5 # Adapts the installed gsi-openssh environment to the current machine,
6 # performing actions that originally occurred during the package's
7 # 'make install' phase.
9 # Send comments/fixes/suggestions to:
10 # Chase Phillips <cphillip@ncsa.uiuc.edu>
14 # Get user's GPT_LOCATION since we may be installing this using a new(er)
18 $gptpath = $ENV{GPT_LOCATION};
21 # And the old standby..
24 $gpath = $ENV{GLOBUS_LOCATION};
27 die "GLOBUS_LOCATION needs to be set before running this script"
31 # Include standard modules
39 # modify the ld library path for when we call ssh executables
42 $oldldpath = $ENV{LD_LIBRARY_PATH};
43 $newldpath = "$gpath/lib";
44 if (length($oldldpath) > 0)
46 $newldpath .= ":$oldldpath";
48 $ENV{LD_LIBRARY_PATH} = "$newldpath";
51 # i'm including this because other perl scripts in the gpt setup directories
55 if (defined($gptpath))
57 @INC = (@INC, "$gptpath/lib/perl", "$gpath/lib/perl");
61 @INC = (@INC, "$gpath/lib/perl");
64 require Grid::GPT::Setup;
67 # script-centred variable initialization
70 my $globusdir = $gpath;
71 my $myname = "setup-openssh.pl";
74 # Set up path prefixes for use in the path translations
77 $prefix = ${globusdir};
78 $exec_prefix = "${prefix}";
79 $bindir = "${exec_prefix}/bin";
80 $sbindir = "${exec_prefix}/sbin";
81 $sysconfdir = "$prefix/etc/ssh";
82 $localsshdir = "/etc/ssh";
83 $setupdir = "$prefix/setup/gsi_openssh_setup";
86 # standard key types and their root file name mappings
90 "dsa" => "ssh_host_dsa_key",
91 "rsa" => "ssh_host_rsa_key",
92 "rsa1" => "ssh_host_key",
96 # argument specification. we offload some processing work from later functions
97 # to verify correct args by using anon subs in various places.
100 my($interactive, $force, $verbose);
103 'interactive!' => \$interactive,
105 'verbose' => \$verbose,
109 # main execution. This should find its way into a subroutine at some future
113 print "$myname: Configuring package 'gsi_openssh'...\n";
114 print "---------------------------------------------------------------------\n";
115 print "Hi, I'm the setup script for the gsi_openssh package! There\n";
116 print "are some last minute details that I've got to set straight\n";
117 print "in the sshd config file, along with generating the ssh keys\n";
118 print "for this machine (if it doesn't already have them).\n";
120 print "If I find a pair of host keys in /etc/ssh, I will copy them into\n";
121 print "\$GLOBUS_LOCATION/etc/ssh. If they aren't present, I will generate\n";
122 print "them for you.\n";
125 $response = query_boolean("Do you wish to continue with the setup package?","y");
126 if ($response eq "n")
129 print "Exiting gsi_openssh setup.\n";
137 $keyhash = determineKeys();
138 runKeyGen($keyhash->{gen});
139 copyKeyFiles($keyhash->{copy});
143 my $metadata = new Grid::GPT::Setup(package_name => "gsi_openssh_setup");
148 print "Additional Notes:\n";
150 print " o I see that you have your GLOBUS_LOCATION environmental variable\n";
153 print " \t\"$gpath\"\n";
155 print " Remember to keep this variable set (correctly) when you want to\n";
156 print " use the executables that came with this package.\n";
158 print " After that you may run, e.g.:\n";
160 print " \t\$ . \$GLOBUS_LOCATION/etc/globus-user-env.sh\n";
162 print " to prepare your environment for running the gsi_openssh\n";
163 print " executables.\n";
164 print "---------------------------------------------------------------------\n";
165 print "$myname: Finished configuring package 'gsi_openssh'.\n";
175 # initialize the PRNG pathname hash
181 # standard prng to executable conversion names
184 addPRNGCommand("\@PROG_LS\@", "ls");
185 addPRNGCommand("\@PROG_NETSTAT\@", "netstat");
186 addPRNGCommand("\@PROG_ARP\@", "arp");
187 addPRNGCommand("\@PROG_IFCONFIG\@", "ifconfig");
188 addPRNGCommand("\@PROG_PS\@", "ps");
189 addPRNGCommand("\@PROG_JSTAT\@", "jstat");
190 addPRNGCommand("\@PROG_W\@", "w");
191 addPRNGCommand("\@PROG_WHO\@", "who");
192 addPRNGCommand("\@PROG_LAST\@", "last");
193 addPRNGCommand("\@PROG_LASTLOG\@", "lastlog");
194 addPRNGCommand("\@PROG_DF\@", "df");
195 addPRNGCommand("\@PROG_SAR\@", "sar");
196 addPRNGCommand("\@PROG_VMSTAT\@", "vmstat");
197 addPRNGCommand("\@PROG_UPTIME\@", "uptime");
198 addPRNGCommand("\@PROG_IPCS\@", "ipcs");
199 addPRNGCommand("\@PROG_TAIL\@", "tail");
201 print "Determining paths for PRNG commands...\n";
203 $paths = determinePRNGPaths();
208 ### getDirectoryPaths( )
210 # return an array ref containing all of the directories in which we should search
211 # for our listing of executable names.
