Compare commits
7 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| bde91186e7 | |||
| 01cd128311 | |||
| 794d2c0838 | |||
| b6d3471b50 | |||
| abc3a45733 | |||
| 7e8582287e | |||
| 0834d4af5e |
+1
-2
@@ -1,2 +1 @@
|
||||
/openwsmand.8.gz
|
||||
/v2.7.1.tar.gz
|
||||
openwsman-2.2.3.tar.bz2
|
||||
|
||||
@@ -1,13 +0,0 @@
|
||||
diff -up openwsman-2.6.8/etc/pam/openwsman.orig openwsman-2.6.8/etc/pam/openwsman
|
||||
--- openwsman-2.6.8/etc/pam/openwsman.orig 2018-11-21 13:51:52.776325243 +0100
|
||||
+++ openwsman-2.6.8/etc/pam/openwsman 2018-11-21 13:54:17.066351134 +0100
|
||||
@@ -2,6 +2,6 @@
|
||||
auth required pam_unix.so nullok
|
||||
auth required pam_nologin.so
|
||||
account required pam_unix.so
|
||||
-password required pam_cracklib.so nullok
|
||||
-password required pam_unix.so nullok use_first_pass use_authtok nis shadow
|
||||
-session required pam_unix.so none
|
||||
+password required pam_pwquality.so
|
||||
+password required pam_unix.so nullok use_first_pass use_authtok
|
||||
+session required pam_unix.so
|
||||
@@ -1,12 +0,0 @@
|
||||
diff -up openwsman-2.4.12/bindings/ruby/extconf.rb.orig openwsman-2.4.12/bindings/ruby/extconf.rb
|
||||
--- openwsman-2.4.12/bindings/ruby/extconf.rb.orig 2015-02-09 09:28:58.232581263 +0100
|
||||
+++ openwsman-2.4.12/bindings/ruby/extconf.rb 2015-02-09 09:38:22.836772879 +0100
|
||||
@@ -32,7 +32,7 @@ swig = find_executable("swig")
|
||||
raise "SWIG not found" unless swig
|
||||
|
||||
major, minor, path = RUBY_VERSION.split(".")
|
||||
-raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i")
|
||||
+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.1/include/ -o openwsman_wrap.c openwsman.i")
|
||||
|
||||
$CPPFLAGS = "-I/usr/include/openwsman -I.."
|
||||
|
||||
@@ -1,135 +0,0 @@
|
||||
diff -up openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig openwsman-2.7.0/src/server/shttpd/compat_unix.h
|
||||
--- openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig 2020-05-25 15:16:28.000000000 +0200
|
||||
+++ openwsman-2.7.0/src/server/shttpd/compat_unix.h 2021-03-09 09:15:26.750942006 +0100
|
||||
@@ -27,10 +27,6 @@
|
||||
pthread_create(&tid, NULL, (void *(*)(void *))a, c); } while (0)
|
||||
#endif /* !NO_THREADS */
|
||||
|
||||
-#ifndef SSL_LIB
|
||||
-#define SSL_LIB "libssl.so"
|
||||
-#endif
|
||||
-
|
||||
#define DIRSEP '/'
|
||||
#define IS_DIRSEP_CHAR(c) ((c) == '/')
|
||||
#define O_BINARY 0
|
||||
diff -up openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig openwsman-2.7.0/src/server/shttpd/io_ssl.c
|
||||
--- openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig 2020-05-25 15:16:28.000000000 +0200
|
||||
+++ openwsman-2.7.0/src/server/shttpd/io_ssl.c 2021-03-09 09:15:26.750942006 +0100
|
||||
@@ -11,28 +11,6 @@
|
||||
#include "defs.h"
|
||||
|
||||
#if !defined(NO_SSL)
|
||||
-struct ssl_func ssl_sw[] = {
|
||||
- {"SSL_free", {0}},
|
||||
- {"SSL_accept", {0}},
|
||||
- {"SSL_connect", {0}},
|
||||
- {"SSL_read", {0}},
|
||||
- {"SSL_write", {0}},
|
||||
- {"SSL_get_error", {0}},
|
||||
- {"SSL_set_fd", {0}},
|
||||
- {"SSL_new", {0}},
|
||||
- {"SSL_CTX_new", {0}},
|
||||
-#if OPENSSL_VERSION_NUMBER < 0x10100000L
|
||||
- {"SSLv23_server_method", {0}},
|
||||
- {"SSL_library_init", {0}},
|
||||
-#else
|
||||
- {"TLS_server_method", {0}},
|
||||
- {"OPENSSL_init_ssl", {0}},
|
||||
-#endif
|
||||
- {"SSL_CTX_use_PrivateKey_file", {0}},
|
||||
- {"SSL_CTX_use_certificate_file",{0}},
|
||||
- {NULL, {0}}
|
||||
-};
|
||||
-
|
||||
void
|
||||
_shttpd_ssl_handshake(struct stream *stream)
|
||||
{
|
||||
diff -up openwsman-2.7.0/src/server/shttpd/shttpd.c.orig openwsman-2.7.0/src/server/shttpd/shttpd.c
|
||||
--- openwsman-2.7.0/src/server/shttpd/shttpd.c.orig 2020-05-25 15:16:28.000000000 +0200
|
||||
+++ openwsman-2.7.0/src/server/shttpd/shttpd.c 2021-03-09 09:16:58.843241510 +0100
|
||||
@@ -1489,25 +1489,13 @@ set_ssl(struct shttpd_ctx *ctx, const ch
|
||||
int retval = FALSE;
|
||||
EC_KEY* key;
|
||||
|
||||
- /* Load SSL library dynamically */
