#!/bin/bash
# info: copy mail ssl certificate
# options: USER DOMAIN [RESTART]
#
# The function copies user domain SSL to mail SSL directory


#----------------------------------------------------------#
#                    Variable&Function                     #
#----------------------------------------------------------#

# Argument definition
user=$1
domain=$2
restart=$3

# Includes
source $VESTA/func/main.sh
source $VESTA/func/domain.sh
source $VESTA/conf/vesta.conf


#----------------------------------------------------------#
#                    Verifications                         #
#----------------------------------------------------------#

check_args '2' "$#" 'USER DOMAIN [RESTART]'
is_format_valid 'user' 'domain'
is_system_enabled "$MAIL_SYSTEM" 'MAIL_SYSTEM'
is_object_valid 'user' 'USER' "$user"
is_object_valid 'web' 'DOMAIN' "$domain"
is_object_value_exist 'web' 'DOMAIN' "$domain" '$SSL'


#----------------------------------------------------------#
#                       Action                             #
#----------------------------------------------------------#

# Defining certificate location
dom_crt="/home/$user/conf/web/ssl.$domain.pem"
dom_key="/home/$user/conf/web/ssl.$domain.key"
vst_crt="$VESTA/ssl/mail.crt"
vst_key="$VESTA/ssl/mail.key"

# Checking certificate
if [ ! -e "$dom_crt" ] || [ ! -e "$dom_key" ]; then
    check_result $E_NOTEXIST "$domain certificate doesn't exist"
fi

# Checking difference
diff $dom_crt $vst_crt >/dev/null 2>&1
if [ $? -ne 0 ]; then
    rm -f $vst_crt.old $vst_key.old
    mv $vst_crt $vst_crt.old >/dev/null 2>&1
    mv $vst_key $vst_key.old >/dev/null 2>&1
    cp $dom_crt $vst_crt 2>/dev/null
    cp $dom_key $vst_key 2>/dev/null
    chown root:mail $vst_crt $vst_key
else
    restart=no
fi

# Updating mail certificate
case $MAIL_SYSTEM in
    exim)           conf='/etc/exim/exim.conf';;
    exim4)          conf='/etc/exim4/exim4.conf.template';;
esac
if [ -e "$conf" ]; then
    sed -e "s|^tls_certificate.*|tls_certificate = $vst_crt|" \
        -e "s|^tls_privatekey.*|tls_privatekey = $vst_key|" -i $conf
fi

# Updating imap certificate
conf="/etc/dovecot/conf.d/10-ssl.conf"
if [ ! -z "$IMAP_SYSTEM" ] && [ -e "$conf" ]; then
    sed -e "s|ssl_cert.*|ssl_cert = <$vst_crt|" \
        -e "s|ssl_key.*|ssl_key = <$vst_key|" -i $conf
fi


#----------------------------------------------------------#
#                       Vesta                              #
#----------------------------------------------------------#

# Restarting services
if [ "$restart" != 'no' ]; then
    if [ ! -z "$MAIL_SYSTEM" ]; then
        $BIN/v-restart-service $MAIL_SYSTEM
    fi
    if [ ! -z "$IMAP_SYSTEM" ]; then
        $BIN/v-restart-service $IMAP_SYSTEM
    fi
fi

# Updating vesta.conf
if [ -z "$(grep MAIL_CERTIFICATE $VESTA/conf/vesta.conf)" ]; then
    echo "MAIL_CERTIFICATE='$user:$domain'" >> $VESTA/conf/vesta.conf
else
    sed -i "s/MAIL_CERTIFICATE.*/MAIL_CERTIFICATE='$user:$domain'/g" \
        $VESTA/conf/vesta.conf
fi

# Logging
log_event "$OK" "$ARGUMENTS"

exit