3 ## Name: dns_pleskxml.sh
5 ## Also uses some code from PR#1832 by @romanlum (https://github.com/Neilpang/acme.sh/pull/1832/files)
7 ## This DNS01 method uses the Plesk XML API described at:
8 ## https://docs.plesk.com/en-US/12.5/api-rpc/about-xml-api.28709
9 ## and more specifically: https://docs.plesk.com/en-US/12.5/api-rpc/reference.28784
11 ## Note: a DNS ID with host = empty string is OK for this API, see
12 ## https://docs.plesk.com/en-US/obsidian/api-rpc/about-xml-api/reference/managing-dns/managing-dns-records/adding-dns-record.34798
13 ## For example, to add a TXT record to DNS alias domain "acme-alias.com" would be a valid Plesk action.
14 ## So this API module can handle such a request, if needed.
16 ## For ACME v2 purposes, new TXT records are appended when added, and removing one TXT record will not affect any other TXT records.
18 ## The plesk plugin uses the xml api to add and remvoe the dns records. Therefore the url, username
19 ## and password have to be configured by the user before this module is called.
22 ## export pleskxml_uri="https://address-of-my-plesk-server.net:8443/enterprise/control/agent.php"
23 ## (or probably something similar)
24 ## export pleskxml_user="my plesk username"
25 ## export pleskxml_pass="my plesk password"
28 ## Ok, let's issue a cert now:
30 ## acme.sh --issue --dns dns_pleskxml -d example.com -d www.example.com
33 ## The `pleskxml_uri`, `pleskxml_user` and `pleskxml_pass` will be saved in `~/.acme.sh/account.conf` and reused when needed.
35 #################### INTERNAL VARIABLES + NEWLINE + API TEMPLATES ##################################
37 pleskxml_init_checks_done
=0
39 # Variable containing bare newline - not a style issue
40 # shellcheck disable=SC1004
44 pleskxml_tplt_get_domains
="<packet><customer><get-domain-list><filter/></get-domain-list></customer></packet>"
45 # Get a list of domains that PLESK can manage, so we can check root domain + host for acme.sh
46 # Also used to test credentials and URI.
49 pleskxml_tplt_get_dns_records
="<packet><dns><get_rec><filter><site-id>%s</site-id></filter></get_rec></dns></packet>"
50 # Get all DNS records for a Plesk domain ID.
51 # PARAM = Plesk domain id to query
53 pleskxml_tplt_add_txt_record
="<packet><dns><add_rec><site-id>%s</site-id><type>TXT</type><host>%s</host><value>%s</value></add_rec></dns></packet>"
54 # Add a TXT record to a domain.
55 # PARAMS = (1) Plesk internal domain ID, (2) "hostname" for the new record, eg '_acme_challenge', (3) TXT record value
57 pleskxml_tplt_rmv_dns_record
="<packet><dns><del_rec><filter><id>%s</id></filter></del_rec></dns></packet>"
58 # Delete a specific TXT record from a domain.
59 # PARAM = the Plesk internal ID for the DNS record to be deleted
61 #################### Public functions ##################################
63 #Usage: dns_pleskxml_add _acme-challenge.www.domain.com "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
68 _info
"Entering dns_pleskxml_add() to add TXT record '$txtvalue' to domain '$fulldomain'..."
70 # Get credentials if not already checked, and confirm we can log in to Plesk XML API
71 if ! _credential_check
; then
75 # Get root and subdomain details, and Plesk domain ID
76 if ! _pleskxml_get_root_domain
"$fulldomain"; then
80 _debug
'Credentials OK, and domain identified. Calling Plesk XML API to add TXT record'
82 # printf using template in a variable - not a style issue
83 # shellcheck disable=SC2059
84 request
="$(printf "$pleskxml_tplt_add_txt_record" "$root_domain_id" "$sub_domain_name" "$txtvalue")"
85 if ! _call_api
"$request"; then
89 # OK, we should have added a TXT record. Let's check and return success if so.
90 # All that should be left in the result, is one section, containing <result><status>ok</status><id>NEW_DNS_RECORD_ID</id></result>
92 results
="$(_api_response_split "$pleskxml_prettyprint_result" 'result' '<status>')"
94 if ! _value
"$results" |
grep '<status>ok</status>' |
grep -qE '<id>[0-9]+</id>'; then
95 # Error - doesn't contain expected string. Something's wrong.