|
||||
- if ((lib = dlopen(SSL_LIB, RTLD_LAZY)) == NULL) {
|
||||
- _shttpd_elog(E_LOG, NULL, "set_ssl: cannot load %s", SSL_LIB);
|
||||
- return (FALSE);
|
||||
- }
|
||||
-
|
||||
- for (fp = ssl_sw; fp->name != NULL; fp++)
|
||||
- if ((fp->ptr.v_void = dlsym(lib, fp->name)) == NULL) {
|
||||
- _shttpd_elog(E_LOG, NULL,"set_ssl: cannot find %s", fp->name);
|
||||
- return (FALSE);
|
||||
- }
|
||||
-
|
||||
/* Initialize SSL crap */
|
||||
|
||||
#if OPENSSL_VERSION_NUMBER < 0x10100000L
|
||||
SSL_library_init();
|
||||
if ((CTX = SSL_CTX_new(SSLv23_server_method())) == NULL)
|
||||
#else
|
||||
- OPENSSL_init_ssl();
|
||||
+ OPENSSL_init_ssl(0, NULL);
|
||||
if ((CTX = SSL_CTX_new(TLS_server_method())) == NULL)
|
||||
#endif
|
||||
_shttpd_elog(E_LOG, NULL, "SSL_CTX_new error");
|
||||
diff -up openwsman-2.7.0/src/server/shttpd/ssl.h.orig openwsman-2.7.0/src/server/shttpd/ssl.h
|
||||
--- openwsman-2.7.0/src/server/shttpd/ssl.h.orig 2020-05-25 15:16:28.000000000 +0200
|
||||
+++ openwsman-2.7.0/src/server/shttpd/ssl.h 2021-03-09 09:15:26.750942006 +0100
|
||||
@@ -12,55 +12,4 @@
|
||||
|
||||
#include <openssl/ssl.h>
|
||||
|
||||
-#else
|
||||
-
|
||||
-/*
|
||||
- * Snatched from OpenSSL includes. I put the prototypes here to be independent
|
||||
- * from the OpenSSL source installation. Having this, shttpd + SSL can be
|
||||
- * built on any system with binary SSL libraries installed.
|
||||
- */
|
||||
-
|
||||
-typedef struct ssl_st SSL;
|
||||
-typedef struct ssl_method_st SSL_METHOD;
|
||||
-typedef struct ssl_ctx_st SSL_CTX;
|
||||
-
|
||||
-#define SSL_ERROR_WANT_READ 2
|
||||
-#define SSL_ERROR_WANT_WRITE 3
|
||||
-#define SSL_ERROR_SYSCALL 5
|
||||
-#define SSL_FILETYPE_PEM 1
|
||||
-
|
||||
-#endif
|
||||
-
|
||||
-/*
|
||||
- * Dynamically loaded SSL functionality
|
||||
- */
|
||||
-struct ssl_func {
|
||||
- const char *name; /* SSL function name */
|
||||
- union variant ptr; /* Function pointer */
|
||||
-};
|
||||
-
|
||||
-extern struct ssl_func ssl_sw[];
|
||||
-
|
||||
-#define FUNC(x) ssl_sw[x].ptr.v_func
|
||||
-
|
||||
-#define SSL_free(x) (* (void (*)(SSL *)) FUNC(0))(x)
|
||||
-#define SSL_accept(x) (* (int (*)(SSL *)) FUNC(1))(x)
|
||||
-#define SSL_connect(x) (* (int (*)(SSL *)) FUNC(2))(x)
|
||||
-#define SSL_read(x,y,z) (* (int (*)(SSL *, void *, int)) FUNC(3))((x),(y),(z))
|
||||
-#define SSL_write(x,y,z) \
|
||||
- (* (int (*)(SSL *, const void *,int)) FUNC(4))((x), (y), (z))
|
||||
-#define SSL_get_error(x,y)(* (int (*)(SSL *, int)) FUNC(5))((x), (y))
|
||||
-#define SSL_set_fd(x,y) (* (int (*)(SSL *, int)) FUNC(6))((x), (y))
|
||||
-#define SSL_new(x) (* (SSL * (*)(SSL_CTX *)) FUNC(7))(x)
|
||||
-#define SSL_CTX_new(x) (* (SSL_CTX * (*)(const SSL_METHOD *)) FUNC(8))(x)
|
||||
-#if OPENSSL_VERSION_NUMBER < 0x10100000L
|
||||
-#define SSLv23_server_method() (* (SSL_METHOD * (*)(void)) FUNC(9))()
|
||||
-#define SSL_library_init() (* (int (*)(void)) FUNC(10))()
|
||||
-#else
|
||||
-#define TLS_server_method() (* (SSL_METHOD * (*)(void)) FUNC(9))()
|
||||
-#define OPENSSL_init_ssl() (* (int (*)(void)) FUNC(10))()
|
||||
#endif
|
||||
-#define SSL_CTX_use_PrivateKey_file(x,y,z) (* (int (*)(SSL_CTX *, \
|
||||
- const char *, int)) FUNC(11))((x), (y), (z))
|
||||
-#define SSL_CTX_use_certificate_file(x,y,z) (* (int (*)(SSL_CTX *, \
|
||||
- const char *, int)) FUNC(12))((x), (y), (z))
|
||||
@@ -1,39 +0,0 @@
|
||||
diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/wsmand-listener.c.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/wsmand-listener.c
|
||||
--- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/wsmand-listener.c.orig 2016-07-27 16:03:55.000000000 +0200
|
||||
+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/wsmand-listener.c 2018-01-22 13:05:04.478923300 +0100
|
||||
@@ -344,6 +344,35 @@ DONE:
|
||||
if (fault_reason == NULL) {
|
||||
// this is a way to segfault, investigate
|
||||
//fault_reason = shttpd_reason_phrase(status);
|
||||
+ // ugly workaround follows...
