@@ -24,14 +24,14 @@ data:
2424 {{- if .Values.graylog.config.tls.updateKeyStore}}
2525 # check if root CA is in cert file
2626 openssl crl2pkcs7 -nocrl -certfile "/mnt/tls/tls.crt" | openssl pkcs7 -print_certs -outform PEM | awk -v out="cert" '
27- /-----BEGIN CERTIFICATE-----/ {n++; f=sprintf("%s-%03d.pem", out, n)}
28- {print > f}
29- /-----END CERTIFICATE-----/ {close(f)}
27+ /-----BEGIN CERTIFICATE-----/ {n++; f=sprintf("%s-%03d.pem", out, n); writing=1 }
28+ writing {print > f}
29+ /-----END CERTIFICATE-----/ {close(f); writing=0 }
3030 '
3131 ROOT_CA=""
3232 for f in cert-*.pem; do
33- subj="$(openssl x509 -in "$f" -noout -subject -nameopt RFC2253 | sed "s/^subject= //")"
34- issu="$(openssl x509 -in "$f" -noout -issuer -nameopt RFC2253 | sed "s/^issuer= //")"
33+ subj="$(openssl x509 -in "$f" -noout -subject -nameopt RFC2253 | sed "s/^subject=//")"
34+ issu="$(openssl x509 -in "$f" -noout -issuer -nameopt RFC2253 | sed "s/^issuer=//")"
3535 if [ "$subj" = "$issu" ]; then
3636 ROOT_CA="root-ca.pem"
3737 cp "$f" "${ROOT_CA}"
5050 cp "${JAVA_HOME_LOCAL}/lib/security/cacerts" "${CACERTS_SRC}/graylog.jks"
5151 chown graylog:graylog "${CACERTS_SRC}/graylog.jks"
5252 keytool -importcert -noprompt -alias byoc -file "/mnt/tls/tls.crt" -keystore "${CACERTS_SRC}/graylog.jks" -storepass {{ .Values.graylog.config.tls.keyStorePass | default "changeit" }}
53- [ -n "${ROOT_CA}" ] && keytool -importcert -noprompt -alias byoc-ca -file "${ROOT_CA}" -keystore "${CACERTS_SRC}/graylog.jks" -storepass {{ .Values.graylog.config.tls.keyStorePass | default "changeit" }}
53+ [ -n "${ROOT_CA}" ] && echo "Adding root CA..." && keytool -importcert -noprompt -alias byoc-ca -file "${ROOT_CA}" -keystore "${CACERTS_SRC}/graylog.jks" -storepass {{ .Values.graylog.config.tls.keyStorePass | default "changeit" }}
5454 if [ ! -e "${CACERTS_DST}/graylog.jks" ] || ! cmp -s "${CACERTS_SRC}/graylog.jks" "${CACERTS_DST}/graylog.jks"; then
5555 cp "${CACERTS_SRC}/graylog.jks" "${CACERTS_DST}/graylog.jks"
5656 echo "Updated Java Key Store."
0 commit comments