96 _err
'Error when calling Plesk XML API.'
97 _err
'The result did not contain the expected <id>XXXXX</id> section, or contained other values as well.'
98 _err
'This is unexpected: something has gone wrong.'
99 _err
'The full response was:\n' "$pleskxml_prettyprint_result"
103 recid
="$(_value "$results" | grep -E '<id>[0-9]+</id>' | sed -E 's/^.*<id>([0-9]+)<\/id>.*$/\1/')"
105 _info
"Success. TXT record appears to be correctly added (Plesk record ID=$recid). Exiting dns_pleskxml_add()."
110 #Usage: dns_pleskxml_rm _acme-challenge.www.domain.com "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
115 _info
"Entering dns_pleskxml_rm() to remove TXT record '$txtvalue' from domain '$fulldomain'..."
117 # Get credentials if not already checked, and confirm we can log in to Plesk XML API
118 if ! _credential_check
; then
122 # Get root and subdomain details, and Plesk domain ID
123 if ! _pleskxml_get_root_domain
"$fulldomain"; then
127 _debug
'Credentials OK, and domain identified. Calling Plesk XML API to get list of TXT records and their IDs'
129 # printf using template in a variable - not a style issue
130 # shellcheck disable=SC2059
131 request
="$(printf "$pleskxml_tplt_get_dns_records" "$root_domain_id")"
132 if ! _call_api
"$request"; then
136 # Reduce output to one line per DNS record, filtered for TXT records with a record ID only (which they should all have)
137 reclist
="$(_api_response_split "$pleskxml_prettyprint_result" 'result' '<status>ok</status>' \
138 | grep "<site-id
>${root_domain_id}</site-id
>" \
139 | grep -E '<id>[0-9]+</id>' \
140 | grep '<type>TXT</type>'
143 if [ -z "$reclist" ]; then
144 _err
"No TXT records found for root domain ${root_domain_name} (Plesk domain ID ${root_domain_id}). Exiting."
148 _debug
"Got list of DNS TXT records for root domain '$root_domain_name'"':\n'"$reclist"
150 recid
="$(_value "$reclist" \
151 | grep "<host>$1.
</host>" \
152 | grep "<value
>$txtvalue</value
>" \
153 | sed -E 's/(^.*<id>|<\/id>.*$)//g'
156 _debug
"List of DNS TXT records for host:"'\n'"$(_value "$reclist" | grep "<host>$1.
</host>")"
158 if ! _value
"$recid" |
grep -Eq '^[0-9]+$'; then
159 _err
"DNS records for root domain '${root_domain_name}' (Plesk ID ${root_domain_id}) + host '${sub_domain_name}' do not contain the TXT record '${txtvalue}'"
160 _err
"Cannot delete TXT record. Exiting."
164 _debug
"Found Plesk record ID for target text string '${txtvalue}': ID=${recid}"
165 _debug
'Calling Plesk XML API to remove TXT record'
167 # printf using template in a variable - not a style issue
168 # shellcheck disable=SC2059
169 request
="$(printf "$pleskxml_tplt_rmv_dns_record" "$recid")"
170 if ! _call_api
"$request"; then
174 # OK, we should have removed a TXT record. Let's check and return success if so.
175 # All that should be left in the result, is one section, containing <result><status>ok</status><id>PLESK_DELETED_DNS_RECORD_ID</id></result>
177 results
="$(_api_response_split "$pleskxml_prettyprint_result" 'result' '<status>')"
179 if ! _value
"$results" |
grep '<status>ok</status>' |
grep -qE '<id>[0-9]+</id>'; then
180 # Error - doesn't contain expected string. Something's wrong.
181 _err
'Error when calling Plesk XML API.'
182 _err
'The result did not contain the expected <id>XXXXX</id> section, or contained other values as well.'
183 _err
'This is unexpected: something has gone wrong.'
184 _err
'The full response was:\n' "$pleskxml_prettyprint_result"
188 _info
"Success. TXT record appears to be correctly removed. Exiting dns_pleskxml_rm()."