|
||||
+ switch (status) {
|
||||
+ case 200:
|
||||
+ fault_reason = "OK";
|
||||
+ break;
|
||||
+ case 400:
|
||||
+ fault_reason = "Bad request";
|
||||
+ break;
|
||||
+ case 401:
|
||||
+ fault_reason = "Unauthorized";
|
||||
+ break;
|
||||
+ case 403:
|
||||
+ fault_reason = "Forbidden";
|
||||
+ break;
|
||||
+ case 404:
|
||||
+ fault_reason = "Not found";
|
||||
+ break;
|
||||
+ case 500:
|
||||
+ fault_reason = "Internal Error";
|
||||
+ break;
|
||||
+ case 501:
|
||||
+ fault_reason = "Not implemented";
|
||||
+ break;
|
||||
+ case 415:
|
||||
+ fault_reason = "Unsupported Media Type";
|
||||
+ break;
|
||||
+ default:
|
||||
+ fault_reason = "";
|
||||
+ }
|
||||
}
|
||||
debug("Response status=%d (%s)", status, fault_reason);
|
||||
|
||||
@@ -1,12 +0,0 @@
|
||||
diff -up openwsman-2.7.1/etc/ssleay.cnf.orig openwsman-2.7.1/etc/ssleay.cnf
|
||||
--- openwsman-2.7.1/etc/ssleay.cnf.orig 2021-11-09 08:27:48.577749509 +0100
|
||||
+++ openwsman-2.7.1/etc/ssleay.cnf 2021-11-09 08:28:10.499967010 +0100
|
||||
@@ -3,7 +3,7 @@
|
||||
#
|
||||
|
||||
[ req ]
|
||||
-default_bits = 1024
|
||||
+default_bits = 2048
|
||||
default_keyfile = privkey.pem
|
||||
distinguished_name = req_distinguished_name
|
||||
|
||||
@@ -1,12 +0,0 @@
|
||||
diff -up openwsman-2.7.1/bindings/ruby/helpers.h.orig openwsman-2.7.1/bindings/ruby/helpers.h
|
||||
--- openwsman-2.7.1/bindings/ruby/helpers.h.orig 2021-04-07 17:25:55.000000000 +0200
|
||||
+++ openwsman-2.7.1/bindings/ruby/helpers.h 2022-10-21 08:36:24.901459057 +0200
|
||||
@@ -47,7 +47,7 @@
|
||||
*
|
||||
*/
|
||||
|
||||
-#if SWIGVERSION > 0x020004
|
||||
+#if SWIG_VERSION > 0x020004
|
||||
#define KLASS_DECL(k,t) swig_class *k = (swig_class *)(t->clientdata)
|
||||
#define KLASS_OF(x) x->klass
|
||||
#else
|
||||
@@ -1,56 +0,0 @@
|
||||
diff -up openwsman-2.7.1/src/lib/wsman-curl-client-transport.c.orig openwsman-2.7.1/src/lib/wsman-curl-client-transport.c
|
||||
--- openwsman-2.7.1/src/lib/wsman-curl-client-transport.c.orig 2021-04-07 17:25:55.000000000 +0200
|
||||
+++ openwsman-2.7.1/src/lib/wsman-curl-client-transport.c 2022-07-19 09:25:22.435355610 +0200
|
||||
@@ -459,6 +459,7 @@ wsmc_handler( WsManClient *cl,
|
||||
long http_code;
|
||||
long auth_avail = 0;
|
||||
char *_user = NULL, *_pass = NULL;
|
||||
+ int _no_auth = 0; /* 0 if authentication is used, 1 if no authentication was used */
|
||||
u_buf_t *response = NULL;
|
||||
//char *soapaction;
|
||||
char *tmp_str = NULL;
|
||||
@@ -564,6 +565,7 @@ wsmc_handler( WsManClient *cl,
|
||||
_user = wsmc_get_user(cl);
|
||||
_pass = wsmc_get_password(cl);
|
||||
if (_user && _pass && cl->data.auth_set) {
|
||||
+ _no_auth = 0;
|
||||
r = curl_easy_setopt(curl, CURLOPT_HTTPAUTH, cl->data.auth_set);
|
||||
if (r != CURLE_OK) {
|
||||
cl->fault_string = u_strdup(curl_easy_strerror(r));
|
||||
@@ -584,6 +586,11 @@ wsmc_handler( WsManClient *cl,
|
||||
curl_err("curl_easy_setopt(curl, CURLOPT_USERPWD, ..) failed");
|
||||
goto DONE;
|
||||
}
|
||||
+ } else {
|
||||
+ /* request without user credentials, remember this for
|
||||
+ * later use when it might become necessary to print an error message
|
||||
+ */
|
||||
+ _no_auth = 1;
|
||||
}
|
||||
|
||||
if (wsman_debug_level_debugged(DEBUG_LEVEL_MESSAGE)) {
|
||||
@@ -616,6 +623,24 @@ wsmc_handler( WsManClient *cl,
|
||||
break;
|
||||
case 401:
|
||||
// The server requires authentication.
