#!/bin/bash
#
# YACHT (Yet Another CA How To) Placed in public domain. RLamb 2019
#
wdest="root@mywebserver:/siteroot"
read -p "CKA_ID: " kid
lst=`./hcardshow 2>/dev/null | grep ID | cut -f2 -d':' | sort -u`
for i in $lst; do
  if [ "$i" = "$kid" ]; then break; fi
done
if [ "$i" != "$kid" ]; then
  echo "$kid CKA_ID does not exist in HSM. Check with hcardshow."
  exit 0
fi
ca2dir="../smime"
pushd $ca2dir
openssl ecparam -out ecparam.pem -name prime256v1
openssl req -config careq.cnf -new -newkey ec:ecparam.pem -nodes -keyout ca.key -out ca.csr -subj "/CN=Example Client Authentication and Secure Email CA/O=Example/L=Ballarat/ST=California/C=US"
popd
#
enddate=`date -u --date='+ 10 years' +%y%m%d%H`"0000Z"
startdate=`date -u --date='yesterday' +%y%m%d%H`"0000Z"
openssl ca -config ca.cnf -engine pkcs11 -keyform engine -keyfile 1:$kid -startdate $startdate -enddate $enddate -cert ca.crt -extensions v3_ca -in $ca2dir/ca.csr -out $ca2dir/ca.crt
cp -p ca.crt $ca2dir/rootca.crt
echo scp -p index.txt $wdest/docs/ca/ocsp/
