Adapt host configuration
Adapt the configuration of the test hosts to the new Debian-based system.
This commit is contained in:
committed by
Tobias Brunner
parent
108040800d
commit
766466b8d1
@@ -0,0 +1 @@
|
||||
AddType text/plain .iptables .log .sql
|
||||
@@ -1,22 +0,0 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDtTCCAp2gAwIBAgIBADANBgkqhkiG9w0BAQQFADBFMQswCQYDVQQGEwJDSDEZ
|
||||
MBcGA1UEChMQTGludXggc3Ryb25nU3dhbjEbMBkGA1UEAxMSc3Ryb25nU3dhbiBS
|
||||
b290IENBMB4XDTA0MDkxMDExMDE0NVoXDTE0MDkwODExMDE0NVowRTELMAkGA1UE
|
||||
BhMCQ0gxGTAXBgNVBAoTEExpbnV4IHN0cm9uZ1N3YW4xGzAZBgNVBAMTEnN0cm9u
|
||||
Z1N3YW4gUm9vdCBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL/y
|
||||
X2LqPVZuWLPIeknK86xhz6ljd3NNhC2z+P1uoCP3sBMuZiZQEjFzhnKcbXxCeo2f
|
||||
FnvhOOjrrisSuVkzuu82oxXD3fIkzuS7m9V4E10EZzgmKWIf+WuNRfbgAuUINmLc
|
||||
4YGAXBQLPyzpP4Ou48hhz/YQo58Bics6PHy5v34qCVROIXDvqhj91P8g+pS+F21/
|
||||
7P+CH2jRcVIEHZtG8M/PweTPQ95dPzpYd2Ov6SZ/U7EWmbMmT8VcUYn1aChxFmy5
|
||||
gweVBWlkH6MP+1DeE0/tL5c87xo5KCeGK8Tdqpe7sBRC4pPEEHDQciTUvkeuJ1Pr
|
||||
K+1LwdqRxo7HgMRiDw8CAwEAAaOBrzCBrDAPBgNVHRMBAf8EBTADAQH/MAsGA1Ud
|
||||
DwQEAwIBBjAdBgNVHQ4EFgQUXafdcAZRMn7ntm2zteXgYOouTe8wbQYDVR0jBGYw
|
||||
ZIAUXafdcAZRMn7ntm2zteXgYOouTe+hSaRHMEUxCzAJBgNVBAYTAkNIMRkwFwYD
|
||||
VQQKExBMaW51eCBzdHJvbmdTd2FuMRswGQYDVQQDExJzdHJvbmdTd2FuIFJvb3Qg
|
||||
Q0GCAQAwDQYJKoZIhvcNAQEEBQADggEBAJrXTj5gWS37myHHhii9drYwkMFyDHS/
|
||||
lHU8rW/drcnHdus507+qUhNr9SiEAHg4Ywj895UDvT0a1sFaw44QyEa/94iKA8/n
|
||||
+g5kS1IrKvWu3wu8UI3EgzChgHV3cncQlQWbK+FI9Y3Ax1O1np1r+wLptoWpKKKE
|
||||
UxsYcxP9K4Nbyeon0AIHOajUheiL3t6aRc3m0o7VU7Do6S2r+He+1Zq/nRUfFeTy
|
||||
0Atebkn8tmUpPSKWaXkmwpVNrjZ1Qu9umAU+dtJyhzL2zmnyhPC4VqpsKCOp7imy
|
||||
gKZvUIKPm1zyf4T+yjwxwkiX2xVseoM3aKswb1EoZFelHwndU7u0GQ8=
|
||||
-----END CERTIFICATE-----
|
||||
@@ -1,24 +0,0 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIEFTCCAv2gAwIBAgIBDjANBgkqhkiG9w0BAQQFADBFMQswCQYDVQQGEwJDSDEZ
