check-certificates: make the warning time configurable

This commit is contained in:
Christian Hesse 2023-01-23 17:27:34 +01:00
parent 36a8938dea
commit 555d0e8bfc
5 changed files with 7 additions and 2 deletions

View file

@ -13,6 +13,7 @@
:global CertRenewPass;
:global CertRenewTime;
:global CertRenewUrl;
:global CertWarnTime;
:global Identity;
:global CertificateAvailable
@ -103,7 +104,8 @@ $WaitFullyConnected;
}
}
:foreach Cert in=[ /certificate/find where !revoked !scep-url !(expires-after=[]) expires-after<2w !(fingerprint=[]) ] do={
:foreach Cert in=[ /certificate/find where !revoked !scep-url !(expires-after=[]) \
expires-after<$CertWarnTime !(fingerprint=[]) ] do={
:local CertVal [ /certificate/get $Cert ];
:if ([ :len [ /certificate/scep-server/find where ca-cert=($CertVal->"ca") ] ] > 0) do={