3 # $Id: svc_acct.export,v 1.6 2000-03-06 14:48:29 ivan Exp $
5 # Create and export password files: passwd, passwd.adjunct, shadow,
6 # acp_passwd, acp_userinfo, acp_dialup, users
8 # ivan@voicenet.com late august/september 96
9 # (the password encryption bits were from melody)
11 # use a temporary copy of svc_acct to minimize lock time on the real file,
12 # and skip blank entries.
14 # ivan@voicenet.com 96-Oct-6
16 # change users / acp_dialup file formats
17 # ivan@voicenet.com 97-jan-28-31
19 # change priority (after copies) to 19, not 10
20 # ivan@voicenet.com 97-feb-5
22 # added exit if stuff is already locked 97-apr-15
24 # rewrite ivan@sisd.com 98-mar-9
26 # Changed 'password' to '_password' because Pg6.3 reserves this word
27 # Added code to create a FreeBSD style master.passwd file
28 # bmccane@maxbaud.net 98-Apr-3
30 # don't export non-root 0 UID's, even if they get put in the database
31 # ivan@sisd.com 98-jul-14
33 # Uses Idle_Timeout, Port_Limit, Framed_Netmask and Framed_Route if they
34 # exist; need some way to support arbitrary radius fields. also
35 # /var/spool/freeside/conf/ ivan@sisd.com 98-jul-26, aug-9
37 # OOPS! added arbitrary radius fields (pry 98-aug-16) but forgot to say so.
38 # ivan@sisd.com 98-sep-18
40 # $Log: svc_acct.export,v $
41 # Revision 1.6 2000-03-06 14:48:29 ivan
42 # s/icradiusmachine/machine/
44 # Revision 1.2 1998/12/10 07:23:15 ivan
45 # use FS::Conf, need user (for datasrc)
53 use FS::SSH qw(scp ssh sshopen2);
54 use FS::UID qw(adminsuidsetup datasrc dbh);
55 use FS::Record qw(qsearch fields);
58 my $user = shift or die &usage;
63 my @shellmachines = $conf->config('shellmachines')
64 if $conf->exists('shellmachines');
66 my @bsdshellmachines = $conf->config('bsdshellmachines')
67 if $conf->exists('bsdshellmachines');
69 my @nismachines = $conf->config('nismachines')
70 if $conf->exists('nismachines');
72 my @erpcdmachines = $conf->config('erpcdmachines')
73 if $conf->exists('erpcdmachines');
75 my @radiusmachines = $conf->config('radiusmachines')
76 if $conf->exists('radiusmachines');
78 my $icradiusmachines = $conf->exists('icradiusmachines');
79 my @icradiusmachines = $conf->config('icradiusmachines') if $icradiusmachines;
80 my $icradius_mysqldest =
81 $conf->config('icradius_mysqldest') || "/usr/local/var/radius"
83 my $icradius_mysqlsource =
84 $conf->config('icradius_mysqlsource') || "/usr/local/var/freeside"
86 my $icradius_dbh = dbh; #could eventually get it from a config file if you're
87 #not running MySQL for your Freeside database
89 my(@saltset)= ( 'a'..'z' , 'A'..'Z' , '0'..'9' , '.' , '/' );
90 require 5.004; #srand(time|$$);
92 my $spooldir = "/usr/local/etc/freeside/export.". datasrc;
93 my $spoollock = "/usr/local/etc/freeside/svc_acct.export.lock.". datasrc;
95 open(EXPORT,"+>>$spoollock") or die "Can't open $spoollock: $!";
96 select(EXPORT); $|=1; select(STDOUT);
97 unless ( flock(EXPORT,LOCK_EX|LOCK_NB) ) {
101 #no reason to start loct of blocking processes
102 die "Is another export process running under pid $pid?\n";
