summaryrefslogtreecommitdiff
path: root/programs/_plutoload/_plutoload.in
blob: 73841197dba2008f295ba9465d777454f5599cb1 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
#!/bin/sh
# Pluto database-loading script
# Copyright (C) 1998, 1999, 2001  Henry Spencer.
# 
# This program is free software; you can redistribute it and/or modify it
# under the terms of the GNU General Public License as published by the
# Free Software Foundation; either version 2 of the License, or (at your
# option) any later version.  See <http://www.fsf.org/copyleft/gpl.txt>.
# 
# This program is distributed in the hope that it will be useful, but
# WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
# or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
# for more details.
#
# RCSID $Id: _plutoload.in,v 1.2 2004/03/31 16:15:10 as Exp $
#
# exit status is 13 for protocol violation, that of Pluto otherwise

me='ipsec _plutoload'		# for messages

for dummy
do
	case "$1" in
	--load)	plutoload="$2" ; shift	;;
	--start)	plutostart="$2" ; shift	;;
	--wait)	plutowait="$2" ; shift	;;
	--post)	postpluto="$2" ; shift	;;
	--)	shift ; break	;;
	-*)	echo "$me: unknown option \`$1'" >&2 ; exit 2	;;
	*)	break	;;
	esac
	shift
done

# load ca information
eval `ipsec _confread --varprefix PLUTO --type ca --search auto add start`
if test " $PLUTO_confreadstatus" != " "
then
	echo "auto=add/start search: $PLUTO_confreadstatus"
	echo "unable to determine what ca information to add -- adding none"
	caload=
else
	caload="$PLUTO_confreadnames"
fi

# searches, if needed
# the way the searches were done ensures plutoload >= plutoroute >= plutostart

# search for things to "ipsec auto --add": auto in "add" "route" "start"
eval `ipsec _confread --varprefix PLUTO --search auto add route start`
if test " $PLUTO_confreadstatus" != " "
then
	echo "auto=add/route/start search: $PLUTO_confreadstatus"
	echo "unable to determine what conns to add -- adding none"
	plutoload=
else
	plutoload="$PLUTO_confreadnames"
fi

# search for things to "ipsec auto --route": auto in  "route" "start"
eval `ipsec _confread --varprefix PLUTO --search auto route start`
if test " $PLUTO_confreadstatus" != " "
then
	echo "auto=route/start search: $PLUTO_confreadstatus"
	echo "unable to determine what conns to route -- routing none"
	plutoroute=
else
	plutoroute="$PLUTO_confreadnames"
fi

# search for things to "ipsec auto --up": auto in  "start"
eval `ipsec _confread --varprefix PLUTO --search auto start`
if test " $PLUTO_confreadstatus" != " "
then
	echo "auto=start search: $PLUTO_confreadstatus"
	echo "unable to determine what conns to start -- starting none"
	plutostart=
else
	plutostart="$PLUTO_confreadnames"
fi

# await Pluto's readiness (not likely to be an issue, but...)
eofed=y
while read saying
do
	case "$saying" in
	'Pluto initialized')	eofed= ; break	;;	# NOTE BREAK OUT
	*)	echo "pluto unexpectedly said \`$saying'"	;;
	esac
done
if test "$eofed"
then
	echo "pluto died unexpectedly!?!"
	exit 13
fi

# ca database load
for tu in $caload
do
	ipsec auto --type ca --add $tu ||
		echo "...could not add ca \"$tu\""
done

# conn database load
for tu in $plutoload
do
	ipsec auto --add $tu ||
		echo "...could not add conn \"$tu\""
done

# enable listening
ipsec auto --ready

# execute any post-startup cleanup
if test " $postpluto" != " "
then
	$postpluto
	st=$?
	if test " $st" -ne 0
	then
		echo "...postpluto command exited with status $st"
	fi
fi

# quickly establish routing
for tu in $plutoroute
do
	ipsec auto --route $tu ||
		echo "...could not route conn \"$tu\""
done

# tunnel initiation, which may take a while
async=
if test " $plutowait" = " no"
then
	async="--asynchronous"
fi
for tu in $plutostart
do
	ipsec auto --up $async $tu ||
		echo "...could not start conn \"$tu\""
done

# report any further utterances, and watch for exit status
eofed=y
while read saying
do
	case "$saying" in
	exit)	eofed= ; break	;;		# NOTE BREAK OUT
	*)	echo "pluto unexpectedly says \`$saying'"	;;
	esac
done
if test "$eofed"
then
	echo "pluto died without exit status!?!"
	exit 13
fi
if read status
then
	exit $status
else
	echo "pluto yielded no exit status!?!"
	exit 13
fi