Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #!/bin/bash
- ## changeable variables
- sshusername="username"
- ## groups to check/add - put ssh user group first - separate with spaces.
- groups="group1 group2"
- ## don't change variables
- grouparray=($groups)
- today=`date +-%d.%m.%G`
- ### Functions
- ## checking/adding groups
- groupcheck () {
- group="$(cat /etc/group | grep ^$1 | awk 'BEGIN{FS=":"};{print $1}')"
- echo "checking for the $1 group"
- if [[ "$1" != $group ]]
- then
- echo "wasn't there; creating"
- groupadd $1
- if [[ "$1" == $(cat /etc/group | grep ^$1 | awk 'BEGIN{FS=":"};{print $1}') ]]
- then
- echo "$1 group created"
- fi
- else
- echo "$1 group present"
- fi
- }
- ## replace files
- sudoers () {
- ## backup /etc/sudoers
- cp /etc/sudoers /etc/sudoers.bk$today
- ## create /etc/sudoers
- echo "Cmnd_Alias EXCEPTIONS = /usr/sbin/visudo, /usr/bin/su, /bin/su, /bin/bash
- Defaults requiretty
- Defaults !visiblepw
- Defaults always_set_home
- Defaults env_reset
- Defaults env_keep = \"COLORS DISPLAY HOSTNAME HISTSIZE INPUTRC KDEDIR LS_COLORS\"
- Defaults env_keep += \"MAIL PS1 PS2 QTDIR USERNAME LANG LC_ADDRESS LC_CTYPE\"
- Defaults env_keep += \"LC_COLLATE LC_IDENTIFICATION LC_MEASUREMENT LC_MESSAGES\"
- Defaults env_keep += \"LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER LC_TELEPHONE\"
- Defaults env_keep += \"LC_TIME LC_ALL LANGUAGE LINGUAS _XKB_CHARSET XAUTHORITY\"
- Defaults secure_path = /sbin:/bin:/usr/sbin:/usr/bin
- root ALL=(ALL) ALL
- %admin ALL=(ALL) ALL,!EXCEPTIONS" > /etc/sudoers
- }
- logindefs () {
- ## backup /etc/login.defs
- cp /etc/login.defs /etc/login.defs.bk$today
- ## create /etc/login.defs
- echo "# Please note that the parameters in this configuration file control the
- # behavior of the tools from the shadow-utils component. None of these
- # tools uses the PAM mechanism, and the utilities that use PAM (such as the
- # passwd command) should therefore be configured elsewhere. Refer to
- # /etc/pam.d/system-auth for more information.
- # *REQUIRED*
- # Directory where mailboxes reside, _or_ name of file, relative to the
- # home directory. If you _do_ define both, MAIL_DIR takes precedence.
- # QMAIL_DIR is for Qmail
- #QMAIL_DIR Maildir
- MAIL_DIR /var/spool/mail
- #MAIL_FILE .mail
- # Password aging controls:
- # PASS_MAX_DAYS Maximum number of days a password may be used.
- # PASS_MIN_DAYS Minimum number of days allowed between password changes.
- # PASS_MIN_LEN Minimum acceptable password length.
- # PASS_WARN_AGE Number of days warning given before a password expires.
- PASS_MAX_DAYS 90
- PASS_MIN_DAYS 0
- PASS_MIN_LEN 8
- PASS_WARN_AGE 15
- # Min/max values for automatic uid selection in useradd
- UID_MIN 500
- UID_MAX 60000
- # Min/max values for automatic gid selection in groupadd
- GID_MIN 500
- GID_MAX 60000
- # If defined, this command is run when removing a user.
- # It should remove any at/cron/print jobs etc. owned by
- # the user to be removed (passed as the first argument).
- #USERDEL_CMD /usr/sbin/userdel_local
- # If useradd should create home directories for users by default
- # On RH systems, we do. This option is overridden with the -m flag on
- # useradd command line.
- CREATE_HOME yes
- # The permission mask is initialized to this value. If not specified,
- # the permission mask will be initialized to 022.
- UMASK 077
- # This enables userdel to remove user groups if no members exist.
- #
- USERGROUPS_ENAB yes
- # Use SHA512 to encrypt password.
