# Generates passwd, shadow and group files from the ldap directory.
# Copyright (c) 2000-2001 Jason Gunthorpe <jgg@debian.org>
-# Copyright (c) 2001-2005 Ryan Murray <rmurray@debian.org>
# Copyright (c) 2003-2004 James Troup <troup@debian.org>
# Copyright (c) 2004-2005 Joey Schulze <joey@infodrom.org>
+# Copyright (c) 2001-2006 Ryan Murray <rmurray@debian.org>
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# along with this program; if not, write to the Free Software
# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
-import string, re, time, ldap, getopt, sys, os, pwd, posix, socket;
+import string, re, time, ldap, getopt, sys, os, pwd, posix, socket, base64, sha;
from userdir_ldap import *;
global Allowed;
CurrentHost = "";
EmailCheck = re.compile("^([^ <>@]+@[^ ,<>@]+)?$");
-BSMTPCheck = re.compile(".*mx 0 (klecker|gluck)\.debian\.org\..*",re.DOTALL);
+BSMTPCheck = re.compile(".*mx 0 (gluck)\.debian\.org\..*",re.DOTALL);
DNSZone = ".debian.net"
def Sanitize(Str):
raise;
Done(File,F,None);
+# Generate the DNS SSHFP records
+def GenSSHFP(l,File,HomePrefix):
+ F = None
+ try:
+ F = open(File + ".tmp","w")
+
+ # Fetch all the hosts
+ global HostAttrs
+ if HostAttrs == None:
+ raise "No Hosts"
+
+ for x in HostAttrs:
+ if x[1].has_key("hostname") == 0 or \
+ x[1].has_key("sshRSAHostKey") == 0:
+ continue
+ Host = GetAttr(x,"hostname");
+ Algorithm = None
+ for I in x[1]["sshRSAHostKey"]:
+ Split = string.split(I)
+ if Split[0] == 'ssh-rsa':
+ Algorithm = 1
+ if Split[0] == 'ssh-dss':
+ Algorithm = 2
+ if Algorithm == None:
+ continue
+ Fingerprint = sha.new(base64.decodestring(Split[1])).hexdigest()
+ Line = "%s. IN SSHFP %u 1 %s" % (Host,Algorithm,Fingerprint)
+ Line = Sanitize(Line) + "\n"
+ F.write(Line)
+ # Oops, something unspeakable happened.
+ except:
+ Die(File,F,None)
+ raise;
+ Done(File,F,None)
+
# Generate the BSMTP file
def GenBSMTP(l,File,HomePrefix):
F = None;
F = open(File + ".tmp","w",0644);
os.umask(OldMask);
- # Fetch all the hosts
- HostKeys = l.search_s(HostBaseDn,ldap.SCOPE_ONELEVEL,"sshRSAHostKey=*",\
- ["hostname","sshRSAHostKey"]);
-
- if HostKeys == None:
+ global HostAttrs
+ if HostAttrs == None:
raise "No Hosts";
-
- for x in HostKeys:
+
+ for x in HostAttrs:
if x[1].has_key("hostname") == 0 or \
x[1].has_key("sshRSAHostKey") == 0:
continue;
if x[1].has_key("hostname") == 0:
continue;
Host = GetAttr(x,"hostname");
- Addr = socket.gethostbyname(Host);
- F.write(Addr + "\n");
+ try:
+ Addr = socket.gethostbyname(Host);
+ F.write(Addr + "\n");
+ except:
+ pass
# Oops, something unspeakable happened.
except:
Die(File,F,None);
"shadowexpire","emailForward","latitude","longitude",\
"allowedHost","sshRSAAuthKey","dnsZoneEntry","cn","sn",\
"keyFingerPrint","privateSub"]);
+# Fetch all the hosts
+HostAttrs = l.search_s(HostBaseDn,ldap.SCOPE_ONELEVEL,"sshRSAHostKey=*",\
+ ["hostname","sshRSAHostKey"]);
# Open the control file
if len(sys.argv) == 1:
if ExtraList.has_key("[DNS]"):
GenDNS(l,OutDir+"dns-zone",Split[1]);
+ GenSSHFP(l,OutDir+"dns-sshfp",Split[1])
if ExtraList.has_key("[BSMTP]"):
- GenBSMTP(l,OutDir+"bsmtp",Split[1]);
+ GenBSMTP(l,OutDir+"bsmtp",Split[1])
if ExtraList.has_key("[PRIVATE]"):
- DoLink(GlobalDir,OutDir,"debian-private");
-
+ DoLink(GlobalDir,OutDir,"debian-private")