From: cajus Date: Mon, 5 May 2008 15:27:23 +0000 (+0000) Subject: Added gosa encrypted password migration utility X-Git-Url: https://git.tokkee.org/?a=commitdiff_plain;h=2953aec0ed571cec2879351b19a11fda727d37fc;p=gosa.git Added gosa encrypted password migration utility git-svn-id: https://oss.gonicus.de/repositories/gosa/trunk@10768 594d385d-05f5-0310-b6e9-bd551577e9d8 --- diff --git a/gosa-core/bin/gosa-encrypt-passwords b/gosa-core/bin/gosa-encrypt-passwords new file mode 100755 index 000000000..0f8c5ada1 --- /dev/null +++ b/gosa-core/bin/gosa-encrypt-passwords @@ -0,0 +1,114 @@ +#!/usr/bin/php +load("/etc/gosa/gosa.conf") or die ("Cannot read /etc/gosa/gosa.conf - aborted\n"); +$conf->encoding = 'UTF-8'; +$referrals= $conf->getElementsByTagName("referral"); +echo "* encrypting existent passwords with master key\n"; +foreach($referrals as $referral){ + $pw= $referral->attributes->getNamedItem("password"); + $pw->nodeValue= cred_encrypt($pw->nodeValue, $master_key); +} + +# Move original gosa.conf out of the way and make it unreadable for the web user +echo "* creating backup in /etc/gosa/gosa.conf.orig\n"; +rename("/etc/gosa/gosa.conf", "/etc/gosa/gosa.conf.orig"); +chmod("/etc/gosa/gosa.conf.orig", 0600); +chown ("/etc/gosa/gosa.conf.orig", "root"); +chgrp ("/etc/gosa/gosa.conf.orig", "root"); + +# Save new passwords +echo "* saving modified /etc/gosa/gosa.conf\n"; +$conf->save("/etc/gosa/gosa.conf") or die("Cannot write modified /etc/gosa/gosa.conf - aborted\n"); +chmod("/etc/gosa/gosa.conf", 0640); +chown ("/etc/gosa/gosa.conf", "root"); +chgrp ("/etc/gosa/gosa.conf", "www-data"); +echo "OK\n\n"; + +# Print reminder +echo<< + php_admin_flag engine on + php_admin_value open_basedir "/etc/gosa/:/usr/share/gosa/:/var/cache/gosa/:/var/spool/gosa/" + php_admin_flag register_globals off + php_admin_flag allow_call_time_pass_reference off + php_admin_flag expose_php off + php_admin_flag zend.ze1_compatibility_mode off + php_admin_flag register_long_arrays off + php_admin_flag magic_quotes_gpc on + include /etc/gosa/gosa.secrets + + + +Please reload your httpd configuration after you've modified anything. + + +EOF; +?> diff --git a/gosa-core/debian/gosa.install b/gosa-core/debian/gosa.install index fc1a0cfb7..a1a1bc9fb 100644 --- a/gosa-core/debian/gosa.install +++ b/gosa-core/debian/gosa.install @@ -1,4 +1,5 @@ update-gosa /usr/sbin +bin/gosa-encrypt-passwords /usr/sbin html /usr/share/gosa ihtml /usr/share/gosa include /usr/share/gosa