From 157885902b77d703d72f864d98b0dfcb4c650e54 Mon Sep 17 00:00:00 2001 From: ston1th Date: Fri, 4 Mar 2016 19:24:01 +0100 Subject: [PATCH] go1.6 + ssh script bsd support --- build-go.sh | 8 +++---- ssh-config.sh | 62 +++++++++++++++++++++++++++++++++------------------ 2 files changed, 44 insertions(+), 26 deletions(-) diff --git a/build-go.sh b/build-go.sh index 6d413a3..118349c 100755 --- a/build-go.sh +++ b/build-go.sh @@ -11,7 +11,7 @@ GITHUB="https://github.com/golang/go/archive/" V14="go1.4.3" TGZ14="${V14}.tar.gz" -Vnew="go1.5.2" +Vnew="go1.6" TGZnew="${Vnew}.tar.gz" INSTALL="/usr/local" @@ -36,9 +36,9 @@ cd ${INSTALL}/${V14}/src export GOROOT_BOOTSTRAP=${INSTALL}/${V14} if [ "$(uname -m)" == "x86_64" ]; then - export GOARCH=386 -else export GOARCH=amd64 +else + export GOARCH=386 fi cd ${INSTALL}/${Vnew}/src @@ -57,7 +57,7 @@ echo "" echo "export CGO_ENABLED=0" echo "export GOPATH=~/go" echo "export GOROOT=/usr/local/go" -echo "export PATH=\${PATH}:${GOROOT}" +echo "export PATH=\${PATH}:${GOROOT}/bin:~/go/bin" echo "" go version diff --git a/ssh-config.sh b/ssh-config.sh index d839f95..9a1bd45 100755 --- a/ssh-config.sh +++ b/ssh-config.sh @@ -1,9 +1,20 @@ -#!/bin/bash +#!/bin/sh -if [ ${EUID} -ne 0 ]; then - echo "error: this script must be run as root" 1>&2 - exit 1 -fi +UNAME=$(uname) +case ${UNAME} in + Linux) + if [ ${EUID} -ne 0 ]; then + echo "error: this script must be run as root" 1>&2 + exit 1 + fi + ;; + OpenBSD|FreeBSD) + if [ $(id -u) -ne 0 ]; then + echo "error: this script must be run as root" 1>&2 + exit 1 + fi + ;; +esac echo "warning: this script will disable ssh password authentication" read -p "continue? [y/N] " answer @@ -41,29 +52,30 @@ HostKey /etc/ssh/ssh_host_rsa_key KexAlgorithms curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256 Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-ripemd160-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160,umac-128@openssh.com -UsePrivilegeSeparation yes -SyslogFacility AUTH -LogLevel INFO -LoginGraceTime 120 +UsePrivilegeSeparation sandbox PermitRootLogin no -StrictModes yes RSAAuthentication no PubkeyAuthentication yes -AuthorizedKeysFile %h/.ssh/authorized_keys -IgnoreRhosts yes -RhostsRSAAuthentication no -HostbasedAuthentication no -PermitEmptyPasswords no ChallengeResponseAuthentication no PasswordAuthentication no -X11Forwarding no PrintMotd no -PrintLastLog yes -TCPKeepAlive yes -AcceptEnv LANG LC_* +EOF + +case ${UNAME} in + Linux) + cat << EOF >> /etc/ssh/sshd_config +AuthorizedKeysFile %h/.ssh/authorized_keys Subsystem sftp /usr/lib/openssh/sftp-server UsePAM yes EOF + ;; + OpenBSD|FreeBSD) + cat << EOF >> /etc/ssh/sshd_config +Subsystem sftp /usr/libexec/sftp-server +AuthorizedKeysFile .ssh/authorized_keys +EOF + ;; +esac read -p "enter your username " user @@ -91,10 +103,16 @@ echo "${sshkey}" > /home/${user}/.ssh/authorized_keys chmod 600 /home/${user}/.ssh/authorized_keys chown ${user}:root /home/${user}/.ssh/authorized_keys -service ssh restart +case ${UNAME} in + Linux) + service ssh restart + ;; + OpenBSD|FreeBSD) + /etc/rc.d/sshd restart + ;; +esac -ssh=$(ps aux | awk '/\/usr\/s?bin\/sshd/') -if [ -z "${ssh}" ]; then +if [ -z "$(ps aux | awk '/\/usr\/s?bin\/sshd/')" ]; then echo "error: ssh service failed to restart" 1>&2 echo "please check for sshd config errors manually" 1>&2 exit 1