X-Git-Url: https://codewiz.org/gitweb?a=blobdiff_plain;f=src%2Fmonkeysphere-server;h=bc8be054aef9e5e89f9015211e568aa90bfaaa06;hb=0e12dd66f1d450d773c5e4403739371ef03860a8;hp=31bce7da81ac31de8f333879cd0a5b31e128a83b;hpb=8cf936aa9d62f6e8655904375a2d8217f559947a;p=monkeysphere.git diff --git a/src/monkeysphere-server b/src/monkeysphere-server index 31bce7d..bc8be05 100755 --- a/src/monkeysphere-server +++ b/src/monkeysphere-server @@ -40,9 +40,9 @@ subcommands: update-users (u) [USER]... update user authorized_keys files gen-key (g) [NAME[:PORT]] generate gpg key for the server - -l|--length BITS key length in bits (2048) - -e|--expire EXPIRE date to expire - -r|--revoker FINGERPRINT add a revoker + --length (-l) BITS key length in bits (2048) + --expire (-e) EXPIRE date to expire + --revoker (-r) FINGERPRINT add a revoker add-hostname (n+) NAME[:PORT] add hostname user ID to server key revoke-hostname (n-) NAME[:PORT] revoke hostname user ID show-key (s) output all server host key information @@ -51,15 +51,16 @@ subcommands: diagnostics (d) report on server monkeysphere status add-id-certifier (c+) KEYID import and tsign a certification key - -n|--domain DOMAIN limit ID certifications to DOMAIN - -t|--trust TRUST trust level of certifier (full) - -d|--depth DEPTH trust depth for certifier (1) + --domain (-n) DOMAIN limit ID certifications to DOMAIN + --trust (-t) TRUST trust level of certifier (full) + --depth (-d) DEPTH trust depth for certifier (1) remove-id-certifier (c-) KEYID remove a certification key list-id-certifiers (c) list certification keys gpg-authentication-cmd CMD gnupg-authentication command - -h|--help|help (h,?) this help + help (h,?) this help + EOF } @@ -102,7 +103,8 @@ gpg_authentication() { # output just key fingerprint fingerprint_server_key() { - gpg_host --list-secret-keys --fingerprint --with-colons --fixed-list-mode | \ + gpg_host --list-secret-keys --fingerprint \ + --with-colons --fixed-list-mode 2> /dev/null | \ grep '^fpr:' | head -1 | cut -d: -f10 } @@ -375,6 +377,8 @@ EOF add_hostname() { local userID local fingerprint + local tmpuidMatch + local line local adduidCommand if [ -z "$1" ] ; then @@ -383,19 +387,26 @@ add_hostname() { userID="ssh://${1}" - if [ "$(gpg_host --list-key "=${userID}" 2> /dev/null)" ] ; then + fingerprint=$(fingerprint_server_key) + + # match to only ultimately trusted user IDs + tmpuidMatch="u:$(echo $userID | gpg_escape)" + + # find the index of the requsted user ID + # NOTE: this is based on circumstantial evidence that the order of + # this output is the appropriate index + if line=$(gpg_host --list-keys --with-colons --fixed-list-mode "0x${fingerprint}!" \ + | egrep '^(uid|uat):' | cut -f2,10 -d: | grep -n -x -F "$tmpuidMatch") ; then failure "Host userID '$userID' already exists." fi echo "The following user ID will be added to the host key:" - echo " '$userID'" + echo " $userID" read -p "Are you sure you would like to add this user ID? (y/N) " OK; OK=${OK:=N} if [ ${OK/y/Y} != 'Y' ] ; then - failure "user ID not added." + failure "User ID not added." fi - fingerprint=$(fingerprint_server_key) - # edit-key script command to add user ID adduidCommand=$(cat < /dev/null | \ - egrep "^(uid|uat):" | cut -d: -f10 | gpg_unescape | cat -n | \ - grep "$userID" | awk '{ print $1 }') - - if [ -z "$uidIndex" ] ; then - failure "User ID '$userID' not found in host key." + if line=$(gpg_host --list-keys --with-colons --fixed-list-mode "0x${fingerprint}!" \ + | egrep '^(uid|uat):' | cut -f2,10 -d: | grep -n -x -F "$tmpuidMatch") ; then + uidIndex=${line%%:*} + else + failure "No non-revoked user ID '$userID' is found." fi - echo "The following user ID will be revoked from the host key:" - echo " '$userID'" + echo "The following host key user ID will be revoked:" + echo " $userID" read -p "Are you sure you would like to revoke this user ID? (y/N) " OK; OK=${OK:=N} if [ ${OK/y/Y} != 'Y' ] ; then - failure "user ID not revoked." + failure "User ID not revoked." fi + message="Hostname removed by monkeysphere-server $DATE" + # edit-key script command to revoke user ID revuidCommand=$(cat <