|
||||
MBcGA1UEChMQTGludXggc3Ryb25nU3dhbjEbMBkGA1UEAxMSc3Ryb25nU3dhbiBS
|
||||
b290IENBMB4XDTA1MDYwODE5MTcxNFoXDTEwMDYwNzE5MTcxNFowSjELMAkGA1UE
|
||||
BhMCQ0gxGTAXBgNVBAoTEExpbnV4IHN0cm9uZ1N3YW4xIDAeBgNVBAMTF3dpbm5l
|
||||
dG91LnN0cm9uZ3N3YW4ub3JnMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
|
||||
AQEAwBkz95BmByWVZaEW8cDbeuGr4C1caGAj4QPmuwaIriK+7XqXuh16Ahe3S5vZ
|
||||
F56WhUSvMDOIyULckKH84oSa3Jx/SCz0g7X42x8vZuq92tpsjcP/u7BlyqpBUtLa
|
||||
r14qm5wYw/1nQqMcSG3k9MQOQ+e9KgaGqpidxWM/8T4M/41AaFRBK2gQGBUULo26
|
||||
sjoq3af7Z2jYmWkP/kzj1CHLy9Mgt+UvhKeA+ag5cZnyOG596cqVjlKyqG7vdggk
|
||||
wW2n+/KDpHNOndYfT7GMFeGXUNzJPkCImWlttic7ssi0mjP3q3MuOP3FNHIRMd2H
|
||||
AcNcqT0bgdJHqnNzGv8C0Ei9XQIDAQABo4IBCTCCAQUwCQYDVR0TBAIwADALBgNV
|
||||
HQ8EBAMCA6gwHQYDVR0OBBYEFEMS0mbhrA4zDvmfKf4MntUNxkH4MG0GA1UdIwRm
|
||||
MGSAFF2n3XAGUTJ+57Zts7Xl4GDqLk3voUmkRzBFMQswCQYDVQQGEwJDSDEZMBcG
|
||||
A1UEChMQTGludXggc3Ryb25nU3dhbjEbMBkGA1UEAxMSc3Ryb25nU3dhbiBSb290
|
||||
IENBggEAMCIGA1UdEQQbMBmCF3dpbm5ldG91LnN0cm9uZ3N3YW4ub3JnMDkGA1Ud
|
||||
HwQyMDAwLqAsoCqGKGh0dHA6Ly9jcmwuc3Ryb25nc3dhbi5vcmcvc3Ryb25nc3dh
|
||||
bi5jcmwwDQYJKoZIhvcNAQEEBQADggEBACO4+j1Mwt/lbkopeSJst46uFh7OtegG
|
||||
6IWNE30i3l3FIn9slSwAOMtmZR0hAF8sExvk61EPlzCR/d9trSJ5+gyjPkeF/enw
|
||||
p61rxPMT13Grzomi9gYlk6Q/0zLmE9uYWEY69Q0bEIUcfdZfwB+F7kesa946JNMc
|
||||
yHfVEhKtvzmns9ueG0S/8E+6MPDeJv+JHQ++SdWSvOVg6JNxXDGusnim2fjM2Aln
|
||||
JmqA6iU4IaPl9DUCuXlLOVv/YhwhviNEbF94upyHq8xjOZdzPbKroHXg/2yvalAw
|
||||
4aXc/ZsnFxqsq3i6a2Fj1Y4J7gYsNO/HwA0xvKz3loOTqHaJqO/qeow=
|
||||
-----END CERTIFICATE-----
|
||||
@@ -1,27 +0,0 @@
|
||||
-----BEGIN RSA PRIVATE KEY-----
|
||||
MIIEpAIBAAKCAQEAwBkz95BmByWVZaEW8cDbeuGr4C1caGAj4QPmuwaIriK+7XqX
|
||||
uh16Ahe3S5vZF56WhUSvMDOIyULckKH84oSa3Jx/SCz0g7X42x8vZuq92tpsjcP/
|
||||
u7BlyqpBUtLar14qm5wYw/1nQqMcSG3k9MQOQ+e9KgaGqpidxWM/8T4M/41AaFRB
|
||||
K2gQGBUULo26sjoq3af7Z2jYmWkP/kzj1CHLy9Mgt+UvhKeA+ag5cZnyOG596cqV
|
||||
jlKyqG7vdggkwW2n+/KDpHNOndYfT7GMFeGXUNzJPkCImWlttic7ssi0mjP3q3Mu
|
||||
OP3FNHIRMd2HAcNcqT0bgdJHqnNzGv8C0Ei9XQIDAQABAoIBACYiWrCgl8B/c4Lz
|
||||
Uay4Tlm8hvQ/zQJjY3v93EXwbB21hBV8qrYlt9zGfHqj+5q2vsbB9c0pzdO2VDba
|
||||
EWueS2fUIWhglEG5VCebrztNCldx2O7jo9bMk8iBt+oLNaJunSK7ACeYHHGcE7dF
|
||||
KZh1eyd7z4+SMBWZqmhO5ZisasQoHCusVGepcyyMGQNkc3XKJ6resGAsOqrOoq7Q
|
||||
C4vO5Kkbnk8nnEGmQ/ldD8LwIyq1hzVLDiiqWXZgh6S5l4BEo7Dy3KYrZoZfVcZK
|
||||
GMVhAI2+uA1ZqY9twpwryT6VZ3eK4DXF/COQntiBW5pLOpaqTOnKqiVmZFwfbo3u
|
||||
cq8n5jkCgYEA5zgzRLifbM0q34c2HX8pTegh+BH7MGCxtcoU2uRPaXiGkqQObHI9
|
||||
aItrgUQp+pAmKSBnEWJKgKsOh2Uf5ogjIeNuruGG/AXw/Pw2ORHNueenhDuhu69T
|
||||
E2I4yxT3PPYbdzJ4ylBElfgm9WTrv7Wi7wSSfgQ6rEFdWukXa5vvsqMCgYEA1K+q
|
||||
m1Jv9MGVIVc6MxhuOOj2Ym+qcWt/Pjvg78rR8SRsKwHlGTuv1rdWUSXYDr3f2Nf7
|
||||
6DdbJtaSx5f8gY/UG34yGZx5FFbYV03vcCYBaLXsi/b6H7vb/VW74Y5g6bXqnprv
|
||||
4mcdVU7xfyNFgdbLPAP9sYVLijPYDwm0Qq3cz/8CgYBKSJz4BBR8AQI4JBl3qoXb
|
||||
mKtpJmW76iTN0amXlWgJ64XYkMptftpJvxj/w6V08WDBL77NL/XdlpcpWozAJJac
|
||||
6ZOCrcQPLd15eZH2Dck5Y7pG2l2gjbgz7wdt/0NbG3pBdj6mSNlwEPR7PDwdMD6z
|
||||
aZWi1LsA4lMaxO4YTVXZ3wKBgQCoFhTNH/+e/YawjNFQJFSn4WUnMn0Pmhc7xfLl
|
||||
T/NPkqtx6dN3d7ZmCQrMow33yJOqOje5tFXzgc0KtNE4S8Uj3T4XA5SlQGVFyjAa
|
||||