|
||||
+ /* RFC 2616 states:
|
||||
+ *
|
||||
+ * If the request already included Authorization credentials, then the 401
|
||||
+ * response indicates that authorization has been refused for those
|
||||
+ * credentials. If the 401 response contains the same challenge as the
|
||||
+ * prior response, and the user agent has already attempted
|
||||
+ * authentication at least once, then the user SHOULD be presented the
|
||||
+ * entity that was given in the response, since that entity might
|
||||
+ * include relevant diagnostic information.
|
||||
+ */
|
||||
+ if (_no_auth == 0) {
|
||||
+ /* no authentication credentials were used. It is only
|
||||
+ * possible to write a message about the current situation. There
|
||||
+ * is no information about the last attempt to access the resource.
|
||||
+ * Maybe at a later point in time I will implement more state information.
|
||||
+ */
|
||||
+ fprintf(stdout,"Authentication failed, please retry\n");
|
||||
+ }
|
||||
break;
|
||||
default:
|
||||
// The status code does not indicate success.
|
||||
@@ -0,0 +1,14 @@
|
||||
diff -up openwsman-2.2.3/AUTHORS.diff openwsman-2.2.3/AUTHORS
|
||||
--- openwsman-2.2.3/AUTHORS.diff 2010-04-20 10:42:40.156797595 -0500
|
||||
+++ openwsman-2.2.3/AUTHORS 2010-04-20 10:43:10.440803220 -0500
|
||||
@@ -13,5 +13,10 @@ Contributions and Patches by:
|
||||
Viktor Mihajlovski, IBM
|
||||
Klaus Kaempf, Novell
|
||||
|
||||
+AUTHORS from Spec file:
|
||||
+ Anas Nashif <anas.nashif@intel.com>
|
||||
+ Vadim Revyakin <vadim.revyakin@intel.com>
|
||||
+ Denis Sadykov <denis.sadykov@intel.com>
|
||||
+
|
||||
|
||||
If you think you name should be here and I forgot it, please let me know.
|
||||
@@ -0,0 +1,112 @@
|
||||
diff -up ./etc/init/openwsmand.sh.in.old ./etc/init/openwsmand.sh.in
|
||||
--- ./etc/init/openwsmand.sh.in.old 2010-08-04 16:43:40.212100948 -0500
|
||||
+++ ./etc/init/openwsmand.sh.in 2010-08-04 17:26:20.013849220 -0500
|
||||
@@ -4,15 +4,15 @@
|
||||
# Provides: openwsmand
|
||||
# Required-Start: $remote_fs
|
||||
# Required-Stop: $network
|
||||
-# Default-Start: 2 3 4 5
|
||||
-# Default-Stop: 0 1 6
|
||||
+# Default-Start:
|
||||
+# Default-Stop:
|
||||
# Short-Description: Openwsman Daemon
|
||||
# Description: openwsmand
|
||||
# Start/Stop the Openwsman Daemon
|
||||
### END INIT INFO
|
||||
#
|
||||
#
|
||||
-# chkconfig: 2345 36 64
|
||||
+# chkconfig: - 36 64
|
||||
# description: Openwsman Daemon
|
||||
# processname: openwsmand
|
||||
|
||||
@@ -56,20 +56,16 @@ start()
|
||||
echo "Using common server certificate /etc/ssl/servercerts/servercert.pem"
|
||||
ln -s /etc/ssl/servercerts/server{cert,key}.pem @SYSCONFDIR@
|
||||
else
|
||||
- echo "Generating Openwsman server public certificate and private key"
|
||||
- FQDN=`hostname --fqdn`
|
||||
- if [ "x${FQDN}" = "x" ]; then
|
||||
- FQDN=localhost.localdomain
|
||||
- fi
|
||||
-cat << EOF | sh @SYSCONFDIR@/owsmangencert.sh > /dev/null 2>&1
|
||||
---
|
||||
-SomeState
|
||||
-SomeCity
|
||||
-SomeOrganization
|
||||
-SomeOrganizationalUnit
|
||||
-${FQDN}
|
||||
-root@${FQDN}
|
||||
-EOF
|
||||
+ echo "FAILED: Starting openwsman server"
|
||||
+ echo "There is no ssl server key available for openwsman server to use."
