2006-04-28 07:14:48 +00:00
|
|
|
#! /bin/sh
|
|
|
|
# prefix command to run stuff from our programs directory
|
|
|
|
# Copyright (C) 1998-2002 Henry Spencer.
|
2006-05-04 07:55:42 +00:00
|
|
|
# Copyright (C) 2006 Andreas Steffen
|
2006-05-16 14:24:03 +00:00
|
|
|
# Copyright (C) 2006 Martin Willi
|
2006-04-28 07:14:48 +00:00
|
|
|
#
|
|
|
|
# This program is free software; you can redistribute it and/or modify it
|
|
|
|
# under the terms of the GNU General Public License as published by the
|
|
|
|
# Free Software Foundation; either version 2 of the License, or (at your
|
|
|
|
# option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
|
|
|
#
|
|
|
|
# This program is distributed in the hope that it will be useful, but
|
|
|
|
# WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
|
|
|
# or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
|
|
|
# for more details.
|
|
|
|
#
|
2007-10-08 19:59:18 +00:00
|
|
|
# RCSID $Id$
|
2006-04-28 07:14:48 +00:00
|
|
|
|
2006-05-16 14:24:03 +00:00
|
|
|
# name and version of the ipsec implementation
|
|
|
|
IPSEC_NAME="@IPSEC_NAME@"
|
|
|
|
IPSEC_VERSION="U@IPSEC_VERSION@/K`uname -r`"
|
2006-04-28 07:14:48 +00:00
|
|
|
|
|
|
|
# where the private directory and the config files are
|
2006-05-16 14:24:03 +00:00
|
|
|
IPSEC_DIR="@IPSEC_DIR@"
|
|
|
|
IPSEC_SBINDIR="@IPSEC_SBINDIR@"
|
|
|
|
IPSEC_CONFDIR="@IPSEC_CONFDIR@"
|
|
|
|
IPSEC_PIDDIR="@IPSEC_PIDDIR@"
|
2006-04-28 07:14:48 +00:00
|
|
|
|
2006-05-16 14:24:03 +00:00
|
|
|
IPSEC_STARTER_PID="${IPSEC_PIDDIR}/starter.pid"
|
|
|
|
IPSEC_PLUTO_PID="${IPSEC_PIDDIR}/pluto.pid"
|
|
|
|
IPSEC_CHARON_PID="${IPSEC_PIDDIR}/charon.pid"
|
2006-04-28 07:14:48 +00:00
|
|
|
|
2006-05-16 14:24:03 +00:00
|
|
|
IPSEC_WHACK="${IPSEC_DIR}/whack"
|
|
|
|
IPSEC_STROKE="${IPSEC_DIR}/stroke"
|
|
|
|
IPSEC_STARTER="${IPSEC_DIR}/starter"
|
2006-04-28 07:14:48 +00:00
|
|
|
|
2006-05-16 14:24:03 +00:00
|
|
|
export IPSEC_DIR IPSEC_SBINDIR IPSEC_CONFDIR IPSEC_PIDDIR IPSEC_VERSION IPSEC_NAME IPSEC_STARTER_PID IPSEC_PLUTO_PID IPSEC_CHARON_PID
|
2006-04-28 07:14:48 +00:00
|
|
|
|
2007-06-27 07:25:19 +00:00
|
|
|
IPSEC_DISTRO="Institute for Internet Technologies and Applications\nUniversity of Applied Sciences Rapperswil, Switzerland"
|
2006-04-28 07:14:48 +00:00
|
|
|
|
|
|
|
case "$1" in
|
|
|
|
'')
|
|
|
|
echo "Usage: ipsec command argument ..."
|
|
|
|
echo "Use --help for list of commands, or see ipsec(8) manual page"
|
|
|
|
echo "or the $IPSEC_NAME documentation for names of the common ones."
|
|
|
|
echo "Most have their own manual pages, e.g. ipsec_auto(8)."
|
|
|
|
echo "See <http://www.strongswan.org> for more general info."
|
|
|
|
exit 0
|
|
|
|
;;
|
|
|
|
--help)
|
|
|
|
echo "Usage: ipsec command argument ..."
|
|
|
|
echo "where command is one of:"
|
|
|
|
echo " start|restart arguments..."