214 sub getDirectoryPaths( )
217 # read in the PATH environmental variable and prepend a set of 'safe'
218 # directories from which to test PRNG commands.
222 $path = "/bin:/usr/bin:/sbin:/usr/sbin:/etc:" . $path;
223 @dirs = split(/:/, $path);
226 # sanitize each directory listed in the array.
232 $tmp =~ s:^\s+|\s+$::g;
239 ### addPRNGCommand( $prng_name, $exec_name )
241 # given a PRNG name and a corresponding executable name, add it to our list of
242 # PRNG commands for which to find on the system.
247 my($prng_name, $exec_name) = @_;
249 prngAddNode($prng_name, $exec_name);
254 # read in ssh_prng_cmds.in, translate the program listings to the paths we have
255 # found on the local system, and then write the output to ssh_prng_cmds.
260 my($fileInput, $fileOutput);
261 my($mode, $uid, $gid);
264 if ( isPresent("/dev/random") && !isForced() )
266 printf("/dev/random found and not forced. Not installing ssh_prng_cmds...\n");
272 print "Fixing paths in ssh_prng_cmds...\n";
274 $fileInput = "$setupdir/ssh_prng_cmds.in";
275 $fileOutput = "$sysconfdir/ssh_prng_cmds";
278 # verify that we are prepared to work with $fileInput
281 if ( !isReadable($fileInput) )
283 printf("Cannot read $fileInput... skipping.\n");
288 # verify that we are prepared to work with $fileOuput
291 if ( !prepareFileWrite($fileOutput) )
297 # Grab the current mode/uid/gid for use later
300 $mode = (stat($fileInput))[2];
301 $uid = (stat($fileInput))[4];
302 $gid = (stat($fileInput))[5];
305 # Open the files for reading and writing, and loop over the input's contents
308 $data = readFile($fileInput);
309 for my $k (keys %$prngcmds)
311 $sub = prngGetExecPath($k);
312 $data =~ s:$k:$sub:g;
314 writeFile($fileOutput, $data);
317 # An attempt to revert the new file back to the original file's
321 chmod($mode, $fileOutput);
322 chown($uid, $gid, $fileOutput);
327 ### determinePRNGPaths( )
329 # for every entry in the PRNG hash, seek out and find the path for the
330 # corresponding executable name.
333 sub determinePRNGPaths
336 my($exec_name, $exec_path);
338 $dirs = getDirectoryPaths();
340 for my $k (keys %$prngcmds)
342 $exec_name = prngGetExecName($k);
343 $exec_path = findExecutable($exec_name, $dirs);
344 prngSetExecPath($k, $exec_path);
350 ### prngAddNode( $prng_name, $exec_name )
352 # add a new node to the PRNG hash
357 my($prng_name, $exec_name) = @_;
360 if (!defined($prngcmds))
366 $node->{prng} = $prng_name;
367 $node->{exec} = $exec_name;
369 $prngcmds->{$prng_name} = $node;
372 ### prngGetExecName( $key )
374 # get the executable name from the prng commands hash named by $key
381 return $prngcmds->{$key}->{exec};
384 ### prngGetExecPath( $key )
386 # get the executable path from the prng commands hash named by $key
393 return $prngcmds->{$key}->{exec_path};
396 ### prngGetNode( $key )
398 # return a reference to the node named by $key
405 return ${$prngcmds}{$key};
408 ### prngSetExecPath( $key, $path )
410 # given a key, set the executable path in that node to $path
415 my($key, $path) = @_;
417 $prngcmds->{$key}->{exec_path} = $path;
420 ### findExecutable( $exec_name, $dirs )
422 # given an executable name, test each possible path in $dirs to see if such
423 # an executable exists.
428 my($exec_name, $dirs) = @_;
432 $test = "$d/$exec_name";
434 if ( isExecutable($test) )
443 ### copyKeyFiles( $copylist )
445 # given an array of keys to copy, copy both the key and its public variant into
446 # the gsi-openssh configuration directory.