|
||||
+ echo -e "Please generate one with the following script and start the openwsman service again:\n"
|
||||
+ echo "##################################"
|
||||
+ echo "/etc/openwsman/owsmangencert.sh"
|
||||
+ echo "================================="
|
||||
+
|
||||
+ echo "NOTE: The script uses /dev/random device for generating some random bits while generating the server key."
|
||||
+ echo " If this takes too long, you can replace the value of \"RANDFILE\" in @SYSCONFDIR@/ssleay.cnf with /dev/urandom."
|
||||
+
|
||||
fi
|
||||
fi
|
||||
|
||||
@@ -145,6 +141,10 @@ case "$1" in
|
||||
fi
|
||||
;;
|
||||
|
||||
+ condrestart)
|
||||
+ [ -e $lockfile ] && restart
|
||||
+ ;;
|
||||
+
|
||||
*)
|
||||
echo "Usage: $0 {restart|start|stop|reload|force-reload|status}"
|
||||
esac
|
||||
diff -up ./etc/owsmangencert.sh.in.old ./etc/owsmangencert.sh.in
|
||||
--- ./etc/owsmangencert.sh.in.old 2010-08-04 17:14:31.241100874 -0500
|
||||
+++ ./etc/owsmangencert.sh.in 2010-08-04 17:21:02.944850958 -0500
|
||||
@@ -1,7 +1,5 @@
|
||||
#!/bin/sh
|
||||
|
||||
-#!/bin/sh -e
|
||||
-
|
||||
CERTFILE=@SYSCONFDIR@/servercert.pem
|
||||
KEYFILE=@SYSCONFDIR@/serverkey.pem
|
||||
CNFFILE=@SYSCONFDIR@/ssleay.cnf
|
||||
@@ -15,19 +13,33 @@ if [ "$1" = "--force" ]; then
|
||||
shift
|
||||
fi
|
||||
|
||||
+FQDN=`hostname --fqdn`
|
||||
+ if [ "x${FQDN}" = "x" ]; then
|
||||
+ FQDN=localhost.localdomain
|
||||
+ fi
|
||||
echo
|
||||
echo creating selfsingned certificate
|
||||
echo "replace it with one signed by a certification authority (CA)"
