CLI: Update
This commit is contained in:
@@ -362,6 +362,52 @@ wxi-repeat() {
|
|||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
|
wx-eas(){
|
||||||
|
wxi-header "Emergency Access System" h2
|
||||||
|
|
||||||
|
LOCATION="$WX_HOME/credentials"
|
||||||
|
wxi-eas-login
|
||||||
|
|
||||||
|
wxi-repeat "\n" 1
|
||||||
|
|
||||||
|
case ${args['2']} in
|
||||||
|
data)
|
||||||
|
wxi-eas-data
|
||||||
|
;;
|
||||||
|
token)
|
||||||
|
wxi-eas-token
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
wxi-content status "Error" "This feature isn't implemented yet"
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
}
|
||||||
|
|
||||||
|
wxi-eas-login(){
|
||||||
|
if [[ $(systemd-detect-virt) == "wsl" ]]
|
||||||
|
then
|
||||||
|
echo 'KERNEL=="hidraw*", SUBSYSTEM=="hidraw", MODE="0666", TAG+="uaccess", GROUP="plugdev", ATTRS{idVendor}=="1050", ATTRS{idProduct}=="0407"' | sudo tee /etc/udev/rules.d/99-yubikey.rules > /dev/null
|
||||||
|
sudo udevadm control --reload
|
||||||
|
fi
|
||||||
|
|
||||||
|
YUBIKEYS=$(ykman list --serials 2>/dev/null | jq -R -s 'split("\n")[:-1]')
|
||||||
|
|
||||||
|
if [[ $(echo $YUBIKEYS | jq 'length') != 1 ]]
|
||||||
|
then
|
||||||
|
if [[ ${args['1']} == "eas" ]]
|
||||||
|
then
|
||||||
|
wxi-content status "Error" "You need to attach atleast one Yubikey and unplug all other Yubikeys"
|
||||||
|
wxi-stop
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
SERIAL=$(echo $YUBIKEYS | jq -r '.[0]')
|
||||||
|
wxi-content text "Emergency Access System - Serial Number: $SERIAL"
|
||||||
|
export SERIAL
|
||||||
|
fi
|
||||||
|
|
||||||
|
sudo systemctl enable --now pcscd &> /dev/null
|
||||||
|
}
|
||||||
|
|
||||||
wx-help(){
|
wx-help(){
|
||||||
|
|
||||||
wxi-header "Help"
|
wxi-header "Help"
|
||||||
@@ -685,7 +731,153 @@ wx-logout(){
|
|||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
wxi-eas-data(){
|
||||||
|
case ${args['3']} in
|
||||||
|
encrypt)
|
||||||
|
wxi-eas-data-encrypt
|
||||||
|
;;
|
||||||
|
decrypt)
|
||||||
|
wxi-eas-data-decrypt
|
||||||
|
;;
|
||||||
|
retrieve)
|
||||||
|
wxi-eas-data-retrieve
|
||||||
|
;;
|
||||||
|
deliver)
|
||||||
|
wxi-eas-data-deliver
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
wx-help
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
}
|
||||||
|
|
||||||
|
wxi-eas-token(){
|
||||||
|
case ${args['3']} in
|
||||||
|
create)
|
||||||
|
wxi-eas-token-create
|
||||||
|
;;
|
||||||
|
erase)
|
||||||
|
wxi-eas-token-erase
|
||||||
|
;;
|
||||||
|
sign)
|
||||||
|
wxi-eas-token-sign
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
}
|
||||||
|
|
||||||
wx-install(){
|
wx-install(){
|
||||||
|
if [[ "${args['1']}" == "install" ]]
|
||||||
|
then
|
||||||
|
wxi-header "Install" h2
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ ! -L "$HOME/bin/wx" && ! -f "/opt/ansible/bin/ansible-playbook" && ! -f "/bin/jq" && ! -f "/bin/podman" && ! -f "/bin/ykman"|| "${args['1']}" == "upgrade" ]]
|
||||||
|
then
|
||||||
|
cd "$PWD"
|
||||||
|
|
||||||
|
wxi-repeat "\n" 1
|
||||||
|
|
||||||
|
wxi-header "Git" h3
|
||||||
|
git stash -- cli.sh
|
||||||
|
git pull
|
||||||
|
wxi-repeat "\n" 1
|
||||||
|
|
||||||
|
wxi-header "Elevated Privileges" h3
|
||||||
|
sudo echo 'This command uses sudo!'