/85JRM2naA8RGVSpCCKuBeoNilnb8zL2SOvjyboN8oAyNuDzk2vh6ihjFsoASHkP
|
||||
4XwLXQKBgQC0k6rzt/plIwEiP56XXOqwOxJj6kuE/hx1zGIiGT6lWiOsih20Ym2T
|
||||
kYegVFvuDIWmSIAxGONWyee1lfnJbEuaHRixWQTnHUpqrU0FSnZTubnR3q/faZat
|
||||
hrvLDdpa0ydAKoMEn3qUPSrh3CdBfi3KTQAQn2Mlk7bGHh9ICWi3vA==
|
||||
-----END RSA PRIVATE KEY-----
|
||||
@@ -1,61 +0,0 @@
|
||||
# DefaultType: the default MIME type the server will use for a document
|
||||
# if it cannot otherwise determine one, such as from filename extensions.
|
||||
# If your server contains mostly text or HTML documents, "text/plain" is
|
||||
# a good value. If most of your content is binary, such as applications
|
||||
# or images, you may want to use "application/octet-stream" instead to
|
||||
# keep browsers from trying to display binary files as though they are
|
||||
# text.
|
||||
DefaultType text/plain
|
||||
|
||||
<IfModule mime_module>
|
||||
# TypesConfig points to the file containing the list of mappings from
|
||||
# filename extension to MIME-type.
|
||||
TypesConfig /etc/mime.types
|
||||
|
||||
# AddType allows you to add to or override the MIME configuration
|
||||
# file specified in TypesConfig for specific file types.
|
||||
#AddType application/x-gzip .tgz
|
||||
|
||||
# AddEncoding allows you to have certain browsers uncompress
|
||||
# information on the fly. Note: Not all browsers support this.
|
||||
#AddEncoding x-compress .Z
|
||||
#AddEncoding x-gzip .gz .tgz
|
||||
|
||||
# If the AddEncoding directives above are commented-out, then you
|
||||
# probably should define those extensions to indicate media types:
|
||||
AddType application/x-compress .Z
|
||||
AddType application/x-gzip .gz .tgz
|
||||
|
||||
# AddHandler allows you to map certain file extensions to "handlers":
|
||||
# actions unrelated to filetype. These can be either built into the server
|
||||
# or added with the Action directive (see below)
|
||||
|
||||
# To use CGI scripts outside of ScriptAliased directories:
|
||||
# (You will also need to add "ExecCGI" to the "Options" directive.)
|
||||
AddHandler cgi-script .cgi
|
||||
|
||||
# For files that include their own HTTP headers:
|
||||
#AddHandler send-as-is asis
|
||||
|
||||
# For server-parsed imagemap files:
|
||||
#AddHandler imap-file map
|
||||
|
||||
# For type maps (negotiated resources):
|
||||
AddHandler type-map var
|
||||
|
||||
# Filters allow you to process content before it is sent to the client.
|
||||
#
|
||||
# To parse .shtml files for server-side includes (SSI):
|
||||
# (You will also need to add "Includes" to the "Options" directive.)
|
||||
#AddType text/html .shtml
|
||||
#AddOutputFilter INCLUDES .shtml
|
||||
</IfModule>
|
||||
|
||||
<IfModule mime_magic_module>
|
||||
# The mod_mime_magic module allows the server to use various hints from the
|
||||
# contents of the file itself to determine its type. The MIMEMagicFile
|
||||
# directive tells the module where the hint definitions are located.
|
||||
MIMEMagicFile /etc/apache2/magic
|
||||
</IfModule>
|
||||
|
||||
# vim: ts=4 filetype=apache
|
||||
+2
@@ -2,6 +2,8 @@
|
||||
|
||||
Listen 8880
|
||||
|
||||
AddHandler cgi-script .cgi
|
||||
|
||||
<VirtualHost *:8880>
