Reformattage des scripts principaux, sécurisation
Reformattage des scripts entrypoint.sh et server_menu.sh avec l'outil shfmt. Sécurisation des variables et mise en conformité avec les standards du scripting bash avec l'outil shellcheck.
This commit is contained in:
parent
b573c37be8
commit
a8408b7180
@ -2,17 +2,17 @@
|
|||||||
|
|
||||||
if ! grep -qo "^Port ${PORT}$" /etc/ssh/sshd_config; then
|
if ! grep -qo "^Port ${PORT}$" /etc/ssh/sshd_config; then
|
||||||
echo "Génération de la configuration de SSH pour le bastion Monosphere..."
|
echo "Génération de la configuration de SSH pour le bastion Monosphere..."
|
||||||
echo "Port ${PORT}" >> /etc/ssh/sshd_config
|
echo "Port ${PORT}" >>/etc/ssh/sshd_config
|
||||||
echo "#Last authentication configurations" >> /etc/ssh/sshd_config
|
echo "#Last authentication configurations" >>/etc/ssh/sshd_config
|
||||||
if [ "${PASSWORD_AUTH}" -eq "1" ]; then
|
if [[ ${PASSWORD_AUTH} -eq "1" ]]; then
|
||||||
echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config
|
echo "PasswordAuthentication yes" >>/etc/ssh/sshd_config
|
||||||
else
|
else
|
||||||
echo "PasswordAuthentication no" >> /etc/ssh/sshd_config
|
echo "PasswordAuthentication no" >>/etc/ssh/sshd_config
|
||||||
fi
|
fi
|
||||||
if [ "${KEY_AUTH}" -eq "1" ]; then
|
if [[ ${KEY_AUTH} -eq "1" ]]; then
|
||||||
echo "PubkeyAuthentication yes" >> /etc/ssh/sshd_config
|
echo "PubkeyAuthentication yes" >>/etc/ssh/sshd_config
|
||||||
else
|
else
|
||||||
echo "PubkeyAuthentication no" >> /etc/ssh/sshd_config
|
echo "PubkeyAuthentication no" >>/etc/ssh/sshd_config
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
sshd -t
|
sshd -t
|
||||||
@ -43,38 +43,38 @@ echo "Fin de la création des groupes d'utilisateurs."
|
|||||||
|
|
||||||
echo "Création des utilisateurs en cours..."
|
echo "Création des utilisateurs en cours..."
|
||||||
userfile=$(cat /root/scripts/users/bastion_users.txt)
|
userfile=$(cat /root/scripts/users/bastion_users.txt)
|
||||||
for userinfo in $userfile; do
|
for userinfo in ${userfile}; do
|
||||||
user=$(echo "$userinfo" | cut -d ';' -f 1)
|
user=$(echo "${userinfo}" | cut -d ';' -f 1)
|
||||||
is_bastion=$(echo "$userinfo" | cut -d ';' -f 2)
|
is_bastion=$(echo "${userinfo}" | cut -d ';' -f 2)
|
||||||
password=$(echo "$userinfo" | cut -d ';' -f 3)
|
password=$(echo "${userinfo}" | cut -d ';' -f 3)
|
||||||
setkeys=$(echo "$userinfo" | cut -d ';' -f 4)
|
setkeys=$(echo "${userinfo}" | cut -d ';' -f 4)
|
||||||
|
|
||||||
adduser --disabled-password --gecos "" "$user" --shell /bin/bash
|
adduser --disabled-password --gecos "" "${user}" --shell /bin/bash
|
||||||
|
|
||||||
if [ "$is_bastion" -eq "1" ]; then
|
if [[ ${is_bastion} -eq "1" ]]; then
|
||||||
usermod -aG bastionuser "$user"
|
usermod -aG bastionuser "${user}"
|
||||||
elif [ "$is_bastion" -eq "0" ]; then
|
elif [[ ${is_bastion} -eq "0" ]]; then
|
||||||
usermod -aG bastionadmin "$user"
|
usermod -aG bastionadmin "${user}"
|
||||||
if ! grep -qo "^$user ALL=(ALL) NOPASSWD:" /etc/sudoers; then
|
if ! grep -qo "^${user} ALL=(ALL) NOPASSWD:" /etc/sudoers; then
|
||||||
echo "$user ALL=(ALL) NOPASSWD: /usr/local/bin/ttyplay*" | sudo EDITOR='tee -a' visudo
|
echo "${user} ALL=(ALL) NOPASSWD: /usr/local/bin/ttyplay*" | sudo EDITOR='tee -a' visudo
|
||||||
echo "$user ALL=(ALL) NOPASSWD: /bin/ls*" | sudo EDITOR='tee -a' visudo
|
echo "${user} ALL=(ALL) NOPASSWD: /bin/ls*" | sudo EDITOR='tee -a' visudo
|
||||||
fi
|
fi
|
||||||
mkdir /home/"$user"
|
mkdir /home/"${user}"
|
||||||
ln -s /opt/public/scripts/server_menu.sh /home/"$user"/server_menu.sh
|
ln -s /opt/public/scripts/server_menu.sh /home/"${user}"/server_menu.sh
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [ "$password" != "0" ]; then
|
if [[ ${password} != "0" ]]; then
|
||||||
echo "$user:$password" | chpasswd
|
echo "${user}:${password}" | chpasswd
|
||||||
else
|
else
|
||||||
echo "$user:$user" | chpasswd
|
echo "${user}:${user}" | chpasswd
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [ "$setkeys" -eq "1" ]; then
|
if [[ ${setkeys} -eq "1" ]]; then
|
||||||
mkdir -p /home/"$user"/.ssh
|
mkdir -p /home/"${user}"/.ssh
|
||||||
chmod 700 /home/"$user"/.ssh
|
chmod 700 /home/"${user}"/.ssh
|
||||||
cp -r /root/scripts/users/"$user"/* /home/"$user"/.ssh/
|
cp -r /root/scripts/users/"${user}"/* /home/"${user}"/.ssh/
|
||||||
chown -R "$user":"$user" /home/"$user"/.ssh
|
chown -R "${user}":"${user}" /home/"${user}"/.ssh
|
||||||
chmod 600 /home/"$user"/.ssh/*
|
chmod 600 /home/"${user}"/.ssh/*
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
echo "Création des utilisateurs terminée."
