#!/bin/bash

ssleverywhere_file=/home/yazan/ssleverywhere_client
certs_file=/home/yazan/ssleverywhere_client/certs
csr_file=/home/yazan/ssleverywhere_client/csr
keys_file=/home/yazan/ssleverywhere_client/private
base_url="192.168.250.16:8000"

#mkdir -p $ssleverywhere_file/ $certs_file/ $csr_file/ $keys_file/

# Check if at least one argument is provided
if [ $# -lt 1 ]; then
    echo "Usage: ssleverywhere <command>"
    exit 1
fi

# Parse the command
command="$1"
shift # Remove the first argument (the command)

case "$command" in
    "-gen_cert")
        # Check if at least two arguments (name) are provided
        if [ $# -lt 2 ]; then
            echo "Usage: ssleverywhere -gen_cert -name <name> [-default | -manual]"
            exit 1
        fi
        name=""
        config=""
        manual=false

        while [ $# -gt 0 ]; do
            case "$1" in
                -name)
                    shift
                    name="$1"
                    if [[ ! "$name" =~ ^[A-Z]{2}$ ]]; then
                        echo "Error: The name must consist of two uppercase letters (e.g., 'US')."
                        exit 1
                    fi
                    ;;
                -default)
                    config="default"
                    ;;
                -manual)
                    config="manual"
                    manual=true
                    counter=0
                    ;;
                -key_type)
                    if $manual; then
                        shift
                        key_type="$1"
			let counter=counter+1
                    else
                        echo "Error: -key_type can only be used with -manual."
                        exit 1
                    fi
                    ;;
                -key_length)
                    if $manual; then
                        shift
                        key_length="$1"
                        let counter=counter+1
                    else
                        echo "Error: -key_length can only be used with -manual."
                        exit 1
                    fi
                    ;;
                -encryption)
                    if $manual; then
                        shift
                        encryption="$1"
                        let counter=counter+1
                    else
                        echo "Error: -encryption can only be used with -manual."
                        exit 1
                    fi
                    ;;
                -hash)
                    if $manual; then
                        shift
                        hash="$1"
			let counter=counter+1
                    else
                        echo "Error: -hash can only be used with -manual."
                        exit 1
                    fi
                    ;;
                *)
                    echo "Usage: ssleverywhere -gen_cert -name <name> [-default | -manual]"
                    exit 1
                    ;;
            esac
            shift
        done

        if [ "$config" == "default" ]; then
	    mac_address=$(getmac)
	    #mkdir -p /home/ssleverywhere_client/ /home/ssleverywhere_client/certs/ /home/ssleverywhere_client/csr/ /home/ssleverywhere_client/private/
	    #chmod 777 /home/ssleverywhere_client/ /home/ssleverywhere_client/certs/ /home/ssleverywhere_client/csr/ /home/ssleverywhere_client/private
	    openssl genrsa -aes256 -out "$keys_file/server_$mac_address.key.pem" -passout pass:1234 2048
            openssl req -key "$keys_file/server_$mac_address.key.pem" -new -sha256 -out "$csr_file/server_$mac_address.csr.pem" --passin pass:1234 -subj "/C=CN/ST=JS/L=SZ/O=PP/OU=GP/CN=SPKI SSL ROOT CA 01/emailAddress=test@test.com"
            api_request="curl -X POST -H 'Content-Type: application/pkcs10' --data-binary @$csr_file/server_$mac_address.csr.pem http://$base_url/sign-csr/mac=$mac_address --output $certs_file/server_$mac_address.cert.pem"
	    api_request2="curl http://$base_url/get-root-ca/mac=$mac_address --output $certs_file/spki.cert.pem"

        elif [ "$config" == "manual" ] && [ $counter == 4 ]; then
            # Validate and construct the API request with manual configuration options
            # Replace the placeholders with actual values
            api_request="curl $base_url/gen-cert/cn=$name&key_type=$key_type&key_length=$key_length&encryption=$encryption&hash=$hash"
        elif [ "$config" == "manual" ] && [ $counter != 4 ]; then
	    echo "Error: Invalid configuration option. When manual configuration, use -key_type <private key type> -key_length <private key length> -encryption <private key encryption> -hash <hashing algorithm>"
	    exit 1        
        else
            echo "Error: Invalid configuration option. Use -default or -manual."
            exit 1
        fi
        ;;

    *)
        echo "Unknown command: $command"
        exit 1
        ;;
esac

# Execute the constructed API request and display the response
response=$(eval "$api_request")
response2=$(eval "$api_request2")

# Display the response to the terminal
echo "API Response:"
echo "$response"
echo "$response2"