|
||||
echo
|
||||
-echo enter your ServerName at the Common Name prompt
|
||||
+#echo enter your ServerName at the Common Name prompt
|
||||
echo
|
||||
|
||||
# use special .cnf, because with normal one no valid selfsigned
|
||||
# certificate is created
|
||||
|
||||
-export RANDFILE=/dev/random
|
||||
-openssl req -days 365 $@ -config $CNFFILE \
|
||||
+#export RANDFILE=/dev/random
|
||||
+cat <<EOF |openssl req -days 365 $@ -config $CNFFILE \
|
||||
-new -x509 -nodes -out $CERTFILE \
|
||||
-keyout $KEYFILE
|
||||
+--
|
||||
+SomeState
|
||||
+SomeCity
|
||||
+SomeOrganization
|
||||
+SomeOrganizationalUnit
|
||||
+${FQDN}
|
||||
+root@${FQDN}
|
||||
+EOF
|
||||
+
|
||||
+
|
||||
chmod 600 $KEYFILE
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
diff -up ./etc/ssleay.cnf.new ./etc/ssleay.cnf
|
||||
--- ./etc/ssleay.cnf.new 2009-12-16 17:04:15.000000000 -0600
|
||||
+++ ./etc/ssleay.cnf 2009-12-16 17:04:55.000000000 -0600
|
||||
@@ -2,7 +2,7 @@
|
||||
# SSLeay example configuration file.
|
||||
#
|
||||
|
||||
-RANDFILE = $ENV::HOME/.rnd
|
||||
+RANDFILE = /dev/random
|
||||
|
||||
[ req ]
|
||||
default_bits = 1024
|
||||
@@ -0,0 +1,29 @@
|
||||
diff -up ./bindings/ruby/Makefile.am.diff ./bindings/ruby/Makefile.am
|
||||
--- ./bindings/ruby/Makefile.am.diff 2010-08-02 16:57:20.407937479 -0500
|
||||
+++ ./bindings/ruby/Makefile.am 2010-08-02 16:57:54.718188163 -0500
|
||||
@@ -4,8 +4,10 @@
|
||||
|
||||
SUBDIRS = openwsman tests
|
||||
|
||||
-rubyarchdir = $(shell ruby -r rbconfig -e "vad = Config::CONFIG['vendorarchdir']; print(vad ? vad : Config::CONFIG['sitearchdir'])")
|
||||
-rubydir = $(shell ruby -r rbconfig -e "vd = Config::CONFIG['vendorlibdir']; print(vd ? vd : Config::CONFIG['sitelibdir'])")
|
||||
+#rubyarchdir = $(shell ruby -r rbconfig -e "vad = Config::CONFIG['vendorarchdir']; print(vad ? vad : Config::CONFIG['sitearchdir'])")
|
||||
+rubyarchdir = $(shell ruby -r rbconfig -e " print( Config::CONFIG['sitearchdir'])")
|
||||
+#rubydir = $(shell ruby -r rbconfig -e "vd = Config::CONFIG['vendorlibdir']; print(vd ? vd : Config::CONFIG['sitelibdir'])")
|
||||
+rubydir = $(shell ruby -r rbconfig -e " print(Config::CONFIG['sitelibdir'])")
|
||||
rubyincdir = $(shell ruby -r rbconfig -e "print(Config::CONFIG['archdir'])")
|
||||
|
||||
INCLUDES = \
|
||||
diff -up ./bindings/ruby/openwsman/Makefile.am.diff ./bindings/ruby/openwsman/Makefile.am
|
||||
--- ./bindings/ruby/openwsman/Makefile.am.diff 2010-08-02 16:58:05.201189127 -0500
|
||||
+++ ./bindings/ruby/openwsman/Makefile.am 2010-08-02 16:58:20.999937941 -0500
|
||||
@@ -2,7 +2,8 @@
|
||||
# Makefile.am for openwsman/bindings/ruby/openwsman
|
||||
#
|
||||
|
||||
-rubylibdir = $(shell ruby -r rbconfig -e "vld = Config::CONFIG['vendorlibdir']; print(vld ? vld : Config::CONFIG['sitelibdir'])")
|
||||
+#rubylibdir = $(shell ruby -r rbconfig -e "vld = Config::CONFIG['vendorlibdir']; print(vld ? vld : Config::CONFIG['sitelibdir'])")
|
||||
+rubylibdir = $(shell ruby -r rbconfig -e "print( Config::CONFIG['sitelibdir'])")
|
||||
|
||||
install-data-local:
|
||||
$(mkinstalldirs) $(DESTDIR)$(rubylibdir)/openwsman
|
||||
@@ -0,0 +1,82 @@
|
||||
diff -up ./acinclude.m4.old ./acinclude.m4
|
||||
--- ./acinclude.m4.old 2010-08-02 12:13:27.135937703 -0500
|
||||
+++ ./acinclude.m4 2010-08-02 12:15:07.896938631 -0500
|
||||
@@ -157,6 +157,20 @@ AC_SUBST(SFCC_LDFLAGS)
|
||||
# may extend this special exception to the GPL to apply to your
|
||||
# modified version as well.
|
||||
|
||||
+AC_DEFUN([SWIG_VERSION_GOOD],[
|
||||
+ AC_MSG_NOTICE([SWIG executable is '$SWIG'])
|
||||
+ SWIG_LIB=`$SWIG -swiglib`
|
||||
+ AC_MSG_NOTICE([SWIG library directory is '$SWIG_LIB'])
|
||||
+ SWIG_VERSION=`echo $(( $available_major * 100 * 100 + $available_minor * 100 + $available_patch ))`
|
||||
+ AC_MSG_NOTICE([SWIG version is '$SWIG_VERSION'])
|
||||
+ # AM_CONDITIONAL(SWIG_NEW_OPTIONS, test "$SWIG_VERSION" \> 10331)
|
||||
+])
|
||||
+
|
||||
+AC_DEFUN([SWIG_VERSION_BAD],[
|
||||
+ AC_MSG_WARN([SWIG version >= $1 is required. You have $swig_version. You should look at http://www.swig.org])
|
||||
+ SWIG='echo "Error: SWIG version >= $1 is required. You have '"$swig_version"'. You should look at http://www.swig.org" ; false'
|
||||
+])
|
||||
+
|
||||
AC_DEFUN([AC_PROG_SWIG],[
|
||||
AC_PATH_PROG([SWIG],[swig])
|
||||
if test -z "$SWIG" ; then
|
||||
@@ -199,19 +213,44 @@ AC_DEFUN([AC_PROG_SWIG],[
|
||||
if test -z "$available_patch" ; then
|
||||
[available_patch=0]
|
||||
fi
|
||||
- if test $available_major -ne $required_major \
|
||||
- -o $available_minor -ne $required_minor \
|
||||
- -o $available_patch -lt $required_patch ; then
|
||||
- AC_MSG_WARN([SWIG version >= $1 is required. You have $swig_version. You should look at http://www.swig.org])
|
||||
- SWIG='echo "Error: SWIG version >= $1 is required. You have '"$swig_version"'. You should look at http://www.swig.org" ; false'
|
||||
- else
|
||||
- AC_MSG_NOTICE([SWIG executable is '$SWIG'])
|
||||
- SWIG_LIB=`$SWIG -swiglib`
|
||||
- AC_MSG_NOTICE([SWIG library directory is '$SWIG_LIB'])
|
||||
- SWIG_VERSION=`echo $(( $available_major * 100 * 100 + $available_minor * 100 + $available_patch ))`
|
||||
- AC_MSG_NOTICE([SWIG version is '$SWIG_VERSION'])
|
||||
- # AM_CONDITIONAL(SWIG_NEW_OPTIONS, test "$SWIG_VERSION" \> 10331)
|
||||
- fi
|
||||
+
|
||||
+
|
||||
+
|
||||
+ if test $available_major -gt $required_major; then
|
||||
+ # the available major is greater than required major --GOOD
|
||||
+ SWIG_VERSION_GOOD()
|
||||
+
|
||||
+ elif test $available_major -lt $required_major ; then
|
||||
+ # the avialable major is less than required major -- BAD
|
||||
+ SWIG_VERSION_BAD()
|
||||
+ else
|
||||
+ # the available and require major are equal check the minor and patch versions.
