mirror of
https://github.com/rootzoll/raspiblitz.git
synced 2025-02-24 22:58:43 +01:00
Merge branch 'dev' of https://github.com/rootzoll/raspiblitz into dev
This commit is contained in:
commit
e92bfd6547
3 changed files with 56 additions and 35 deletions
|
@ -265,12 +265,12 @@ fi
|
||||||
# if backup is available on HDD/SSD
|
# if backup is available on HDD/SSD
|
||||||
################################
|
################################
|
||||||
|
|
||||||
if [ -d "/var/cache/raspiblitz/hdd-inspect/ssh" ]; then
|
if [ -d "/var/cache/raspiblitz/hdd-inspect/sshd" ]; then
|
||||||
# INIT OLD SSH HOST KEYS on Update/Recovery to prevent "Unknown Host" on ssh client
|
# INIT OLD SSH HOST KEYS on Update/Recovery to prevent "Unknown Host" on ssh client
|
||||||
echo "SSH SERVER CERTS RESTORE activating old SSH host keys" >> $logFile
|
echo "SSH SERVER CERTS RESTORE activating old SSH host keys" >> $logFile
|
||||||
/home/admin/config.scripts/blitz.ssh.sh restore /var/cache/raspiblitz/hdd-inspect >> $logFile
|
/home/admin/config.scripts/blitz.ssh.sh restore /var/cache/raspiblitz/hdd-inspect >> $logFile
|
||||||
else
|
else
|
||||||
echo "No SSH SERVER CERTS RESTORE because no /var/cache/raspiblitz/hdd-inspect/ssh" >> $logFile
|
echo "No SSH SERVER CERTS RESTORE because no /var/cache/raspiblitz/hdd-inspect" >> $logFile
|
||||||
fi
|
fi
|
||||||
|
|
||||||
################################
|
################################
|
||||||
|
|
|
@ -239,9 +239,21 @@ if [ "$1" = "status" ]; then
|
||||||
# make copy of WIFI config to RAMDISK (if available)
|
# make copy of WIFI config to RAMDISK (if available)
|
||||||
cp /mnt/hdd${subVolumeDir}/app-data/wpa_supplicant.conf /var/cache/raspiblitz/hdd-inspect/wpa_supplicant.conf 2>/dev/null
|
cp /mnt/hdd${subVolumeDir}/app-data/wpa_supplicant.conf /var/cache/raspiblitz/hdd-inspect/wpa_supplicant.conf 2>/dev/null
|
||||||
|
|
||||||
# make copy of SSH keys to RAMDISK (if available)
|
# Convert old ssh backup data structure (if needed)
|
||||||
cp -r /mnt/hdd${subVolumeDir}/ssh /var/cache/raspiblitz/hdd-inspect/ssh 2>/dev/null
|
if [ -d "/mnt/hdd/ssh" ]; then
|
||||||
|
# make a complete backup of directory
|
||||||
|
cp -a /mnt/hdd/ssh /mnt/hdd/app-storage/ssh-old-bakup
|
||||||
|
# delete old false sub directory (if exists)
|
||||||
|
rm -r /mnt/hdd/ssh/ssh 2>/dev/null
|
||||||
|
# move ssh root keys into new directory (if exists)
|
||||||
|
mv /mnt/hdd/ssh/root_backup /mnt/hdd/app-data/ssh-root 2>/dev/null
|
||||||
|
# move sshd keys into new directory
|
||||||
|
mv /mnt/hdd/ssh /mnt/hdd/app-data/sshd
|
||||||
|
fi
|
||||||
|
|
||||||
|
# make copy of SSH keys to RAMDISK (if available)
|
||||||
|
cp -r /mnt/hdd${subVolumeDir}/app-data/sshd /var/cache/raspiblitz/hdd-inspect/sshd 2>/dev/null
|
||||||
|
cp -r /mnt/hdd${subVolumeDir}/app-data/ssh-root /var/cache/raspiblitz/hdd-inspect/ssh-root 2>/dev/null
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# comment this line out if case to study the contect of the data section
|
# comment this line out if case to study the contect of the data section
|
||||||
|
|
|