|
||||
ServerAdmin [email protected]
|
||||
DocumentRoot /etc/openssl/ocsp
|
||||
@@ -1 +0,0 @@
|
||||
HOSTNAME=winnetou
|
||||
@@ -1,10 +0,0 @@
|
||||
# /etc/conf.d/net:
|
||||
|
||||
# This is basically the ifconfig argument without the ifconfig $iface
|
||||
#
|
||||
config_eth0=( "PH_IP_WINNETOU broadcast 192.168.0.255 netmask 255.255.255.0"
|
||||
"PH_IP6_WINNETOU/16" )
|
||||
|
||||
# For setting the default gateway
|
||||
#
|
||||
routes_eth0=( "default via 192.168.0.254" )
|
||||
@@ -1,8 +0,0 @@
|
||||
# conf.d file for the openldap-2.1 series
|
||||
#
|
||||
# To enable both the standard unciphered server and the ssl encrypted
|
||||
# one uncomment this line or set any other server starting options
|
||||
# you may desire.
|
||||
#
|
||||
# OPTS="-h 'ldaps:// ldap:// ldapi://%2fvar%2frun%2fopenldap%2fslapd.sock'"
|
||||
OPTS="-4"
|
||||
@@ -1,121 +0,0 @@
|
||||
#!/sbin/runscript
|
||||
# Copyright 1999-2007 Gentoo Foundation
|
||||
# Distributed under the terms of the GNU General Public License v2
|
||||
|
||||
opts="configtest fullstatus graceful gracefulstop modules reload"
|
||||
|
||||
depend() {
|
||||
need net
|
||||
use mysql dns logger netmount postgresql
|
||||
after sshd
|
||||
}
|
||||
|
||||
configtest() {
|
||||
ebegin "Checking Apache Configuration"
|
||||
checkconfig
|
||||
eend $?
|
||||
}
|
||||
|
||||
checkconfig() {
|
||||
SERVERROOT="${SERVERROOT:-/usr/lib/apache2}"
|
||||
if [ ! -d ${SERVERROOT} ]; then
|
||||
eerror "SERVERROOT does not exist: ${SERVERROOT}"
|
||||
return 1
|
||||
fi
|
||||
|
||||
CONFIGFILE="${CONFIGFILE:-/etc/apache2/httpd.conf}"
|
||||
[ "${CONFIGFILE#/}" = "${CONFIGFILE}" ] && CONFIGFILE="${SERVERROOT}/${CONFIGFILE}"
|
||||
if [ ! -r "${CONFIGFILE}" ]; then
|
||||
eerror "Unable to read configuration file: ${CONFIGFILE}"
|
||||
return 1
|
||||
fi
|
||||
|
||||
APACHE2_OPTS="${APACHE2_OPTS} -d ${SERVERROOT}"
|
||||
APACHE2_OPTS="${APACHE2_OPTS} -f ${CONFIGFILE}"
|
||||
[ -n "${STARTUPERRORLOG}" ] && APACHE2_OPTS="${APACHE2_OPTS} -E ${STARTUPERRORLOG}"
|
||||
|
||||
APACHE2="/usr/sbin/apache2"
|
||||
|
||||
${APACHE2} ${APACHE2_OPTS} -t 1>/dev/null 2>&1
|
||||
ret=$?
|
||||
if [ $ret -ne 0 ]; then
|
||||
eerror "Apache2 has detected a syntax error in your configuration files:"
|
||||
${APACHE2} ${APACHE2_OPTS} -t
|
||||
fi
|
||||
|
||||
return $ret
|
||||
}
|
||||
|
||||
start() {
|
||||
checkconfig || return 1
|
||||
ebegin "Starting apache2"
|
||||
[ -f /var/log/apache2/ssl_scache ] && rm /var/log/apache2/ssl_scache
|
||||
|
||||
start-stop-daemon --start --exec ${APACHE2} -- ${APACHE2_OPTS} -k start
|
||||
eend $?
|
||||
}
|
||||
|
||||
stop() {
|
||||
checkconfig || return 1
|
||||
ebegin "Stopping apache2"
|
||||
start-stop-daemon --stop --retry -TERM/5/-KILL/5 --exec ${APACHE2} --pidfile /var/run/apache2.pid
|
||||
eend $?
|
||||
}
|
||||
|
||||
reload() {
|
||||
RELOAD_TYPE="${RELOAD_TYPE:-graceful}"
|
||||
|
||||
checkconfig || return 1
|
||||
if [ "${RELOAD_TYPE}" = "restart" ]; then
|
||||
ebegin "Restarting apache2"
|
||||
start-stop-daemon --stop --oknodo --signal HUP --exec ${APACHE2} --pidfile /var/run/apache2.pid
|
||||
eend $?
