/usr/sbin
NameSizeModeActions
accessdb128880755editdlrm
accton140160755editdlrm
addgnupghome30750755editdlrm
addpart254560755editdlrm
adduser1517200755editdlrm
agetty638880755editdlrm
alternatives375360755editdlrm
anacron419760755editdlrm
apachectl48040755editdlrm
applygnupgdefaults22170755editdlrm
arp662640755editdlrm
arpd1121520755editdlrm
arping294320755editdlrm
atd334080755editdlrm
atrun670755editdlrm
authconfig220570755editdlrm
avcstat167920755editdlrm
badblocks333680755editdlrm
blkdeactivate163510555editdlrm
blkdiscard297520755editdlrm
blkid1010240755editdlrm
blkmapd547520755editdlrm
blkzone509440755editdlrm
blockdev422960755editdlrm
bridge1620480755editdlrm
build-locale-archive8612480700editdlrm
capsh332240755editdlrm
cfdisk1007680755editdlrm
chcpu295200755editdlrm
chgpasswd713600755editdlrm
chkconfig461920755editdlrm
chpasswd628960755editdlrm
chroot424480755editdlrm
clock667840755editdlrm
clockdiff209200755editdlrm
consoletype121440755editdlrm
convertquota805680755editdlrm
cracklib-check133600755editdlrm
cracklib-format2510755editdlrm
cracklib-packer133680755editdlrm
cracklib-unpacker92480755editdlrm
create-cracklib-dict9900755editdlrm
crond757120755editdlrm
csf2509790700editdlrm
ctrlaltdel253840755editdlrm
ctstat259360755editdlrm
dcb1587600755editdlrm
ddns-confgen209520755editdlrm
debugfs2371840755editdlrm
delpart254560755editdlrm
depmod1637840755editdlrm
devlink2210480755editdlrm
dhclient4645680755editdlrm
dhclient-script336460755editdlrm
dmfilemapd251360555editdlrm
dmsetup1624480555editdlrm
dmstats1624480555editdlrm
dnssec-checkds9360755editdlrm
dnssec-coverage9380755editdlrm
dnssec-dsfromkey623040755editdlrm
dnssec-importkey622960755editdlrm
dnssec-keyfromlabel663120755editdlrm
dnssec-keygen745840755editdlrm
dnssec-keymgr9340755editdlrm
dnssec-revoke581040755editdlrm
dnssec-settime623040755editdlrm
dnssec-signzone1200160755editdlrm
dnssec-verify541120755editdlrm
dovecot1660720755editdlrm
dovecot_cpshutdown33440755editdlrm
dpkg-fsys-usrunmess123990755editdlrm
dump-acct298480755editdlrm
dump-utmp256160755editdlrm
dumpe2fs332960755editdlrm
e2freefrag168160755editdlrm
e2fsck3364000755editdlrm
e2image374880755editdlrm
e2label1132800755editdlrm
e2mmpstatus332960755editdlrm
e2undo208640755editdlrm
e4crypt251360755editdlrm
e4defrag291760755editdlrm
edquota934320755editdlrm
ether-wake757680755editdlrm
ethtool5711760755editdlrm
exicyclog113650755editdlrm
exigrep117100755editdlrm
exim17050964755editdlrm
eximstats1525460755editdlrm
exim_checkaccess49430755editdlrm
exim_dbmbuild246880755editdlrm
exim_dumpdb601120755editdlrm
exim_fixdb656560755editdlrm
exim_lock272240755editdlrm
exim_tidydb561200755editdlrm
exinext82170755editdlrm
exiqgrep67390755editdlrm
exiqsumm64430755editdlrm
exiwhat45240755editdlrm
exportfs843520755editdlrm
faillock210160755editdlrm
fcgistarter175200755editdlrm
fdformat339680755editdlrm
fdisk1340480755editdlrm
filefrag168560755editdlrm
findfs126720755editdlrm
fix-info-dir80330755editdlrm
fixfiles107270755editdlrm
fsck547520755editdlrm
fsck.cramfs424080755editdlrm
fsck.ext23364000755editdlrm
fsck.ext33364000755editdlrm
fsck.ext43364000755editdlrm
fsck.minix1011200755editdlrm
fsfreeze167760755editdlrm
fstrim507920755editdlrm
fuse2fs720800755editdlrm
fuser390560755editdlrm
g13-syshelp1943120755editdlrm
genhomedircon299760755editdlrm
genhostid121440755editdlrm
genl1243200755editdlrm
genrandom126720755editdlrm
getcap126480755editdlrm
