2 # Copyright (C) 2016 Ian Kelling
4 # Licensed under the Apache License, Version 2.0 (the "License");
5 # you may not use this file except in compliance with the License.
6 # You may obtain a copy of the License at
8 # http://www.apache.org/licenses/LICENSE-2.0
10 # Unless required by applicable law or agreed to in writing, software
11 # distributed under the License is distributed on an "AS IS" BASIS,
12 # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 # See the License for the specific language governing permissions and
14 # limitations under the License.
17 trap 'echo "$0:$LINENO:error: \"$BASH_COMMAND\" returned $?" >&2' ERR
19 [[ $EUID == 0 ]] ||
exec sudo
-E "${BASH_SOURCE[0]}" "$@"
22 if [[ -L /root
/.
ssh ]]; then
30 user_ssh_dir
=$
(eval echo ~
$user)/.
ssh
31 if [[ ! -s $user_ssh_dir/authorized_keys
]]; then
32 echo missing
$user_ssh_dir/authorized_keys. bad sign. bailing
>&2
36 # remove broken links, or else rsync has error about them.
37 find $user_ssh_dir -xtype l
-exec rm '{}' \
;
38 # -t times, so it won't rewrite the file every time,
40 rsync
--exclude=/h
--exclude=/h.pub
--exclude /config
--exclude /confighome
-rtL --delete $user_ssh_dir/ /root
/.
ssh
41 if [[ -e /q
/root
/h
]]; then
42 cp -a /q
/root
/h
{,.pub
} /root
/.
ssh
45 if [[ -e $user_ssh_dir/config
]]; then
46 ### The h key is like the home key, but only a whitelist of commands allowed, and
47 # not encrypted, so cron and whatnot can use it.
48 # For any interactive ssh command we want to run as root that is not in that
49 # whitelist, we need to ssh -F $HOME/.ssh/confighome
50 ### I run a separate ssh-agent for root where I add keys without
51 # confirm. This the root ssh-agent is only available
52 # to root, and it allows us to have a working ssh when X isnt available,
53 # eg, in an ssh shell. confirm for regular user provides some protection
54 # that a rouge user program cant use my ssh key.
55 sed 's,^AddKeysToAgent confirm,AddKeysToAgent yes,' $user_ssh_dir/config
>/root
/.ssh
/confighome
56 sed 's,^IdentityFile ~/\.ssh/home$,IdentityFile ~/\.ssh/h,' /root
/.ssh
/confighome
>/root
/.ssh
/config
58 chown
-R root
:root
/root
/.
ssh
60 # notably: installs hssh
61 /a
/exe
/install-my-scripts
62 if [[ -e /a
/opt
/btrbk
/ssh_filter_btrbk.sh
]]; then
63 install /a
/opt
/btrbk
/ssh_filter_btrbk.sh
/usr
/local
/bin
66 if [[ -e /etc
/systemd
/system
/ssh-agent-root.service
]]; then
67 systemctl
enable --now ssh-agent-root
70 d
=/etc
/initramfs-tools
71 if [[ -e $d ]] && ! diff -q /root
/.ssh
/authorized_keys
$d/root
/.ssh
/authorized_keys
&>/dev
/null
; then
72 mkdir
-p $d/root
/.
ssh /etc
/dropbear-initramfs
73 chmod 700 $d/root
$d/root
/.
ssh
74 cp -p /root
/.ssh
/authorized_keys
$d/root
/.ssh
/authorized_keys
75 cp -p /root
/.ssh
/authorized_keys
/etc
/dropbear-initramfs
76 if [[ -e /root
/.ssh
/authorized_keys2
]]; then
77 cat /root
/.ssh
/authorized_keys2
>>/etc
/dropbear-initramfs
79 update-initramfs
-u -k all