|
||||
elif [ "${RELOAD_TYPE}" = "graceful" ]; then
|
||||
ebegin "Gracefully restarting apache2"
|
||||
start-stop-daemon --stop --oknodo --signal USR1 --exec ${APACHE2} --pidfile /var/run/apache2.pid
|
||||
eend $?
|
||||
else
|
||||
eerror "${RELOAD_TYPE} is not a valid RELOAD_TYPE. Please edit /etc/conf.d/apache2"
|
||||
fi
|
||||
}
|
||||
|
||||
graceful() {
|
||||
checkconfig || return 1
|
||||
ebegin "Gracefully restarting apache2"
|
||||
start-stop-daemon --stop --signal USR1 --exec ${APACHE2} --pidfile /var/run/apache2.pid
|
||||
eend $?
|
||||
}
|
||||
|
||||
gracefulstop() {
|
||||
checkconfig || return 1
|
||||
|
||||
# zap!
|
||||
if service_started "${myservice}"; then
|
||||
mark_service_stopped "${myservice}"
|
||||
fi
|
||||
|
||||
ebegin "Gracefully stopping apache2"
|
||||
# 28 is SIGWINCH
|
||||
start-stop-daemon --stop --signal 28 --exec ${APACHE2} --pidfile /var/run/apache2.pid
|
||||
eend $?
|
||||
}
|
||||
|
||||
modules() {
|
||||
checkconfig || return 1
|
||||
|
||||
${APACHE2} ${APACHE2_OPTS} -M 2>&1
|
||||
}
|
||||
|
||||
status() {
|
||||
LYNX="${LYNX:-lynx -dump}"
|
||||
STATUSURL="${STATUSURL:-http://localhost/server-status}"
|
||||
|
||||
${LYNX} ${STATUSURL} | awk ' /process$/ { print; exit } { print } '
|
||||
}
|
||||
|
||||
fullstatus() {
|
||||
LYNX="${LYNX:-lynx -dump}"
|
||||
STATUSURL="${STATUSURL:-http://localhost/server-status}"
|
||||
|
||||
${LYNX} ${STATUSURL}
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -1,25 +0,0 @@
|
||||
#!/sbin/runscript
|
||||
# Copyright 1999-2004 Gentoo Foundation
|
||||
# Distributed under the terms of the GNU General Public License v2
|
||||
# $Header: /var/cvsroot/strongswan/testing/hosts/winnetou/etc/init.d/slapd,v 1.2 2005/05/31 14:04:43 as Exp $
|
||||
|
||||
depend() {
|
||||
need net
|
||||
}
|
||||
|
||||
start() {
|
||||
ebegin "Starting ldap-server"
|
||||
eval start-stop-daemon --start --quiet --pidfile /var/run/openldap/slapd.pid --exec /usr/lib/openldap/slapd -- -u ldap -g ldap "${OPTS}"
|
||||
eend $?
|
||||
if [ ! -e /var/lib/openldap-data/objectClass.bdb ]
|
||||
then
|
||||
sleep 5
|
||||
ldapadd -x -D "cn=Manager, o=Linux strongSwan, c=CH" -w tuxmux -f /etc/openldap/ldif.txt
|
||||
fi
|
||||
}
|
||||
|
||||
stop() {
|
||||
ebegin "Stopping ldap-server"
|
||||
start-stop-daemon --stop --signal 2 --quiet --pidfile /var/run/openldap/slapd.pid
|
||||
eend $?
|
||||
}
|
||||
+1
-2
@@ -28,7 +28,7 @@ cACertificate;binary:< file:///etc/openssl/research/researchCert.der
