diff options
Diffstat (limited to 'frontends/scripts')
| -rw-r--r-- | frontends/scripts/dserver-update-key-cache-freebsd.sh.tpl | 4 | ||||
| -rw-r--r-- | frontends/scripts/dserver-update-key-cache.sh.tpl | 31 |
2 files changed, 19 insertions, 16 deletions
diff --git a/frontends/scripts/dserver-update-key-cache-freebsd.sh.tpl b/frontends/scripts/dserver-update-key-cache-freebsd.sh.tpl index 22173d7..5b11acf 100644 --- a/frontends/scripts/dserver-update-key-cache-freebsd.sh.tpl +++ b/frontends/scripts/dserver-update-key-cache-freebsd.sh.tpl @@ -1,6 +1,8 @@ #!/bin/sh # Refresh the dserver SSH key cache from user authorized_keys files. -# Called by /usr/local/etc/periodic/daily/200.dserver-update-key-cache. +# FreeBSD variant: called from the dserver rc.d start_precmd (because +# /var/run is volatile across reboots — cleanvar purges it) and by +# /usr/local/etc/periodic/daily/200.dserver-update-key-cache. CACHEDIR=/var/run/dserver/cache DSERVER_USER=dserver diff --git a/frontends/scripts/dserver-update-key-cache.sh.tpl b/frontends/scripts/dserver-update-key-cache.sh.tpl index 86b5ecf..fc6bf9e 100644 --- a/frontends/scripts/dserver-update-key-cache.sh.tpl +++ b/frontends/scripts/dserver-update-key-cache.sh.tpl @@ -1,4 +1,8 @@ #!/bin/ksh +# Refresh the dserver SSH key cache from user authorized_keys files. +# OpenBSD variant: called from the dserver rc.d rc_pre (because /var/run is +# wiped by /etc/rc at boot) and from a daily /etc/daily.local entry added by +# the Rex 'dtail' task — see the pkgrepo skill's dtail-package.md. CACHEDIR=/var/run/dserver/cache DSERVER_USER=_dserver @@ -7,27 +11,24 @@ DSERVER_GROUP=_dserver echo 'Updating SSH key cache' ls /home/ | while read remoteuser; do - keysfile=/home/$remoteuser/.ssh/authorized_keys + keysfile="/home/$remoteuser/.ssh/authorized_keys" - if [ -f $keysfile ]; then - cachefile=$CACHEDIR/$remoteuser.authorized_keys + if [ -f "$keysfile" ]; then + cachefile="$CACHEDIR/$remoteuser.authorized_keys" echo "Caching $keysfile -> $cachefile" - cp $keysfile $cachefile - chown $DSERVER_USER:$DSERVER_GROUP $cachefile - chmod 600 $cachefile + cp "$keysfile" "$cachefile" + chown "$DSERVER_USER:$DSERVER_GROUP" "$cachefile" + chmod 600 "$cachefile" fi done -# Cleanup obsolete public SSH keys -find $CACHEDIR -name \*.authorized_keys -type f | -while read cachefile; do - remoteuser=$(basename $cachefile | cut -d. -f1) - keysfile=/home/$remoteuser/.ssh/authorized_keys - - if [ ! -f $keysfile ]; then - echo 'Deleting obsolete cache file $cachefile' - rm $cachefile +# Remove stale cache entries for users whose authorized_keys no longer exist +find "$CACHEDIR" -name '*.authorized_keys' -type f | while read cachefile; do + remoteuser=$(basename "$cachefile" .authorized_keys) + if [ ! -f "/home/$remoteuser/.ssh/authorized_keys" ]; then + echo "Deleting obsolete cache file $cachefile" + rm "$cachefile" fi done |
