X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=ud-host;h=956c046940f1efdec62ed1cfe2761275164398ce;hb=8bedb26f6cfb5410fdfee34a78ff4644f6d5ced0;hp=09a91ec7cc548bd9eb015d52a12f7950c6a01555;hpb=c36736bdd1248d73961a9c5df8f3b8e0434b75f1;p=mirror%2Fuserdir-ldap.git diff --git a/ud-host b/ud-host index 09a91ec..956c046 100755 --- a/ud-host +++ b/ud-host @@ -1,16 +1,40 @@ #!/usr/bin/env python # -*- mode: python -*- + +# Copyright (c) 2000-2001 Jason Gunthorpe +# Copyright (c) 2001 Ryan Murray +# Copyright (c) 2003 James Troup +# Copyright (c) 2004-2005 Joey Schulze +# +# This program is free software; you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation; either version 2 of the License, or +# (at your option) any later version. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program; if not, write to the Free Software +# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA. + # This script is an interactive way to manipulate fields in the LDAP directory. # When run it connects to the directory using the current users ID and fetches -# all the attributes for the first machine. It then formats them nicely and +# all the attributes for the first machine. It then formats them nicely and # allows the user to change them. # # Usage: userinfo -a -u -c -r -# -a Set the authentication user (the user whose password you are +# -a Set the authentication user (the user whose password you are # going to enter) # -h Set the host to display +# -l list all hosts and their status +# -f list all SSH fingerprints import string, time, os, pwd, sys, getopt, ldap, crypt, whrandom, readline, copy; +from tempfile import mktemp +from os import O_CREAT, O_EXCL, O_WRONLY from userdir_ldap import *; RootMode = 0; @@ -26,8 +50,8 @@ AttrInfo = {"description": ["Machine Descr.", 1], "machine": ["Machine Hardware", 10], "memory": ["Memory", 11], "disk": ["Disk", 12], - "sshrsahostkey": ["SSH RSA", 14], - "bandwidth": ["Bandwidth", 16]}; + "sshRSAHostKey": ["SSH Host Keys", 14], + "bandwidth": ["Bandwidth", 15]}; AttrPrompt = {"description": ["Purpose of the machine"], "hostname": ["The hostnames for the box (ipv4/ipv6)"], @@ -37,11 +61,11 @@ AttrPrompt = {"description": ["Purpose of the machine"], "distribution": ["The distribution version"], "access": ["all, developer only, restricted"], "admin": ["Admin email address"], - "architecture": ["Debian Arhitecture string"], + "architecture": ["Debian Architecture string"], "machine": ["Hardware description"], "memory": ["Installed RAM"], "disk": ["Disk Space, RAID levels, etc"], - "sshrsahostkey": ["A copy of /etc/ssh/ssh_*host_key.pub"], + "sshRSAHostKey": ["A copy of /etc/ssh/ssh_*host_key.pub"], "bandwidth": ["Available outbound"]}; # Create a map of IDs to desc,value,attr @@ -53,14 +77,14 @@ OrigOrderedIndex = copy.deepcopy(OrderedIndex); # Print out the automatic time stamp information def PrintModTime(Attrs): - Stamp = GetAttr(Attrs,"modifytimestamp",""); + Stamp = GetAttr(Attrs,"modifyTimestamp",""); if len(Stamp) >= 13: Time = (int(Stamp[0:4]),int(Stamp[4:6]),int(Stamp[6:8]), int(Stamp[8:10]),int(Stamp[10:12]),int(Stamp[12:14]),0,0,-1); print "%-24s:" % ("Record last modified on"), time.strftime("%a %d/%m/%Y %X UTC",Time), - print "by",ldap.explode_dn(GetAttr(Attrs,"modifiersname"),1)[0]; + print "by",ldap.explode_dn(GetAttr(Attrs,"modifiersName"),1)[0]; - Stamp = GetAttr(Attrs,"createtimestamp",""); + Stamp = GetAttr(Attrs,"createTimestamp",""); if len(Stamp) >= 13: Time = (int(Stamp[0:4]),int(Stamp[4:6]),int(Stamp[6:8]), int(Stamp[8:10]),int(Stamp[10:12]),int(Stamp[12:14]),0,0,-1); @@ -80,7 +104,7 @@ def ShowAttrs(Attrs): print; else: OrderedIndex[AttrInfo[at][1]][1] = Attrs[1][at]; - + Keys = OrderedIndex.keys(); Keys.sort(); for at in Keys: @@ -90,15 +114,28 @@ def ShowAttrs(Attrs): print "'%s'" % (re.sub('[\n\r]','?',x)), print; +def Overview(Attrs): + """Display a one-line overview for a given host""" + if 'status' in Attrs[1].keys(): + status = Attrs[1]['status'][0] + else: + status = '' + print "%-12s %-10s %-38s %-25s %s" % (\ + Attrs[1]['host'][0], \ + Attrs[1]['architecture'][0], \ + Attrs[1]['distribution'][0], \ + Attrs[1]['access'][0], \ + status) + # Change a single attribute def ChangeAttr(Attrs,Attr): - if (Attr == "sponsor" or Attr == "hostname" or Attr == "sshrsahostkey"): + if (Attr == "sponsor" or Attr == "hostname" or Attr == "sshRSAHostKey"): return MultiChangeAttr(Attrs,Attr); print "Old value: '%s'" % (GetAttr(Attrs,Attr,"")); print "Press