Reformattage des scripts principaux, sécurisation

Reformattage des scripts entrypoint.sh et server_menu.sh avec l'outil
shfmt.
Sécurisation des variables et mise en conformité avec les standards du
scripting bash avec l'outil shellcheck.
This commit is contained in:
Siphonight 2025-01-18 20:44:20 +01:00
parent b573c37be8
commit a8408b7180
2 changed files with 94 additions and 94 deletions

View File

@ -1,19 +1,19 @@
#!/bin/bash #!/bin/bash
if ! grep -qo "^Port ${PORT}$" /etc/ssh/sshd_config; then if ! grep -qo "^Port ${PORT}$" /etc/ssh/sshd_config; then
echo "Génération de la configuration de SSH pour le bastion Monosphere..." echo "Génération de la configuration de SSH pour le bastion Monosphere..."
echo "Port ${PORT}" >> /etc/ssh/sshd_config echo "Port ${PORT}" >>/etc/ssh/sshd_config
echo "#Last authentication configurations" >> /etc/ssh/sshd_config echo "#Last authentication configurations" >>/etc/ssh/sshd_config
if [ "${PASSWORD_AUTH}" -eq "1" ]; then if [[ ${PASSWORD_AUTH} -eq "1" ]]; then
echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config echo "PasswordAuthentication yes" >>/etc/ssh/sshd_config
else else
echo "PasswordAuthentication no" >> /etc/ssh/sshd_config echo "PasswordAuthentication no" >>/etc/ssh/sshd_config
fi fi
if [ "${KEY_AUTH}" -eq "1" ]; then if [[ ${KEY_AUTH} -eq "1" ]]; then
echo "PubkeyAuthentication yes" >> /etc/ssh/sshd_config echo "PubkeyAuthentication yes" >>/etc/ssh/sshd_config
else else
echo "PubkeyAuthentication no" >> /etc/ssh/sshd_config echo "PubkeyAuthentication no" >>/etc/ssh/sshd_config
fi fi
fi fi
sshd -t sshd -t
echo "Configuration du service SSHD de Monosphere vérifiée." echo "Configuration du service SSHD de Monosphere vérifiée."
@ -33,49 +33,49 @@ echo "Répertoire public configuré."
echo "Création des groupes d'utilisateurs." echo "Création des groupes d'utilisateurs."
if ! grep -q "bastionuser" /etc/group; then if ! grep -q "bastionuser" /etc/group; then
addgroup bastionuser addgroup bastionuser
fi fi
if ! grep -q "bastionadmin" /etc/group; then if ! grep -q "bastionadmin" /etc/group; then
addgroup bastionadmin addgroup bastionadmin
fi fi
echo "Fin de la création des groupes d'utilisateurs." echo "Fin de la création des groupes d'utilisateurs."
echo "Création des utilisateurs en cours..." echo "Création des utilisateurs en cours..."
userfile=$(cat /root/scripts/users/bastion_users.txt) userfile=$(cat /root/scripts/users/bastion_users.txt)
for userinfo in $userfile; do for userinfo in ${userfile}; do
user=$(echo "$userinfo" | cut -d ';' -f 1) user=$(echo "${userinfo}" | cut -d ';' -f 1)
is_bastion=$(echo "$userinfo" | cut -d ';' -f 2) is_bastion=$(echo "${userinfo}" | cut -d ';' -f 2)
password=$(echo "$userinfo" | cut -d ';' -f 3) password=$(echo "${userinfo}" | cut -d ';' -f 3)
setkeys=$(echo "$userinfo" | cut -d ';' -f 4) setkeys=$(echo "${userinfo}" | cut -d ';' -f 4)
adduser --disabled-password --gecos "" "$user" --shell /bin/bash adduser --disabled-password --gecos "" "${user}" --shell /bin/bash
if [ "$is_bastion" -eq "1" ]; then if [[ ${is_bastion} -eq "1" ]]; then
usermod -aG bastionuser "$user" usermod -aG bastionuser "${user}"
elif [ "$is_bastion" -eq "0" ]; then elif [[ ${is_bastion} -eq "0" ]]; then
usermod -aG bastionadmin "$user" usermod -aG bastionadmin "${user}"
if ! grep -qo "^$user ALL=(ALL) NOPASSWD:" /etc/sudoers; then if ! grep -qo "^${user} ALL=(ALL) NOPASSWD:" /etc/sudoers; then
echo "$user ALL=(ALL) NOPASSWD: /usr/local/bin/ttyplay*" | sudo EDITOR='tee -a' visudo echo "${user} ALL=(ALL) NOPASSWD: /usr/local/bin/ttyplay*" | sudo EDITOR='tee -a' visudo
echo "$user ALL=(ALL) NOPASSWD: /bin/ls*" | sudo EDITOR='tee -a' visudo echo "${user} ALL=(ALL) NOPASSWD: /bin/ls*" | sudo EDITOR='tee -a' visudo
fi fi
mkdir /home/"$user" mkdir /home/"${user}"
ln -s /opt/public/scripts/server_menu.sh /home/"$user"/server_menu.sh ln -s /opt/public/scripts/server_menu.sh /home/"${user}"/server_menu.sh
fi fi
if [ "$password" != "0" ]; then if [[ ${password} != "0" ]]; then
echo "$user:$password" | chpasswd echo "${user}:${password}" | chpasswd
else else
echo "$user:$user" | chpasswd echo "${user}:${user}" | chpasswd
fi fi
if [ "$setkeys" -eq "1" ]; then if [[ ${setkeys} -eq "1" ]]; then
mkdir -p /home/"$user"/.ssh mkdir -p /home/"${user}"/.ssh
chmod 700 /home/"$user"/.ssh chmod 700 /home/"${user}"/.ssh
cp -r /root/scripts/users/"$user"/* /home/"$user"/.ssh/ cp -r /root/scripts/users/"${user}"/* /home/"${user}"/.ssh/
chown -R "$user":"$user" /home/"$user"/.ssh chown -R "${user}":"${user}" /home/"${user}"/.ssh
chmod 600 /home/"$user"/.ssh/* chmod 600 /home/"${user}"/.ssh/*
fi fi
done done
echo "Création des utilisateurs terminée." echo "Création des utilisateurs terminée."
echo "Monosphere a bien été configuré et démarré avec succès." echo "Monosphere a bien été configuré et démarré avec succès."

