Remove keys in a safer way

This commit is contained in:
Bob Mottram 2016-05-07 16:50:00 +01:00
parent 2a9f449460
commit 7ca018673b
1 changed files with 43 additions and 33 deletions

View File

@ -38,87 +38,97 @@ MY_USERNAME=$1
COMPLETION_FILE=$HOME/${PROJECT_NAME}-completed.txt COMPLETION_FILE=$HOME/${PROJECT_NAME}-completed.txt
if [ ! $MY_USERNAME ]; then if [ ! $MY_USERNAME ]; then
echo $'Please specify a username to remove' echo $'Please specify a username to remove'
exit 1 exit 1
fi fi
if [[ $MY_USERNAME == 'git' || $MY_USERNAME == 'mirrors' ]]; then if [[ $MY_USERNAME == 'git' || $MY_USERNAME == 'mirrors' ]]; then
echo $'Cannot remove reserved users' echo $'Cannot remove reserved users'
exit 2 exit 2
fi fi
if [ ! -d /home/$MY_USERNAME ]; then if [ ! -d /home/$MY_USERNAME ]; then
echo $"Home directory does not exist for $MY_USERNAME" echo $"Home directory does not exist for $MY_USERNAME"
exit 3 exit 3
fi fi
if [ ! -f $COMPLETION_FILE ]; then if [ ! -f $COMPLETION_FILE ]; then
echo $"$COMPLETION_FILE not found" echo $"$COMPLETION_FILE not found"
exit 4 exit 4
fi fi
if ! grep -q "Admin user" $COMPLETION_FILE; then if ! grep -q "Admin user" $COMPLETION_FILE; then
echo $"No admin user specified in $COMPLETION_FILE" echo $"No admin user specified in $COMPLETION_FILE"
exit 5 exit 5
fi fi
ADMIN_USERNAME=$(cat $COMPLETION_FILE | grep "Admin user" | awk -F ':' '{print $2}') ADMIN_USERNAME=$(cat $COMPLETION_FILE | grep "Admin user" | awk -F ':' '{print $2}')
if [ ! $ADMIN_USERNAME ]; then if [ ! $ADMIN_USERNAME ]; then
echo $"No admin username specified in $COMPLETION_FILE" echo $"No admin username specified in $COMPLETION_FILE"
exit 6 exit 6
fi fi
if [[ $MY_USERNAME == $ADMIN_USERNAME ]]; then if [[ $MY_USERNAME == $ADMIN_USERNAME ]]; then
echo $"The administrator user cannot be removed" echo $"The administrator user cannot be removed"
exit 7 exit 7
fi fi
echo $'>>> REMOVE USER <<<' echo $'>>> REMOVE USER <<<'
read -p $"Do you really wish to remove the user '$MY_USERNAME' (y/n) ?" yn read -p $"Do you really wish to remove the user '$MY_USERNAME' (y/n) ?" yn
if [[ $yn != 'y' && $yn != 'Y' && $yn != 'yes' && $yn != 'Yes' && $yn != 'YES' ]]; then if [[ $yn != 'y' && $yn != 'Y' && $yn != 'yes' && $yn != 'Yes' && $yn != 'YES' ]]; then
echo $"User $MY_USERNAME was not removed" echo $"User $MY_USERNAME was not removed"
exit 8 exit 8
fi fi
if grep -q "install_xmpp" $COMPLETION_FILE; then if grep -q "install_xmpp" $COMPLETION_FILE; then
${PROJECT_NAME}-rmxmpp -e "$MY_USERNAME@$HOSTNAME" ${PROJECT_NAME}-rmxmpp -e "$MY_USERNAME@$HOSTNAME"
fi fi
if grep -q "Blog domain" $COMPLETION_FILE; then if grep -q "Blog domain" $COMPLETION_FILE; then
FULLBLOG_DOMAIN_NAME=$(cat $COMPLETION_FILE | grep "Blog domain" | awk -F ':' '{print $2}') FULLBLOG_DOMAIN_NAME=$(cat $COMPLETION_FILE | grep "Blog domain" | awk -F ':' '{print $2}')
if [ -f /var/www/$FULLBLOG_DOMAIN_NAME/htdocs/config/users/$MY_USERNAME.ini ]; then if [ -f /var/www/$FULLBLOG_DOMAIN_NAME/htdocs/config/users/$MY_USERNAME.ini ]; then
rm /var/www/$FULLBLOG_DOMAIN_NAME/htdocs/config/users/$MY_USERNAME.ini rm /var/www/$FULLBLOG_DOMAIN_NAME/htdocs/config/users/$MY_USERNAME.ini
fi fi
fi fi
if grep -q "install_sip" $COMPLETION_FILE; then if grep -q "install_sip" $COMPLETION_FILE; then
${PROJECT_NAME}-rmsipuser $MY_USERNAME ${PROJECT_NAME}-rmsipuser $MY_USERNAME
fi fi
if grep -q "GNU Social domain" $COMPLETION_FILE; then if grep -q "GNU Social domain" $COMPLETION_FILE; then
MICROBLOG_DOMAIN_NAME=$(cat $COMPLETION_FILE | grep "GNU Social domain" | awk -F ':' '{print $2}') MICROBLOG_DOMAIN_NAME=$(cat $COMPLETION_FILE | grep "GNU Social domain" | awk -F ':' '{print $2}')
if [ -d /var/www/$MICROBLOG_DOMAIN_NAME ]; then if [ -d /var/www/$MICROBLOG_DOMAIN_NAME ]; then
cd /var/www/$MICROBLOG_DOMAIN_NAME/htdocs cd /var/www/$MICROBLOG_DOMAIN_NAME/htdocs
php scripts/deleteprofile.php -n $MY_USERNAME -y php scripts/deleteprofile.php -n $MY_USERNAME -y
echo $'Removed GNU Social user' echo $'Removed GNU Social user'
fi fi
fi fi
if [ -f /etc/nginx/.htpasswd ]; then if [ -f /etc/nginx/.htpasswd ]; then
if grep "${MY_USERNAME}:" /etc/nginx/.htpasswd; then if grep "${MY_USERNAME}:" /etc/nginx/.htpasswd; then
htpasswd -D /etc/nginx/.htpasswd $MY_USERNAME htpasswd -D /etc/nginx/.htpasswd $MY_USERNAME
fi fi
fi fi
# remove user from SIP TURN/STUN # remove user from SIP TURN/STUN
if [ -d /etc/turnserver ]; then if [ -d /etc/turnserver ]; then
sed -i "/${MY_USERNAME}:/d" /etc/turnserver/turnusers.txt sed -i "/${MY_USERNAME}:/d" /etc/turnserver/turnusers.txt
fi
# remove gpg keys
if [ -d /home/$MY_USERNAME/.gnupg ]; then
shred -u /home/$MY_USERNAME/.gnupg/*
fi
# remove ssh keys
if [ -d /home/$MY_USERNAME/.ssh ]; then
shred -u /home/$MY_USERNAME/.ssh/*
fi fi
userdel -r $MY_USERNAME userdel -r $MY_USERNAME
if [ -d /home/$MY_USERNAME ]; then if [ -d /home/$MY_USERNAME ]; then
rm -rf /home/$MY_USERNAME rm -rf /home/$MY_USERNAME
fi fi
echo $"User $MY_USERNAME was removed" echo $"User $MY_USERNAME was removed"