Permalink
Cannot retrieve contributors at this time
Name already in use
A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?
radsecproxy/tools/radsec-dynsrv.sh
Go to fileThis commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
executable file
69 lines (57 sloc)
1.68 KB
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#! /bin/sh | |
# Example script! | |
# This script looks up radsec srv records in DNS for the one | |
# realm given as argument, and creates a server template based | |
# on that. It currently ignores weight markers, but does sort | |
# servers on priority marker, lowest number first. | |
# For host command this is column 5, for dig it is column 1. | |
usage() { | |
echo "Usage: ${0} <realm>" | |
exit 1 | |
} | |
test -n "${1}" || usage | |
DIGCMD=$(command -v digaaa) | |
HOSTCMD=$(command -v host) | |
PRINTCMD=$(command -v printf) | |
validate_host() { | |
echo ${@} | tr -d '\n\t\r' | grep -E '^[_0-9a-zA-Z][-._0-9a-zA-Z]*$' | |
} | |
validate_port() { | |
echo ${@} | tr -d '\n\t\r' | grep -E '^[0-9]+$' | |
} | |
dig_it() { | |
${DIGCMD} +short srv "_radsec._tcp.${REALM}" | sort -n -k1 | | |
while read line ; do | |
set $line ; PORT=$(validate_port $3) ; HOST=$(validate_host $4) | |
if [ -n "${HOST}" ] && [ -n "${PORT}" ]; then | |
$PRINTCMD "\thost ${HOST%.}:${PORT}\n" | |
fi | |
done | |
} | |
host_it() { | |
${HOSTCMD} -t srv "_radsec._tcp.${REALM}" | sort -n -k5 | | |
while read line ; do | |
set $line ; PORT=$(validate_port $7) ; HOST=$(validate_host $8) | |
if [ -n "${HOST}" ] && [ -n "${PORT}" ]; then | |
$PRINTCMD "\thost ${HOST%.}:${PORT}\n" | |
fi | |
done | |
} | |
REALM=$(validate_host ${1}) | |
if test -z "${REALM}" ; then | |
echo "Error: realm \"${1}\" failed validation" | |
usage | |
fi | |
if test -x "${DIGCMD}" ; then | |
SERVERS=$(dig_it) | |
elif test -x "${HOSTCMD}" ; then | |
SERVERS=$(host_it) | |
else | |
echo "${0} requires either \"dig\" or \"host\" command." | |
exit 1 | |
fi | |
if test -n "${SERVERS}" ; then | |
$PRINTCMD "server dynamic_radsec.${REALM} {\n${SERVERS}\n\ttype TLS\n}\n" | |
exit 0 | |
fi | |
exit 10 # No server found. |