View File

@ -1,10 +1,10 @@
#!/bin/bash #!/bin/bash
AUTHORIZED_SERVERS_PATH="opt/public/servers" AUTHORIZED_SERVERS_PATH="opt/public/servers"
AUTHORIZED_SERVERS_FILE="/$AUTHORIZED_SERVERS_PATH/authorized_servers.txt" AUTHORIZED_SERVERS_FILE="/${AUTHORIZED_SERVERS_PATH}/authorized_servers.txt"
CONNECTED_USER="$(whoami)" CONNECTED_USER="$(whoami)"
USER_SERVERS=$(awk -v user="$CONNECTED_USER" ' USER_SERVERS=$(awk -v user="${CONNECTED_USER}" '
{ {
split($5, users, ","); split($5, users, ",");
for (i in users) { for (i in users) {
@ -12,62 +12,62 @@ USER_SERVERS=$(awk -v user="$CONNECTED_USER" '
print $0; print $0;
} }
} }
}' "$AUTHORIZED_SERVERS_FILE") }' "${AUTHORIZED_SERVERS_FILE}")
if [ -z "$USER_SERVERS" ]; then if [[ -z "${USER_SERVERS}" ]]; then
echo "Vous n'avez pas l'autorisation de vous connecter à un serveur." echo "Vous n'avez pas l'autorisation de vous connecter à un serveur."
exit 1 exit 1
fi fi
function main_menu () { function main_menu() {
echo "Veuillez sélectionner un serveur auquel vous connecter :" echo "Veuillez sélectionner un serveur auquel vous connecter :"
counter=1 counter=1
declare -A server_map declare -A server_map
while read -r line; do while read -r line; do
ip=$(echo "$line" | cut -d ' ' -f 1) ip=$(echo "${line}" | cut -d ' ' -f 1)
port=$(echo "$line" | cut -d ' ' -f 2) port=$(echo "${line}" | cut -d ' ' -f 2)
custom_name=$(echo "$line" | cut -d ' ' -f 3) custom_name=$(echo "${line}" | cut -d ' ' -f 3)
server_user=$(echo "$line" | cut -d ' ' -f 4) server_user=$(echo "${line}" | cut -d ' ' -f 4)
server_authmethod=$(echo "$line" | cut -d ' ' -f 6) server_authmethod=$(echo "${line}" | cut -d ' ' -f 6)
server_auth=$(echo "$line" | cut -d ' ' -f 7) server_auth=$(echo "${line}" | cut -d ' ' -f 7)
server_map[$counter]="$ip $port $server_user $server_authmethod $server_auth" server_map[${counter}]="${ip} ${port} ${server_user} ${server_authmethod} ${server_auth}"
echo "$counter) $custom_name - $server_user $ip:$port" echo "${counter}) ${custom_name} - ${server_user} ${ip}:${port}"
counter=$((counter + 1)) counter=$((counter + 1))
done <<< "$USER_SERVERS" done <<<"${USER_SERVERS}"
echo "$counter) Tapez 'quit' ou $counter pour vous déconnecter." echo "${counter}) Tapez 'quit' ou ${counter} pour vous déconnecter."
read -r -p "Votre choix (1-$counter): " choice read -r -p "Votre choix (1-${counter}): " choice
if [ "$choice" == "quit" ] || [ "$choice" == "$counter" ]; then if [[ "${choice}" == "quit" ]] || [[ "${choice}" == "${counter}" ]]; then
echo "Déconnexion du bastion." echo "Déconnexion du bastion."
exit 0 exit 0
elif [ -z "$choice" ] || [ -z "${server_map[$choice]}" ]; then elif [[ -z "${choice}" ]] || [[ -z "${server_map[${choice}]}" ]]; then
echo "Sélection invalide." echo "Sélection invalide."
else else
local selected_server local selected_server
selected_server="${server_map[$choice]}" selected_server="${server_map[${choice}]}"
