1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586 |
- set -e
- set -u
- if [ -z "${1:-}" ]; then
- echo "Usage: $0 <authority identity fingerprint>" 2>&1
- exit 3
- fi
- identity="$1"
- DIRSERVERS=""
- DIRSERVERS="$DIRSERVERS 86.59.21.38:80"
- DIRSERVERS="$DIRSERVERS 128.31.0.34:9031"
- DIRSERVERS="$DIRSERVERS 216.224.124.114:9030"
- DIRSERVERS="$DIRSERVERS 88.198.7.215:80"
- DIRSERVERS="$DIRSERVERS 140.247.60.64:80"
- TMPFILE="`tempfile`"
- trap 'rm -f "$TMPFILE"' 0
- for dirserver in $DIRSERVERS; do
- wget -q -O "$TMPFILE" "http://$dirserver/tor/keys/fp/$identity"
- if [ "$?" = 0 ]; then
- break
- else
- cat /dev/null > "$TMPFILE"
- continue
- fi
- done
- if ! [ -s "$TMPFILE" ] ; then
- echo "UNKNOWN: Downloading certificate for $identity failed."
- exit 3
- fi
- expirydate="$(awk '$1=="dir-key-expires" {printf "%s %s", $2, $3}' < "$TMPFILE")"
- expiryunix=$(TZ=UTC date -d "$expirydate" +%s)
- now=$(date +%s)
- if [ "$now" -ge "$expiryunix" ]; then
- echo "CRITICAL: Certificate expired $expirydate (authority $identity)."
- exit 2
- elif [ "$(( $now + 7*24*60*60 ))" -ge "$expiryunix" ]; then
- echo "CRITICAL: Certificate expires $expirydate (authority $identity)."
- exit 2
- elif [ "$(( $now + 30*24*60*60 ))" -ge "$expiryunix" ]; then
- echo "WARNING: Certificate expires $expirydate (authority $identity)."
- exit 1
- else
- echo "OK: Certificate expires $expirydate (authority $identity)."
- exit 0
- fi
|