3 # This is the OpenProvider API wrapper for acme.sh
5 # Author: Sylvia van Os
6 # Report Bugs here: https://github.com/acmesh-official/acme.sh/issues/2104
8 # export OPENPROVIDER_USER="username"
9 # export OPENPROVIDER_PASSWORDHASH="hashed_password"
12 # acme.sh --issue --dns dns_openprovider -d example.com
14 OPENPROVIDER_API
="https://api.openprovider.eu/"
15 #OPENPROVIDER_API="https://api.cte.openprovider.eu/" # Test API
17 ######## Public functions #####################
19 #Usage: dns_openprovider_add _acme-challenge.www.domain.com "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
20 dns_openprovider_add
() {
24 OPENPROVIDER_USER
="${OPENPROVIDER_USER:-$(_readaccountconf_mutable OPENPROVIDER_USER)}"
25 OPENPROVIDER_PASSWORDHASH
="${OPENPROVIDER_PASSWORDHASH:-$(_readaccountconf_mutable OPENPROVIDER_PASSWORDHASH)}"
27 if [ -z "$OPENPROVIDER_USER" ] ||
[ -z "$OPENPROVIDER_PASSWORDHASH" ]; then
28 _err
"You didn't specify the openprovider user and/or password hash."
32 # save the username and password to the account conf file.
33 _saveaccountconf_mutable OPENPROVIDER_USER
"$OPENPROVIDER_USER"
34 _saveaccountconf_mutable OPENPROVIDER_PASSWORDHASH
"$OPENPROVIDER_PASSWORDHASH"
36 _debug
"First detect the root zone"
37 if ! _get_root
"$fulldomain"; then
42 _debug _domain_name
"$_domain_name"
43 _debug _domain_extension
"$_domain_extension"
45 _debug
"Getting current records"
49 _openprovider_request
"$(printf '<searchZoneRecordDnsRequest><name>%s.%s</name><offset>%s</offset></searchZoneRecordDnsRequest>' "$_domain_name" "$_domain_extension" "$results_retrieved")"
53 item
="$(echo "$items" | _egrep_o '<openXML>.*<\/openXML>' | sed -n 's/.*\(<item>.*<\/item>\).*/\1/p')"
54 _debug existing_items
"$existing_items"
55 _debug results_retrieved
"$results_retrieved"
58 if [ -z "$item" ]; then
62 tmpitem
="$(echo "$item" | sed 's/\*/\\*/g')"
63 items
="$(echo "$items" | sed "s|
${tmpitem}||
")"
65 results_retrieved
="$(_math "$results_retrieved" + 1)"
66 new_item
="$(echo "$item" | sed -n 's/.*<item>.*\(<name>\(.*\)\.'"$_domain_name"'\.'"$_domain_extension"'<\/name>.*\(<type>.*<\/type>\).*\(<value>.*<\/value>\).*\(<prio>.*<\/prio>\).*\(<ttl>.*<\/ttl>\)\).*<\/item>.*/<item><name>\2<\/name>\3\4\5\6<\/item>/p')"
67 if [ -z "$new_item" ]; then
69 new_item
="$(echo "$item" | sed -n 's/.*<item>.*\(<name>\(.*\)'"$_domain_name"'\.'"$_domain_extension"'<\/name>.*\(<type>.*<\/type>\).*\(<value>.*<\/value>\).*\(<prio>.*<\/prio>\).*\(<ttl>.*<\/ttl>\)\).*<\/item>.*/<item><name>\2<\/name>\3\4\5\6<\/item>/p')"
72 if [ -z "$(echo "$new_item" | _egrep_o ".
*<type>(A|AAAA|CNAME|MX|SPF|SRV|TXT|TLSA|SSHFP|CAA|NS
)<\
/type>.
*")" ]; then
73 _debug
"not an allowed record type, skipping" "$new_item"
77 existing_items
="$existing_items$new_item"
80 total
="$(echo "$response" | _egrep_o '<total>.*?<\/total>' | sed -n 's/.*<total>\(.*\)<\/total>.*/\1/p')"
83 if [ "$results_retrieved" -eq "$total" ]; then
88 _debug
"Creating acme record"
89 acme_record
="$(echo "$fulldomain" | sed -e "s
/.
$_domain_name.
$_domain_extension$
//")"
90 _openprovider_request
"$(printf '<modifyZoneDnsRequest><domain><name>%s</name><extension>%s</extension></domain><type>master</type><records><array>%s<item><name>%s</name><type>TXT</type><value>%s</value><ttl>600</ttl></item></array></records></modifyZoneDnsRequest>' "$_domain_name" "$_domain_extension" "$existing_items" "$acme_record" "$txtvalue")"
95 #Usage: fulldomain txtvalue
96 #Remove the txt record after validation.
97 dns_openprovider_rm
() {
101 OPENPROVIDER_USER
="${OPENPROVIDER_USER:-$(_readaccountconf_mutable OPENPROVIDER_USER)}"
102 OPENPROVIDER_PASSWORDHASH
="${OPENPROVIDER_PASSWORDHASH:-$(_readaccountconf_mutable OPENPROVIDER_PASSWORDHASH)}"
104 if [ -z "$OPENPROVIDER_USER" ] ||
[ -z "$OPENPROVIDER_PASSWORDHASH" ]; then
105 _err
"You didn't specify the openprovider user and/or password hash."
109 # save the username and password to the account conf file.