|
||||||
|
|
||||||
|
wxi-repeat "\n" 1
|
||||||
|
|
||||||
|
wxi-header "Ansible" h3
|
||||||
|
|
||||||
|
wxi-content text* "Dependencies: "
|
||||||
|
sudo apt-get update &> /dev/null
|
||||||
|
sudo apt-get install -y python3-pip python3-venv jq git curl lsb-release sudo sshpass rsync &> /dev/null
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
|
||||||
|
wxi-content text* "Python 3 - Virtual Environment: "
|
||||||
|
sudo python3 -m venv /opt/ansible &> /dev/null
|
||||||
|
if [[ -d "/opt/ansible" ]]
|
||||||
|
then
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
else
|
||||||
|
wxi-content text "Failed ✖"
|
||||||
|
fi
|
||||||
|
|
||||||
|
wxi-content text* "Ansible: "
|
||||||
|
sudo /opt/ansible/bin/pip3 install ansible-core &> /dev/null
|
||||||
|
if [[ -f "/opt/ansible/bin/ansible-playbook" ]]
|
||||||
|
then
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
else
|
||||||
|
wxi-content text "Failed ✖"
|
||||||
|
fi
|
||||||
|
|
||||||
|
wxi-content text* "Python3 Libraries - Dependencies: "
|
||||||
|
sudo /opt/ansible/bin/pip3 install cryptography dnspython hvac jmespath netaddr passlib pexpect xmltodict ansi2html --upgrade &> /dev/null
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
|
||||||
|
wxi-content text* "Collections: "
|
||||||
|
sudo ln -s /opt/ansible/collections /usr/share/ansible/collections &> /dev/null
|
||||||
|
sudo /opt/ansible/bin/ansible-galaxy collection install -r ansible/requirements.yml -p /usr/share/ansible/collections --upgrade &> /dev/null
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
|
||||||
|
wxi-repeat "\n" 1
|
||||||
|
|
||||||
|
wxi-header "CLI Tool" h3
|
||||||
|
|
||||||
|
if [[ -d "./cli/src" ]]
|
||||||
|
then
|
||||||
|
wxi-content text* "Dependencies: "
|
||||||
|
sudo apt-get update &> /dev/null
|
||||||
|
sudo apt-get install -y jq yubikey-manager &> /dev/null
|
||||||
|
|
||||||
|
if [[ -f "/bin/jq" && -f "/bin/ykman" ]]
|
||||||
|
then
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
else
|
||||||
|
wxi-content text "Failed ✖"
|
||||||
|
fi
|
||||||
|
|
||||||
|
wxi-content text* "Generate: "
|
||||||
|
python3 cli/generator.py
|
||||||
|
|
||||||
|
if [[ -f "./cli/cli.sh" ]]
|
||||||
|
then
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
|
||||||
|
wxi-content text* "Deploying: "
|
||||||
|
mv -f ./cli/cli.sh ./cli.sh
|
||||||
|
chmod +x ./cli.sh
|
||||||
|
|
||||||
|
if [[ ! -L "$HOME/bin/wx" ]]
|
||||||
|
then
|
||||||
|
mkdir -p "$HOME/bin"
|
||||||
|
ln -s "$PWD/cli.sh" "$HOME/bin/wx"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ $(systemd-detect-virt) == "wsl" ]]
|
||||||
|
then
|
||||||
|
if [[ ! -L "/bin/wx" ]]
|
||||||
|
then
|
||||||
|
sudo ln -s "$PWD/cli.sh" "/bin/wx"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ -f "./cli.sh" ]]
|
||||||
|
then
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
wxi-content text "Failed ✖"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
cd "$OLDPWD"
|
||||||
|
else
|
||||||
|
wxi-content text "You have already installed!"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
wx-install2(){
|
||||||
wxi-header "Install"
|
wxi-header "Install"
|
||||||
wxi-restricted --user
|
wxi-restricted --user