|
||||
+
|
||||
+ if test $available_minor -gt $required_minor ; then
|
||||
+ # GOOD
|
||||
+ SWIG_VERSION_GOOD()
|
||||
+ elif test $avaialble_minor -lt $required_minor ; then
|
||||
+ # BAD
|
||||
+ SWIG_VERSION_BAD()
|
||||
+ else
|
||||
+ # the minor version are also equal
|
||||
+
|
||||
+ if test $available_patch -gt $required_patch ; then
|
||||
+ # GOOD
|
||||
+ SWIG_VERSION_GOOD()
|
||||
+ elif test $available_minor -lt $required_minor ; then
|
||||
+ # BAD
|
||||
+ SWIG_VERSION_BAD()
|
||||
+ else
|
||||
+ # all the available major, minor and patch levels are the same as the required -- GOOD
|
||||
+ SWIG_VERSION_GOOD()
|
||||
+ fi
|
||||
+ fi
|
||||
+ fi
|
||||
+
|
||||
+
|
||||
+
|
||||
+
|
||||
else
|
||||
AC_MSG_WARN([cannot determine SWIG version])
|
||||
SWIG='echo "Error: Cannot determine SWIG version. You should look at http://www.swig.org" ; false'
|
||||
@@ -1,7 +0,0 @@
|
||||
/usr/lib/systemd/system/openwsmand.* -- gen_context(system_u:object_r:openwsman_unit_file_t,s0)
|
||||
|
||||
/usr/sbin/openwsmand -- gen_context(system_u:object_r:openwsman_exec_t,s0)
|
||||
|
||||
/var/log/wsmand.* -- gen_context(system_u:object_r:openwsman_log_t,s0)
|
||||
|
||||
/var/run/wsmand.* -- gen_context(system_u:object_r:openwsman_run_t,s0)
|
||||
@@ -1,79 +0,0 @@
|
||||
## <summary>WS-Management Server</summary>
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Execute openwsman in the openwsman domin.
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed to transition.
|
||||
## </summary>
|
||||
## </param>
|
||||
#
|
||||
interface(`openwsman_domtrans',`
|
||||
gen_require(`
|
||||
type openwsman_t, openwsman_exec_t;
|
||||
')
|
||||
|
||||
corecmd_search_bin($1)
|
||||
domtrans_pattern($1, openwsman_exec_t, openwsman_t)
|
||||
')
|
||||
########################################
|
||||
## <summary>
|
||||
## Execute openwsman server in the openwsman domain.
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed to transition.
|
||||
## </summary>
|
||||
## </param>
|
||||
#
|
||||
interface(`openwsman_systemctl',`
|
||||
gen_require(`
|
||||
type openwsman_t;
|
||||
type openwsman_unit_file_t;
|
||||
')
|
||||
|
||||
systemd_exec_systemctl($1)
|
||||
init_reload_services($1)
|
||||
systemd_read_fifo_file_passwd_run($1)
|
||||
allow $1 openwsman_unit_file_t:file read_file_perms;
|
||||
allow $1 openwsman_unit_file_t:service manage_service_perms;
|
||||
|
||||
ps_process_pattern($1, openwsman_t)
|
||||
')
|
||||
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## All of the rules required to administrate
|
||||
## an openwsman environment
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed access.
|
||||
## </summary>
|
||||
## </param>
|
||||
## <rolecap/>
|
||||
#
|
||||
interface(`openwsman_admin',`
|
||||
gen_require(`
|
||||
type openwsman_t;
|
||||
type openwsman_unit_file_t;
|
||||
')
|
||||
|
||||
allow $1 openwsman_t:process { signal_perms };
|
||||
ps_process_pattern($1, openwsman_t)
|
||||
|
||||
tunable_policy(`deny_ptrace',`',`
|
||||
allow $1 openwsman_t:process ptrace;
|
||||
')
|
||||
|
||||
openwsman_systemctl($1)
|
||||
admin_pattern($1, openwsman_unit_file_t)
|
||||
allow $1 openwsman_unit_file_t:service all_service_perms;
|
||||
optional_policy(`
|
||||
systemd_passwd_agent_exec($1)
|
||||
systemd_read_fifo_file_passwd_run($1)
|
||||
')
|
||||
')
|
||||
+173
-706
File diff suppressed because it is too large
Load Diff
@@ -1,74 +0,0 @@
|
||||
policy_module(openwsman, 1.0.0)
|
||||
|
||||
########################################
|
||||
#
|
||||
# Declarations
|
||||
#
|
||||
|
||||
type openwsman_t;
|
||||
type openwsman_exec_t;
|
||||
init_daemon_domain(openwsman_t, openwsman_exec_t)
|
||||
|
||||
type openwsman_tmp_t;
|
||||
files_tmp_file(openwsman_tmp_t)
|
||||
|
||||
type openwsman_tmpfs_t;
|
||||
files_tmpfs_file(openwsman_tmpfs_t)
|
||||
|
||||
type openwsman_log_t;
|
||||
logging_log_file(openwsman_log_t)
|
||||
|
||||
type openwsman_run_t;
|
||||
