blob: 73841197dba2008f295ba9465d777454f5599cb1 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
|
#!/bin/sh
# Pluto database-loading script
# Copyright (C) 1998, 1999, 2001 Henry Spencer.
#
# This program is free software; you can redistribute it and/or modify it
# under the terms of the GNU General Public License as published by the
# Free Software Foundation; either version 2 of the License, or (at your
# option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
#
# This program is distributed in the hope that it will be useful, but
# WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
# or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
# for more details.
#
# RCSID $Id: _plutoload.in,v 1.2 2004/03/31 16:15:10 as Exp $
#
# exit status is 13 for protocol violation, that of Pluto otherwise
me='ipsec _plutoload' # for messages
for dummy
do
case "$1" in
--load) plutoload="$2" ; shift ;;
--start) plutostart="$2" ; shift ;;
--wait) plutowait="$2" ; shift ;;
--post) postpluto="$2" ; shift ;;
--) shift ; break ;;
-*) echo "$me: unknown option \`$1'" >&2 ; exit 2 ;;
*) break ;;
esac
shift
done
# load ca information
eval `ipsec _confread --varprefix PLUTO --type ca --search auto add start`
if test " $PLUTO_confreadstatus" != " "
then
echo "auto=add/start search: $PLUTO_confreadstatus"
echo "unable to determine what ca information to add -- adding none"
caload=
else
caload="$PLUTO_confreadnames"
fi
# searches, if needed
# the way the searches were done ensures plutoload >= plutoroute >= plutostart
# search for things to "ipsec auto --add": auto in "add" "route" "start"
eval `ipsec _confread --varprefix PLUTO --search auto add route start`
if test " $PLUTO_confreadstatus" != " "
then
echo "auto=add/route/start search: $PLUTO_confreadstatus"
echo "unable to determine what conns to add -- adding none"
plutoload=
else
plutoload="$PLUTO_confreadnames"
fi
# search for things to "ipsec auto --route": auto in "route" "start"
eval `ipsec _confread --varprefix PLUTO --search auto route start`
if test " $PLUTO_confreadstatus" != " "
then
echo "auto=route/start search: $PLUTO_confreadstatus"
echo "unable to determine what conns to route -- routing none"
plutoroute=
else
plutoroute="$PLUTO_confreadnames"
fi
# search for things to "ipsec auto --up": auto in "start"
eval `ipsec _confread --varprefix PLUTO --search auto start`
if test " $PLUTO_confreadstatus" != " "
then
echo "auto=start search: $PLUTO_confreadstatus"
echo "unable to determine what conns to start -- starting none"
plutostart=
else
plutostart="$PLUTO_confreadnames"
fi
# await Pluto's readiness (not likely to be an issue, but...)
eofed=y
while read saying
do
case "$saying" in
'Pluto initialized') eofed= ; break ;; # NOTE BREAK OUT
*) echo "pluto unexpectedly said \`$saying'" ;;
esac
done
if test "$eofed"
then
echo "pluto died unexpectedly!?!"
exit 13
fi
# ca database load
for tu in $caload
do
ipsec auto --type ca --add $tu ||
echo "...could not add ca \"$tu\""
done
# conn database load
for tu in $plutoload
do
ipsec auto --add $tu ||
echo "...could not add conn \"$tu\""
done
# enable listening
ipsec auto --ready
# execute any post-startup cleanup
if test " $postpluto" != " "
then
$postpluto
st=$?
if test " $st" -ne 0
then
echo "...postpluto command exited with status $st"
fi
fi
# quickly establish routing
for tu in $plutoroute
do
ipsec auto --route $tu ||
echo "...could not route conn \"$tu\""
done
# tunnel initiation, which may take a while
async=
if test " $plutowait" = " no"
then
async="--asynchronous"
fi
for tu in $plutostart
do
ipsec auto --up $async $tu ||
echo "...could not start conn \"$tu\""
done
# report any further utterances, and watch for exit status
eofed=y
while read saying
do
case "$saying" in
exit) eofed= ; break ;; # NOTE BREAK OUT
*) echo "pluto unexpectedly says \`$saying'" ;;
esac
done
if test "$eofed"
then
echo "pluto died without exit status!?!"
exit 13
fi
if read status
then
exit $status
else
echo "pluto yielded no exit status!?!"
exit 13
fi
|