#!/bin/bash
#
# YACHT (Yet Another CA How To) Placed in public domain. RLamb 2019
#
wdest="root@mywebserver:/siteroot"
read -p "CKA_ID: " kid
lst=`./hcardshow 2>/dev/null | grep ID | cut -f2 -d':' | sort -u`
for i in $lst; do
    if [ "$i" = "$kid" ]; then break; fi
done
if [ "$i" != "$kid" ]; then
    echo "$kid CKA_ID does not exist in HSM. Check with hcardshow."
    exit 0
fi
CN="OCSP"
export SAN="DNS:null"
openssl ecparam -out ecparam.pem -name prime256v1
openssl req -config ca.cnf -new -newkey ec:ecparam.pem -nodes -keyout ocsp.key -out ocsp.csr -subj "/CN=$CN"
openssl ca -config ca.cnf -engine pkcs11 -keyform engine -keyfile 1:$kid -cert ca.crt -out ocsp.crt -name ocsp -in ocsp.csr -out ocsp.crt
cat ocsp.crt ocsp.key > ocsp.pem
echo scp -p ocsp.pem $wdest/ocsp.pem
cat ca.crt > cafile.pem
echo scp -p cafile.pem $wdest/docs/ca/
echo scp -p index.txt index.txt.attr $wdest/docs/ca/ocsp/
# Test with
# openssl ocsp -issuer ca.crt -cert new.crt -header Host www.example.com -url http://www.example.com/ca/ocsp/ -CAfile cafile.pem
#