- ENCRYPT_METHOD MD5
- MD5_CRYPT_ENAB yes" > /etc/login.defs
- }
- pamsshd () {
- ## backup /etc/pam.d/sshd
- cp /etc/pam.d/sshd /etc/pam.d/sshd.bk$today
- ## create /etc/pam.d/sshd
- echo "#%PAM-1.0
- # Uncomment this line to deny sshd
- #auth requisite pam_deny.so
- auth required pam_sepermit.so
- auth include password-auth
- account required pam_nologin.so
- account include password-auth
- password include password-auth
- # pam_selinux.so close should be the first session rule
- session required pam_selinux.so close
- session required pam_loginuid.so
- # pam_selinux.so open should only be followed by sessions to be executed in the user context
- session required pam_selinux.so open env_params
- session optional pam_keyinit.so force revoke
- session include password-auth" > /etc/pam.d/sshd
- }
- pamsystemauth () {
- ## backup /etc/pam.d/system-auth
- cp /etc/pam.d/system-auth /etc/pam.d/system-auth.bk$today
- ## create /etc/pam.d/system-auth
- echo "#%PAM-1.0
- # This file is auto-generated.
- auth required pam_env.so
- auth sufficient pam_unix.so nullok try_first_pass
- auth requisite pam_succeed_if.so uid >= 500 quiet
- auth required pam_deny.so
- account required pam_unix.so
- account sufficient pam_localuser.so
- account sufficient pam_succeed_if.so uid < 500 quiet
- account required pam_permit.so
- password requisite pam_passwdqc.so min=disabled,disabled,16,12,8 disable_firstupper_lastdigit_check
- password sufficient pam_unix.so sha512 shadow try_first_pass use_authtok remember=5
- password required pam_deny.so
- session optional pam_keyinit.so revoke
- session required pam_limits.so
- session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
- session required pam_unix.so" > /etc/pam.d/system-auth
- }
- sshconfig () {
- ## backup /etc/ssh/ssh_config
- cp /etc/ssh/ssh_config /etc/ssh/ssh_config.bk$today
- ## create /etc/ssh/ssh_config
- echo "Host *
- GSSAPIAuthentication yes
- SendEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES
- SendEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT
- SendEnv LC_IDENTIFICATION LC_ALL LANGUAGE
- SendEnv XMODIFIERS" > /etc/ssh/ssh_config
- ## backup /etc/ssh/sshd_config
- cp /etc/ssh/sshd_config /etc/ssh/sshd_config.bk
- }
- sshdconfig () {
- ## backup /etc/ssh/sshd_config
- cp /etc/ssh/sshd_config /etc/ssh/sshd_config.bk$today
- ## create /etc/ssh/sshd_config
- echo "Protocol 2
- SyslogFacility AUTHPRIV
- LogLevel VERBOSE
- PermitRootLogin no
- MaxAuthTries 4
- AllowGroups sshusers
- HostbasedAuthentication no
- IgnoreRhosts yes
- PermitEmptyPasswords no
- PasswordAuthentication yes
- ChallengeResponseAuthentication no
- GSSAPIAuthentication yes
- GSSAPICleanupCredentials yes
- UsePAM yes
- AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES
- AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT
- AcceptEnv LC_IDENTIFICATION LC_ALL LANGUAGE
- AcceptEnv XMODIFIERS
- X11Forwarding no
- PermitUserEnvironment no
- ClientAliveInterval 1800
- ClientAliveCountMax 0
- Banner /etc/issue
- Subsystem sftp /usr/libexec/openssh/sftp-server" > /etc/ssh/sshd_config
- }
- ## call the replace file functions
- sudoers
- logindefs
- pamsshd
- pamsystemauth
- sshconfig
- sshdconfig
- ## check groups and users
- for i in `echo ${grouparray[@]}`; do
- groupcheck $i;
- done
- ## check if $sshusername user exist if not create
- sshuser=`cat /etc/passwd | grep ^$sshusername | awk 'BEGIN{FS=":"};{print $1}'`
- echo "checking for sshuser user"
- if [[ "$sshusername" != $sshuser ]]
- then
- echo "wasn't there; creating"
- useradd -G ${grouparray[0]} $sshusername
- elif [[ "$sshusername" == $sshuser ]]
- then
- echo "was there; adding to sshusers group"
- usermod -a -G sshusers $sshusername
- fi
Advertisement
Add Comment
Please, Sign In to add comment