192 #################### Private functions below (utility functions) ##################################
194 # Outputs value of a variable without additional newlines etc
199 # Outputs value of a variable (FQDN) and cuts it at 2 specified '.' delimiters, returning the text in between
200 # $1, $2 = where to cut
203 printf '%s' "$3" | cut
-d .
-f "${1}-${2}"
206 # Counts '.' present in a domain name
209 _value
"$1" |
tr -dc '.' |
wc -c
212 # Cleans up an API response, splits it "one line per item in the response" and greps for a string that in the context, identifies "useful" lines
213 # $1 - result string from API
214 # $2 - tag to resplit on (usually "result" or "domain")
215 # $3 - regex to recognise useful return lines
216 _api_response_split
() {
218 |
sed -E 's/(^[[:space:]]+|[[:space:]]+$)//g' \
220 |
sed -E "s/<\/?$2>/${NEWLINE}/g" \
224 #################### Private functions below (DNS functions) ##################################
226 # Calls Plesk XML API, and checks results for obvious issues
231 _debug
'Entered _call_api(). Calling Plesk XML API with request:\n' "'${request}'"
233 export _H1
="HTTP_AUTH_LOGIN: $pleskxml_user"
234 export _H2
="HTTP_AUTH_PASSWD: $pleskxml_pass"
235 export _H3
="content-Type: text/xml"
236 export _H4
="HTTP_PRETTY_PRINT: true"
237 pleskxml_prettyprint_result
="$(_post "${request}" "$pleskxml_uri" "" "POST
")"
238 pleskxml_retcode
="$?"
239 _debug
'The responses from the Plesk XML server were:\n' "retcode=$pleskxml_retcode. Literal response:"'\n' "'$pleskxml_prettyprint_result'"
241 # Detect any <status> that isn't "ok". None of the used calls should fail if the API is working correctly.
242 # Also detect if there simply aren't any status lines (null result?) and report that, as well.
244 statuslines
="$(echo "$pleskxml_prettyprint_result" | grep -E '^[[:space:]]*<status>[^<]*</status>[[:space:]]*$')"
246 if _value
"$statuslines" |
grep -qv '<status>ok</status>'; then
248 # We have some status lines that aren't "ok". Get the details
249 errtext
="$(_value "$pleskxml_prettyprint_result" \
250 | grep -E "(<status
>|
<errcode
>|
<errtext
>)" \
251 | sed -E 's/^<(status|errcode|errtext)>/\1: /' \
252 | sed -E 's/(^[[:space:]]+|<\/(status|errcode|errtext)>$)//g' \
255 elif ! _value
"$statuslines" |
grep -q '<status>ok</status>'; then
257 # We have no status lines at all. Results are empty
258 errtext
='The Plesk XML API unexpectedly returned an empty set of results for this call.'
262 if [ "$pleskxml_retcode" -ne 0 ] ||
[ "$errtext" != "" ]; then
263 # Call failed, for reasons either in the retcode or the response text...
265 if [ "$pleskxml_retcode" -eq 0 ]; then
266 _err
"The POST request was successfully sent to the Plesk server."
268 _err
"The return code for the POST request was $pleskxml_retcode (non-zero = could not submit request to server)."
271 if [ "$errtext" != "" ]; then
272 _err
'The error responses received from the Plesk server were:\n' "$errtext"
274 _err
"No additional error messages were received back from the Plesk server"
277 _err
"The Plesk XML API call failed."
282 _debug
"Leaving _call_api(). Successful call."
287 # Startup checks (credentials, URI)
288 _credential_check
() {
289 _debug
"Checking Plesk XML API login credentials and URI..."
291 if [ "$pleskxml_init_checks_done" -eq 1 ]; then
292 _debug
"Initial checks already done, no need to repeat. Skipped."
296 pleskxml_user
="${pleskxml_user:-$(_readaccountconf_mutable pleskxml_user)}"
297 pleskxml_pass
="${pleskxml_pass:-$(_readaccountconf_mutable pleskxml_pass)}"
298 pleskxml_uri
="${pleskxml_uri:-$(_readaccountconf_mutable pleskxml_uri)}"
300 _debug
"Credentials - User: '${pleskxml_user}' Passwd: ****** URI: '${pleskxml_uri}'"
302 if [ -z "$pleskxml_user" ] ||
[ -z "$pleskxml_pass" ] ||
[ -z "$pleskxml_uri" ]; then
306 _err
"You didn't specify one or more of the Plesk XML API username, password, or URI."