getenforce80240755editdlrm
getpcaps125680755editdlrm
getsebool121520755editdlrm
groupadd976320755editdlrm
groupdel932800755editdlrm
groupmems629600755editdlrm
groupmod1017600755editdlrm
grpck629440755editdlrm
grpconv586400755editdlrm
grpunconv586320755editdlrm
grub2-bios-setup12139840755editdlrm
grub2-get-kernel-settings27420755editdlrm
grub2-install15114640755editdlrm
grub2-mkconfig88880755editdlrm
grub2-probe12139280755editdlrm
grub2-reboot40850755editdlrm
grub2-rpm-sort2899360755editdlrm
grub2-set-bootflag167444755editdlrm
grub2-set-default35350755editdlrm
grub2-set-password31190755editdlrm
grub2-setpassword31190755editdlrm
grub2-switch-to-blscfg88090755editdlrm
grubby2600755editdlrm
gss-server252000755editdlrm
gssproxy1352480755editdlrm
halt2236960755editdlrm
hardlink174960755editdlrm
htcacheclean454240755editdlrm
httpd10152560755editdlrm
hwclock667840755editdlrm
iconvconfig338400755editdlrm
ifconfig828000755editdlrm
ifdown21230755editdlrm
ifenslave255440755editdlrm
ifstat1204960755editdlrm
ifup54630755editdlrm
init16136240755editdlrm
insmod1637840755editdlrm
install-info514320755editdlrm
installkernel3230755editdlrm
ip7099440755editdlrm
ip6tables943920755editdlrm
ip6tables-legacy943920755editdlrm
ip6tables-legacy-restore943920755editdlrm
ip6tables-legacy-save943920755editdlrm
ip6tables-restore943920755editdlrm
ip6tables-save943920755editdlrm
ipmaddr215040755editdlrm
ipset92240755editdlrm
iptables943920755editdlrm
iptables-legacy943920755editdlrm
iptables-legacy-restore943920755editdlrm
iptables-legacy-save943920755editdlrm
iptables-restore943920755editdlrm
iptables-save943920755editdlrm
iptraf-ng1891040755editdlrm
iptunnel256000755editdlrm
isc-hmac-fixup121440755editdlrm
key.dns_resolver251040755editdlrm
kpartx502320755editdlrm
lchage168000755editdlrm
ldattach337840755editdlrm
ldconfig10097680755editdlrm
lfd3916290700editdlrm
lgroupadd121600755editdlrm
lgroupdel121600755editdlrm
lgroupmod203520755editdlrm
lid166640755editdlrm
lnewusers203440755editdlrm
lnstat259360755editdlrm
load_policy125760755editdlrm
logrotate952640755editdlrm
logsave168000755editdlrm
losetup927680755editdlrm
lpasswd208400755editdlrm
lsmod1637840755editdlrm
luseradd203520755editdlrm
luserdel162560755editdlrm
lusermod203600755editdlrm
lwresd8611200755editdlrm
mariadbd254524800755editdlrm
matchpathcon126640755editdlrm
mii-diag260080755editdlrm
mii-tool215360755editdlrm
mkdict2510755editdlrm
mke2fs1417680755editdlrm
mkfs168720755editdlrm
mkfs.cramfs422560755editdlrm
mkfs.ext21417680755editdlrm
mkfs.ext31417680755editdlrm
mkfs.ext41417680755editdlrm
mkfs.minix886400755editdlrm
mkhomedir_helper250240755editdlrm
mklost+found121440755editdlrm
mkswap885520755editdlrm
modinfo1637840755editdlrm
modprobe1637840755editdlrm
modsec-sdbm-util264480750editdlrm
mount.nfs2019764755editdlrm
mount.nfs42019764755editdlrm
mountstats432370755editdlrm
mysqld254524800755editdlrm
named8611200755editdlrm
named-checkconf417680755editdlrm
named-checkzone375120755editdlrm
named-compilezone375120755editdlrm
named-journalprint121360755editdlrm
nameif173840755editdlrm
newusers1098000755editdlrm
nfsconf383760755editdlrm
nfsconvert133470755editdlrm
nfsdcld674480755editdlrm
nfsdclddb102420755editdlrm
nfsdclnts92330755editdlrm
nfsdcltrack509760755editdlrm
nfsidmap464480755editdlrm
nfsiostat239220755editdlrm
nfsref673760755editdlrm
nfsstat363680755editdlrm
nft249920755editdlrm
nologin121520755editdlrm
