#!/bin/bash
#
# YACHT (Yet Another CA How To) Placed in public domain. RLamb 2019
#
wdest="root@mywebserver:/siteroot"
if [ ! -f index.txt ]; then
    touch index.txt
    openssl x509 -in ca.crt -outform der -out ca.cer
    echo scp -p ca.crt ca.cer $wdest/docs/ca/smime/    
fi
if [ ! -f index.txt.attr ]; then echo "unique_subject = no" > index.txt.attr; fi
if [ ! -f serial ]; then echo "01" >serial; fi
if [ ! -d newcerts ]; then mkdir newcerts; fi
if [ ! -f crlnumber ]; then echo 01 > crlnumber; fi
# Extract X509v3 Subject Alternative Name: from CSR
export SAN=`openssl req -in new.csr -noout -text | grep -A1 "X509v3 Subject Alternative Name:" | tail -1`
openssl ca -config ca2.cnf -cert ca.crt -keyfile ca.key -out new.crt -infiles new.csr
openssl pkcs12 -export -in new.crt -inkey new.key -certfile ca.crt -out new.p12
echo scp -p index.txt $wdest/docs/ca/smime/ocsp/
