die "GLOBUS_LOCATION needs to be set before running this script"
}
+#
+# modify the ld library path for when we call ssh executables
+#
+
+$oldldpath = $ENV{LD_LIBRARY_PATH};
+$newldpath = "$gpath/lib";
+if (length($oldldpath) > 0)
+{
+ $newldpath .= ":$oldldpath";
+}
+$ENV{LD_LIBRARY_PATH} = "$newldpath";
+
#
# i'm including this because other perl scripts in the gpt setup directories
# do so
"rsa1" => "ssh_host_key",
};
-#
-# Check that we are running as root
-#
-
-$uid = $>;
-
-if ($uid != 0)
-{
- print "--> NOTE: You must be root to run this script! <--\n";
- exit 0;
-}
-
sub copyKeyFiles
{
my($copylist) = @_;
my($regex, $basename);
- print "Copying ssh host keys...\n";
-
- for my $f (@$copylist)
+ if (@$copylist)
{
- $f =~ s:/+:/:g;
+ print "Copying ssh host keys...\n";
- if (length($f) > 0)
+ for my $f (@$copylist)
{
- $keyfile = "$f";
- $pubkeyfile = "$f.pub";
+ $f =~ s:/+:/:g;
+
+ if (length($f) > 0)
+ {
+ $keyfile = "$f";
+ $pubkeyfile = "$f.pub";
- action("cp $localsshdir/$keyfile $sysconfdir/$keyfile");
- action("cp $localsshdir/$pubkeyfile $sysconfdir/$pubkeyfile");
+ action("cp $localsshdir/$keyfile $sysconfdir/$keyfile");
+ action("cp $localsshdir/$pubkeyfile $sysconfdir/$pubkeyfile");
+ }
}
}
}
}
}
+sub isPresent
+{
+ my($file) = @_;
+
+ if ( -e $file )
+ {
+ return 1;
+ }
+ else
+ {
+ return 0;
+ }
+}
+
sub determineKeys
{
my($keyhash, $keylist);
my($count);
+ #
+ # initialize our variables
+ #
+
$count = 0;
$keyhash = {};
$keyhash->{gen} = []; # a list of keytypes to generate
$keyhash->{copy} = []; # a list of files to copy from the
+
$genlist = $keyhash->{gen};
$copylist = $keyhash->{copy};
+ #
+ # loop over our keytypes and determine what we need to do for each of them
+ #
+
for my $keytype (keys %$keyfiles)
{
$basekeyfile = $keyfiles->{$keytype};
- $keyfile = "$localsshdir/$basekeyfile";
- $pubkeyfile = "$keyfile.pub";
- if ( !isReadable($keyfile) || !isReadable($pubkeyfile) )
+ #
+ # if the key's are already present, we don't need to bother with this rigamarole
+ #
+
+ $gkeyfile = "$sysconfdir/$basekeyfile";
+ $gpubkeyfile = "$sysconfdir/$basekeyfile.pub";
+
+ if ( isPresent($gkeyfile) && isPresent($gpubkeyfile) )
{
- push(@$genlist, $keytype);
- $count++;
+ next;
}
- }
- for my $keytype (keys %$keyfiles)
- {
- if ( !grep(/^$keytype$/, @$genlist) )
+ #
+ # if we can find a copy of the keys in /etc/ssh, we'll copy them to the user's
+ # globus location
+ #
+
+ $mainkeyfile = "$localsshdir/$basekeyfile";
+ $mainpubkeyfile = "$localsshdir/$basekeyfile.pub";
+
+ if ( isReadable($mainkeyfile) && isReadable($mainpubkeyfile) )
{
- $keyfile = $keyfiles->{$keytype};
- push(@$copylist, $keyfile);
+ push(@$copylist, $basekeyfile);
$count++;
+ next;
}
+
+ #
+ # otherwise, we need to generate the key
+ #
+
+ push(@$genlist, $keytype);
+ $count++;
}
if ($count > 0)
{
my($gen_keys) = @_;
- print "Generating ssh host keys...\n";
-
- for my $k (@$gen_keys)
+ if (@$gen_keys)
{
- $keyfile = $keyfiles->{$k};
+ print "Generating ssh host keys...\n";
- # if $sysconfdir/$keyfile doesn't exist..