452 my($regex, $basename);
456 print "Copying ssh host keys...\n";
458 for my $f (@$copylist)
465 $pubkeyfile = "$f.pub";
467 copyFile("$localsshdir/$keyfile", "$sysconfdir/$keyfile");
468 copyFile("$localsshdir/$pubkeyfile", "$sysconfdir/$pubkeyfile");
476 # return true if the user passed in the force flag. return false otherwise.
481 if ( defined($force) && $force )
491 ### isReadable( $file )
493 # given a file, return true if that file both exists and is readable by the
494 # effective user id. return false otherwise.
501 if ( ( -e $file ) && ( -r $file ) )
511 ### isExecutable( $file )
513 # return true if $file is executable. return false otherwise.
530 ### isWritable( $file )
532 # given a file, return true if that file does not exist or is writable by the
533 # effective user id. return false otherwise.
540 if ( ( ! -e $file ) || ( -w $file ) )
550 ### isPresent( $file )
552 # given a file, return true if that file exists. return false otherwise.
571 # make the gsi-openssh configuration directory if it doesn't already exist.
576 if ( isPresent($sysconfdir) )
578 if ( -d $sysconfdir )
583 die("${sysconfdir} already exists and is not a directory!\n");
586 print "Could not find ${sysconfdir} directory... creating.\n";
587 action("mkdir -p $sysconfdir");
594 # based on a set of key types, triage them to determine if for each key type, that
595 # key type should be copied from the main ssh configuration directory, or if it
596 # should be generated using ssh-keygen.
601 my($keyhash, $keylist);
605 # initialize our variables
611 $keyhash->{gen} = []; # a list of keytypes to generate
612 $keyhash->{copy} = []; # a list of files to copy from the
614 $genlist = $keyhash->{gen};
615 $copylist = $keyhash->{copy};
618 # loop over our keytypes and determine what we need to do for each of them
621 for my $keytype (keys %$keyfiles)
623 $basekeyfile = $keyfiles->{$keytype};
626 # if the key's are already present, we don't need to bother with this rigamarole
629 $gkeyfile = "$sysconfdir/$basekeyfile";
630 $gpubkeyfile = "$sysconfdir/$basekeyfile.pub";
632 if ( isPresent($gkeyfile) && isPresent($gpubkeyfile) )
636 if ( isWritable("$sysconfdir/$basekeyfile") && isWritable("$sysconfdir/$basekeyfile.pub") )
638 action("rm $sysconfdir/$basekeyfile");
639 action("rm $sysconfdir/$basekeyfile.pub");
649 # if we can find a copy of the keys in /etc/ssh, we'll copy them to the user's
653 $mainkeyfile = "$localsshdir/$basekeyfile";
654 $mainpubkeyfile = "$localsshdir/$basekeyfile.pub";
656 if ( isReadable($mainkeyfile) && isReadable($mainpubkeyfile) )
658 push(@$copylist, $basekeyfile);
664 # otherwise, we need to generate the key
667 push(@$genlist, $keytype);
674 ### runKeyGen( $gen_keys )
676 # given a set of key types, generate private and public keys for that key type and
677 # place them in the gsi-openssh configuration directory.
683 my $keygen = "$bindir/ssh-keygen";
685 if (@$gen_keys && -x $keygen)
687 print "Generating ssh host keys...\n";
689 for my $k (@$gen_keys)
691 $keyfile = $keyfiles->{$k};
693 if ( !isPresent("$sysconfdir/$keyfile") )
695 action("$bindir/ssh-keygen -t $k -f $sysconfdir/$keyfile -N \"\"");
703 ### copySSHDConfigFile( )
705 # this subroutine 'edits' the paths in sshd_config to suit them to the current environment
706 # in which the setup script is being run.
709 sub copySSHDConfigFile
711 my($fileInput, $fileOutput);
712 my($mode, $uid, $gid);
715 print "Fixing paths in sshd_config...\n";
717 $fileInput = "$setupdir/sshd_config.in";
718 $fileOutput = "$sysconfdir/sshd_config";
721 # verify that we are prepared to work with $fileInput
724 if ( !isReadable($fileInput) )
726 printf("Cannot read $fileInput... skipping.\n");
731 # verify that we are prepared to work with $fileOuput
734 if ( !prepareFileWrite($fileOutput) )
740 # Grab the current mode/uid/gid for use later
743 $mode = (stat($fileInput))[2];
744 $uid = (stat($fileInput))[4];
745 $gid = (stat($fileInput))[5];
748 # Open the files for reading and writing, and loop over the input's contents
751 open(IN, "<$fileInput") || die ("$0: input file $fileInput missing!\n");
752 open(OUT, ">$fileOutput") || die ("$0: unable to open output file $fileOutput!\n");
757 # sorry for the whacky regex, but i need to verify a whole line
761 if ( $line =~ /^\s*Subsystem\s+sftp\s+\S+\s*$/ )
763 $line = "Subsystem\tsftp\t$gpath/libexec/sftp-server\n";
766 elsif ( $line =~ /^\s*PidFile.*$/ )
768 $line = "PidFile\t$gpath/var/sshd.pid\n";
783 # An attempt to revert the new file back to the original file's
787 chmod($mode, $fileOutput);
788 chown($uid, $gid, $fileOutput);
793 ### prepareFileWrite( $file )
795 # test $file to prepare for writing to it.