105 print EXPORT $$,"\n";
107 my(@svc_acct)=qsearch('svc_acct',{});
109 ( open(MASTER,">$spooldir/master.passwd")
110 and flock(MASTER,LOCK_EX|LOCK_NB)
111 ) or die "Can't open $spooldir/master.passwd: $!";
112 ( open(PASSWD,">$spooldir/passwd")
113 and flock(PASSWD,LOCK_EX|LOCK_NB)
114 ) or die "Can't open $spooldir/passwd: $!";
115 ( open(SHADOW,">$spooldir/shadow")
116 and flock(SHADOW,LOCK_EX|LOCK_NB)
117 ) or die "Can't open $spooldir/shadow: $!";
118 ( open(ACP_PASSWD,">$spooldir/acp_passwd")
119 and flock (ACP_PASSWD,LOCK_EX|LOCK_NB)
120 ) or die "Can't open $spooldir/acp_passwd: $!";
121 ( open (ACP_DIALUP,">$spooldir/acp_dialup")
122 and flock(ACP_DIALUP,LOCK_EX|LOCK_NB)
123 ) or die "Can't open $spooldir/acp_dialup: $!";
124 ( open (USERS,">$spooldir/users")
125 and flock(USERS,LOCK_EX|LOCK_NB)
126 ) or die "Can't open $spooldir/users: $!";
128 chmod 0644, "$spooldir/passwd",
129 "$spooldir/acp_dialup",
131 chmod 0600, "$spooldir/master.passwd",
132 "$spooldir/acp_passwd",
137 if ( $icradiusmachines ) {
138 my $sth = $icradius_dbh->prepare("DELETE FROM radcheck");
139 $sth->execute or die "Can't reset radcheck table: ". $sth->errstr;
145 foreach $svc_acct (@svc_acct) {
147 my($password)=$svc_acct->getfield('_password');
148 my($cpassword,$rpassword);
149 if ( ( length($password) <= 8 )
150 && ( $password ne '*' )
151 && ( $password ne '' )
153 $cpassword=crypt($password,
154 $saltset[int(rand(64))].$saltset[int(rand(64))]
156 $rpassword=$password;
158 $cpassword=$password;
162 if ( $svc_acct->uid =~ /^(\d+)$/ ) {
164 die "Non-root user ". $svc_acct->username. " has 0 UID!"
165 if $svc_acct->uid == 0 && $svc_acct->username ne 'root';
168 # FORMAT OF FreeBSD MASTER PASSWD FILE HERE
169 print MASTER join(":",
170 $svc_acct->username, # User name
171 $cpassword, # Encrypted password
172 $svc_acct->uid, # User ID
173 $svc_acct->gid, # Group ID
175 "0", # Password Change Time
176 "0", # Password Expiration Time
177 $svc_acct->finger, # Users name
178 $svc_acct->dir, # Users home directory
179 $svc_acct->shell, # shell
183 # FORMAT OF THE PASSWD FILE HERE
184 print PASSWD join(":",
186 'x', # "##". $svc_acct->$username,
195 # FORMAT OF THE SHADOW FILE HERE
196 print SHADOW join(":",
210 if ( $svc_acct->slipip ne '' ) {
213 # FORMAT OF THE ACP_* FILES HERE
214 print ACP_PASSWD join(":",
224 my($ip)=$svc_acct->slipip;
226 unless ( $ip eq '0.0.0.0' || $svc_acct->slipip eq '0e0' ) {
227 print ACP_DIALUP $svc_acct->username, "\t*\t", $svc_acct->slipip, "\n";
231 # FORMAT OF THE USERS FILE HERE
233 $svc_acct->username, qq(\tPassword = "$rpassword"\n\t),
238 my($field,$attrib)=($1,$2);
240 "$attrib = \"". $svc_acct->getfield($field). "\"";
241 } grep /^radius_/ && $svc_acct->getfield($_), fields('svc_acct')
243 if ( $ip && $ip ne '0e0' ) {
244 print USERS qq(,\n\tFramed-Address = "$ip"\n\n);
246 print USERS qq(\n\n);
251 if ( $icradiusmachines ) {
252 my $sth = $icradius_dbh->prepare(
253 "INSERT INTO radcheck ( id, UserName, Attribute, Value ) VALUES ( ".
