diff options
author | Silvio Rhatto <rhatto@riseup.net> | 2020-11-06 11:00:33 -0300 |
---|---|---|
committer | Silvio Rhatto <rhatto@riseup.net> | 2020-11-06 11:00:33 -0300 |
commit | c3d66da7c162508a7fdfddbf4aaaf2adfc4f7a58 (patch) | |
tree | 4b50b1cb677a7a1d6a2df2f4d7840d148c54d6cd /share/provision/njalla | |
parent | e7162cbba6161ea316f9415b672d842074bafd4a (diff) | |
download | kvmx-c3d66da7c162508a7fdfddbf4aaaf2adfc4f7a58.tar.gz kvmx-c3d66da7c162508a7fdfddbf4aaaf2adfc4f7a58.tar.bz2 |
Feat: WIP: ipredator/njalla migration
Diffstat (limited to 'share/provision/njalla')
-rwxr-xr-x | share/provision/njalla | 49 |
1 files changed, 49 insertions, 0 deletions
diff --git a/share/provision/njalla b/share/provision/njalla new file mode 100755 index 0000000..9598d8c --- /dev/null +++ b/share/provision/njalla @@ -0,0 +1,49 @@ +#!/usr/bin/env bash +# +# Full desktop provision example +# +# Copyright (C) 2017 Silvio Rhatto - rhatto at riseup.net +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published +# by the Free Software Foundation, either version 3 of the License, +# or any later version. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see <http://www.gnu.org/licenses/>. +# + +# Parameters +DIRNAME="`dirname $0`" +BASENAME="`basename $0`" +HOSTNAME="$1" +DOMAIN="$2" +MIRROR="$3" +APT_INSTALL="sudo LC_ALL=C DEBIAN_FRONTEND=noninteractive apt-get install -y" + +# Provision the basic stuff +$DIRNAME/vpn $HOSTNAME $DOMAIN $MIRROR + +# Firewall +$APT_INSTALL ferm ulogd2 ulogd2-pcap +sudo cp $DIRNAME/files/njalla/etc/ferm/ferm.conf /etc/ferm +sudo cp $DIRNAME/files/njalla/etc/udev/rules.d/81-vpn-firewall.rules /etc/udev/rules.d +sudo cp $DIRNAME/files/njalla/usr/local/bin/fermreload.sh /usr/local/bin +sudo chmod 555 /usr/local/bin/fermreload.sh +sudo sed -i -e 's/^ENABLED=.*$/ENABLED="yes"/' /etc/default/ferm +sudo service ferm restart + +# Njalla +#sudo cp $DIRNAME/files/njalla/etc/openvpn/njalla.conf /etc/openvpn +#sudo touch /etc/openvpn/njalla.auth +#sudo chown root:root /etc/openvpn/njalla.conf +#sudo chown root:root /etc/openvpn/njalla.auth +#sudo chmod 400 /etc/openvpn/njalla.conf +#sudo chmod 400 /etc/openvpn/njalla.auth +#echo "Please set user/password at /etc/openvpn/njalla.auth" +echo "Please configure /etc/openvpn/njalla.conf" |