nscd1604480755editdlrm
nsec3hash125840755editdlrm
nstat1162960755editdlrm
ntsysv419520755editdlrm
oddjobd794960755editdlrm
packer133680755editdlrm
pam_console_apply462800755editdlrm
pam_timestamp_check121524755editdlrm
paperconfig41700755editdlrm
partx967680755editdlrm
pidof170960755editdlrm
ping677120755editdlrm
ping6677120755editdlrm
pivot_root126800755editdlrm
plipconfig130160755editdlrm
pluginviewer210640755editdlrm
poweroff2236960755editdlrm
pure-authd196960755editdlrm
pure-certd196000755editdlrm
pure-config.pl47550755editdlrm
pure-ftpd1864400755editdlrm
pure-ftpwho274720755editdlrm
pure-mrtginfo114320755editdlrm
pure-quotacheck192720755editdlrm
pure-uploadscript195360755editdlrm
pwck586400755editdlrm
pwconv543760755editdlrm
pwhistory_helper209200755editdlrm
pwunconv544000755editdlrm
quot805600755editdlrm
quotacheck1185280755editdlrm
quotaoff851520755editdlrm
quotaon851520755editdlrm
quotastats169360755editdlrm
rcmysql-0editdlrm
rdisc251360755editdlrm
rdma1918800755editdlrm
readprofile210400755editdlrm
reboot2236960755editdlrm
repquota852400755editdlrm
request-key249680755editdlrm
resize2fs664720755editdlrm
resizepart425680755editdlrm
resolvconf2004480755editdlrm
restorecon210240755editdlrm
restorecon_xattr168080755editdlrm
rfkill547440755editdlrm
rmmod1637840755editdlrm
rndc374080755editdlrm
rndc-confgen209360755editdlrm
rotatelogs312400755editdlrm
route692480755editdlrm
rpc.gssd1090960755editdlrm
rpc.idmapd632160755editdlrm
rpc.mountd1669520755editdlrm
rpc.nfsd511200755editdlrm
rpc.statd1057760755editdlrm
rpcbind630240755editdlrm
rpcctl96310755editdlrm
rpcdebug198400755editdlrm
rpcinfo334240755editdlrm
rsyslogd7421200755editdlrm
rtacct480640755editdlrm
rtcwake504880755editdlrm
rtmon1200800755editdlrm
rtstat259360755editdlrm
runlevel2236960755editdlrm
runq17050964755editdlrm
runuser501680755editdlrm
sa477360755editdlrm
safe_finger128800755editdlrm
saslauthd966880755editdlrm
sasldblistusers2212640755editdlrm
saslpasswd2168160755editdlrm
sefcontext_compile669200755editdlrm
selabel_digest125760755editdlrm
selabel_lookup125680755editdlrm
selabel_lookup_best_match121760755editdlrm
selabel_partial_match121680755editdlrm
selinuxconlist121600755editdlrm
selinuxdefcon121600755editdlrm
selinuxenabled80240755editdlrm
selinuxexeccon121440755editdlrm
selinux_check_access126560755editdlrm
semanage421710755editdlrm
semodule299760755editdlrm
sendmail173202755editdlrm
service37290755editdlrm
sestatus209040755editdlrm
setcap166640755editdlrm
setenforce125600755editdlrm
setfiles210240755editdlrm
setquota935680755editdlrm
setsebool167680755editdlrm
sfdisk1213520755editdlrm
showmount215680755editdlrm
shutdown2236960755editdlrm
sim_server121520755editdlrm
slattach448080755editdlrm
sm-notify800080755editdlrm
smartctl9241200755editdlrm
smartd7419840755editdlrm
snmpd332320755editdlrm
snmptrapd333840755editdlrm
ss1958880755editdlrm
sshd8905680755editdlrm
start-statd8380755editdlrm
start-stop-daemon470880755editdlrm
suexec259044755editdlrm
sulogin504240755editdlrm
suphp68817604750editdlrm
swaplabel168960755editdlrm
swapoff212480755editdlrm
swapon505920755editdlrm
switch_root168880755editdlrm
sysctl295680755editdlrm
t1libconfig39210755editdlrm
tcpd432560755editdlrm
tcpdmatch475760755editdlrm
tcpdump10570720755editdlrm
tcpslice334160755editdlrm
tcsd3171520755editdlrm
telinit2236960755editdlrm
testsaslauthd170560755editdlrm
tipc1669840755editdlrm
tmpwatch363200755editdlrm