254 join(", ", map { $icradius_dbh->quote( $_ ) } qw (
261 $sth->execute or die "Can't insert into radcheck table: ". $sth->errstr;
268 flock(MASTER,LOCK_UN);
269 flock(PASSWD,LOCK_UN);
270 flock(SHADOW,LOCK_UN);
271 flock(ACP_DIALUP,LOCK_UN);
272 flock(ACP_PASSWD,LOCK_UN);
273 flock(USERS,LOCK_UN);
287 foreach $shellmachine (@shellmachines) {
288 scp("$spooldir/passwd","root\@$shellmachine:/etc/passwd.new")
289 == 0 or die "scp error: $!";
290 scp("$spooldir/shadow","root\@$shellmachine:/etc/shadow.new")
291 == 0 or die "scp error: $!";
292 ssh("root\@$shellmachine",
294 "mv /etc/passwd.new /etc/passwd; ".
295 "mv /etc/shadow.new /etc/shadow; ".
298 == 0 or die "ssh error: $!";
301 my($bsdshellmachine);
302 foreach $bsdshellmachine (@bsdshellmachines) {
303 scp("$spooldir/passwd","root\@$bsdshellmachine:/etc/passwd.new")
304 == 0 or die "scp error: $!";
305 scp("$spooldir/master.passwd","root\@$bsdshellmachine:/etc/master.passwd.new")
306 == 0 or die "scp error: $!";
307 ssh("root\@$bsdshellmachine",
309 "mv /etc/passwd.new /etc/passwd; ".
310 "mv /etc/master.passwd.new /etc/master.passwd; ".
313 == 0 or die "ssh error: $!";
317 foreach $nismachine (@nismachines) {
318 scp("$spooldir/passwd","root\@$nismachine:/etc/global/passwd")
319 == 0 or die "scp error: $!";
320 scp("$spooldir/shadow","root\@$nismachine:/etc/global/shadow")
321 == 0 or die "scp error: $!";
322 ssh("root\@$nismachine",
324 "cd /var/yp; make; ".
327 == 0 or die "ssh error: $!";
331 foreach $erpcdmachine (@erpcdmachines) {
332 scp("$spooldir/acp_passwd","root\@$erpcdmachine:/usr/annex/acp_passwd")
333 == 0 or die "scp error: $!";
334 scp("$spooldir/acp_dialup","root\@$erpcdmachine:/usr/annex/acp_dialup")
335 == 0 or die "scp error: $!";
336 ssh("root\@$erpcdmachine",
338 "kill -USR1 \`cat /usr/annex/erpcd.pid\'".
341 == 0 or die "ssh error: $!";
345 foreach $radiusmachine (@radiusmachines) {
346 scp("$spooldir/users","root\@$radiusmachine:/etc/raddb/users")
347 == 0 or die "scp error: $!";
348 ssh("root\@$erpcdmachine",
353 == 0 or die "ssh error: $!";
356 foreach my $icradiusmachine ( @icradiusmachines ) {
357 my( $machine, $db, $user, $pass ) = split(/\s+/, $icradiusmachine);
358 chdir $icradius_mysqlsource or die "Can't cd $icradius_mysqlsource: $!";
359 my($reader,$writer)=(new IO::Handle, new IO::Handle);
360 sshopen2("root\@$machine", $reader, $writer, "mysql --user=$user -p $db");
361 print $writer "$pass\nLOCK TABLES radcheck WRITE;\n";
362 foreach my $file ( glob("radcheck.*") ) {
363 scp($file,"root\@$machine:$icradius_mysqldest/$db/$file");
370 flock(EXPORT,LOCK_UN);
376 die "Usage:\n\n svc_acct.export user\n";