- action("$bindir/ssh-keygen -t $k -f $sysconfdir/$keyfile -N \"\"");
+ for my $k (@$gen_keys)
+ {
+ $keyfile = $keyfiles->{$k};
+
+ # if $sysconfdir/$keyfile doesn't exist..
+ action("$bindir/ssh-keygen -t $k -f $sysconfdir/$keyfile -N \"\"");
+ }
}
return 0;
while (<IN>)
{
- if ( /Subsystem\s+sftp\s+\S+/ )
+ #
+ # sorry for the whacky regex, but i need to verify a whole line
+ #
+
+ if ( /^\s*Subsystem\s+sftp\s+\S+\s*$/ )
{
$_ = "Subsystem\tsftp\t$gpath/libexec/sftp-server\n";
$_ =~ s:/+:/:g;
close(OUT);
}
-print "---------------------------------------------------------------\n";
+print "---------------------------------------------------------------------\n";
print "Hi, I'm the setup script for the gsi_openssh package! There\n";
print "are some last minute details that I've got to set straight\n";
print "in the sshd config file, along with generating the ssh keys\n";
print "for this machine (if it doesn't already have them).\n";
print "\n";
print "If I find a pair of host keys in /etc/ssh, I will copy them into\n";
-print "$gpath/etc/ssh. If they aren't present, I will generate them\n";
-print "for you.\n";
+print "\$GLOBUS_LOCATION/etc/ssh. If they aren't present, I will generate\n";
+print "them for you.\n";
print "\n";
$response = query_boolean("Do you wish to continue with the setup package?","y");
-
if ($response eq "n")
{
print "\n";
exit 0;
}
+print "\n";
+
$keyhash = determineKeys();
runKeyGen($keyhash->{gen});
copyKeyFiles($keyhash->{copy});
$metadata->finish();
print "\n";
-print "$myname: Finished configuring package 'gsi_openssh'.\n";
+print "Additional Notes:\n";
+print "\n";
+print " o I see that you have your GLOBUS_LOCATION environmental variable\n";
+print " set to:\n";
print "\n";
-print "I see that you have your GLOBUS_LOCATION environmental variable\n";
-print "set to:\n";
-print " $gpath\n";
+print " \t\"$gpath\"\n";
print "\n";
-print "Remember to keep this variable set (correctly) when you want\n";
-print "to use the executables that came with this package.\n";
+print " Remember to keep this variable set (correctly) when you want to\n";
+print " use the executables that came with this package.\n";
print "\n";
-print "Additionally, you may need to set LD_LIBRARY_PATH to point to\n";
-print "the location in which your globus libraries reside. For example:\n";
+print " o You may need to set LD_LIBRARY_PATH to point to the location in\n";
+print " which your globus libraries reside. For example:\n";
print "\n";
-print " export LD_LIBRARY_PATH=\"$gpath/lib\"\n";
+print " \t\$ LD_LIBRARY_PATH=\"$gpath/lib:\$LD_LIBRARY_PATH\"; \\\n";
+print " \t export LD_LIBRARY_PATH\n";
print "\n";
-print "---------------------------------------------------------------\n";
+print "---------------------------------------------------------------------\n";
+print "$myname: Finished configuring package 'gsi_openssh'.\n";
#
# Just need a minimal action() subroutine for now..
printf "$command\n";
- my $result = system("$command 2>&1");
+ my $result = system("LD_LIBRARY_PATH=\"$gpath/lib:\$LD_LIBRARY_PATH\"; $command 2>&1");
if (($result or $?) and $command !~ m!patch!)
{