307 _err
"Please create these and try again."
308 _err
"Instructions are in the module source code."
312 # Test the API is usable, by trying to read the list of managed domains...
313 _call_api
"$pleskxml_tplt_get_domains"
314 if [ "$pleskxml_retcode" -ne 0 ]; then
315 _err
'\nFailed to access Plesk XML API.'
316 _err
"Please check your login credentials and Plesk URI, and that the URI is reachable, and try again."
320 _saveaccountconf_mutable pleskxml_uri
"$pleskxml_uri"
321 _saveaccountconf_mutable pleskxml_user
"$pleskxml_user"
322 _saveaccountconf_mutable pleskxml_pass
"$pleskxml_pass"
324 _debug
"Test login to Plesk XML API successful. Login credentials and URI successfully saved to the acme.sh configuration file for future use."
326 pleskxml_init_checks_done
=1
331 # For a FQDN, identify the root domain managed by Plesk, its domain ID in Plesk, and the host if any.
333 # IMPORTANT NOTE: a result with host = empty string is OK for this API, see
334 # https://docs.plesk.com/en-US/obsidian/api-rpc/about-xml-api/reference/managing-dns/managing-dns-records/adding-dns-record.34798
335 # See notes at top of this file
337 _pleskxml_get_root_domain
() {
338 _debug
"Identifying DNS root domain for '$1' that is managed by the Plesk account."
339 original_full_domain_name
="$1"
340 root_domain_name
="$1"
342 # test if the domain as provided is valid for splitting.
344 if ! _countdots
"$root_domain_name"; then
345 _err
"Invalid domain. The ACME domain must contain at least two parts (aa.bb) to identify a domain and tld for the TXT record."
349 _debug
"Querying Plesk server for list of managed domains..."
351 _call_api
"$pleskxml_tplt_get_domains"
352 if [ "$pleskxml_retcode" -ne 0 ]; then
356 # Generate a crude list of domains known to this Plesk account.
357 # We convert <ascii-name> tags to <name> so it'll flag on a hit with either <name> or <ascii-name> fields,
358 # for non-Western character sets.
359 # Output will be one line per known domain, containing 2 <name> tages and a single <id> tag
360 # We don't actually need to check for type, name, *and* id, but it guarantees only usable lines are returned.
362 output
="$(_api_response_split "$pleskxml_prettyprint_result" 'domain' '<type>domain</type>' | sed -E 's/<(\/?)ascii-name>/<\1name>/g' | grep '<name>' | grep '<id>')"
364 _debug
'Domains managed by Plesk server are (ignore the hacked output):\n' "$output"
366 # loop and test if domain, or any parent domain, is managed by Plesk
367 # Loop until we don't have any '.' in the string we're testing as a candidate Plesk-managed domain
371 _debug
"Checking if '$root_domain_name' is managed by the Plesk server..."
373 root_domain_id
="$(_value "$output" | grep "<name
>$root_domain_name</name
>" | _head_n 1 | sed -E 's/^.*<id>([0-9]+)<\/id>.*$/\1/')"
375 if [ -n "$root_domain_id" ]; then
377 # SEE IMPORTANT NOTE ABOVE - THIS FUNCTION CAN RETURN HOST='', AND THAT'S OK FOR PLESK XML API WHICH ALLOWS IT.
378 # SO WE HANDLE IT AND DON'T PREVENT IT
379 sub_domain_name
="$(_value "$original_full_domain_name" | sed -E "s
/\.?
${root_domain_name}"'$//')"
380 _info
"Success. Matched host '$original_full_domain_name' to: DOMAIN '${root_domain_name}' (Plesk ID '${root_domain_id}'), HOST '${sub_domain_name}'. Returning."
384 # No match, try next parent up (if any)...
386 root_domain_name
="$(_valuecut 2 1000 "$root_domain_name")"
388 if ! _countdots
"$root_domain_name"; then
389 _debug
"No match, and next parent would be a TLD..."
390 _err
"Cannot find '$original_full_domain_name' or any parent domain of it, in Plesk."
391 _err
"Are you sure that this domain is managed by this Plesk server?"
395 _debug
"No match, trying next parent up..."