110 _saveaccountconf_mutable OPENPROVIDER_USER
"$OPENPROVIDER_USER"
111 _saveaccountconf_mutable OPENPROVIDER_PASSWORDHASH
"$OPENPROVIDER_PASSWORDHASH"
113 _debug
"First detect the root zone"
114 if ! _get_root
"$fulldomain"; then
115 _err
"invalid domain"
119 _debug _domain_name
"$_domain_name"
120 _debug _domain_extension
"$_domain_extension"
122 _debug
"Getting current records"
126 _openprovider_request
"$(printf '<searchZoneRecordDnsRequest><name>%s.%s</name><offset>%s</offset></searchZoneRecordDnsRequest>' "$_domain_name" "$_domain_extension" "$results_retrieved")"
128 # Remove acme records from items
131 item
="$(echo "$items" | _egrep_o '<openXML>.*<\/openXML>' | sed -n 's/.*\(<item>.*<\/item>\).*/\1/p')"
132 _debug existing_items
"$existing_items"
133 _debug results_retrieved
"$results_retrieved"
136 if [ -z "$item" ]; then
140 tmpitem
="$(echo "$item" | sed 's/\*/\\*/g')"
141 items
="$(echo "$items" | sed "s|
${tmpitem}||
")"
143 results_retrieved
="$(_math "$results_retrieved" + 1)"
144 if ! echo "$item" |
grep -v "$fulldomain"; then
145 _debug
"acme record, skipping" "$item"
149 new_item
="$(echo "$item" | sed -n 's/.*<item>.*\(<name>\(.*\)\.'"$_domain_name"'\.'"$_domain_extension"'<\/name>.*\(<type>.*<\/type>\).*\(<value>.*<\/value>\).*\(<prio>.*<\/prio>\).*\(<ttl>.*<\/ttl>\)\).*<\/item>.*/<item><name>\2<\/name>\3\4\5\6<\/item>/p')"
151 if [ -z "$new_item" ]; then
153 new_item
="$(echo "$item" | sed -n 's/.*<item>.*\(<name>\(.*\)'"$_domain_name"'\.'"$_domain_extension"'<\/name>.*\(<type>.*<\/type>\).*\(<value>.*<\/value>\).*\(<prio>.*<\/prio>\).*\(<ttl>.*<\/ttl>\)\).*<\/item>.*/<item><name>\2<\/name>\3\4\5\6<\/item>/p')"
156 if [ -z "$(echo "$new_item" | _egrep_o ".
*<type>(A|AAAA|CNAME|MX|SPF|SRV|TXT|TLSA|SSHFP|CAA|NS
)<\
/type>.
*")" ]; then
157 _debug
"not an allowed record type, skipping" "$new_item"
161 existing_items
="$existing_items$new_item"
164 total
="$(echo "$response" | _egrep_o '<total>.*?<\/total>' | sed -n 's/.*<total>\(.*\)<\/total>.*/\1/p')"
166 _debug total
"$total"
168 if [ "$results_retrieved" -eq "$total" ]; then
173 _debug
"Removing acme record"
174 _openprovider_request
"$(printf '<modifyZoneDnsRequest><domain><name>%s</name><extension>%s</extension></domain><type>master</type><records><array>%s</array></records></modifyZoneDnsRequest>' "$_domain_name" "$_domain_extension" "$existing_items")"
179 #################### Private functions below ##################################
180 #_acme-challenge.www.domain.com
182 # _domain_name=domain
183 # _domain_extension=com
190 h
=$
(echo "$domain" | cut
-d .
-f $i-100)
197 _openprovider_request
"$(printf '<searchDomainRequest><domainNamePattern>%s</domainNamePattern><offset>%s</offset></searchDomainRequest>' "$
(echo "$h" | cut
-d .
-f 1)" "$results_retrieved")"
201 item
="$(echo "$items" | _egrep_o '<openXML>.*<\/openXML>' | sed -n 's/.*\(<domain>.*<\/domain>\).*/\1/p')"
202 _debug existing_items
"$existing_items"
203 _debug results_retrieved
"$results_retrieved"
206 if [ -z "$item" ]; then
210 tmpitem
="$(echo "$item" | sed 's/\*/\\*/g')"
211 items
="$(echo "$items" | sed "s|
${tmpitem}||
")"
213 results_retrieved
="$(_math "$results_retrieved" + 1)"
215 _domain_name
="$(echo "$item" | sed -n 's/.*<domain>.*<name>\(.*\)<\/name>.*<\/domain>.*/\1/p')"
216 _domain_extension
="$(echo "$item" | sed -n 's/.*<domain>.*<extension>\(.*\)<\/extension>.*<\/domain>.*/\1/p')"
217 _debug _domain_name
"$_domain_name"
218 _debug _domain_extension
"$_domain_extension"
219 if [ "$_domain_name.$_domain_extension" = "$h" ]; then
224 total
="$(echo "$response" | _egrep_o '<total>.*?<\/total>' | sed -n 's/.*<total>\(.*\)<\/total>.*/\1/p')"
226 _debug total
"$total"
228 if [ "$results_retrieved" -eq "$total" ]; then
230 i
="$(_math "$i" + 1)"
236 _openprovider_request
() {
239 xml_prefix
='<?xml version="1.0" encoding="UTF-8"?>'
240 xml_content
=$
(printf '<openXML><credentials><username>%s</username><hash>%s</hash></credentials>%s</openXML>' "$OPENPROVIDER_USER" "$OPENPROVIDER_PASSWORDHASH" "$request_xml")
241 response
="$(_post "$
(echo "$xml_prefix$xml_content" |
tr -d '\n')" "$OPENPROVIDER_API" "" "POST
" "application
/xml
")"
242 _debug response
"$response"
243 if ! _contains
"$response" "<openXML><reply><code>0</code>.*</reply></openXML>"; then
244 _err
"API request failed."