|
|
|
|
echo " update|reload|stop"
|
|
|
|
echo " up|down|route|unroute <connectionname>"
|
|
|
|
echo " status|statusall [<connectionname>]"
|
|
|
|
echo " ready"
|
|
|
|
echo " listalgs|listpubkeys|listcerts [--utc]"
|
|
|
|
echo " listcacerts|listaacerts|listocspcerts [--utc]"
|
|
|
|
echo " listacerts|listgroups|listcainfos [--utc]"
|
|
|
|
echo " listcrls|listocsp|listcards|listall [--utc]"
|
|
|
|
echo " rereadsecrets|rereadgroups"
|
|
|
|
echo " rereadcacerts|rereadaacerts|rereadocspcerts"
|
|
|
|
echo " rereadacerts|rereadcrls|rereadall"
|
|
|
|
echo " purgeocsp"
|
|
|
|
echo " scencrypt|scdecrypt <value> [--inbase <base>] [--outbase <base>] [--keyid <id>]"
|
2007-09-10 13:32:15 +00:00
|
|
|
echo " openac"
|
2006-04-28 07:14:48 +00:00
|
|
|
echo " pluto"
|
|
|
|
echo " scepclient"
|
|
|
|
echo " secrets"
|
|
|
|
echo " starter"
|
|
|
|
echo " version"
|
|
|
|
echo " whack"
|
2007-07-19 14:12:19 +00:00
|
|
|
echo " stroke"
|
2006-04-28 07:14:48 +00:00
|
|
|
echo
|
|
|
|
echo "Some of these functions have their own manual pages, e.g. ipsec_scepclient(8)."
|
|
|
|
exit 0
|
|
|
|
;;
|
|
|
|
--versioncode)
|
2006-05-16 14:24:03 +00:00
|
|
|
echo "$IPSEC_VERSION"
|
2006-04-28 07:14:48 +00:00
|
|
|
exit 0
|
|
|
|
;;
|
|
|
|
--directory)
|
|
|
|
echo "$IPSEC_DIR"
|
|
|
|
exit 0
|
|
|
|
;;
|
|
|
|
--confdir)
|
2006-05-16 14:24:03 +00:00
|
|
|
echo "$IPSEC_CONFDIR"
|
2006-04-28 07:14:48 +00:00
|
|
|
exit 0
|
|
|
|
;;
|
2007-06-27 07:25:19 +00:00
|
|
|
copyright|--copyright)
|
|
|
|
set _copyright
|
|
|
|
# and fall through, invoking "ipsec _copyright"
|
|
|
|
;;
|
2006-04-28 07:14:48 +00:00
|
|
|
down)
|
|
|
|
shift
|
2006-05-29 07:17:55 +00:00
|
|
|
if [ "$#" -ne 1 ]
|
|
|
|
then
|
|
|
|
echo "Usage: ipsec down <connection name>"
|
2007-11-28 17:02:12 +00:00
|
|
|
exit 2
|
2006-05-29 07:17:55 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
rc=7
|
|
|
|
if [ -e $IPSEC_PLUTO_PID ]
|
2006-05-04 07:55:42 +00:00
|
|
|
then
|
2006-05-16 14:24:03 +00:00
|
|
|
$IPSEC_WHACK --name "$1" --terminate
|
2007-11-28 17:02:12 +00:00
|
|
|
rc="$?"
|
2006-05-04 07:55:42 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_CHARON_PID ]
|
2006-04-28 07:16:42 +00:00
|
|
|
then
|
2006-05-16 14:24:03 +00:00
|
|
|
$IPSEC_STROKE down "$1"
|
2007-11-28 17:02:12 +00:00
|
|
|
rc="$?"
|
2006-04-28 07:16:42 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
exit "$rc"
|
2006-04-28 07:14:48 +00:00
|
|
|
;;
|
2007-08-10 07:16:32 +00:00
|
|
|
listalgs|listpubkeys|\listcards|\rereadgroups)
|
2006-04-28 07:14:48 +00:00
|
|
|
op="$1"
|
|
|
|
shift
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_PLUTO_PID ]
|
2006-04-28 07:16:42 +00:00
|
|
|
then
|
2006-05-16 14:24:03 +00:00
|
|
|
$IPSEC_WHACK "$@" "--$op"
|
2007-11-28 17:02:12 +00:00
|
|
|
exit "$?"