tracepath209280755editdlrm
tracepath6209280755editdlrm
try-from256320755editdlrm
tsig-keygen209520755editdlrm
tune2fs1132800755editdlrm
udevadm4347520755editdlrm
umount.nfs2019764755editdlrm
umount.nfs42019764755editdlrm
unbound-anchor587120755editdlrm
unix_chkpwd377444755editdlrm
unix_update377440700editdlrm
update-alternatives375360755editdlrm
update-smart-drivedb147820755editdlrm
useradd1517200755editdlrm
userdel1098640755editdlrm
userhelper459364711editdlrm
usermod1475680755editdlrm
usernetctl127044755editdlrm
uuserver162560755editdlrm
vdpa1208720755editdlrm
vigr696880755editdlrm
vipw696880755editdlrm
visudo2450240755editdlrm
weak-modules344100755editdlrm
whmapi034969120755editdlrm
whmapi134969120755editdlrm
whmlogin23900755editdlrm
wipefs421040755editdlrm
xinetd1804000755editdlrm
xqmstats168480755editdlrm
xtables-legacy-multi943920755editdlrm
zdump210560755editdlrm
zic540960755editdlrm
zramctl1015040755editdlrm
Edit: /usr/lib/python3.6/site-packages/authselect/authcompat.py (22057B)
#!/usr/libexec/platform-python # -*- coding: utf-8 -*- # # Authors: # Pavel Březina # # Copyright (C) 2018 Red Hat # # This program is free software; you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by # the Free Software Foundation; either version 3 of the License, or # (at your option) any later version. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program. If not, see . # import os import sys import locale import gettext import subprocess from authcompat_Options import Options from authcompat_EnvironmentFile import EnvironmentFile from authcompat_ConfigSnippet import ConfigSnippet _ = gettext.gettext def eprint(*args, **kwargs): print(*args, file=sys.stderr, **kwargs) class Command: TEST = False def __init__(self, command, args, input=None, check=True): self.args = [command] + args self.input = input.encode() if input is not None else None self.check = check self.result = None def run(self): print(_("Executing: %s") % ' '.join(self.args)) if self.TEST: return self.result = subprocess.run(self.args, check=self.check, input=self.input, stdout=subprocess.PIPE, stderr=subprocess.PIPE) class Service: def __init__(self, name): self.name = name + '.service' def runsystemd(self, command, required, enoent_code): try: command.run() except subprocess.CalledProcessError as result: if required and result.returncode == enoent_code: eprint(_("Service %s was not found. Please install the service.") % self.name) elif result.returncode != enoent_code: eprint(_("Command [%s] failed with %d, stderr:") % (' '.join(result.cmd), result.returncode)) eprint(result.stderr.decode()) def enable(self): cmd = Command(Path.System("cmd-systemctl"), ["enable", self.name]) self.runsystemd(cmd, True, 1) def disable(self): cmd = Command(Path.System("cmd-systemctl"), ["disable", self.name]) self.runsystemd(cmd, False, 1) def start(self, Restart=True): if Restart: self.stop() cmd = Command(Path.System("cmd-systemctl"), ["start", self.name]) self.runsystemd(cmd, True, 5) def stop(self): cmd = Command(Path.System("cmd-systemctl"), ["stop", self.name]) self.runsystemd(cmd, False, 5) class Path: LocalDir = os.path.dirname(os.path.realpath(__file__)) Config = EnvironmentFile(LocalDir + "/authcompat_paths") Files = { 'ldap.conf': '/etc/openldap/ldap.conf', 'krb5.conf': '/etc/krb5.conf.d/authconfig-krb.conf', 'sssd.conf': '/etc/sssd/conf.d/authconfig-sssd.conf', 'authconfig': '/etc/sysconfig/authconfig', 