|
||||||
|
|
||||||
@@ -744,6 +936,11 @@ wx-update(){
|
|||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
wx-upgrade(){
|
||||||
|
wxi-header "Upgrade" h2
|
||||||
|
wx-install
|
||||||
|
}
|
||||||
|
|
||||||
wx-auto(){
|
wx-auto(){
|
||||||
wx-login
|
wx-login
|
||||||
|
|
||||||
@@ -821,6 +1018,250 @@ wxi-ssh-keys(){
|
|||||||
esac
|
esac
|
||||||
}
|
}
|
||||||
|
|
||||||
|
pxi-eas-data-decrypt(){
|
||||||
|
pxi-header "Data - Encrypt" h3
|
||||||
|
|
||||||
|
if [[ -n ${args['confirm']} ]]
|
||||||
|
then
|
||||||
|
if [[ -f $LOCATION/ansible-vault/eas/$SERIAL && $(base64 "$LOCATION/ansible-vault/eas/$SERIAL") != "" ]]
|
||||||
|
then
|
||||||
|
i=0
|
||||||
|
for file in "$PWD"/eas/data/$SERIAL/*/*/credentials;
|
||||||
|
do
|
||||||
|
i=$((i + 1))
|
||||||
|
echo "$i)${file#"$PWD/eas/data/$SERIAL/"}"
|
||||||
|
ansible-vault decrypt --vault-id "Pori Entrepreneurship Society - Infra - Emergency Access System ($SERIAL)"@"$LOCATION/ansible-vault/eas/$SERIAL" "$file"
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
pxi-content text "Confirmation Needed ✖ (--confirm)"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
pxi-eas-data-deliver(){
|
||||||
|
px-login vault
|
||||||
|
pxi-repeat "\n" 1
|
||||||
|
pxi-header "Data - Deliver" h3
|
||||||
|
|
||||||
|
if [[ -n ${args['confirm']} ]]
|
||||||
|
then
|
||||||
|
cd "$PWD/ansible"
|
||||||
|
|
||||||
|
playbook=cli
|
||||||
|
tasks=eas-data-deliver
|
||||||
|
limit="${args['limit']:-all}"
|
||||||
|
vaulted=(--vault-id "Pori Entrepreneurship Society - Infra - Emergency Access System ($SERIAL)@~/.pories/credentials/ansible-vault/eas/$SERIAL")
|
||||||
|
|
||||||
|
/opt/ansible/bin/ansible-playbook $playbook.yml -t "$tasks" --limit "$limit,localhost" --extra-vars "${args['vars']}" "${vaulted[@]}"
|
||||||
|
cd "$OLDPWD"
|
||||||
|
else
|
||||||
|
pxi-content text "Confirmation Needed ✖ (--confirm)"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
pxi-eas-data-encrypt(){
|
||||||
|
pxi-header "Data - Encrypt" h3
|
||||||
|
|
||||||
|
if [[ -f $LOCATION/ansible-vault/eas/$SERIAL && $(base64 "$LOCATION/ansible-vault/eas/$SERIAL") != "" ]]
|
||||||
|
then
|
||||||
|
i=0
|
||||||
|
for file in "$PWD"/eas/data/$SERIAL/*/*/credentials;
|
||||||
|
do
|
||||||
|
i=$((i + 1))
|
||||||
|
echo "$i)${file#"$PWD/eas/data/$SERIAL/"}"
|
||||||
|
ansible-vault encrypt --vault-id "Pori Entrepreneurship Society - Infra - Emergency Access System ($SERIAL)"@"$LOCATION/ansible-vault/eas/$SERIAL" "$file"
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
pxi-eas-data-retrieve(){
|
||||||
|
px-login vault
|
||||||
|
pxi-repeat "\n" 1
|
||||||
|
pxi-header "Data - Retrieve" h3
|
||||||
|
|
||||||
|
if [[ -n ${args['confirm']} ]]
|
||||||
|
then
|
||||||
|
cd "$PWD/ansible"
|
||||||
|
|
||||||
|
playbook=cli
|
||||||
|
tasks=eas-data-retrieve
|
||||||
|
limit="${args['limit']:-all}"
|
||||||
|
vaulted=(--vault-id "Pori Entrepreneurship Society - Infra - Emergency Access System ($SERIAL)@~/.pories/credentials/ansible-vault/eas/$SERIAL")
|
||||||
|
|
||||||
|
/opt/ansible/bin/ansible-playbook $playbook.yml -t "$tasks" --limit "$limit,localhost" --extra-vars "${args['vars']}" "${vaulted[@]}"
|
||||||
|
cd "$OLDPWD"
