remove-expired-certs.sh (1175B)
1 #!/bin/sh 2 # Begin remove-expired-certs.sh 3 # 4 # Version 20120211 5 6 # Make sure the date is parsed correctly on all systems 7 mydate() 8 { 9 local y=$( echo $1 | cut -d" " -f4 ) 10 local M=$( echo $1 | cut -d" " -f1 ) 11 local d=$( echo $1 | cut -d" " -f2 ) 12 local m 13 14 [ -z "${d}" ] && d="0" 15 [ "${d}" -lt 10 ] && d="0${d}" 16 17 case $M in 18 Jan) m="01";; 19 Feb) m="02";; 20 Mar) m="03";; 21 Apr) m="04";; 22 May) m="05";; 23 Jun) m="06";; 24 Jul) m="07";; 25 Aug) m="08";; 26 Sep) m="09";; 27 Oct) m="10";; 28 Nov) m="11";; 29 Dec) m="12";; 30 esac 31 32 certdate="${y}${m}${d}" 33 } 34 35 DIR="$1" 36 [ -z "$DIR" ] && DIR=$(pwd) 37 38 today=$(date +%Y%m%d) 39 40 find ${DIR} -type f -a -iname "*.crt" -printf "%p\n" | while read cert; do 41 notafter=$(/usr/bin/openssl x509 -enddate -in "${cert}" -noout) 42 date=$( echo ${notafter} | sed 's/^notAfter=//' ) 43 mydate "$date" 44 45 if [ ${certdate} -lt ${today} ]; then 46 echo "!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!" 47 echo "EXPIRED CERTIFICATE FOUND $certdate: \"$(basename ${cert})\"" 48 echo "!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!" 49 rm -f "${cert}" 50 fi 51 done