|
||||
|
||||
dn: ou=Sales, o=Linux strongSwan, c=CH
|
||||
objectclass: organizationalUnit
|
||||
ou: Sales
|
||||
ou: Sales
|
||||
|
||||
dn: cn=Sales CA, ou=Sales, o=Linux strongSwan, c=CH
|
||||
objectClass: organizationalRole
|
||||
@@ -37,4 +37,3 @@ objectClass: certificationAuthority
|
||||
authorityRevocationList;binary:< file:///etc/openssl/sales/sales.crl
|
||||
certificateRevocationList;binary:< file:///etc/openssl/sales/sales.crl
|
||||
cACertificate;binary:< file:///etc/openssl/sales/salesCert.der
|
||||
|
||||
@@ -0,0 +1,23 @@
|
||||
#
|
||||
# See slapd.conf(5) for details on configuration options.
|
||||
# This file should NOT be world readable.
|
||||
#
|
||||
|
||||
moduleload back_bdb.la
|
||||
|
||||
include /etc/ldap/schema/core.schema
|
||||
|
||||
pidfile /var/run/openldap/slapd.pid
|
||||
argsfile /var/run/openldap/slapd.args
|
||||
|
||||
#######################################################################
|
||||
# BDB database definitions
|
||||
#######################################################################
|
||||
|
||||
database bdb
|
||||
suffix "o=Linux strongSwan,c=CH"
|
||||
rootdn "cn=Manager,o=Linux strongSwan,c=CH"
|
||||
checkpoint 32 30
|
||||
rootpw tuxmux
|
||||
directory /var/lib/ldap
|
||||
index objectClass eq
|
||||
@@ -0,0 +1,12 @@
|
||||
auto lo
|
||||
iface lo inet loopback
|
||||
|
||||
auto eth0
|
||||
iface eth0 inet static
|
||||
address PH_IP_WINNETOU
|
||||
netmask 255.255.255.0
|
||||
broadcast 192.168.0.255
|
||||
gateway 192.168.0.254
|
||||
iface eth0 inet6 static
|
||||
address PH_IP6_WINNETOU
|
||||
netmask 16
|
||||
@@ -1,68 +0,0 @@
|
||||
#
|
||||
# See slapd.conf(5) for details on configuration options.
|
||||
# This file should NOT be world readable.
|
||||
#
|
||||
include /etc/openldap/schema/core.schema
|
||||
|
||||
# Define global ACLs to disable default read access.
|
||||
|
||||
# Do not enable referrals until AFTER you have a working directory
|
||||
# service AND an understanding of referrals.
|
||||
#referral ldap://root.openldap.org
|
||||
|
||||
pidfile /var/run/openldap/slapd.pid
|
||||
argsfile /var/run/openldap/slapd.args
|
||||
|
||||
# Load dynamic backend modules:
|
||||
# modulepath /usr/lib/openldap/openldap
|
||||
# moduleload back_bdb.la
|
||||
# moduleload back_ldap.la
|
||||
# moduleload back_ldbm.la
|
||||
# moduleload back_passwd.la
|
||||
# moduleload back_shell.la
|
||||
|
||||
# Sample security restrictions
|
||||
# Require integrity protection (prevent hijacking)
|
||||
# Require 112-bit (3DES or better) encryption for updates
|
||||
# Require 63-bit encryption for simple bind
|
||||
# security ssf=1 update_ssf=112 simple_bind=64
|
||||
|
||||
# Sample access control policy:
|
||||
# Root DSE: allow anyone to read it
|
||||
# Subschema (sub)entry DSE: allow anyone to read it
|
||||
# Other DSEs:
|
||||
# Allow self write access
|
||||
# Allow authenticated users read access
|
||||
# Allow anonymous users to authenticate
|
||||
# Directives needed to implement policy:
|
||||
# access to dn.base="" by * read
|
||||
# access to dn.base="cn=Subschema" by * read
|
||||
# access to *
|
||||
# by self write
|
||||
# by users read
|
||||
# by anonymous auth
|
||||
#
|
||||
# if no access controls are present, the default policy
|
||||
# allows anyone and everyone to read anything but restricts
|
||||
# updates to rootdn. (e.g., "access to * by * read")
|
||||
#
|
||||
# rootdn can always read and write EVERYTHING!
|
||||
|
||||
#######################################################################
|
||||
# BDB database definitions
|
||||
#######################################################################
|
||||
|
||||
database bdb
|
||||
suffix "o=Linux strongSwan,c=CH"
|
||||
rootdn "cn=Manager,o=Linux strongSwan,c=CH"