echo "Connexion à $( echo "$selected_server" | cut -d " " -f -3)..." echo "Connexion à $(echo "${selected_server}" | cut -d " " -f -3)..."
if [ -z "$(echo "$selected_server" | cut -d ' ' -f 4)" ]; then if [[ -z "$(echo "${selected_server}" | cut -d ' ' -f 4)" ]]; then
ttyrec -z --"$(echo "$selected_server" | cut -d ' ' -f 1)"-"$(echo "$selected_server" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "$selected_server" | cut -d ' ' -f 2)" "$(echo "$selected_server" | cut -d ' ' -f 3)"@"$(echo "$selected_server" | cut -d ' ' -f 1)" ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)"
elif [ "$(echo "$selected_server" | cut -d ' ' -f 4)" == "key" ] && [ -f /"$AUTHORIZED_SERVERS_PATH"/"$(echo "$selected_server" | cut -d ' ' -f 5)" ]; then elif [[ "$(echo "${selected_server}" | cut -d ' ' -f 4)" == "key" ]] && [[ -f /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" ]]; then
eval "$(ssh-agent)" > /dev/null eval "$(ssh-agent)" >/dev/null
trap 'kill $SSH_AGENT_PID' EXIT trap 'kill $SSH_AGENT_PID' EXIT
cat /"$AUTHORIZED_SERVERS_PATH"/"$(echo "$selected_server" | cut -d ' ' -f 5)" | ssh-add - > /dev/null cat /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" | ssh-add - >/dev/null
ttyrec -z --"$(echo "$selected_server" | cut -d ' ' -f 1)"-"$(echo "$selected_server" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "$selected_server" | cut -d ' ' -f 2)" "$(echo "$selected_server" | cut -d ' ' -f 3)"@"$(echo "$selected_server" | cut -d ' ' -f 1)" ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)"
ssh-add -D > /dev/null ssh-add -D >/dev/null
elif [ "$(echo "$selected_server" | cut -d ' ' -f 4)" == "password" ] && [ -f /"$AUTHORIZED_SERVERS_PATH"/"$(echo "$selected_server" | cut -d ' ' -f 5)" ]; then elif [[ "$(echo "${selected_server}" | cut -d ' ' -f 4)" == "password" ]] && [[ -f /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" ]]; then
local ssh_password local ssh_password
ssh_password=$(cat /"$AUTHORIZED_SERVERS_PATH"/"$(echo "$selected_server" | cut -d ' ' -f 5)") ssh_password=$(cat /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)")
ttyrec -z --"$(echo "$selected_server" | cut -d ' ' -f 1)"-"$(echo "$selected_server" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- sshpass -p "$ssh_password" ssh -o StrictHostKeyChecking=accept-new -p "$(echo "$selected_server" | cut -d ' ' -f 2)" "$(echo "$selected_server" | cut -d ' ' -f 3)"@"$(echo "$selected_server" | cut -d ' ' -f 1)" ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- sshpass -p "${ssh_password}" ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)"
unset ssh_password unset ssh_password
else else
echo -e "Un problème de configuration a été détecté sur \nles options de connexion à l'hôte selectionné.\nVeuillez contacter votre administrateur." echo -e "Un problème de configuration a été détecté sur \nles options de connexion à l'hôte selectionné.\nVeuillez contacter votre administrateur."
fi fi
fi fi
} }
while true; do while true; do
main_menu main_menu
done done