'network': '/etc/sysconfig/network', 'pwquality.conf': '/etc/security/pwquality.conf.d/10-authconfig-pwquality.conf', 'yp.conf': '/etc/yp.conf', 'cmd-systemctl': '/usr/bin/systemctl', 'cmd-authselect': '/usr/bin/authselect', 'cmd-realm': '/usr/sbin/realm', 'cmd-domainname': '/usr/bin/domainname', 'cmd-setsebool': '/usr/sbin/setsebool' } @staticmethod def Local(relpath): return "%s/%s" % (Path.LocalDir, relpath) @staticmethod def System(name): return Path.Files[name] class Configuration: class Base(object): def __init__(self, options, ServiceName=None): self.options = options self.service = None if ServiceName is not None: self.service = Service(ServiceName) def isEnabled(self): return True def isDisabled(self): return not self.isEnabled() def enableService(self, nostart): if self.service is None: return self.service.enable() if not nostart: self.service.start() def disableService(self, nostop): if self.service is None: return self.service.disable() if not nostop: self.service.stop() def cleanup(self): return def write(self): return def get(self, name): return self.options.get(name) def isset(self, name): return self.options.isset(name) def getTrueOrNone(self, name): return self.options.getTrueOrNone(name) def getBool(self, name): return self.options.getBool(name) def getBoolAsValue(self, name, if_true, if_false, AllowNone=False): if AllowNone and not self.isset(name): return None value = self.getBool(name) if value: return if_true return if_false def removeFile(self, filename): print(_("Removing file: %s") % filename) if self.options.getBool("test-call"): return try: os.remove(filename) except FileNotFoundError: return class LDAP(Base): def __init__(self, options): super(Configuration.LDAP, self).__init__(options) def write(self): config = EnvironmentFile(Path.System('ldap.conf'), " ", delimiter_re=r"\s\t", quotes=False) if self.isset("ldapserver"): config.set("URI", self.get("ldapserver")) if self.isset("ldapbasedn"): config.set("BASE", self.get("ldapbasedn")) config.write() class Kerberos(Base): def __init__(self, options): super(Configuration.Kerberos, self).__init__(options) def isEnabled(self): if not self.isset("krb5realm") and not self.isset("krb5realmdns"): return None return self.get("krb5realm") != "" or self.getBool("krb5realmdns") def cleanup(self): # Do not remove the file if these options are not set if not self.isset("krb5realm") and not self.isset("krb5realmdns"): return self.removeFile(Path.System('krb5.conf')) def write(self): if self.isDisabled(): return path = Path.Local("snippets/authconfig-krb.conf") config = ConfigSnippet(path, Path.System('krb5.conf')) realm = self.get("krb5realm") keys = { 'realm': self.get("krb5realm"), 'kdc-srv': self.get("krb5kdcdns"), 'realm-srv': self.get("krb5realmdns"), 'kdc': self.get("krb5kdc") if realm else None, 'adminserver': self.get("krb5adminserver") if realm else None, 'domain': realm.lower() if realm else None } config.write(keys) class Network(Base): def __init__(self, options): super(Configuration.Network, self).__init__(options) def write(self): nisdomain = self.get("nisdomain") config = EnvironmentFile(Path.System('network')) if nisdomain is None: return config.set("NISDOMAIN", nisdomain) config.write() class SSSD(Base): def __init__(self, options): super(Configuration.SSSD, self).