|
||||
checkpoint 32 30 # <kbyte> <min>
|
||||
# Cleartext passwords, especially for the rootdn, should
|
||||
# be avoid. See slappasswd(8) and slapd.conf(5) for details.
|
||||
# Use of strong authentication encouraged.
|
||||
rootpw tuxmux
|
||||
# The database directory MUST exist prior to running slapd AND
|
||||
# should only be accessible by the slapd and slap tools.
|
||||
# Mode 700 recommended.
|
||||
directory /var/lib/openldap-data
|
||||
# Indices to maintain
|
||||
index objectClass eq
|
||||
@@ -16,30 +16,32 @@
|
||||
|
||||
export COMMON_NAME=strongSwan
|
||||
|
||||
ROOT=/var/www
|
||||
|
||||
cd /etc/openssl
|
||||
openssl ca -gencrl -crldays 30 -config /etc/openssl/openssl.cnf -out crl.pem
|
||||
openssl crl -in crl.pem -outform der -out strongswan.crl
|
||||
cp strongswan.crl /var/www/localhost/htdocs/
|
||||
cp strongswanCert.pem /var/www/localhost/htdocs/
|
||||
cp index.html /var/www/localhost/htdocs/
|
||||
cp strongswan.crl ${ROOT}
|
||||
cp strongswanCert.pem ${ROOT}
|
||||
cp index.html ${ROOT}
|
||||
cd /etc/openssl/research
|
||||
openssl ca -gencrl -crldays 15 -config /etc/openssl/research/openssl.cnf -out crl.pem
|
||||
openssl crl -in crl.pem -outform der -out research.crl
|
||||
cp research.crl /var/www/localhost/htdocs/
|
||||
cp research.crl ${ROOT}
|
||||
cd /etc/openssl/sales
|
||||
openssl ca -gencrl -crldays 15 -config /etc/openssl/sales/openssl.cnf -out crl.pem
|
||||
openssl crl -in crl.pem -outform der -out sales.crl
|
||||
cp sales.crl /var/www/localhost/htdocs/
|
||||
cp sales.crl ${ROOT}
|
||||
cd /etc/openssl/ecdsa
|
||||
openssl ca -gencrl -crldays 15 -config /etc/openssl/ecdsa/openssl.cnf -out crl.pem
|
||||
openssl crl -in crl.pem -outform der -out strongswan_ec.crl
|
||||
cp strongswan_ec.crl /var/www/localhost/htdocs/
|
||||
cp strongswan_ec.crl ${ROOT}
|
||||
cd /etc/openssl/monster
|
||||
openssl ca -gencrl -crldays 15 -config /etc/openssl/monster/openssl.cnf -out crl.pem
|
||||
openssl crl -in crl.pem -outform der -out strongswan-monster.crl
|
||||
cp strongswan-monster.crl /var/www/localhost/htdocs/
|
||||
cp strongswan-monster.crl ${ROOT}
|
||||
cd /etc/openssl/rfc3779
|
||||
openssl ca -gencrl -crldays 15 -config /etc/openssl/rfc3779/openssl.cnf -out crl.pem
|
||||
openssl crl -in crl.pem -outform der -out strongswan_rfc3779.crl
|
||||
cp strongswan_rfc3779.crl /var/www/localhost/htdocs/
|
||||
cp strongswan_rfc3779.crl ${ROOT}
|
||||
|
||||
|
||||
@@ -5,7 +5,7 @@ cd /etc/openssl
|
||||
echo "Content-type: application/ocsp-response"
|
||||
echo ""
|
||||
|
||||
/usr/bin/openssl ocsp -index index.txt -CA strongswanCert.pem \
|
||||
-rkey ocspKey.pem -rsigner ocspCert.pem \
|
||||
-nmin 5 \
|
||||
-reqin /dev/stdin -respout /dev/stdout
|
||||
cat | /usr/bin/openssl ocsp -index index.txt -CA strongswanCert.pem \
|
||||
-rkey ocspKey.pem -rsigner ocspCert.pem \
|
||||
-nmin 5 \
|
||||
-reqin /dev/stdin -respout /dev/stdout | cat
|
||||
|
||||
@@ -5,7 +5,7 @@ cd /etc/openssl/research
|
||||
echo "Content-type: application/ocsp-response"
|
||||
echo ""
|
||||
|
||||
/usr/bin/openssl ocsp -index index.txt -CA researchCert.pem \
|
||||
-rkey ocspKey.pem -rsigner ocspCert.pem \
|
||||
-nmin 5 \
|
||||
-reqin /dev/stdin -respout /dev/stdout
|
||||
cat | /usr/bin/openssl ocsp -index index.txt -CA researchCert.pem \
|
||||
-rkey ocspKey.pem -rsigner ocspCert.pem \
|
||||
-nmin 5 \
|
||||
-reqin /dev/stdin -respout /dev/stdout | cat
|
||||
|
||||
@@ -5,7 +5,7 @@ cd /etc/openssl/sales
|
||||
echo "Content-type: application/ocsp-response"
|
||||
echo ""
|
||||
|
||||
/usr/bin/openssl ocsp -index index.txt -CA salesCert.pem \
|
||||
-rkey ocspKey.pem -rsigner ocspCert.pem \
|
||||
-nmin 5 \
|
||||
-reqin /dev/stdin -respout /dev/stdout
|
||||
cat | /usr/bin/openssl ocsp -index index.txt -CA salesCert.pem \
|
||||
-rkey ocspKey.pem -rsigner ocspCert.pem \
|
||||
-nmin 5 \
|
||||
-reqin /dev/stdin -respout /dev/stdout | cat
|
||||
|
||||
@@ -1,121 +0,0 @@
|
||||
#!/sbin/runscript
|
||||
# Copyright 1999-2007 Gentoo Foundation
|
||||
# Distributed under the terms of the GNU General Public License v2
|
||||
|
||||
opts="configtest fullstatus graceful gracefulstop modules reload"
|
||||
|
||||
depend() {
|
||||
need net
|
||||
use mysql dns logger netmount postgresql
|
||||
after sshd
|
||||
}
|
||||
|
||||
configtest() {
|
||||
ebegin "Checking Apache Configuration"
|
||||
checkconfig
|
||||
eend $?