@ -12,8 +12,6 @@ if [ $# -eq 0 ] || [ "$1" = "-h" ] || [ "$1" = "--help" ] || [ "$1" = "-help" ];
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
DEFAULTBACKUPBASEDIR="/mnt/hdd" # compiles to /mnt/hdd/ssh
|
|
||||||
|
|
||||||
# check if started with sudo
|
# check if started with sudo
|
||||||
if [ "$EUID" -ne 0 ]; then
|
if [ "$EUID" -ne 0 ]; then
|
||||||
echo "error='missing sudo'"
|
echo "error='missing sudo'"
|
||||||
|
@ -24,7 +22,7 @@ fi
|
||||||
# RENEW
|
# RENEW
|
||||||
###################
|
###################
|
||||||
if [ "$1" = "renew" ]; then
|
if [ "$1" = "renew" ]; then
|
||||||
echo "# *** blitz.ssh.sh renew"
|
echo "# *** $0 $1"
|
||||||
sudo systemctl stop sshd
|
sudo systemctl stop sshd
|
||||||
sudo rm /etc/ssh/ssh_host_*
|
sudo rm /etc/ssh/ssh_host_*
|
||||||
sudo ssh-keygen -A
|
sudo ssh-keygen -A
|
||||||
|
@ -37,7 +35,7 @@ fi
|
||||||
# CLEAR
|
# CLEAR
|
||||||
###################
|
###################
|
||||||
if [ "$1" = "clear" ]; then
|
if [ "$1" = "clear" ]; then
|
||||||
echo "# *** blitz.ssh.sh clear"
|
echo "# *** $0 $1"
|
||||||
sudo rm /etc/ssh/ssh_host_*
|
sudo rm /etc/ssh/ssh_host_*
|
||||||
echo "# OK: SSHD keyfiles & possible backups deleted"
|
echo "# OK: SSHD keyfiles & possible backups deleted"
|
||||||
exit 0
|
exit 0
|
||||||
|
@ -47,7 +45,7 @@ fi
|
||||||
# SESSIONS
|
# SESSIONS
|
||||||
###################
|
###################
|
||||||
if [ "$1" = "sessions" ]; then
|
if [ "$1" = "sessions" ]; then
|
||||||
echo "# *** blitz.ssh.sh sessions"
|
echo "# *** $0 $1"
|
||||||
sessionsCount=$(ss | grep -c ":ssh")
|
sessionsCount=$(ss | grep -c ":ssh")
|
||||||
echo "ssh_session_count=${sessionsCount}"
|
echo "ssh_session_count=${sessionsCount}"
|
||||||
exit 0
|
exit 0
|
||||||
|
@ -57,7 +55,7 @@ fi
|
||||||
# CHECK & REPAIR
|
# CHECK & REPAIR
|
||||||
###################
|
###################
|
||||||
if [ "$1" = "checkrepair" ]; then
|
if [ "$1" = "checkrepair" ]; then
|
||||||
echo "# *** blitz.ssh.sh checkrepair"
|
echo "# *** $0 $1"
|
||||||
|
|
||||||
# check if sshd host keys are missing / need generation
|
# check if sshd host keys are missing / need generation
|
||||||
countKeyFiles=$(ls -la /etc/ssh/ssh_host_* 2>/dev/null | grep -c "/etc/ssh/ssh_host")
|
countKeyFiles=$(ls -la /etc/ssh/ssh_host_* 2>/dev/null | grep -c "/etc/ssh/ssh_host")
|
||||||
|
@ -100,22 +98,26 @@ if [ "$1" = "checkrepair" ]; then
|
||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
DEFAULT_BASEDIR="/mnt/hdd/app-data"
|
||||||
|
|
||||||
###################
|
###################
|
||||||
# BACKUP
|
# BACKUP
|
||||||
###################
|
###################
|
||||||
if [ "$1" = "backup" ]; then
|
if [ "$1" = "backup" ]; then
|
||||||
echo "# *** blitz.ssh.sh backup"
|
echo "# *** $0 $1"
|
||||||
echo "# backup dir: ${DEFAULTBACKUPBASEDIR}/ssh"
|
echo "# backup dir: ${DEFAULT_BASEDIR}"
|
||||||
|
|
||||||
# backup sshd host keys
|
# backup sshd host keys
|
||||||
sudo rm -r $DEFAULTBACKUPBASEDIR/ssh 2>/dev/null # delete backups if exist
|
mkdir -p $DEFAULT_BASEDIR/sshd
|
||||||
sudo cp -r /etc/ssh $DEFAULTBACKUPBASEDIR/ssh 2>/dev/null # copy to backups if exist
|