|
|
|
|
else
|
|
|
|
if [ -e $IPSEC_CHARON_PID ]
|
|
|
|
then
|
|
|
|
exit 3
|
|
|
|
else
|
|
|
|
exit 7
|
|
|
|
fi
|
2006-05-04 07:55:42 +00:00
|
|
|
fi
|
2006-05-19 06:44:08 +00:00
|
|
|
;;
|
2007-04-14 18:09:44 +00:00
|
|
|
listcerts|listcacerts|listaacerts|\
|
2007-04-20 12:23:03 +00:00
|
|
|
listacerts|listgroups|listocspcerts|\
|
2007-02-14 01:08:41 +00:00
|
|
|
listcainfos|listcrls|listocsp|listall|\
|
2007-08-10 07:16:32 +00:00
|
|
|
rereadsecrets|rereadcacerts|rereadaacerts|\
|
|
|
|
rereadacerts|rereadocspcerts|rereadcrls|\
|
2007-02-14 01:08:41 +00:00
|
|
|
rereadall|purgeocsp)
|
2006-05-19 06:44:08 +00:00
|
|
|
op="$1"
|
2007-11-28 17:02:12 +00:00
|
|
|
rc=7
|
2006-05-19 06:44:08 +00:00
|
|
|
shift
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_PLUTO_PID ]
|
2006-05-19 06:44:08 +00:00
|
|
|
then
|
|
|
|
$IPSEC_WHACK "$@" "--$op"
|
2007-11-28 17:02:12 +00:00
|
|
|
rc="$?"
|
2006-05-19 06:44:08 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_CHARON_PID ]
|
2006-05-19 06:44:08 +00:00
|
|
|
then
|
2006-06-12 08:47:28 +00:00
|
|
|
$IPSEC_STROKE "$op" "$@"
|
2007-11-28 17:02:12 +00:00
|
|
|
rc="$?"
|
2006-05-19 06:44:08 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
exit "$rc"
|
2006-04-28 07:14:48 +00:00
|
|
|
;;
|
|
|
|
ready)
|
|
|
|
shift
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_PLUTO_PID ]
|
2006-05-04 07:55:42 +00:00
|
|
|
then
|
2006-05-16 14:24:03 +00:00
|
|
|
$IPSEC_WHACK --listen
|
2007-11-28 17:02:12 +00:00
|
|
|
exit 0
|
|
|
|
else
|
|
|
|
exit 7
|
2006-05-04 07:55:42 +00:00
|
|
|
fi
|
2006-04-28 07:14:48 +00:00
|
|
|
;;
|
|
|
|
reload)
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_STARTER_PID ]
|
2006-04-28 07:14:48 +00:00
|
|
|
then
|
2007-11-28 17:02:12 +00:00
|
|
|
echo "Reloading strongSwan IPsec configuration..." >&2
|
|
|
|
kill -s USR1 `cat $IPSEC_STARTER_PID`
|
|
|
|
exit 0
|
2006-04-28 07:14:48 +00:00
|
|
|
else
|
2007-11-28 17:02:12 +00:00
|
|
|
echo "ipsec starter is not running" >&2
|
|
|
|
exit 7
|
2006-04-28 07:14:48 +00:00
|
|
|
fi
|
|
|
|
exit 0
|
|
|
|
;;
|
|
|
|
restart)
|
|
|
|
$IPSEC_SBINDIR/ipsec stop
|
|
|
|
sleep 2
|
|
|
|
shift
|
|
|
|
$IPSEC_SBINDIR/ipsec start "$@"
|
|
|
|
exit 0
|
|
|
|
;;
|
|
|
|
route|unroute)
|
|
|
|
op="$1"
|
2007-11-28 17:02:12 +00:00
|
|
|
rc=7
|
2006-04-28 07:14:48 +00:00
|
|
|
shift
|
2006-05-29 07:17:55 +00:00
|
|
|
if [ "$#" -ne 1 ]
|
|
|
|
then
|
2007-11-28 17:02:12 +00:00
|
|
|
echo "Usage: ipsec $op <connection name>"
|
|
|
|
exit 2
|
2006-05-29 07:17:55 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_PLUTO_PID ]
|
2006-05-04 07:55:42 +00:00
|
|
|
then
|
2006-05-16 14:24:03 +00:00
|
|
|
$IPSEC_WHACK --name "$1" "--$op"
|
2007-11-28 17:02:12 +00:00
|
|
|
rc="$?"