|
||||||
|
else
|
||||||
|
pxi-content text "Confirmation Needed ✖ (--confirm)"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
wxi-eas-token-create(){
|
||||||
|
wxi-header "Token - Create" h3
|
||||||
|
|
||||||
|
wxi-header "Ansible Vault" h4
|
||||||
|
if [[ $(ykman piv objects export 0x005FFF16 - 2>/dev/null) == "" ]]
|
||||||
|
then
|
||||||
|
wxi-content text* "PIN: "
|
||||||
|
read -s PIN
|
||||||
|
wxi-content text "******"
|
||||||
|
|
||||||
|
if [[ -n $PIN ]]
|
||||||
|
then
|
||||||
|
wxi-content text* "Generating: "
|
||||||
|
echo $(LC_ALL=C tr -dc 'A-Z2-7' </dev/urandom | head -c 64; echo) | ykman piv objects import --pin "$PIN" 0x005FFF16 -
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
else
|
||||||
|
wxi-content text "Failed ✖"
|
||||||
|
wxi-content status "Error" "PIN Required"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
wxi-content text* "Retrieving: "
|
||||||
|
EAS_AVP=$(ykman piv objects export 0x005FFF16 - 2>/dev/null)
|
||||||
|
if [[ $EAS_AVP != "" ]]
|
||||||
|
then
|
||||||
|
echo -e "Pori Entrepreneurship Society - Infra - Emergency Access System ($SERIAL) / Ansible Vault / $EAS_AVP" > "$LOCATION/ansible-vault/eas/$SERIAL"
|
||||||
|
if [[ -f "$LOCATION/ansible-vault/eas/$SERIAL" && $(base64 "$LOCATION/ansible-vault/eas/$SERIAL") != "" ]]
|
||||||
|
then
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
else
|
||||||
|
wxi-content text "Failed ✖"
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
wxi-content text "Failed ✖"
|
||||||
|
fi
|
||||||
|
|
||||||
|
wxi-repeat "\n" 1
|
||||||
|
|
||||||
|
wxi-header "SSH" h4
|
||||||
|
|
||||||
|
if [[ ! -f "$LOCATION/ssh/eas/$SERIAL" || ! -f "$PWD/eas/credentials/ssh/$SERIAL.pub" ]]
|
||||||
|
then
|
||||||
|
if [[ ! -f "$LOCATION/ssh/eas/$SERIAL" && -f "$PWD/eas/credentials/ssh/$SERIAL.pub" ]]
|
||||||
|
then
|
||||||
|
OLDOLDPWD=$OLDPWD
|
||||||
|
cd "$LOCATION/ssh/eas"
|
||||||
|
|
||||||
|
wxi-content text* "Retrieving: "
|
||||||
|
wxi-content text "Processing..."
|
||||||
|
|
||||||
|
wxi-repeat "\n" 1
|
||||||
|
|
||||||
|
ssh-keygen -K
|
||||||
|
|
||||||
|
wxi-repeat "\n" 1
|
||||||
|
|
||||||
|
if [[ -f "id_ed25519_sk_rk_warengroup-infra-eas-$SERIAL" ]]
|
||||||
|
then
|
||||||
|
mv "id_ed25519_sk_rk_warengroup-infra-eas-$SERIAL" "$SERIAL"
|
||||||
|
mv "id_ed25519_sk_rk_warengroup-infra-eas-$SERIAL.pub" "$SERIAL.pub"
|
||||||
|
|
||||||
|
ssh-keygen -c -f "$LOCATION/ssh/eas/$SERIAL" -P "" -C "Pori Entrepreneurship Society - Infra - Emergency Access System ($SERIAL)" &> /dev/null
|
||||||
|
|
||||||
|
wxi-content text* "Retrieving: "
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
else
|
||||||
|
wxi-content text* "Retrieving: "
|
||||||
|
wxi-content text "Failed ✖"
|
||||||
|
fi
|
||||||
|
|
||||||
|
wxi-repeat "\n" 1
|
||||||
|
|
||||||
|
wxi-content text* "Cleaning: "
|
||||||
|
rm -f id_ecdsa_sk_rk_*
|
||||||
|
rm -f id_ed25519_sk_rk_*
|
||||||
|
rm -f id_rsa_sk_rk_*
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
|
||||||
|
cd "$OLDPWD"
|
||||||
|
OLDPWD=$OLDOLDPWD
|
||||||
|
elif [[ ! -f "$LOCATION/ssh/eas/$SERIAL" ]]
|
||||||
|
then
|
||||||
|
wxi-content text* "Generating: "
|
||||||
|
wxi-content text "Processing..."
