summaryrefslogtreecommitdiff
path: root/frontends/scripts/dserver-update-key-cache-netbsd.sh.tpl
diff options
context:
space:
mode:
Diffstat (limited to 'frontends/scripts/dserver-update-key-cache-netbsd.sh.tpl')
-rw-r--r--frontends/scripts/dserver-update-key-cache-netbsd.sh.tpl34
1 files changed, 34 insertions, 0 deletions
diff --git a/frontends/scripts/dserver-update-key-cache-netbsd.sh.tpl b/frontends/scripts/dserver-update-key-cache-netbsd.sh.tpl
new file mode 100644
index 0000000..c50cb72
--- /dev/null
+++ b/frontends/scripts/dserver-update-key-cache-netbsd.sh.tpl
@@ -0,0 +1,34 @@
+#!/bin/sh
+# Refresh the dserver SSH key cache from user authorized_keys files.
+# NetBSD variant: called from the dserver rc.d start_precmd (because
+# /var/run is volatile across reboots) and from a daily root cron job.
+
+CACHEDIR=/var/run/dserver/cache
+DSERVER_USER=dserver
+DSERVER_GROUP=dserver
+
+echo 'Updating SSH key cache'
+
+ls /home/ | while read remoteuser; do
+ keysfile="/home/$remoteuser/.ssh/authorized_keys"
+
+ if [ -f "$keysfile" ]; then
+ cachefile="$CACHEDIR/$remoteuser.authorized_keys"
+ echo "Caching $keysfile -> $cachefile"
+
+ cp "$keysfile" "$cachefile"
+ chown "$DSERVER_USER:$DSERVER_GROUP" "$cachefile"
+ chmod 600 "$cachefile"
+ fi
+done
+
+# Remove stale cache entries for users whose authorized_keys no longer exist
+find "$CACHEDIR" -name '*.authorized_keys' -type f | while read cachefile; do
+ remoteuser=$(basename "$cachefile" .authorized_keys)
+ if [ ! -f "/home/$remoteuser/.ssh/authorized_keys" ]; then
+ echo "Deleting obsolete cache file $cachefile"
+ rm "$cachefile"
+ fi
+done
+
+echo 'All set...'