mouseclone

2 factor user authentication via SSH

Sep 23rd, 2015
132
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 7.47 KB | None | 0 0
  1. #!/bin/bash
  2. ## changeable variables
  3. sshusername="username"
  4.  
  5. ## groups to check/add - put ssh user group first - separate with spaces.
  6. groups="group1 group2"
  7.  
  8. ## don't change variables
  9. grouparray=($groups)
  10. today=`date +-%d.%m.%G`
  11.  
  12. ### Functions
  13. ## checking/adding groups
  14. groupcheck () {
  15.     group="$(cat /etc/group | grep ^$1 | awk 'BEGIN{FS=":"};{print $1}')"
  16.     echo "checking for the $1 group"
  17.     if [[ "$1" != $group ]]
  18.         then
  19.             echo "wasn't there; creating"
  20.             groupadd $1
  21.             if [[ "$1" == $(cat /etc/group | grep ^$1 | awk 'BEGIN{FS=":"};{print $1}') ]]
  22.                 then
  23.                     echo "$1 group created"
  24.             fi
  25.         else
  26.             echo "$1 group present"
  27.     fi
  28. }
  29.  
  30. ## replace files
  31. sudoers () {
  32.     ## backup /etc/sudoers
  33.     cp /etc/sudoers /etc/sudoers.bk$today
  34.  
  35.     ## create /etc/sudoers
  36.     echo "Cmnd_Alias EXCEPTIONS = /usr/sbin/visudo, /usr/bin/su, /bin/su, /bin/bash
  37.     Defaults    requiretty
  38.     Defaults   !visiblepw
  39.     Defaults    always_set_home
  40.     Defaults    env_reset
  41.     Defaults    env_keep =  \"COLORS DISPLAY HOSTNAME HISTSIZE INPUTRC KDEDIR LS_COLORS\"
  42.     Defaults    env_keep += \"MAIL PS1 PS2 QTDIR USERNAME LANG LC_ADDRESS LC_CTYPE\"
  43.     Defaults    env_keep += \"LC_COLLATE LC_IDENTIFICATION LC_MEASUREMENT LC_MESSAGES\"
  44.     Defaults    env_keep += \"LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER LC_TELEPHONE\"
  45.     Defaults    env_keep += \"LC_TIME LC_ALL LANGUAGE LINGUAS _XKB_CHARSET XAUTHORITY\"
  46.     Defaults    secure_path = /sbin:/bin:/usr/sbin:/usr/bin
  47.     root    ALL=(ALL)       ALL
  48.     %admin  ALL=(ALL)       ALL,!EXCEPTIONS" > /etc/sudoers
  49. }
  50.  
  51. logindefs () {
  52.     ## backup /etc/login.defs
  53.     cp /etc/login.defs /etc/login.defs.bk$today
  54.  
  55.     ## create /etc/login.defs
  56.     echo "# Please note that the parameters in this configuration file control the
  57.     # behavior of the tools from the shadow-utils component. None of these
  58.     # tools uses the PAM mechanism, and the utilities that use PAM (such as the
  59.     # passwd command) should therefore be configured elsewhere. Refer to
  60.     # /etc/pam.d/system-auth for more information.
  61.     # *REQUIRED*
  62.     #   Directory where mailboxes reside, _or_ name of file, relative to the
  63.     #   home directory.  If you _do_ define both, MAIL_DIR takes precedence.
  64.     #   QMAIL_DIR is for Qmail
  65.     #QMAIL_DIR      Maildir
  66.     MAIL_DIR        /var/spool/mail
  67.     #MAIL_FILE      .mail
  68.     # Password aging controls:
  69.     #       PASS_MAX_DAYS   Maximum number of days a password may be used.
  70.     #       PASS_MIN_DAYS   Minimum number of days allowed between password changes.
  71.     #       PASS_MIN_LEN    Minimum acceptable password length.
  72.     #       PASS_WARN_AGE   Number of days warning given before a password expires.
  73.     PASS_MAX_DAYS   90
  74.     PASS_MIN_DAYS   0
  75.     PASS_MIN_LEN    8
  76.     PASS_WARN_AGE   15
  77.     # Min/max values for automatic uid selection in useradd
  78.     UID_MIN                   500
  79.     UID_MAX                 60000
  80.     # Min/max values for automatic gid selection in groupadd
  81.     GID_MIN                   500
  82.     GID_MAX                 60000
  83.     # If defined, this command is run when removing a user.
  84.     # It should remove any at/cron/print jobs etc. owned by
  85.     # the user to be removed (passed as the first argument).
  86.     #USERDEL_CMD    /usr/sbin/userdel_local
  87.     # If useradd should create home directories for users by default
  88.     # On RH systems, we do. This option is overridden with the -m flag on
  89.     # useradd command line.
  90.     CREATE_HOME     yes
  91.     # The permission mask is initialized to this value. If not specified,
  92.     # the permission mask will be initialized to 022.
  93.     UMASK           077
  94.     # This enables userdel to remove user groups if no members exist.
  95.     #
  96.     USERGROUPS_ENAB yes
  97.     # Use SHA512 to encrypt password.
  98.     ENCRYPT_METHOD MD5
  99.     MD5_CRYPT_ENAB yes" > /etc/login.defs
  100. }
  101.  