|
2006-05-04 07:55:42 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_CHARON_PID ]
|
2006-07-21 13:31:53 +00:00
|
|
|
then
|
|
|
|
$IPSEC_STROKE "$op" "$1"
|
2007-11-28 17:02:12 +00:00
|
|
|
rc="$?"
|
2006-07-21 13:31:53 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
exit "$rc"
|
2006-04-28 07:14:48 +00:00
|
|
|
;;
|
|
|
|
scencrypt|scdecrypt)
|
|
|
|
op="$1"
|
|
|
|
shift
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_PLUTO_PID ]
|
2006-05-04 07:55:42 +00:00
|
|
|
then
|
2006-05-16 14:24:03 +00:00
|
|
|
$IPSEC_WHACK "--$op" "$@"
|
2007-11-28 17:02:12 +00:00
|
|
|
exit "$?"
|
|
|
|
else
|
|
|
|
exit 7
|
2006-05-04 07:55:42 +00:00
|
|
|
fi
|
2006-04-28 07:14:48 +00:00
|
|
|
;;
|
2006-04-28 08:18:47 +00:00
|
|
|
secrets)
|
2007-11-28 17:02:12 +00:00
|
|
|
rc=7
|
|
|
|
if [ -e $IPSEC_PLUTO_PID ]
|
2006-05-04 07:55:42 +00:00
|
|
|
then
|
2006-05-16 14:24:03 +00:00
|
|
|
$IPSEC_WHACK --rereadsecrets
|
2007-11-28 17:02:12 +00:00
|
|
|
rc="$?"
|
2006-05-04 07:55:42 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_CHARON_PID ]
|
|
|
|
then
|
|
|
|
$IPSEC_STROKE rereadsecrets
|
|
|
|
rc="$?"
|
|
|
|
fi
|
|
|
|
exit "$rc"
|
2006-05-04 07:55:42 +00:00
|
|
|
;;
|
2006-04-28 07:14:48 +00:00
|
|
|
start)
|
|
|
|
shift
|
2006-05-16 14:24:03 +00:00
|
|
|
exec $IPSEC_STARTER "$@"
|
2006-04-28 07:14:48 +00:00
|
|
|
;;
|
|
|
|
status|statusall)
|
|
|
|
op="$1"
|
2007-11-28 17:02:12 +00:00
|
|
|
rc=7
|
2006-04-28 07:14:48 +00:00
|
|
|
shift
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ $# -eq 0 ]
|
2006-04-28 07:14:48 +00:00
|
|
|
then
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_PLUTO_PID ]
|
2006-05-04 07:55:42 +00:00
|
|
|
then
|
2006-05-16 14:24:03 +00:00
|
|
|
$IPSEC_WHACK "--$op"
|
2007-11-28 17:02:12 +00:00
|
|
|
rc="$?"
|
2006-05-04 07:55:42 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_CHARON_PID ]
|
2006-05-04 07:55:42 +00:00
|
|
|
then
|
2006-05-16 14:24:03 +00:00
|
|
|
$IPSEC_STROKE "$op"
|
2007-11-28 17:02:12 +00:00
|
|
|
rc="$?"
|
2006-05-04 07:55:42 +00:00
|
|
|
fi
|
2006-04-28 07:14:48 +00:00
|
|
|
else
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_PLUTO_PID ]
|
2006-05-04 07:55:42 +00:00
|
|
|
then
|
2006-05-16 14:24:03 +00:00
|
|
|
$IPSEC_WHACK --name "$1" "--$op"
|
2007-11-28 17:02:12 +00:00
|
|
|
rc="$?"
|
2006-05-04 07:55:42 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_CHARON_PID ]
|
2006-05-04 07:55:42 +00:00
|
|
|
then
|
2006-05-16 14:24:03 +00:00
|
|
|
$IPSEC_STROKE "$op" "$1"
|
2007-11-28 17:02:12 +00:00
|
|
|
rc="$?"
