# -*- mode: python -*-
# Generates passwd, shadow and group files from the ldap directory.
+# Copyright (c) 2000-2001 Jason Gunthorpe <jgg@debian.org>
+# Copyright (c) 2001-2005 Ryan Murray <rmurray@debian.org>
+# Copyright (c) 2003-2004 James Troup <troup@debian.org>
+# Copyright (c) 2004-2005 Joey Schulze <joey@infodrom.org>
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 2 of the License, or
+# (at your option) any later version.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+
import string, re, time, ldap, getopt, sys, os, pwd, posix, socket;
from userdir_ldap import *;
raise "No Users";
for x in PasswdAttrs:
- if x[1].has_key("uidNumber") == 0 or \
- x[1].has_key("sshRSAAuthKey") == 0:
+ # If the account is locked, do not write it.
+ # This is a partial stop-gap. The ssh also needs to change this
+ # to ignore ~/.ssh/authorized* files.
+ if (string.find(GetAttr(x,"userPassword"),"*LK*") != -1):
continue;
if x[1].has_key("uidNumber") == 0 or \
for x in PasswdAttrs:
if x[1].has_key("dnsZoneEntry") == 0:
continue;
+
+ # If the account has no PGP key, do not write it
+ if x[1].has_key("keyFingerPrint") == 0:
+ continue;
try:
F.write("; %s\n"%(EmailAddress(x)));
for z in x[1]["dnsZoneEntry"]:
for x in PasswdAttrs:
if x[1].has_key("dnsZoneEntry") == 0:
continue;
+
+ # If the account has no PGP key, do not write it
+ if x[1].has_key("keyFingerPrint") == 0:
+ continue;
try:
for z in x[1]["dnsZoneEntry"]:
Split = string.split(string.lower(z));
raise;
Done(File,F,None);
-# Generate the shadow list
+# Generate the ssh known hosts file
def GenSSHKnown(l,File):
F = None;
try:
raise;
Done(File,F,None);
+# Generate the debianhosts file (list of all IP addresses)
+def GenHosts(l,File):
+ F = None;
+ try:
+ OldMask = os.umask(0022);
+ F = open(File + ".tmp","w",0644);
+ os.umask(OldMask);
+
+ # Fetch all the hosts
+ HostNames = l.search_s(HostBaseDn,ldap.SCOPE_ONELEVEL,"hostname=*",\
+ ["hostname"]);
+
+ if HostNames == None:
+ raise "No Hosts";
+
+ for x in HostNames:
+ if x[1].has_key("hostname") == 0:
+ continue;
+ Host = GetAttr(x,"hostname");
+ Addr = socket.gethostbyname(Host);
+ F.write(Addr + "\n");
+ # Oops, something unspeakable happened.
+ except:
+ Die(File,F,None);
+ raise;
+ Done(File,F,None);
# Connect to the ldap server
l = ldap.open(LDAPServer);
GenMarkers(l,GlobalDir+"markers");
GenPrivate(l,GlobalDir+"debian-private");
GenSSHKnown(l,GlobalDir+"ssh_known_hosts");
+GenHosts(l,GlobalDir+"debianhosts");
# Compatibility.
GenForward(l,GlobalDir+"forward-alias");
GroupList[str(GroupIDMap[I])] = None;
Allowed = GroupList;
+ if Allowed == {}:
+ Allowed = None
CurrentHost = Split[0];
sys.stdout.flush();
GenPasswd(l,OutDir+"passwd",Split[1]);
sys.stdout.flush();
GenGroup(l,OutDir+"group");
+ if ExtraList.has_key("[UNTRUSTED]"):
+ continue;
GenShadow(l,OutDir+"shadow");
# Link in global things
DoLink(GlobalDir,OutDir,"markers");
DoLink(GlobalDir,OutDir,"mail-forward.cdb");
DoLink(GlobalDir,OutDir,"ssh_known_hosts");
+ DoLink(GlobalDir,OutDir,"debianhosts");
# Compatibility.
DoLink(GlobalDir,OutDir,"forward-alias");