-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathsetup
More file actions
executable file
·143 lines (123 loc) · 3.71 KB
/
Copy pathsetup
File metadata and controls
executable file
·143 lines (123 loc) · 3.71 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
#!/bin/bash
ONBOARD_USER=onboard
ONBOARD_USER_HOME=/home/$ONBOARD_USER
ONBOARD_GROUP=$ONBOARD_USER
ONBOARD_ROOT=$ONBOARD_USER_HOME/onboard
ONBOARD_GIT="https://github.com/vemarsas/onboard.git"
install_conffiles() {
cd $ONBOARD_ROOT
cd doc/sysadm/examples
install -bvC -m 440 etc/sudoers /etc/
}
setup_core() {
echo " Installing core and OpenVPN functionality..."
apt-get update
apt-get -y upgrade
apt-get -y install sudo git-core openssh-server curl vim-nox mc
adduser --system --shell /bin/bash --home $ONBOARD_USER_HOME --group $ONBOARD_USER && \
echo "$ONBOARD_USER:$ONBOARD_USER" | chpasswd
su - $ONBOARD_USER -c "
if [ -d onboard ]; then
cd onboard
git remote set-url origin $ONBOARD_GIT
git pull --ff-only origin margay || true
else
git clone -b margay $ONBOARD_GIT
# HTTPS passwords have been disabled by GitHub, allow at least to store tokens...
git config --global credential.helper store
fi
"
install_conffiles # including sudoers
cd $ONBOARD_ROOT
bash etc/scripts/platform/debian/setup.sh $ONBOARD_ROOT $ONBOARD_USER
bash modules/openvpn/etc/scripts/platform/debian/setup.sh $ONBOARD_ROOT $ONBOARD_USER
# Raspbian section
# Disable pi user, with its insecure default password...
if id -u pi 2> /dev/null; then # DO not show missing user error here...
echo "Would you like to disable pi user? (y/n)"
read answer
if [[ $answer == y ]] ; then
if id -u $ONBOARD_USER > /dev/null; then # ...but so show it here!
echo 'Disabling/locking user "pi" (Raspberry) for security reasons.'
echo "We have the user '$ONBOARD_USER' instead."
passwd -l pi
fi
else
echo "Change default password for security reasons"
sudo passwd pi
fi
#clone groups from pi to ONBOARD_USER
SRC=pi
DEST=$ONBOARD_USER
SRC_GROUPS=$(groups ${SRC})
NEW_GROUPS=""
i=0
for gr in $SRC_GROUPS
do
if [ $i -gt 2 ]
then
if [ -z "$NEW_GROUPS" ];
then NEW_GROUPS=$gr;
else NEW_GROUPS="$NEW_GROUPS,$gr"; adduser $ONBOARD_USER $gr;
fi
fi
(( i++ ))
done
echo "User $ONBOARD_USER added to the following groups: $NEW_GROUPS"
fi
# Apparently not enabled by default on Raspbian
# TODO: make it optional in order to be security-paranoid?
systemctl start ssh
systemctl enable ssh
}
setup_ap() {
echo " Installing Wireless Access Point functionality..."
cd $ONBOARD_ROOT
bash modules/ap/etc/scripts/platform/debian/setup.sh $ONBOARD_ROOT $ONBOARD_USER
}
setup_hotspot() {
echo " Installing Hotspot/RADIUS functionality..."
cd $ONBOARD_ROOT
bash modules/radius-admin/etc/scripts/platform/debian/setup.sh $ONBOARD_ROOT $ONBOARD_USER
}
setup_virt() {
echo " Installing Virtualization functionality..."
cd $ONBOARD_ROOT
bash modules/qemu/etc/scripts/platform/debian/setup.sh $ONBOARD_ROOT $ONBOARD_USER
}
run_interactive() {
# Contributed by <marco.piscopia@vemarsas.it>
clear
echo 'Select one or more between following options:'
echo
echo '0) Default = core and openvpn functionality'
echo '1) Hotspot/RADIUS functionality'
echo '2) Virtualization functionality'
echo '3) Wireless Access Point functionality'
echo
echo 'Eg.Usage: 0 2 3 [Enter]'
echo
echo -n 'Options: '
read opt1 opt2 opt3 opt4
opt=($opt1 $opt2 $opt3 $opt4)
for op in "${opt[@]}"; do
case "$op" in
0)
setup_core | tee -a /var/log/mgyinstall.log
;;
1)
setup_hotspot | tee -a /var/log/mgyinstall.log
;;
2)
setup_virt | tee -a /var/log/mgyinstall.log
;;
3)
setup_ap | tee -a /var/log/mgyinstall.log
;;
*)
echo " Option not provided"
;;
esac
done
}
run_interactive