#!/bin/bash -x

# generate certificates
if test ! -e /etc/freeradius/certs/freeradius.pem
then
    if test ! -e /etc/ssl/certs/ssl-cert-snakeoil.pem || \
       test ! -e /etc/ssl/private/ssl-cert-snakeoil.key
    then
        make-ssl-cert generate-default-snakeoil
    fi

    cat /etc/ssl/certs/ssl-cert-snakeoil.pem \
        /etc/ssl/private/ssl-cert-snakeoil.key \
        > /etc/freeradius/certs/freeradius.pem

    chown root:freerad /etc/freeradius/certs/freeradius.pem
    chmod 440 /etc/freeradius/certs/freeradius.pem
fi

chmod 755 /var/log/freeradius
