diff --git a/entrypoint.sh b/entrypoint.sh index f1825d2..c753e36 100644 --- a/entrypoint.sh +++ b/entrypoint.sh @@ -1,19 +1,19 @@ #!/bin/bash if ! grep -qo "^Port ${PORT}$" /etc/ssh/sshd_config; then - echo "Génération de la configuration de SSH pour le bastion Monosphere..." - echo "Port ${PORT}" >> /etc/ssh/sshd_config - echo "#Last authentication configurations" >> /etc/ssh/sshd_config - if [ "${PASSWORD_AUTH}" -eq "1" ]; then - echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config - else - echo "PasswordAuthentication no" >> /etc/ssh/sshd_config - fi - if [ "${KEY_AUTH}" -eq "1" ]; then - echo "PubkeyAuthentication yes" >> /etc/ssh/sshd_config - else - echo "PubkeyAuthentication no" >> /etc/ssh/sshd_config - fi + echo "Génération de la configuration de SSH pour le bastion Monosphere..." + echo "Port ${PORT}" >>/etc/ssh/sshd_config + echo "#Last authentication configurations" >>/etc/ssh/sshd_config + if [[ ${PASSWORD_AUTH} -eq "1" ]]; then + echo "PasswordAuthentication yes" >>/etc/ssh/sshd_config + else + echo "PasswordAuthentication no" >>/etc/ssh/sshd_config + fi + if [[ ${KEY_AUTH} -eq "1" ]]; then + echo "PubkeyAuthentication yes" >>/etc/ssh/sshd_config + else + echo "PubkeyAuthentication no" >>/etc/ssh/sshd_config + fi fi sshd -t echo "Configuration du service SSHD de Monosphere vérifiée." @@ -33,49 +33,49 @@ echo "Répertoire public configuré." echo "Création des groupes d'utilisateurs." if ! grep -q "bastionuser" /etc/group; then - addgroup bastionuser + addgroup bastionuser fi if ! grep -q "bastionadmin" /etc/group; then - addgroup bastionadmin + addgroup bastionadmin fi echo "Fin de la création des groupes d'utilisateurs." echo "Création des utilisateurs en cours..." userfile=$(cat /root/scripts/users/bastion_users.txt) -for userinfo in $userfile; do - user=$(echo "$userinfo" | cut -d ';' -f 1) - is_bastion=$(echo "$userinfo" | cut -d ';' -f 2) - password=$(echo "$userinfo" | cut -d ';' -f 3) - setkeys=$(echo "$userinfo" | cut -d ';' -f 4) +for userinfo in ${userfile}; do + user=$(echo "${userinfo}" | cut -d ';' -f 1) + is_bastion=$(echo "${userinfo}" | cut -d ';' -f 2) + password=$(echo "${userinfo}" | cut -d ';' -f 3) + setkeys=$(echo "${userinfo}" | cut -d ';' -f 4) - adduser --disabled-password --gecos "" "$user" --shell /bin/bash + adduser --disabled-password --gecos "" "${user}" --shell /bin/bash - if [ "$is_bastion" -eq "1" ]; then - usermod -aG bastionuser "$user" - elif [ "$is_bastion" -eq "0" ]; then - usermod -aG bastionadmin "$user" - if ! grep -qo "^$user ALL=(ALL) NOPASSWD:" /etc/sudoers; then - echo "$user ALL=(ALL) NOPASSWD: /usr/local/bin/ttyplay*" | sudo EDITOR='tee -a' visudo - echo "$user ALL=(ALL) NOPASSWD: /bin/ls*" | sudo EDITOR='tee -a' visudo - fi - mkdir /home/"$user" - ln -s /opt/public/scripts/server_menu.sh /home/"$user"/server_menu.sh - fi + if [[ ${is_bastion} -eq "1" ]]; then + usermod -aG bastionuser "${user}" + elif [[ ${is_bastion} -eq "0" ]]; then + usermod -aG bastionadmin "${user}" + if ! grep -qo "^${user} ALL=(ALL) NOPASSWD:" /etc/sudoers; then + echo "${user} ALL=(ALL) NOPASSWD: /usr/local/bin/ttyplay*" | sudo EDITOR='tee -a' visudo + echo "${user} ALL=(ALL) NOPASSWD: /bin/ls*" | sudo EDITOR='tee -a' visudo + fi + mkdir /home/"${user}" + ln -s /opt/public/scripts/server_menu.sh /home/"${user}"/server_menu.sh + fi - if [ "$password" != "0" ]; then - echo "$user:$password" | chpasswd - else - echo "$user:$user" | chpasswd - fi + if [[ ${password} != "0" ]]; then + echo "${user}:${password}" | chpasswd + else + echo "${user}:${user}" | chpasswd + fi - if [ "$setkeys" -eq "1" ]; then - mkdir -p /home/"$user"/.ssh - chmod 700 /home/"$user"/.ssh - cp -r /root/scripts/users/"$user"/* /home/"$user"/.ssh/ - chown -R "$user":"$user" /home/"$user"/.ssh - chmod 600 /home/"$user"/.ssh/* - fi + if [[ ${setkeys} -eq "1" ]]; then + mkdir -p /home/"${user}"/.ssh + chmod 700 /home/"${user}"/.ssh + cp -r /root/scripts/users/"${user}"/* /home/"${user}"/.ssh/ + chown -R "${user}":"${user}" /home/"${user}"/.ssh + chmod 600 /home/"${user}"/.ssh/* + fi done echo "Création des utilisateurs terminée." echo "Monosphere a bien été configuré et démarré avec succès." diff --git a/server_menu.sh b/server_menu.sh index 4a98ff4..95fab8d 100644 --- a/server_menu.sh +++ b/server_menu.sh @@ -1,10 +1,10 @@ #!/bin/bash AUTHORIZED_SERVERS_PATH="opt/public/servers" -AUTHORIZED_SERVERS_FILE="/$AUTHORIZED_SERVERS_PATH/authorized_servers.txt" +AUTHORIZED_SERVERS_FILE="/${AUTHORIZED_SERVERS_PATH}/authorized_servers.txt" CONNECTED_USER="$(whoami)" -USER_SERVERS=$(awk -v user="$CONNECTED_USER" ' +USER_SERVERS=$(awk -v user="${CONNECTED_USER}" ' { split($5, users, ","); for (i in users) { @@ -12,62 +12,62 @@ USER_SERVERS=$(awk -v user="$CONNECTED_USER" ' print $0; } } -}' "$AUTHORIZED_SERVERS_FILE") +}' "${AUTHORIZED_SERVERS_FILE}") -if [ -z "$USER_SERVERS" ]; then - echo "Vous n'avez pas l'autorisation de vous connecter à un serveur." - exit 1 +if [[ -z "${USER_SERVERS}" ]]; then + echo "Vous n'avez pas l'autorisation de vous connecter à un serveur." + exit 1 fi -function main_menu () { - echo "Veuillez sélectionner un serveur auquel vous connecter :" +function main_menu() { + echo "Veuillez sélectionner un serveur auquel vous connecter :" - counter=1 - declare -A server_map - while read -r line; do - ip=$(echo "$line" | cut -d ' ' -f 1) - port=$(echo "$line" | cut -d ' ' -f 2) - custom_name=$(echo "$line" | cut -d ' ' -f 3) - server_user=$(echo "$line" | cut -d ' ' -f 4) - server_authmethod=$(echo "$line" | cut -d ' ' -f 6) - server_auth=$(echo "$line" | cut -d ' ' -f 7) - server_map[$counter]="$ip $port $server_user $server_authmethod $server_auth" - echo "$counter) $custom_name - $server_user $ip:$port" - counter=$((counter + 1)) - done <<< "$USER_SERVERS" + counter=1 + declare -A server_map + while read -r line; do + ip=$(echo "${line}" | cut -d ' ' -f 1) + port=$(echo "${line}" | cut -d ' ' -f 2) + custom_name=$(echo "${line}" | cut -d ' ' -f 3) + server_user=$(echo "${line}" | cut -d ' ' -f 4) + server_authmethod=$(echo "${line}" | cut -d ' ' -f 6) + server_auth=$(echo "${line}" | cut -d ' ' -f 7) + server_map[${counter}]="${ip} ${port} ${server_user} ${server_authmethod} ${server_auth}" + echo "${counter}) ${custom_name} - ${server_user} ${ip}:${port}" + counter=$((counter + 1)) + done <<<"${USER_SERVERS}" - echo "$counter) Tapez 'quit' ou $counter pour vous déconnecter." + echo "${counter}) Tapez 'quit' ou ${counter} pour vous déconnecter." - read -r -p "Votre choix (1-$counter): " choice + read -r -p "Votre choix (1-${counter}): " choice - if [ "$choice" == "quit" ] || [ "$choice" == "$counter" ]; then - echo "Déconnexion du bastion." - exit 0 - elif [ -z "$choice" ] || [ -z "${server_map[$choice]}" ]; then - echo "Sélection invalide." - else - local selected_server - selected_server="${server_map[$choice]}" - echo "Connexion à $( echo "$selected_server" | cut -d " " -f -3)..." - if [ -z "$(echo "$selected_server" | cut -d ' ' -f 4)" ]; then - ttyrec -z --"$(echo "$selected_server" | cut -d ' ' -f 1)"-"$(echo "$selected_server" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "$selected_server" | cut -d ' ' -f 2)" "$(echo "$selected_server" | cut -d ' ' -f 3)"@"$(echo "$selected_server" | cut -d ' ' -f 1)" - elif [ "$(echo "$selected_server" | cut -d ' ' -f 4)" == "key" ] && [ -f /"$AUTHORIZED_SERVERS_PATH"/"$(echo "$selected_server" | cut -d ' ' -f 5)" ]; then - eval "$(ssh-agent)" > /dev/null - trap 'kill $SSH_AGENT_PID' EXIT - cat /"$AUTHORIZED_SERVERS_PATH"/"$(echo "$selected_server" | cut -d ' ' -f 5)" | ssh-add - > /dev/null - ttyrec -z --"$(echo "$selected_server" | cut -d ' ' -f 1)"-"$(echo "$selected_server" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "$selected_server" | cut -d ' ' -f 2)" "$(echo "$selected_server" | cut -d ' ' -f 3)"@"$(echo "$selected_server" | cut -d ' ' -f 1)" - ssh-add -D > /dev/null - elif [ "$(echo "$selected_server" | cut -d ' ' -f 4)" == "password" ] && [ -f /"$AUTHORIZED_SERVERS_PATH"/"$(echo "$selected_server" | cut -d ' ' -f 5)" ]; then - local ssh_password - ssh_password=$(cat /"$AUTHORIZED_SERVERS_PATH"/"$(echo "$selected_server" | cut -d ' ' -f 5)") - ttyrec -z --"$(echo "$selected_server" | cut -d ' ' -f 1)"-"$(echo "$selected_server" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- sshpass -p "$ssh_password" ssh -o StrictHostKeyChecking=accept-new -p "$(echo "$selected_server" | cut -d ' ' -f 2)" "$(echo "$selected_server" | cut -d ' ' -f 3)"@"$(echo "$selected_server" | cut -d ' ' -f 1)" - unset ssh_password - else - echo -e "Un problème de configuration a été détecté sur \nles options de connexion à l'hôte selectionné.\nVeuillez contacter votre administrateur." - fi - fi + if [[ "${choice}" == "quit" ]] || [[ "${choice}" == "${counter}" ]]; then + echo "Déconnexion du bastion." + exit 0 + elif [[ -z "${choice}" ]] || [[ -z "${server_map[${choice}]}" ]]; then + echo "Sélection invalide." + else + local selected_server + selected_server="${server_map[${choice}]}" + echo "Connexion à $(echo "${selected_server}" | cut -d " " -f -3)..." + if [[ -z "$(echo "${selected_server}" | cut -d ' ' -f 4)" ]]; then + ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)" + elif [[ "$(echo "${selected_server}" | cut -d ' ' -f 4)" == "key" ]] && [[ -f /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" ]]; then + eval "$(ssh-agent)" >/dev/null + trap 'kill $SSH_AGENT_PID' EXIT + cat /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" | ssh-add - >/dev/null + ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)" + ssh-add -D >/dev/null + elif [[ "$(echo "${selected_server}" | cut -d ' ' -f 4)" == "password" ]] && [[ -f /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" ]]; then + local ssh_password + ssh_password=$(cat /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)") + ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- sshpass -p "${ssh_password}" ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)" + unset ssh_password + else + echo -e "Un problème de configuration a été détecté sur \nles options de connexion à l'hôte selectionné.\nVeuillez contacter votre administrateur." + fi + fi } while true; do - main_menu + main_menu done