802 if ( isPresent($file) )
804 printf("$file already exists... ");
808 if ( isWritable($file) )
810 printf("removing.\n");
816 printf("not writable -- skipping.\n");
822 printf("skipping.\n");
830 ### copyConfigFiles( )
832 # subroutine that copies some extra config files to their proper location in
833 # $GLOBUS_LOCATION/etc/ssh.
839 # copy the sshd_config file into the ssh configuration directory and alter
840 # the paths in the file.
843 copySSHDConfigFile();
846 # do straight copies of the ssh_config and moduli files.
849 printf("Copying ssh_config and moduli to their proper location...\n");
851 copyFile("$setupdir/ssh_config", "$sysconfdir/ssh_config");
852 copyFile("$setupdir/moduli", "$sysconfdir/moduli");
855 # copy and alter the SXXsshd script.
858 copySXXScript("$setupdir/SXXsshd.in", "$sbindir/SXXsshd");
861 ### copyFile( $src, $dest )
863 # copy the file pointed to by $src to the location specified by $dest. in the
864 # process observe the rules regarding when the '-force' flag was passed to us.
869 my($src, $dest) = @_;
871 if ( !isReadable($src) )
873 printf("$src is not readable... not creating $dest.\n");
877 if ( !prepareFileWrite($dest) )
882 action("cp $src $dest");
885 ### copySXXScript( $in, $out )
887 # parse the input file, substituting in place the value of GLOBUS_LOCATION, and
888 # write the result to the output file.
895 if ( !isReadable($in) )
897 printf("$in is not readable... not creating $out.\n");
901 if ( !prepareFileWrite($out) )
906 $data = readFile($in);
907 $data =~ s|\@GLOBUS_LOCATION\@|$gpath|g;
908 writeFile($out, $data);
909 action("chmod 755 $out");
912 ### readFile( $filename )
914 # reads and returns $filename's contents
922 open(IN, "$filename") || die "Can't open '$filename': $!";
931 ### writeFile( $filename, $fileinput )
933 # create the inputs to the ssl program at $filename, appending the common name to the
934 # stream in the process
939 my($filename, $fileinput) = @_;
942 # test for a valid $filename
945 if ( !defined($filename) || (length($filename) lt 1) )
947 die "Filename is undefined";
951 # verify that we are prepared to work with $filename
954 if ( !prepareFileWrite($filename) )
960 # write the output to $filename
963 open(OUT, ">$filename");
964 print OUT "$fileinput";
968 ### action( $command )
970 # run $command within a proper system() command.
979 my $result = system("LD_LIBRARY_PATH=\"$gpath/lib:\$LD_LIBRARY_PATH\"; $command 2>&1");
981 if (($result or $?) and $command !~ m!patch!)
983 die "ERROR: Unable to execute command: $!\n";
987 ### query_boolean( $query_text, $default )
989 # query the user with a string, and expect a response. If the user hits
990 # 'enter' instead of entering an input, then accept the default response.
995 my($query_text, $default) = @_;
996 my($nondefault, $foo, $bar);
999 # Set $nondefault to the boolean opposite of $default.
1002 if ($default eq "n")
1011 print "${query_text} ";
1012 print "[$default] ";
1015 ($bar) = split //, $foo;
1017 if ( grep(/\s/, $bar) )
1019 # this is debatable. all whitespace means 'default'
1023 elsif ($bar ne $default)
1025 # everything else means 'nondefault'.
1031 # extraneous step. to get here, $bar should be eq to $default anyway.
1039 ### absolutePath( $file )
1041 # converts a given pathname into a canonical path using the abs_path function.
1047 my $home = $ENV{'HOME'};
1048 $file =~ s!~!$home!;
1050 $file =~ s!^\./!$startd/!;
1051 $file = "$startd/$file" if $file !~ m!^\s*/!;
1052 $file = abs_path($file);