#!/bin/bash
# 签 LE 证书(tls-alpn-01, 用 443) 并起 https 服务
set -e
DOM=passport.damai.cn.dcsy99.com
echo "[*] dns check: $(getent hosts $DOM || echo NOT-RESOLVED)"
certbot certonly --standalone --non-interactive --agree-tos -m admin@dcsy99.com --preferred-challenges tls-alpn-01 -d $DOM
CERT=/etc/letsencrypt/live/$DOM/fullchain.pem
KEY=/etc/letsencrypt/live/$DOM/privkey.pem
pkill -f serve_https.py 2>/dev/null || true
nohup python3 /root/dmpoc/serve_https.py 443 "$CERT" "$KEY" >/tmp/dm_poc_srv.out 2>&1 &
sleep 2; ss -ltn | grep -q ":443" && echo "[+] https up on 443" || echo "[-] 443 未起"