__init__(options, ServiceName="sssd") def isEnabled(self): if not self.isset("ldap") and not self.isset("sssd"): return None return self.getBool("ldap") or self.getBool("sssd") def cleanup(self): self.removeFile(Path.System('sssd.conf')) def write(self): # Authconfig would not generate sssd in this case so we should not # either. Even if --enablesssd[auth] was provided the configuration # would not be generated. if not self.getBool("ldap"): return path = Path.Local("snippets/authconfig-sssd.conf") config = ConfigSnippet(path, Path.System('sssd.conf')) schema = "rfc2307bis" if self.getBool("rfc2307bis") else None keys = { 'ldap-uri': self.get("ldapserver"), 'ldap-basedn': self.get("ldapbasedn"), 'ldap-tls': self.getTrueOrNone("ldaptls"), 'ldap-schema': schema, 'krb5': self.getTrueOrNone("krb5"), 'kdc-uri': self.get("krb5kdc"), 'kpasswd-uri': self.get("krb5adminserver"), 'realm': self.get("krb5realm"), 'cache-creds': self.getTrueOrNone("cachecreds"), 'cert-auth': self.getTrueOrNone("smartcard") } config.write(keys) os.chmod(Path.System('sssd.conf'), mode=0o600) class Winbind(Base): def __init__(self, options): super(Configuration.Winbind, self).__init__(options, ServiceName="winbind") def isEnabled(self): if not self.isset("winbind") and not self.isset("winbindauth"): return None return self.getBool("winbind") or self.getBool("winbindauth") def write(self): if not self.isset("winbindjoin"): return creds = self.options.get("winbindjoin").split("%", 1) user = creds[0] password = None if len(creds) > 1: password = creds[1] + '\n' args = [ 'join', '-U', '"%s"' % user, '--client-software', 'winbind' ] if self.isset("smbworkgroup"): args.append(self.get("smbworkgroup")) cmd = Command(Path.System('cmd-realm'), args, input=password) try: cmd.run() except FileNotFoundError: eprint(_("%s was not found. Please, install realmd.") % Path.System('cmd-realm')) class PWQuality(Base): def __init__(self, options): super(Configuration.PWQuality, self).__init__(options) def write(self): config = EnvironmentFile(Path.System('pwquality.conf')) value_set = False pwopts = { "minlen": self.get("passminlen"), "minclass": self.get("passminclass"), "maxrepeat": self.get("passmaxrepeat"), "maxclassrepeat": self.get("passmaxclassrepeat"), "lcredit": self.getBoolAsValue("reqlower", -1, 0, AllowNone=True), "ucredit": self.getBoolAsValue("requpper", -1, 0, AllowNone=True), "dcredit": self.getBoolAsValue("reqdigit", -1, 0, AllowNone=True), "ocredit": self.getBoolAsValue("reqother", -1, 0, AllowNone=True) } # Write options only if their are actually set for opt, value in pwopts.items(): if value is not None: print(opt + "=" + str(value)) config.set(opt, value) value_set = True if value_set: config.write() class MakeHomedir(Base): def __init__(self, options): super(Configuration.MakeHomedir, self).__init__(options, ServiceName="oddjobd") def isEnabled(self): if not self.isset("mkhomedir"): return None return self.getBool("mkhomedir") def disableService(self, nostop): # Never disable the service in case it is already running as # other applications may depend on it. return class NIS(Base): def __init__(self, options): super(Configuration.NIS, self).