enter to leave unchanged and a single space to set to empty"; NewValue = raw_input("New? "); - + # Empty string if (NewValue == ""): print "Leaving unchanged."; @@ -139,8 +176,8 @@ def MultiChangeAttr(Attrs,Attr): if (NewValue == ""): print "Leaving unchanged."; return; - - # Delete + + # Delete if (Mode == "D"): print "Deleting.",; try: @@ -158,11 +195,26 @@ def MultiChangeAttr(Attrs,Attr): Attrs[1][Attr].append(NewValue); print; +def CalcTempFile(): + unique = 0 + while unique == 0: + name = mktemp() + try: + fd = os.open(name, O_CREAT | O_EXCL | O_WRONLY, 0600) + except OSError: + continue + os.close(fd) + unique = 1 + return name + + # Main program starts here User = pwd.getpwuid(os.getuid())[0]; BindUser = User; +ListMode = 0 +FingerPrints = 0 # Process options -(options, arguments) = getopt.getopt(sys.argv[1:], "nh:a:r") +(options, arguments) = getopt.getopt(sys.argv[1:], "nh:a:rlf") for (switch, val) in options: if (switch == '-h'): Host = val; @@ -172,33 +224,66 @@ for (switch, val) in options: RootMode = 1; elif (switch == '-n'): BindUser = ""; + elif (switch == '-l'): + BindUser = ""; + ListMode = 1 + elif (switch == '-f'): + BindUser = ""; + FingerPrints = 1 if (BindUser != ""): - print "Accessing LDAP entry", -if (BindUser != User): - if (BindUser != ""): - print "as '" + BindUser + "'"; + l = passwdAccessLDAP(LDAPServer, BaseDn, BindUser) else: - print; -if (BindUser != ""): - Password = getpass(BindUser + "'s password: "); + l = ldap.open(LDAPServer); + l.simple_bind_s("","") + +HBaseDn = "ou=hosts,dc=debian,dc=org"; + +if ListMode == 1: + Attrs = l.search_s(HBaseDn,ldap.SCOPE_ONELEVEL,"host=*") + hosts = [] + for hAttrs in Attrs: + hosts.append(hAttrs[1]['host'][0]) + hosts.sort() + + print "%-12s %-10s %-38s %-25s %s" % ("Host name","Arch","Distribution","Access","Status") + print "-"*115 + for host in hosts: + for hAttrs in Attrs: + if host == hAttrs[1]['host'][0]: + Overview(hAttrs) + sys.exit(0) +elif FingerPrints == 1: + Attrs = l.search_s(HBaseDn,ldap.SCOPE_ONELEVEL,"host=*") + hosts = [] + for hAttrs in Attrs: + hosts.append(hAttrs[1]['host'][0]) + hosts.sort() + + tmpfile = CalcTempFile() + for host in hosts: + for hAttrs in Attrs: + if host == hAttrs[1]['host'][0]: + if 'sshRSAHostKey' in hAttrs[1].keys(): + for key in hAttrs[1]['sshRSAHostKey']: + tmp = open(tmpfile, 'w') + tmp.write(key + '\n') + tmp.close() + fp = os.popen('/usr/bin/ssh-keygen -l -f ' + tmpfile, "r") + input = fp.readline() + fp.close() + fingerprint = input.split(' ') + print "%s %s root@%s" % (fingerprint[0], fingerprint[1], host) + os.unlink(tmpfile) + sys.exit(0) -# Connect to the ldap server -l = ldap.open(LDAPServer); -UserDn = "uid=" + BindUser + "," + BaseDn; -if (BindUser != ""): - l.simple_bind_s(UserDn,Password); -else: - l.simple_bind_s("",""); - -HBaseDn = "ou=hosts,dc=debian,dc=org"; HostDn = "host=" + Host + "," + HBaseDn; # Query the server for all of the attributes Attrs = l.search_s(HBaseDn,ldap.SCOPE_ONELEVEL,"host=" + Host); if len(Attrs) == 0: print "Host",Host,"was not found."; - sys.exit(0); + sys.exit(0); # repeatedly show the account configuration while(1): @@ -212,10 +297,10 @@ while(1): print " d) Delete Host"; print " u) Switch Hosts"; print " x) Exit"; - + # Prompt Response = raw_input("Change? "); - if (Response == "x" or Response == "X" or Response == "q" or + if (Response == "x" or Response == "X" or Response == "q" or Response == "quit" or Response == "exit"): break; @@ -243,11 +328,15 @@ while(1): if len(NAttrs) != 0: print "Host",NewHost,"already exists."; continue; + NewHostName = raw_input("Hostname? "); + if NewHost == "": + continue; Dn = "host=" + NewHost + "," + HBaseDn; - l.add_s(Dn,[("host",NewHost), - ("objectclass","top")]); - - # Switch + l.add_s(Dn,[("host", NewHost), + ("hostname", NewHostName), + ("objectClass", ("top", "debianServer"))]); + + # Switch NAttrs = l.search_s(HBaseDn,ldap.SCOPE_ONELEVEL,"host=" + NewHost); if len(NAttrs) == 0: print "Host",NewHost,"was not found."; @@ -257,7 +346,7 @@ while(1): HostDn = "host=" + Host + "," + HBaseDn; OrderedIndex = copy.deepcopy(OrigOrderedIndex); continue; - + # Handle changing an arbitary value if (Response == "a"): Attr = raw_input("Attr? "); @@ -266,12 +355,12 @@ while(1): if (Response == 'd'): Really = raw_input("Really (type yes)? "); - if Really != 'yes': + if Really != 'yes': continue; print "Deleting",HostDn; l.delete_s(HostDn); continue; - + # Convert the integer response try: ID = int(Response);