|
||||
}
|
||||
|
||||
checkconfig() {
|
||||
SERVERROOT="${SERVERROOT:-/usr/lib/apache2}"
|
||||
if [ ! -d ${SERVERROOT} ]; then
|
||||
eerror "SERVERROOT does not exist: ${SERVERROOT}"
|
||||
return 1
|
||||
fi
|
||||
|
||||
CONFIGFILE="${CONFIGFILE:-/etc/apache2/httpd.conf}"
|
||||
[ "${CONFIGFILE#/}" = "${CONFIGFILE}" ] && CONFIGFILE="${SERVERROOT}/${CONFIGFILE}"
|
||||
if [ ! -r "${CONFIGFILE}" ]; then
|
||||
eerror "Unable to read configuration file: ${CONFIGFILE}"
|
||||
return 1
|
||||
fi
|
||||
|
||||
APACHE2_OPTS="${APACHE2_OPTS} -d ${SERVERROOT}"
|
||||
APACHE2_OPTS="${APACHE2_OPTS} -f ${CONFIGFILE}"
|
||||
[ -n "${STARTUPERRORLOG}" ] && APACHE2_OPTS="${APACHE2_OPTS} -E ${STARTUPERRORLOG}"
|
||||
|
||||
APACHE2="/usr/sbin/apache2"
|
||||
|
||||
${APACHE2} ${APACHE2_OPTS} -t 1>/dev/null 2>&1
|
||||
ret=$?
|
||||
if [ $ret -ne 0 ]; then
|
||||
eerror "Apache2 has detected a syntax error in your configuration files:"
|
||||
${APACHE2} ${APACHE2_OPTS} -t
|
||||
fi
|
||||
|
||||
return $ret
|
||||
}
|
||||
|
||||
start() {
|
||||
checkconfig || return 1
|
||||
ebegin "Starting apache2"
|
||||
[ -f /var/log/apache2/ssl_scache ] && rm /var/log/apache2/ssl_scache
|
||||
|
||||
start-stop-daemon --start --exec ${APACHE2} -- ${APACHE2_OPTS} -k start
|
||||
eend $?
|
||||
}
|
||||
|
||||
stop() {
|
||||
checkconfig || return 1
|
||||
ebegin "Stopping apache2"
|
||||
start-stop-daemon --stop --retry -TERM/5/-KILL/5 --exec ${APACHE2} --pidfile /var/run/apache2.pid
|
||||
eend $?
|
||||
}
|
||||
|
||||
reload() {
|
||||
RELOAD_TYPE="${RELOAD_TYPE:-graceful}"
|
||||
|
||||
checkconfig || return 1
|
||||
if [ "${RELOAD_TYPE}" = "restart" ]; then
|
||||
ebegin "Restarting apache2"
|
||||
start-stop-daemon --stop --oknodo --signal HUP --exec ${APACHE2} --pidfile /var/run/apache2.pid
|
||||
eend $?
|
||||
elif [ "${RELOAD_TYPE}" = "graceful" ]; then
|
||||
ebegin "Gracefully restarting apache2"
|
||||
start-stop-daemon --stop --oknodo --signal USR1 --exec ${APACHE2} --pidfile /var/run/apache2.pid
|
||||
eend $?
|
||||
else
|
||||
eerror "${RELOAD_TYPE} is not a valid RELOAD_TYPE. Please edit /etc/conf.d/apache2"
|
||||
fi
|
||||
}
|
||||
|
||||
graceful() {
|
||||
checkconfig || return 1
|
||||
ebegin "Gracefully restarting apache2"
|
||||
start-stop-daemon --stop --signal USR1 --exec ${APACHE2} --pidfile /var/run/apache2.pid
|
||||
eend $?
|
||||
}
|
||||
|
||||
gracefulstop() {
|
||||
checkconfig || return 1
|
||||
|
||||
# zap!
|
||||
if service_started "${myservice}"; then
|
||||
mark_service_stopped "${myservice}"
|
||||
fi
|
||||
|
||||
ebegin "Gracefully stopping apache2"
|
||||
# 28 is SIGWINCH
|
||||
start-stop-daemon --stop --signal 28 --exec ${APACHE2} --pidfile /var/run/apache2.pid
|
||||
eend $?
|
||||
}
|
||||
|
||||
modules() {
|
||||
checkconfig || return 1
|
||||
|
||||
${APACHE2} ${APACHE2_OPTS} -M 2>&1
|
||||
}
|
||||
|
||||
status() {
|
||||
LYNX="${LYNX:-lynx -dump}"
|
||||
STATUSURL="${STATUSURL:-http://localhost/server-status}"
|
||||
|
||||
${LYNX} ${STATUSURL} | awk ' /process$/ { print; exit } { print } '
|
||||
}
|
||||
|
||||
fullstatus() {
|
||||
LYNX="${LYNX:-lynx -dump}"
|
||||
STATUSURL="${STATUSURL:-http://localhost/server-status}"
|
||||
|
||||
${LYNX} ${STATUSURL}
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user