__init__(options) self.rpcbind = Service("rpcbind") self.ypbind = Service("ypbind") def isEnabled(self): if not self.isset("nis"): return None return self.getBool("nis") def enableService(self, nostart): if not self.isset("nisdomain"): return nisdom = self.get("nisdomain") if not nostart: cmd = Command(Path.System('cmd-domainname'), [nisdom]) cmd.run() cmd = Command(Path.System('cmd-setsebool'), ['-P', 'allow_ypbind', '1']) cmd.run() self.rpcbind.enable() self.ypbind.enable() if not nostart: self.rpcbind.start(Restart=False) self.ypbind.start() def disableService(self, nostop): if not nostop: cmd = Command(Path.System('cmd-domainname'), ["(none)"]) cmd.run() cmd = Command(Path.System('cmd-setsebool'), ['-P', 'allow_ypbind', '0']) cmd.run() self.rpcbind.disable() self.ypbind.disable() if not nostop: self.rpcbind.stop() self.ypbind.stop() def write(self): if not self.isset("nisdomain"): return output = "domain " + self.get("nisdomain") additional_servers = [] if self.isset("nisserver"): servers = self.get("nisserver").split(",") additional_servers = servers[1:] output += " server " + servers[0] + "\n" else: output += " broadcast\n" for server in additional_servers: output += "ypserver " + server + "\n" filename = Path.System('yp.conf') if self.getBool("test-call"): print("========== BEGIN Content of [%s] ==========" % filename) print(output) print("========== END Content of [%s] ==========\n" % filename) return with open(filename, "w") as f: f.write(output) class AuthCompat: def __init__(self): self.sysconfig = EnvironmentFile(Path.System('authconfig')) self.options = Options() self.options.parse() self.options.applysysconfig(self.sysconfig) self.options.updatesysconfig(self.sysconfig) def printWarning(self): print(_("Running authconfig compatibility tool.")) print(_("The purpose of this tool is to enable authentication against " "chosen services with authselect and minimum configuration. " "It does not provide all capabilities of authconfig.\n")) print(_("IMPORTANT: authconfig is replaced by authselect, " "please update your scripts.")) print(_("See man authselect-migration(7) to help you with migration to authselect")) options = self.options.getSetButUnsupported() if options: print(_("Warning: These options are not supported anymore " "and have no effect:")) for name in options: print(" --%s" % name) print("") def printOptions(self): for option in Options.List: print("%s=%s" % (option.name, option.value)) def printSysconfig(self): for line in self.sysconfig.getall(): print("%s=%s" % (line.name, line.value)) def canContinue(self): disallowed = ["test", "probe", "restorebackup", "restorelastbackup"] required = ["update", "updateall", "kickstart"] if not self.options.getBool("test") and os.getuid() != 0: print(_("authconfig can only be run as root")) return False for option in disallowed: if self.options.getBool(option): print(_("Error: option --%s is no longer supported and we " "cannot continue if it is set." % option)) return False if self.options.getBool("winbind") != self.options.getBool("winbindauth"): print(_("Error: Both --enablewinbind and --enablewinbindauth must be set.")) return False # We require one of these options to perform changes # We encourage to use --updateall since we no longer support just pure # --update or --kickstart, they will act as --updateall. for option in required: if self.options.getBool(option): return True print(_("Error: Please, provide --updateall option.")) return False def runAuthselect(self): map = { 'smartcard': 'with-smartcard', 'requiresmartcard': 'with-smartcard-required', 'fingerprint': 'with-fingerprint', 'mkhomedir': 'with-mkhomedir', 'faillock': 'with-faillock', 'pamaccess': 'with-pamaccess', 'winbindkrb5': 'with-krb5' } # Read