|
echo "Création des utilisateurs terminée."
|
||||||
|
|||||||
@ -1,10 +1,10 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
AUTHORIZED_SERVERS_PATH="opt/public/servers"
|
AUTHORIZED_SERVERS_PATH="opt/public/servers"
|
||||||
AUTHORIZED_SERVERS_FILE="/$AUTHORIZED_SERVERS_PATH/authorized_servers.txt"
|
AUTHORIZED_SERVERS_FILE="/${AUTHORIZED_SERVERS_PATH}/authorized_servers.txt"
|
||||||
CONNECTED_USER="$(whoami)"
|
CONNECTED_USER="$(whoami)"
|
||||||
|
|
||||||
USER_SERVERS=$(awk -v user="$CONNECTED_USER" '
|
USER_SERVERS=$(awk -v user="${CONNECTED_USER}" '
|
||||||
{
|
{
|
||||||
split($5, users, ",");
|
split($5, users, ",");
|
||||||
for (i in users) {
|
for (i in users) {
|
||||||
@ -12,55 +12,55 @@ USER_SERVERS=$(awk -v user="$CONNECTED_USER" '
|
|||||||
print $0;
|
print $0;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}' "$AUTHORIZED_SERVERS_FILE")
|
}' "${AUTHORIZED_SERVERS_FILE}")
|
||||||
|
|
||||||
if [ -z "$USER_SERVERS" ]; then
|
if [[ -z "${USER_SERVERS}" ]]; then
|
||||||
echo "Vous n'avez pas l'autorisation de vous connecter à un serveur."
|
echo "Vous n'avez pas l'autorisation de vous connecter à un serveur."
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
function main_menu () {
|
function main_menu() {
|
||||||
echo "Veuillez sélectionner un serveur auquel vous connecter :"
|
echo "Veuillez sélectionner un serveur auquel vous connecter :"
|
||||||
|
|
||||||
counter=1
|
counter=1
|
||||||
declare -A server_map
|
declare -A server_map
|
||||||
while read -r line; do
|
while read -r line; do
|
||||||
ip=$(echo "$line" | cut -d ' ' -f 1)
|
ip=$(echo "${line}" | cut -d ' ' -f 1)
|
||||||
port=$(echo "$line" | cut -d ' ' -f 2)
|
port=$(echo "${line}" | cut -d ' ' -f 2)
|
||||||
custom_name=$(echo "$line" | cut -d ' ' -f 3)
|
custom_name=$(echo "${line}" | cut -d ' ' -f 3)
|
||||||
server_user=$(echo "$line" | cut -d ' ' -f 4)
|
server_user=$(echo "${line}" | cut -d ' ' -f 4)
|
||||||
server_authmethod=$(echo "$line" | cut -d ' ' -f 6)
|
server_authmethod=$(echo "${line}" | cut -d ' ' -f 6)
|
||||||
server_auth=$(echo "$line" | cut -d ' ' -f 7)
|
server_auth=$(echo "${line}" | cut -d ' ' -f 7)
|
||||||
server_map[$counter]="$ip $port $server_user $server_authmethod $server_auth"
|
server_map[${counter}]="${ip} ${port} ${server_user} ${server_authmethod} ${server_auth}"
|
||||||
echo "$counter) $custom_name - $server_user $ip:$port"
|
echo "${counter}) ${custom_name} - ${server_user} ${ip}:${port}"
|
||||||
counter=$((counter + 1))
|
counter=$((counter + 1))
|
||||||
done <<< "$USER_SERVERS"
|
done <<<"${USER_SERVERS}"
|
||||||
|
|
||||||
echo "$counter) Tapez 'quit' ou $counter pour vous déconnecter."