|
2006-05-04 07:55:42 +00:00
|
|
|
fi
|
2006-04-28 07:14:48 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
exit "$rc"
|
2006-04-28 07:14:48 +00:00
|
|
|
;;
|
|
|
|
stop)
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_STARTER_PID ]
|
2006-04-28 07:14:48 +00:00
|
|
|
then
|
2007-11-28 17:02:12 +00:00
|
|
|
echo "Stopping strongSwan IPsec..." >&2
|
|
|
|
kill `cat $IPSEC_STARTER_PID`
|
|
|
|
exit 0
|
2006-04-28 07:14:48 +00:00
|
|
|
else
|
2007-11-28 17:02:12 +00:00
|
|
|
echo "ipsec starter is not running" >&2
|
|
|
|
exit 7
|
2006-04-28 07:14:48 +00:00
|
|
|
fi
|
|
|
|
;;
|
|
|
|
up)
|
|
|
|
shift
|
2006-05-29 07:17:55 +00:00
|
|
|
if [ "$#" -ne 1 ]
|
|
|
|
then
|
|
|
|
echo "Usage: ipsec up <connection name>"
|
2007-11-28 17:02:12 +00:00
|
|
|
exit 2
|
2006-05-29 07:17:55 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
rc=7
|
|
|
|
if [ -e $IPSEC_PLUTO_PID ]
|
2006-05-04 07:55:42 +00:00
|
|
|
then
|
2006-05-16 14:24:03 +00:00
|
|
|
$IPSEC_WHACK --name "$1" --initiate
|
2007-11-28 17:02:12 +00:00
|
|
|
rc="$?"
|
2006-05-04 07:55:42 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_CHARON_PID ]
|
2006-04-28 07:16:42 +00:00
|
|
|
then
|
2007-11-28 17:02:12 +00:00
|
|
|
$IPSEC_STROKE up "$1"
|
|
|
|
rc="$?"
|
2006-04-28 07:16:42 +00:00
|
|
|
fi
|
2007-11-28 17:02:12 +00:00
|
|
|
exit "$rc"
|
2006-04-28 07:14:48 +00:00
|
|
|
;;
|
|
|
|
update)
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ -e $IPSEC_STARTER_PID ]
|
2006-04-28 07:14:48 +00:00
|
|
|
then
|
2006-05-04 07:55:42 +00:00
|
|
|
echo "Updating strongSwan IPsec configuration..." >&2
|
|
|
|
kill -s HUP `cat $IPSEC_STARTER_PID`
|
2007-11-28 17:02:12 +00:00
|
|
|
exit 0
|
2006-04-28 07:14:48 +00:00
|
|
|
else
|
2006-05-04 07:55:42 +00:00
|
|
|
echo "ipsec starter is not running" >&2
|
2007-11-28 17:02:12 +00:00
|
|
|
exit 7
|
2006-04-28 07:14:48 +00:00
|
|
|
fi
|
|
|
|
;;
|
|
|
|
version|--version)
|
2006-05-16 14:24:03 +00:00
|
|
|
echo "Linux $IPSEC_NAME $IPSEC_VERSION"
|
2007-06-27 07:25:19 +00:00
|
|
|
echo -e $IPSEC_DISTRO
|
2006-04-28 07:14:48 +00:00
|
|
|
echo "See \`ipsec --copyright' for copyright information."
|
|
|
|
exit 0
|
|
|
|
;;
|
|
|
|
--*)
|
|
|
|
echo "$0: unknown option \`$1' (perhaps command name was omitted?)" >&2
|
2007-11-28 17:02:12 +00:00
|
|
|
exit 2
|
2006-04-28 07:14:48 +00:00
|
|
|
;;
|
|
|
|
esac
|
|
|
|
|
|
|
|
cmd="$1"
|
|
|
|
shift
|
|
|
|
|
2006-05-16 14:24:03 +00:00
|
|
|
path="$IPSEC_DIR/$cmd"
|
2006-04-28 07:14:48 +00:00
|
|
|
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ ! -x "$path" ]
|
2006-04-28 07:14:48 +00:00
|
|
|
then
|
2006-05-16 14:24:03 +00:00
|
|
|
path="$IPSEC_DIR/$cmd"
|
2007-11-28 17:02:12 +00:00
|
|
|
if [ ! -x "$path" ]
|
2006-04-28 07:14:48 +00:00
|
|
|
then
|
|
|
|
echo "$0: unknown IPsec command \`$cmd' (\`ipsec --help' for list)" >&2
|
2007-11-28 17:02:12 +00:00
|
|
|
exit 2
|
2006-04-28 07:14:48 +00:00
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
exec $path "$@"
|