# -*- mode: python -*-
# Generates passwd, shadow and group files from the ldap directory.
-import string, re, time, ldap, getopt, sys, os, pwd, posix, socket;
+# Copyright (c) 2000-2001 Jason Gunthorpe <jgg@debian.org>
+# Copyright (c) 2003-2004 James Troup <troup@debian.org>
+# Copyright (c) 2004-2005 Joey Schulze <joey@infodrom.org>
+# Copyright (c) 2001-2006 Ryan Murray <rmurray@debian.org>
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 2 of the License, or
+# (at your option) any later version.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+
+import string, re, time, ldap, getopt, sys, os, pwd, posix, socket, base64, sha;
from userdir_ldap import *;
global Allowed;
CurrentHost = "";
EmailCheck = re.compile("^([^ <>@]+@[^ ,<>@]+)?$");
-BSMTPCheck = re.compile(".*mx 0 (klecker|gluck)\.debian\.org\..*",re.DOTALL);
+BSMTPCheck = re.compile(".*mx 0 (gluck)\.debian\.org\..*",re.DOTALL);
DNSZone = ".debian.net"
def Sanitize(Str):
for x in PasswdAttrs:
if x[1].has_key("dnsZoneEntry") == 0:
continue;
+
+ # If the account has no PGP key, do not write it
+ if x[1].has_key("keyFingerPrint") == 0:
+ continue;
try:
F.write("; %s\n"%(EmailAddress(x)));
for z in x[1]["dnsZoneEntry"]:
raise;
Done(File,F,None);
+# Generate the DNS SSHFP records
+def GenSSHFP(l,File,HomePrefix):
+ F = None
+ try:
+ F = open(File + ".tmp","w")
+
+ # Fetch all the hosts
+ global HostAttrs
+ if HostAttrs == None:
+ raise "No Hosts"
+
+ for x in HostAttrs:
+ if x[1].has_key("hostname") == 0 or \
+ x[1].has_key("sshRSAHostKey") == 0:
+ continue
+ Host = GetAttr(x,"hostname");
+ Algorithm = None
+ for I in x[1]["sshRSAHostKey"]:
+ Split = string.split(I)
+ if Split[0] == 'ssh-rsa':
+ Algorithm = 1
+ if Split[0] == 'ssh-dss':
+ Algorithm = 2
+ if Algorithm == None:
+ continue
+ Fingerprint = sha.new(base64.decodestring(Split[1])).hexdigest()
+ Line = "%s. IN SSHFP %u 1 %s" % (Host,Algorithm,Fingerprint)
+ Line = Sanitize(Line) + "\n"
+ F.write(Line)
+ # Oops, something unspeakable happened.
+ except:
+ Die(File,F,None)
+ raise;
+ Done(File,F,None)
+
# Generate the BSMTP file
def GenBSMTP(l,File,HomePrefix):
F = None;
for x in PasswdAttrs:
if x[1].has_key("dnsZoneEntry") == 0:
continue;
+
+ # If the account has no PGP key, do not write it
+ if x[1].has_key("keyFingerPrint") == 0:
+ continue;
try:
for z in x[1]["dnsZoneEntry"]:
Split = string.split(string.lower(z));
raise;
Done(File,F,None);
-# Generate the shadow list
+# Generate the ssh known hosts file
def GenSSHKnown(l,File):
F = None;
try:
F = open(File + ".tmp","w",0644);
os.umask(OldMask);
- # Fetch all the hosts
- HostKeys = l.search_s(HostBaseDn,ldap.SCOPE_ONELEVEL,"sshRSAHostKey=*",\
- ["hostname","sshRSAHostKey"]);
-
- if HostKeys == None:
+ global HostAttrs
+ if HostAttrs == None:
raise "No Hosts";
-
- for x in HostKeys:
+
+ for x in HostAttrs:
if x[1].has_key("hostname") == 0 or \
x[1].has_key("sshRSAHostKey") == 0:
continue;
raise;
Done(File,F,None);
+# Generate the debianhosts file (list of all IP addresses)
+def GenHosts(l,File):
+ F = None;
+ try:
+ OldMask = os.umask(0022);
+ F = open(File + ".tmp","w",0644);
+ os.umask(OldMask);
+
+ # Fetch all the hosts
+ HostNames = l.search_s(HostBaseDn,ldap.SCOPE_ONELEVEL,"hostname=*",\
+ ["hostname"]);
+
+ if HostNames == None:
+ raise "No Hosts";
+
+ for x in HostNames:
+ if x[1].has_key("hostname") == 0:
+ continue;
+ Host = GetAttr(x,"hostname");
+ try:
+ Addr = socket.gethostbyname(Host);
+ F.write(Addr + "\n");
+ except:
+ pass
+ # Oops, something unspeakable happened.
+ except:
+ Die(File,F,None);
+ raise;
+ Done(File,F,None);
# Connect to the ldap server
l = ldap.open(LDAPServer);
"shadowexpire","emailForward","latitude","longitude",\
"allowedHost","sshRSAAuthKey","dnsZoneEntry","cn","sn",\
"keyFingerPrint","privateSub"]);
+# Fetch all the hosts
+HostAttrs = l.search_s(HostBaseDn,ldap.SCOPE_ONELEVEL,"sshRSAHostKey=*",\
+ ["hostname","sshRSAHostKey"]);
# Open the control file
if len(sys.argv) == 1:
GenMarkers(l,GlobalDir+"markers");
GenPrivate(l,GlobalDir+"debian-private");
GenSSHKnown(l,GlobalDir+"ssh_known_hosts");
+GenHosts(l,GlobalDir+"debianhosts");
# Compatibility.
GenForward(l,GlobalDir+"forward-alias");
GroupList[str(GroupIDMap[I])] = None;
Allowed = GroupList;
+ if Allowed == {}:
+ Allowed = None
CurrentHost = Split[0];
sys.stdout.flush();
GenPasswd(l,OutDir+"passwd",Split[1]);
sys.stdout.flush();
GenGroup(l,OutDir+"group");
- if CurrentHost == "haydn.debian.org" or CurrentHost == "costa.debian.org":
+ if ExtraList.has_key("[UNTRUSTED]"):
continue;
GenShadow(l,OutDir+"shadow");
DoLink(GlobalDir,OutDir,"markers");
DoLink(GlobalDir,OutDir,"mail-forward.cdb");
DoLink(GlobalDir,OutDir,"ssh_known_hosts");
+ DoLink(GlobalDir,OutDir,"debianhosts");
# Compatibility.
DoLink(GlobalDir,OutDir,"forward-alias");
if ExtraList.has_key("[DNS]"):
GenDNS(l,OutDir+"dns-zone",Split[1]);
+ GenSSHFP(l,OutDir+"dns-sshfp",Split[1])
if ExtraList.has_key("[BSMTP]"):
- GenBSMTP(l,OutDir+"bsmtp",Split[1]);
+ GenBSMTP(l,OutDir+"bsmtp",Split[1])
if ExtraList.has_key("[PRIVATE]"):
- DoLink(GlobalDir,OutDir,"debian-private");
-
+ DoLink(GlobalDir,OutDir,"debian-private")