current configuration first. (profile, features) = self.getCurrentAuthselectConfig() # Change profile if requested. if (self.options.getBool("ldap") or self.options.getBool("ldapauth") or self.options.getBool("sssd") or self.options.getBool("sssdauth")): profile = "sssd" elif self.options.getBool("nis"): profile = "nis" elif self.options.getBool("winbind"): profile = "winbind" # Default to sssd if profile is None: profile = "sssd" # Add enabled and remove disabled features. for option, feature in map.items(): if not self.options.isset(option): continue enabled = self.options.getBool(option) if enabled: features.append(feature) else: while feature in features: features.remove(feature) # Add lock-on-smartcard-removal if requested if self.options.isset("smartcardaction"): if int(self.options.get("smartcardaction")) == 0: features.append("with-smartcard-lock-on-removal") else: features.remove("with-smartcard-lock-on-removal") # Remove duplicates. The order is not kept but that does not matter. features = list(set(features)) # Always run with --force. This is either first call of authconfig # in installation script or it is run on already configured system. # We want to use authselect in both cases anyway, since authconfig # would change the configuration either way. args = ["select", profile] args.extend(features) args.append("--force") cmd = Command(Path.System('cmd-authselect'), args) cmd.run() def getCurrentAuthselectConfig(self): cmd = Command(Path.System('cmd-authselect'), ['check'], check=False) cmd.run() if cmd.result is None or cmd.result.returncode != 0: return (None, []) cmd = Command(Path.System('cmd-authselect'), ['current', '--raw']) cmd.run() current = cmd.result.stdout.decode("utf-8").split() return (current[0], current[1:]) def writeConfiguration(self): configs = [ Configuration.LDAP(self.options), Configuration.Network(self.options), Configuration.Kerberos(self.options), Configuration.SSSD(self.options), Configuration.Winbind(self.options), Configuration.PWQuality(self.options), Configuration.MakeHomedir(self.options), Configuration.NIS(self.options) ] for config in configs: # Configuration decides if it needs to write something or not config.write() # Enable or disable service if needed nostart = self.options.getBool("nostart") try: enabled = config.isEnabled() # Skip service management if it can not be decided if enabled is None: continue if enabled: config.enableService(nostart) else: config.disableService(nostart) config.cleanup() except subprocess.CalledProcessError as result: # This is not fatal error. eprint(_("Command [%s] failed with %d, stderr:") % (' '.join(result.cmd), result.returncode)) eprint(result.stderr.decode()) def main(): try: locale.setlocale(locale.LC_ALL, '') except locale.Error: sys.stderr.write('Warning: Unsupported locale setting.\n') authcompat = AuthCompat() authcompat.printWarning() Command.TEST = authcompat.options.getBool("test-call") EnvironmentFile.TEST = authcompat.options.getBool("test-call") ConfigSnippet.TEST = authcompat.options.getBool("test-call") if not authcompat.canContinue(): sys.exit(1) try: authcompat.runAuthselect() authcompat.writeConfiguration() authcompat.sysconfig.write() except subprocess.CalledProcessError as result: eprint(_("Command [%s] failed with %d, stderr:") % (' '.join(result.cmd), result.returncode)) eprint(result.stderr.decode()) sys.exit(0) if __name__ == "__main__": main()