|
echo "${counter}) Tapez 'quit' ou ${counter} pour vous déconnecter."
|
||||||
|
|
||||||
read -r -p "Votre choix (1-$counter): " choice
|
read -r -p "Votre choix (1-${counter}): " choice
|
||||||
|
|
||||||
if [ "$choice" == "quit" ] || [ "$choice" == "$counter" ]; then
|
if [[ "${choice}" == "quit" ]] || [[ "${choice}" == "${counter}" ]]; then
|
||||||
echo "Déconnexion du bastion."
|
echo "Déconnexion du bastion."
|
||||||
exit 0
|
exit 0
|
||||||
elif [ -z "$choice" ] || [ -z "${server_map[$choice]}" ]; then
|
elif [[ -z "${choice}" ]] || [[ -z "${server_map[${choice}]}" ]]; then
|
||||||
echo "Sélection invalide."
|
echo "Sélection invalide."
|
||||||
else
|
else
|
||||||
local selected_server
|
local selected_server
|
||||||
selected_server="${server_map[$choice]}"
|
selected_server="${server_map[${choice}]}"
|
||||||
echo "Connexion à $( echo "$selected_server" | cut -d " " -f -3)..."
|
echo "Connexion à $(echo "${selected_server}" | cut -d " " -f -3)..."
|
||||||
if [ -z "$(echo "$selected_server" | cut -d ' ' -f 4)" ]; then
|
if [[ -z "$(echo "${selected_server}" | cut -d ' ' -f 4)" ]]; then
|
||||||
ttyrec -z --"$(echo "$selected_server" | cut -d ' ' -f 1)"-"$(echo "$selected_server" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "$selected_server" | cut -d ' ' -f 2)" "$(echo "$selected_server" | cut -d ' ' -f 3)"@"$(echo "$selected_server" | cut -d ' ' -f 1)"
|
ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)"
|
||||||
elif [ "$(echo "$selected_server" | cut -d ' ' -f 4)" == "key" ] && [ -f /"$AUTHORIZED_SERVERS_PATH"/"$(echo "$selected_server" | cut -d ' ' -f 5)" ]; then
|
elif [[ "$(echo "${selected_server}" | cut -d ' ' -f 4)" == "key" ]] && [[ -f /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" ]]; then
|
||||||
eval "$(ssh-agent)" > /dev/null
|
eval "$(ssh-agent)" >/dev/null
|
||||||
trap 'kill $SSH_AGENT_PID' EXIT
|
trap 'kill $SSH_AGENT_PID' EXIT
|
||||||
cat /"$AUTHORIZED_SERVERS_PATH"/"$(echo "$selected_server" | cut -d ' ' -f 5)" | ssh-add - > /dev/null
|
cat /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" | ssh-add - >/dev/null
|
||||||
ttyrec -z --"$(echo "$selected_server" | cut -d ' ' -f 1)"-"$(echo "$selected_server" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "$selected_server" | cut -d ' ' -f 2)" "$(echo "$selected_server" | cut -d ' ' -f 3)"@"$(echo "$selected_server" | cut -d ' ' -f 1)"
|
ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)"
|
||||||
ssh-add -D > /dev/null
|
ssh-add -D >/dev/null
|
||||||
elif [ "$(echo "$selected_server" | cut -d ' ' -f 4)" == "password" ] && [ -f /"$AUTHORIZED_SERVERS_PATH"/"$(echo "$selected_server" | cut -d ' ' -f 5)" ]; then
|
elif [[ "$(echo "${selected_server}" | cut -d ' ' -f 4)" == "password" ]] && [[ -f /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" ]]; then
|
||||||
local ssh_password
|
local ssh_password
|
||||||
ssh_password=$(cat /"$AUTHORIZED_SERVERS_PATH"/"$(echo "$selected_server" | cut -d ' ' -f 5)")
|
ssh_password=$(cat /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)")
|
||||||
ttyrec -z --"$(echo "$selected_server" | cut -d ' ' -f 1)"-"$(echo "$selected_server" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- sshpass -p "$ssh_password" ssh -o StrictHostKeyChecking=accept-new -p "$(echo "$selected_server" | cut -d ' ' -f 2)" "$(echo "$selected_server" | cut -d ' ' -f 3)"@"$(echo "$selected_server" | cut -d ' ' -f 1)"
|
ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- sshpass -p "${ssh_password}" ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)"
|
||||||
unset ssh_password
|
unset ssh_password
|
||||||
else
|
else
|
||||||
echo -e "Un problème de configuration a été détecté sur \nles options de connexion à l'hôte selectionné.\nVeuillez contacter votre administrateur."
|
echo -e "Un problème de configuration a été détecté sur \nles options de connexion à l'hôte selectionné.\nVeuillez contacter votre administrateur."
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user