|
||||||
|
|
||||||
|
wxi-repeat "\n" 1
|
||||||
|
|
||||||
|
ssh-keygen -t ed25519-sk -f "$LOCATION/ssh/eas/$SERIAL" -O resident -O verify-required -O "application=ssh:warengroup-infra-eas-$SERIAL" -N "" -C "Warén Group - Infra - Emergency Access System ($SERIAL)"
|
||||||
|
|
||||||
|
wxi-repeat "\n" 1
|
||||||
|
|
||||||
|
if [[ -f "$LOCATION/ssh/eas/$SERIAL" ]]
|
||||||
|
then
|
||||||
|
wxi-content text* "Generating: "
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
else
|
||||||
|
wxi-content text* "Generating: "
|
||||||
|
wxi-content text "Failed ✖"
|
||||||
|
fi
|
||||||
|
|
||||||
|
wxi-repeat "\n" 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ -f "$LOCATION/ssh/eas/$SERIAL.pub" && ! -f "$PWD/eas/credentials/ssh/$SERIAL.pub" ]]
|
||||||
|
then
|
||||||
|
wxi-content text* "Delivering: "
|
||||||
|
cp "$LOCATION/ssh/eas/$SERIAL.pub" "$PWD/eas/credentials/ssh/$SERIAL.pub"
|
||||||
|
if [[ -f "$PWD/eas/credentials/ssh/$SERIAL.pub" ]]
|
||||||
|
then
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
else
|
||||||
|
wxi-content text "Failed ✖"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
wxi-content text* "Processing: "
|
||||||
|
wxi-content text "Done ✔"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
wxi-eas-token-erase(){
|
||||||
|
wxi-header "Token - Erase" h3
|
||||||
|
|
||||||
|
wxi-content text* "Processing: "
|
||||||
|
|
||||||
|
if [[ -f "$LOCATION/$serial" || -f "$LOCATION/$serial.pub" || -f "$PWD/eas/credentials/ssh/$serial.pub" ]]
|
||||||
|
then
|
||||||
|
if [[ -n ${args['confirm']} ]]
|
||||||
|
then
|
||||||
|
rm -f "$LOCATION/ssh/eas/$serial"
|
||||||
|
rm -f "$LOCATION/ssh/eas/$serial.pub"
|
||||||
|
rm -f "$PWD/eas/credentials/ssh/$serial.pub"
|
||||||
|
|
||||||
|
if [[ ! -f "$LOCATION/ssh/eas/$serial" && ! -f "$LOCATION/ssh/eas/$serial.pub" && ! -f "$PWD/eas/credentials/ssh/$serial.pub" ]]
|
||||||
|
then
|
||||||
|
wxi-content text "Ready ✔"
|
||||||
|
else
|
||||||
|
wxi-content text "Failed ✖"
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
wxi-content text "Confirmation Needed ✖ (--confirm)"
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
wxi-content text "Done ✔"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
wxi-eas-token-sign(){
|
||||||
|
wxi-header "Token - Sign" h3
|
||||||
|
|
||||||
|
wxi-eas-token-sign-gen
|
||||||
|
}
|
||||||
|
|
||||||
|
wxi-eas-token-sign-gen(){
|
||||||
|
LOCATION="$WX_HOME/credentials"
|
||||||
|
if [[ -f "$LOCATION/ssh/eas/$SERIAL" ]]
|
||||||
|
then
|
||||||
|
if [[ ! -f "$LOCATION/ssh/eas/$SERIAL-" ]]
|
||||||
|
then
|
||||||
|
pxi-ssh-keys-generate "eas/$SERIAL-" "Warén Group - Infra - Emergency Access System ($SERIAL)" &> /dev/null
|
||||||
|
fi
|
||||||
|
|
||||||
|
ssh-keygen -s "$LOCATION/ssh/eas/$SERIAL" -I "Warén Group - Infra - Emergency Access System ($SERIAL)" -n root -V -1m:+30m "$LOCATION/ssh/eas/$SERIAL-.pub"
|
||||||
|
mv -f "$LOCATION/ssh/eas/$SERIAL--cert.pub" "$LOCATION/ssh/eas/$SERIAL-.sig"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
wxi-ssh-config-clean(){
|
wxi-ssh-config-clean(){
|
||||||
wxi-header "SSH / Config / Clean"
|
wxi-header "SSH / Config / Clean"
|
||||||
wxi-restricted
|
wxi-restricted
|
||||||
|
|||||||
Reference in New Issue
Block a user