2008-02-05 01:16:40 +00:00
|
|
|
#!/bin/sh
|
2007-10-26 22:44:33 +00:00
|
|
|
# IBM(c) 2007 EPL license http://www.eclipse.org/legal/epl-v10.html
|
|
|
|
#egan@us.ibm.com
|
|
|
|
#(C)IBM Corp
|
|
|
|
#
|
|
|
|
|
2008-02-05 01:16:40 +00:00
|
|
|
if [ -r /etc/ssh/sshd_config ]
|
|
|
|
then
|
|
|
|
logger -t xcat "Install: setup /etc/ssh/sshd_config"
|
|
|
|
cp /etc/ssh/sshd_config /etc/ssh/sshd_config.ORIG
|
|
|
|
perl -pi -e 's/^X11Forwarding .*$/X11Forwarding yes/' /etc/ssh/sshd_config
|
|
|
|
perl -pi -e 's/^KeyRegenerationInterval .*$/KeyRegenerationInterval 0/' /etc/ssh/sshd_config
|
|
|
|
perl -pi -e 's/(.*MaxStartups.*)/#\1/' /etc/ssh/sshd_config
|
|
|
|
echo "MaxStartups 1024" >>/etc/ssh/sshd_config
|
|
|
|
echo "PasswordAuthentication no" >>/etc/ssh/sshd_config
|
|
|
|
fi
|
2007-10-26 22:44:33 +00:00
|
|
|
|
2008-04-16 20:30:54 +00:00
|
|
|
if [ -r /etc/ssh/sshd_config ]
|
|
|
|
then
|
|
|
|
echo " StrictHostKeyChecking no" >> /etc/ssh/ssh_config
|
|
|
|
fi
|
|
|
|
|
2008-02-05 01:16:40 +00:00
|
|
|
if [ -d /xcatpost/.ssh ]
|
|
|
|
then
|
|
|
|
logger -t xcat "Install: setup root .ssh"
|
|
|
|
cd /xcatpost/.ssh
|
|
|
|
mkdir -p /root/.ssh
|
|
|
|
cp -f * /root/.ssh
|
2008-04-16 21:08:57 +00:00
|
|
|
cd -
|
2008-02-05 01:16:40 +00:00
|
|
|
chmod 700 /root/.ssh
|
|
|
|
chmod 600 /root/.ssh/*
|
|
|
|
fi
|
|
|
|
if [ -d /xcatpost/hostkeys ]
|
|
|
|
then
|
|
|
|
logger -t xcat "Install: using server provided host key for convenience."
|
|
|
|
cp /xcatpost/hostkeys/*_key /etc/ssh/
|
|
|
|
fi
|
2007-10-26 22:44:33 +00:00
|
|
|
|
2008-02-05 01:16:40 +00:00
|
|
|
|
2008-04-16 21:08:57 +00:00
|
|
|
if [ ! -x /usr/sbin/stunnel ]; then #Stop if no stunnel to help the next bit
|
|
|
|
exit 0
|
|
|
|
fi
|
|
|
|
|
|
|
|
echo client=yes > /etc/stunnel/stunnel.conf
|
|
|
|
echo foreground=yes >> /etc/stunnel/stunnel.conf
|
|
|
|
echo output=/dev/null >> /etc/stunnel/stunnel.conf
|
|
|
|
echo verify=0 >> /etc/stunnel/stunnel.conf
|
|
|
|
echo '[xcatd]' >> /etc/stunnel/stunnel.conf
|
|
|
|
echo accept=400 >> /etc/stunnel/stunnel.conf
|
|
|
|
echo connect=$MASTER:3001 >> /etc/stunnel/stunnel.conf
|
|
|
|
|
|
|
|
stunnel &
|
|
|
|
STUN_PID=$!
|
|
|
|
sleep 1
|
2007-10-26 22:44:33 +00:00
|
|
|
|
2008-04-16 21:08:57 +00:00
|
|
|
umask 0077
|
|
|
|
|
|
|
|
mkdir -p /root/.ssh/
|
2008-04-29 13:57:57 +00:00
|
|
|
allowcred.awk &
|
|
|
|
sleep 1
|
2008-04-16 21:08:57 +00:00
|
|
|
getcredentials.awk ssh_root_key | grep -v '<'|sed -e 's/</</' -e 's/>/>/' -e 's/&/&/' -e 's/"/"/' -e "s/'/'/" > /root/.ssh/id_rsa
|
|
|
|
if ! grep "PRIVATE KEY" /root/.ssh/id_rsa > /dev/null 2>&1 ; then
|
|
|
|
rm /root/.ssh/id_rsa
|
|
|
|
fi
|
|
|
|
kill $STUN_PID
|