sudo rm -rf $DEFAULT_BASEDIR/sshd/*
|
||||||
|
sudo cp -a /etc/ssh $DEFAULT_BASEDIR/sshd
|
||||||
|
|
||||||
# backup root use ssh keys
|
# backup root use ssh keys
|
||||||
sudo rm -r $DEFAULTBACKUPBASEDIR/ssh/root_backup 2>/dev/null
|
mkdir -p $DEFAULT_BASEDIR/ssh-root
|
||||||
sudo cp -r /root/.ssh $DEFAULTBACKUPBASEDIR/ssh/root_backup 2>/dev/null
|
sudo rm -rf $DEFAULT_BASEDIR/ssh-root/*
|
||||||
|
sudo cp -a /root/.ssh $DEFAULT_BASEDIR/ssh-root
|
||||||
|
|
||||||
if [ -d "${DEFAULTBACKUPBASEDIR}/ssh" ]; then
|
if [ -d "${DEFAULT_BASEDIR}/sshd" ] && [ -d "${DEFAULT_BASEDIR}/ssh-root" ]; then
|
||||||
echo "# OK - ssh keys backup done"
|
echo "# OK - ssh keys backup done"
|
||||||
else
|
else
|
||||||
echo "error='ssh keys backup failed - backup location may not exist'"
|
echo "error='ssh keys backup failed - backup location may not exist'"
|
||||||
|
@ -127,33 +129,40 @@ fi
|
||||||
# RESTORE
|
# RESTORE
|
||||||
###################
|
###################
|
||||||
if [ "$1" = "restore" ]; then
|
if [ "$1" = "restore" ]; then
|
||||||
echo "# *** blitz.ssh.sh restore"
|
echo "# *** $0 $1"
|
||||||
|
ALT_BASEDIR=$2
|
||||||
# second parameter (optional)
|
if [ "${ALT_BASEDIR}" != "" ]; then
|
||||||
ALTBACKUPBASEDIR=$2
|
DEFAULT_BASEDIR="${ALT_BASEDIR}"
|
||||||
if [ "${ALTBACKUPBASEDIR}" != "" ]; then
|
|
||||||
DEFAULTBACKUPBASEDIR="${ALTBACKUPBASEDIR}"
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
echo "# backup dir: ${DEFAULTBACKUPBASEDIR}/ssh"
|
echo "# backup dir: ${DEFAULT_BASEDIR}"
|
||||||
if [ -d "${DEFAULTBACKUPBASEDIR}/ssh" ]; then
|
if [ -d "${DEFAULT_BASEDIR}/sshd" ]; then
|
||||||
|
|
||||||
# restore sshd host keys
|
# restore sshd host keys
|
||||||
sudo rm -r /etc/ssh/*
|
sudo rm -rf /etc/ssh/*
|
||||||
sudo cp -r $DEFAULTBACKUPBASEDIR/ssh/* /etc/ssh/
|
sudo cp -a $DEFAULT_BASEDIR/sshd/* /etc/ssh/
|
||||||
sudo chown -R root:root /etc/ssh
|
sudo chown -R root:root /etc/ssh
|
||||||
sudo dpkg-reconfigure openssh-server
|
sudo dpkg-reconfigure openssh-server
|
||||||
sudo systemctl restart sshd
|
sudo systemctl restart sshd
|
||||||
|
echo "# OK - sshd keys restore done"
|
||||||
# restore root use keys
|
|
||||||
sudo rm -r /root/.ssh 2>/dev/null
|
|
||||||
sudo cp -r $DEFAULTBACKUPBASEDIR/ssh/root_backup /root/.ssh 2>/dev/null
|
|
||||||
sudo chown -R root:root /root/.ssh 2>/dev/null
|
|
||||||
|
|
||||||
echo "# OK - ssh keys restore done"
|
|
||||||
else
|
else
|
||||||
echo "error='ssh keys backup not found'"
|
echo "error='sshd keys backup not found'"
|
||||||
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
if [ -d "${DEFAULT_BASEDIR}/ssh-root" ]; then
|
||||||
|
|
||||||
|
# restore root use keys (directory may not exist)
|
||||||
|
sudo rm -rf /root/.ssh
|
||||||
|
sudo mkdir /root/.ssh
|
||||||
|
sudo cp -a $DEFAULT_BASEDIR/ssh-root/* /root/.ssh
|
||||||
|
sudo chown -R root:root /root/.ssh
|
||||||
|
|
||||||
|
echo "# OK - ssh-root keys restore done"
|
||||||
|
else
|
||||||
|
echo "# INFO - ssh-root keys backup not available"
|
||||||
|
fi
|
||||||
|
|
||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|
Loading…
Add table
Reference in a new issue