  102. pamsshd () {
  103.     ## backup /etc/pam.d/sshd
  104.     cp /etc/pam.d/sshd /etc/pam.d/sshd.bk$today
  105.  
  106.     ## create /etc/pam.d/sshd
  107.     echo "#%PAM-1.0
  108.     # Uncomment this line to deny sshd
  109.     #auth      requisite    pam_deny.so
  110.     auth       required     pam_sepermit.so
  111.     auth       include      password-auth
  112.     account    required     pam_nologin.so
  113.     account    include      password-auth
  114.     password   include      password-auth
  115.     # pam_selinux.so close should be the first session rule
  116.     session    required     pam_selinux.so close
  117.     session    required     pam_loginuid.so
  118.     # pam_selinux.so open should only be followed by sessions to be executed in the user context
  119.     session    required     pam_selinux.so open env_params
  120.     session    optional     pam_keyinit.so force revoke
  121.     session    include      password-auth" > /etc/pam.d/sshd
  122. }
  123.  
  124. pamsystemauth () {
  125.     ## backup /etc/pam.d/system-auth
  126.     cp /etc/pam.d/system-auth /etc/pam.d/system-auth.bk$today
  127.  
  128.     ## create /etc/pam.d/system-auth
  129.     echo "#%PAM-1.0
  130.     # This file is auto-generated.
  131.     auth        required      pam_env.so
  132.     auth        sufficient    pam_unix.so nullok try_first_pass
  133.     auth        requisite     pam_succeed_if.so uid >= 500 quiet
  134.     auth        required      pam_deny.so
  135.  
  136.     account     required      pam_unix.so
  137.     account     sufficient    pam_localuser.so
  138.     account     sufficient    pam_succeed_if.so uid < 500 quiet
  139.     account     required      pam_permit.so
  140.  
  141.     password requisite pam_passwdqc.so min=disabled,disabled,16,12,8 disable_firstupper_lastdigit_check
  142.     password    sufficient    pam_unix.so sha512 shadow try_first_pass use_authtok remember=5
  143.     password    required      pam_deny.so
  144.  
  145.     session     optional      pam_keyinit.so revoke
  146.     session     required      pam_limits.so
  147.     session     [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
  148.     session     required      pam_unix.so" > /etc/pam.d/system-auth
  149. }
  150.  
  151. sshconfig () {
  152.     ## backup /etc/ssh/ssh_config
  153.     cp /etc/ssh/ssh_config /etc/ssh/ssh_config.bk$today
  154.  
  155.     ## create /etc/ssh/ssh_config
  156.     echo "Host *
  157.             GSSAPIAuthentication yes
  158.             SendEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES
  159.             SendEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT
  160.             SendEnv LC_IDENTIFICATION LC_ALL LANGUAGE
  161.             SendEnv XMODIFIERS" > /etc/ssh/ssh_config
  162.  
  163.     ## backup /etc/ssh/sshd_config
  164.     cp /etc/ssh/sshd_config /etc/ssh/sshd_config.bk
  165. }
  166.  
  167. sshdconfig () {
  168.     ## backup /etc/ssh/sshd_config
  169.     cp /etc/ssh/sshd_config /etc/ssh/sshd_config.bk$today
  170.    
  171.     ## create /etc/ssh/sshd_config
  172.     echo "Protocol 2
  173.     SyslogFacility AUTHPRIV
  174.     LogLevel VERBOSE
  175.     PermitRootLogin no
  176.     MaxAuthTries 4
  177.     AllowGroups sshusers
  178.     HostbasedAuthentication no
  179.     IgnoreRhosts yes
  180.     PermitEmptyPasswords no
  181.     PasswordAuthentication yes
  182.     ChallengeResponseAuthentication no
  183.     GSSAPIAuthentication yes
  184.     GSSAPICleanupCredentials yes
  185.     UsePAM yes
  186.     AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES
  187.     AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT
  188.     AcceptEnv LC_IDENTIFICATION LC_ALL LANGUAGE
  189.     AcceptEnv XMODIFIERS
  190.     X11Forwarding no
  191.     PermitUserEnvironment no
  192.     ClientAliveInterval 1800
  193.     ClientAliveCountMax 0
  194.     Banner /etc/issue
  195.     Subsystem       sftp    /usr/libexec/openssh/sftp-server" > /etc/ssh/sshd_config
  196. }
  197.  
  198. ## call the replace file functions
  199. sudoers
  200. logindefs
  201. pamsshd
  202. pamsystemauth
  203. sshconfig
  204. sshdconfig
  205.  
  206. ## check groups and users
  207. for i in `echo ${grouparray[@]}`; do
  208.     groupcheck $i;
  209. done
  210.  
  211.  
  212. ## check if $sshusername user exist if not create
  213. sshuser=`cat /etc/passwd | grep ^$sshusername | awk 'BEGIN{FS=":"};{print $1}'`
  214. echo "checking for sshuser user"
  215. if [[ "$sshusername" != $sshuser ]]
  216.     then
  217.         echo "wasn't there; creating"
  218.         useradd -G ${grouparray[0]} $sshusername
  219. elif [[ "$sshusername" == $sshuser ]]
  220.     then
  221.         echo "was there; adding to sshusers group"
  222.         usermod -a -G sshusers $sshusername
  223. fi
Advertisement
Add Comment
Please, Sign In to add comment