From eab5eca5bda076aae57e6cc82b6e08dbd5025ff3 Mon Sep 17 00:00:00 2001 From: Tom Barrett Date: Fri, 20 Mar 2020 04:30:39 -0500 Subject: new way of generating interfaces, only have to change hosts file now --- scripts/debian_roll | 45 +++++++++++++++++++++++---------------------- scripts/kerberos | 22 ---------------------- scripts/krb | 23 +++++++++++++++++++++++ scripts/ldap | 2 +- 4 files changed, 47 insertions(+), 45 deletions(-) delete mode 100755 scripts/kerberos create mode 100755 scripts/krb (limited to 'scripts') diff --git a/scripts/debian_roll b/scripts/debian_roll index 83b7d76..caf652c 100755 --- a/scripts/debian_roll +++ b/scripts/debian_roll @@ -7,35 +7,36 @@ PASS=tom ROOT_PASS=root # init -lxc-create -n $NAME -t download -- --dist debian --release buster --arch amd64 -lxc-start -n $NAME +lxc-create $NAME -t download -- --dist debian --release buster --arch amd64 +lxc-start $NAME # TODO maybe just info until ip shows up? sleep 15 # install basics -lxc-attach -n $NAME -- apt-get update -lxc-attach -n $NAME -- apt-get dist-upgrade -lxc-attach -n $NAME -- apt-get install -y apt-utils -lxc-attach -n $NAME -- apt-get install -y sudo openssh-server x11-xserver-utils +lxc-attach $NAME -- apt-get update +lxc-attach $NAME -- apt-get dist-upgrade +lxc-attach $NAME -- apt-get install -y apt-utils +lxc-attach $NAME -- apt-get install -y sudo openssh-server x11-xserver-utils # setup users -lxc-attach -n $NAME -- bash -c 'echo -e "'$ROOT_PASS'\n'$ROOT_PASS'" | passwd' -lxc-attach -n $NAME -- adduser $USER --gecos "" --disabled-password -lxc-attach -n $NAME -- bash -c 'echo -e "'$PASS'\n'$PASS'" | passwd $USER' +lxc-attach $NAME -- bash -c 'echo -e "'$ROOT_PASS'\n'$ROOT_PASS'" | passwd' +lxc-attach $NAME -- adduser $USER --gecos "" --disabled-password +lxc-attach $NAME -- bash -c 'echo -e "'$PASS'\n'$PASS'" | passwd $USER' # setup x11 forwarding -lxc-attach -n $NAME -- bash -c 'echo "AllowTcpForwarding yes" >> /etc/ssh/sshd_config' -lxc-attach -n $NAME -- bash -c 'echo "X11UseLocalhost yes" >> /etc/ssh/sshd_config' -lxc-attach -n $NAME -- bash -c 'echo "PermitRootLogin yes" >> /etc/ssh/sshd_config' -lxc-attach -n $NAME -- systemctl restart sshd +lxc-attach $NAME -- bash -c 'echo "AllowTcpForwarding yes" >> /etc/ssh/sshd_config' +lxc-attach $NAME -- bash -c 'echo "X11UseLocalhost yes" >> /etc/ssh/sshd_config' +lxc-attach $NAME -- bash -c 'echo "PermitRootLogin yes" >> /etc/ssh/sshd_config' +lxc-attach $NAME -- systemctl restart sshd # setup networking -IP="$(lxc-info -n $NAME | grep IP | tr -s ' ' | cut -d ' ' -f 2)" -sshpass -p $ROOT_PASS ssh-copy-id -o "StrictHostKeyChecking=no" root@$IP -scp configs/$NAME/interfaces root@$IP:/etc/network/ -scp configs/hosts root@$IP:/etc/ -lxc-attach -n $NAME -- systemctl restart networking -ssh-keygen -R "$IP" - -IP="$(lxc-info -n $NAME | grep IP | tr -s ' ' | cut -d ' ' -f 2)" -sshpass -p $ROOT_PASS ssh-copy-id -o "StrictHostKeyChecking=no" root@$IP +IP="$(lxc-info $NAME | grep IP | tr -s ' ' | cut -d ' ' -f 2)" +DESIRED_IP="$(grep $NAME configs/hosts | cut -d ' ' -f 1)" + +sed "s/ADDRESS/$DESIRED_IP/" configs/interfaces > tmp/interfaces +sshpass -p $ROOT_PASS scp -o "StrictHostKeyChecking=no" tmp/interfaces root@$IP:/etc/network/interfaces +sshpass -p $ROOT_PASS scp -o "StrictHostKeyChecking=no" configs/hosts root@$IP:/etc/hosts +lxc-attach $NAME -- systemctl restart networking + +# add ssh key +sshpass -p $ROOT_PASS ssh-copy-id -o "StrictHostKeyChecking=no" root@$DESIRED_IP diff --git a/scripts/kerberos b/scripts/kerberos deleted file mode 100755 index 919ee7d..0000000 --- a/scripts/kerberos +++ /dev/null @@ -1,22 +0,0 @@ -#!/bin/bash -set -e - -ROOT_PASS=root -KRB5_PASS=krb5 -KRB5_ADMIN_PASS=pass -USER_PASS=tommie - -scripts/debian_roll kerberos -lxc-attach -n kerberos -v DEBIAN_FRONTEND=noninteractive -- apt-get -y install krb5-admin-server - -scp configs/kerberos/krb5.conf root@192.168.122.100:/etc/ -scp configs/kerberos/kdc.conf root@192.168.122.100:/etc/krb5kdc/ -scp configs/kerberos/kadm5.acl root@192.168.122.100:/etc/krb5kdc/ - -lxc-attach -n kerberos -- bash -c 'echo -e "'$KRB5_PASS'\n'$KRB5_PASS'" | krb5_newrealm' -lxc-attach -n kerberos -- bash -c 'echo -e "'$KRB5_ADMIN_PASS'\n'$KRB5_ADMIN_PASS'" | kadmin.local addprinc root/admin' - -lxc-attach -n kerberos -- systemctl restart krb5-admin-server -lxc-attach -n kerberos -- systemctl restart krb5-kdc - -lxc-attach --clear-env -n kerberos -- bash -c 'echo -e "'$KRB5_ADMIN_PASS'\n'$USER_PASS'\n'$USER_PASS'\n" | kadmin addprinc tom' diff --git a/scripts/krb b/scripts/krb new file mode 100755 index 0000000..4df7fef --- /dev/null +++ b/scripts/krb @@ -0,0 +1,23 @@ +#!/bin/bash +set -e + +ROOT_PASS=root +KRB5_PASS=krb5 +KRB5_ADMIN_PASS=pass +USER_PASS=tommie +IP="$(grep krb configs/hosts | cut -d ' ' -f 1)" + +scripts/debian_roll krb +lxc-attach krb -v DEBIAN_FRONTEND=noninteractive -- apt-get -y install krb5-admin-server + +scp configs/krb/krb5.conf root@$IP:/etc/ +scp configs/krb/kdc.conf root@$IP:/etc/krb5kdc/ +scp configs/krb/kadm5.acl root@$IP:/etc/krb5kdc/ + +lxc-attach krb -- bash -c 'echo -e "'$KRB5_PASS'\n'$KRB5_PASS'" | krb5_newrealm' +lxc-attach krb -- bash -c 'echo -e "'$KRB5_ADMIN_PASS'\n'$KRB5_ADMIN_PASS'" | kadmin.local addprinc root/admin' + +lxc-attach krb -- systemctl restart krb5-admin-server +lxc-attach krb -- systemctl restart krb5-kdc + +lxc-attach --clear-env krb -- bash -c 'echo -e "'$KRB5_ADMIN_PASS'\n'$USER_PASS'\n'$USER_PASS'\n" | kadmin addprinc tom' diff --git a/scripts/ldap b/scripts/ldap index 26afcf8..594f37b 100755 --- a/scripts/ldap +++ b/scripts/ldap @@ -2,4 +2,4 @@ set -e scripts/debian_roll ldap -#lxc-attach -n ldap -v DEBIAN_FRONTEND=noninteractive -- apt-get -y install slapd ldap-utils ldapscripts +#lxc-attach ldap -v DEBIAN_FRONTEND=noninteractive -- apt-get -y install slapd ldap-utils ldapscripts -- cgit v1.2.3