#!/bin/bash
#
# YACHT (Yet Another CA How To) Placed in public domain. RLamb 2019
#
wdest="root@mywebserver:/siteroot"
read -p "CKA_ID: " kid
lst=`./hcardshow 2>/dev/null | grep ID | cut -f2 -d':' | sort -u`
for i in $lst; do
  if [ "$i" = "$kid" ]; then break; fi
done
if [ "$i" != "$kid" ]; then
  echo "$kid CKA_ID does not exist in HSM. Check with hcardshow."
  exit 0
fi
openssl ca -config ca.cnf -gencrl -engine pkcs11 -keyform engine -keyfile 1:$kid -cert ca.crt -crldays 365 -out crl.pem
openssl crl -in crl.pem -outform der -out ca.crl
echo scp -p ca.crl $wdest/docs/ca/ca.crl
