,rsg_glob,selfURL,dispsecinfo,unix2DosTime,addFile,system,get_users,view_size,DirFiles,DirFilesWide,DirPrintHTMLHeaders,GetFilesTotal,GetTitles,GetTimeTotal,GetMatchesCount,GetFileMatchesCount,GetResultFiles,fs_copy_dir,fs_copy_obj,fs_move_dir,fs_move_obj,fs_rmdir,SearchText,getmicrotime MySQL : ON | cURL : ON | WGET : ON | Perl : ON | Python : ON | Sudo : ON | Pkexec : ON Directory : /scripts/ |
Upload File : |
#!/usr/local/cpanel/3rdparty/bin/perl # cpanel - scripts/expunge_expired_certificates_from_sslstorage # Copyright 2022 cPanel, L.L.C. # All rights reserved. # copyright@cpanel.net http://cpanel.net # This code is subject to the cPanel license. Unauthorized copying is prohibited package scripts::expunge_expired_certificates_from_sslstorage; use strict; use warnings; use parent qw( Cpanel::HelpfulScript ); use Cpanel::Config::Users (); use Cpanel::PIDFile (); use Cpanel::SSLStorage::User (); use Cpanel::PwCache::Build (); use Cpanel::PwCache (); use Cpanel::AccessIds::ReducedPrivileges (); use Try::Tiny; =encoding utf-8 =head1 NAME scripts::expunge_expired_certificates_from_sslstorage =head1 SYNOPSIS expunge_expired_certificates_from_sslstorage [ --user <username> | --help ] =head1 DESCRIPTION This command will look at the SSLStorage databases for all the users (or optionally a specific user) and checks for certificates that have been expired for over a set time (C<$Cpanel::SSLStorage::EXPUNGE_CERTIFICATES_AFTER_SECONDS> seconds) and removes them. NOTE: This only operates on the user's SSL Storage database. This does not uninstall certificates from websites, mail, cpsrvd, or other services. =cut our $PID_FILE = '/var/run/expunge_expired_certificates_from_sslstorage.pid'; sub _OPTIONS { return qw( user=s ); } __PACKAGE__->new(@ARGV)->script() unless caller(); sub script { my ($self) = @_; if ( $self->getopt('user') ) { my $user = $self->getopt('user'); print "Checking for expired certificates for the user '$user'.\n"; try { my $expired_certs = $self->call_for_one_user($user); print "Found and expunged " . scalar @$expired_certs . " expired certificates for '$user'.\n"; } catch { warn "There was an error expunging certificates for '$user': $_\n"; }; return; } Cpanel::PwCache::Build::init_passwdless_pwcache(); Cpanel::PIDFile->do( $PID_FILE, sub { print "Checking for expired certificates for all users.\n"; my @users = ( Cpanel::Config::Users::getcpusers(), 'root' ); for my $user (@users) { try { my $expired_certs = $self->call_for_one_user($user); print "Found and expunged " . scalar @$expired_certs . " expired certificates for '$user'.\n"; } catch { warn "There was an error expunging certificates for '$user': $_\n"; }; } } ); return; } sub call_for_one_user { my ( $self, $user ) = @_; my $expired_certs; my $privs; if ( $user ne 'root' ) { my $homedir = Cpanel::PwCache::gethomedir($user); die "No ssl storage exists for '$user'" if !-d "$homedir/ssl" || -z "$homedir/ssl/ssl.db"; $privs = Cpanel::AccessIds::ReducedPrivileges->new($user); } my ( $ok, $storage ) = Cpanel::SSLStorage::User->new( user => $user, 'disable_required_fields_check' => 1 ); die "There was an error getting the SSLStorage database for '$user': $storage" if !$ok; ( $ok, $expired_certs ) = $storage->_expunge_expired_certificates(); # we already reduced privs die "There was an error expunging expired certificates for '$user': $expired_certs" if !$ok; return $expired_certs; } 1;