files_pid_file(openwsman_run_t)
|
||||
|
||||
type openwsman_unit_file_t;
|
||||
systemd_unit_file(openwsman_unit_file_t)
|
||||
|
||||
########################################
|
||||
#
|
||||
# openwsman local policy
|
||||
#
|
||||
|
||||
allow openwsman_t self:capability setuid;
|
||||
|
||||
allow openwsman_t self:process { fork };
|
||||
allow openwsman_t self:fifo_file rw_fifo_file_perms;
|
||||
allow openwsman_t self:unix_stream_socket create_stream_socket_perms;
|
||||
allow openwsman_t self:tcp_socket { accept create_socket_perms listen };
|
||||
|
||||
manage_files_pattern(openwsman_t, openwsman_tmp_t, openwsman_tmp_t)
|
||||
manage_dirs_pattern(openwsman_t, openwsman_tmp_t, openwsman_tmp_t)
|
||||
files_tmp_filetrans(openwsman_t, openwsman_tmp_t, { dir file })
|
||||
|
||||
manage_files_pattern(openwsman_t, openwsman_tmpfs_t, openwsman_tmpfs_t)
|
||||
manage_dirs_pattern(openwsman_t, openwsman_tmpfs_t, openwsman_tmpfs_t)
|
||||
fs_tmpfs_filetrans(openwsman_t, openwsman_tmpfs_t, { dir file })
|
||||
|
||||
manage_files_pattern(openwsman_t, openwsman_log_t, openwsman_log_t)
|
||||
logging_log_filetrans(openwsman_t, openwsman_log_t, { file })
|
||||
|
||||
manage_files_pattern(openwsman_t, openwsman_run_t, openwsman_run_t)
|
||||
files_pid_filetrans(openwsman_t, openwsman_run_t, { file })
|
||||
|
||||
auth_use_nsswitch(openwsman_t)
|
||||
auth_domtrans_chkpwd(openwsman_t)
|
||||
|
||||
corenet_tcp_connect_pegasus_https_port(openwsman_t)
|
||||
corenet_tcp_bind_vnc_port(openwsman_t)
|
||||
corenet_tcp_bind_http_port(openwsman_t)
|
||||
|
||||
dev_read_urand(openwsman_t)
|
||||
|
||||
logging_send_syslog_msg(openwsman_t)
|
||||
logging_send_audit_msgs(openwsman_t)
|
||||
|
||||
optional_policy(`
|
||||
sblim_stream_connect_sfcbd(openwsman_t)
|
||||
sblim_rw_semaphores_sfcbd(openwsman_t)
|
||||
sblim_getattr_exec_sfcbd(openwsman_t)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
unconfined_domain(openwsman_t)
|
||||
')
|
||||
|
||||
@@ -1,12 +0,0 @@
|
||||
[Unit]
|
||||
Description=Openwsman WS-Management Service
|
||||
After=syslog.target
|
||||
|
||||
[Service]
|
||||
Type=forking
|
||||
ExecStart=/usr/sbin/openwsmand -S
|
||||
ExecStartPre=/etc/openwsman/owsmantestcert.sh
|
||||
PIDFile=/var/run/wsmand.pid
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -1,21 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
if [ ! -f "/etc/openwsman/serverkey.pem" ]; then
|
||||
if [ -f "/etc/ssl/servercerts/servercert.pem" \
|
||||
-a -f "/etc/ssl/servercerts/serverkey.pem" ]; then
|
||||
echo "Using common server certificate /etc/ssl/servercerts/servercert.pem"
|
||||
ln -s /etc/ssl/servercerts/server{cert,key}.pem /etc/openwsman
|
||||
exit 0
|
||||
else
|
||||
echo "FAILED: Starting openwsman server"
|
||||
echo "There is no ssl server key available for openwsman server to use."
|
||||
echo -e "Please generate one with the following script and start the openwsman service again:\n"
|
||||
echo "##################################"
|
||||
echo "/etc/openwsman/owsmangencert.sh"
|
||||
echo "================================="
|
||||
|
||||
echo "NOTE: The script uses /dev/random device for generating some random bits while generating the server key."
|
||||
echo " If this takes too long, you can replace the value of \"RANDFILE\" in /etc/openwsman/ssleay.cnf with /dev/urandom. Please understand the implications of replacing the RNADFILE."
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
@@ -1,2 +1 @@
|
||||
SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c
|
||||
SHA512 (v2.7.1.tar.gz) = 37738bc5be7b1c3fa961587fca4db74b8e7714fc0641a550682275fbe925b2c8e18a683cf493f4740e479f7461cc98392d3d675f4769f5cf04e7249f1e9ee880
|
||||
79f637d86a2cbd2d6763b80f68e4bc96 openwsman-2.2.3.tar.bz2
|
||||
|
||||
@@ -1,37 +0,0 @@
|
||||
- hosts: localhost
|
||||
|
||||
roles:
|
||||
- role: standard-test-beakerlib
|
||||
tags:
|
||||
- classic
|
||||
repositories:
|
||||
- repo: https://pagure.io/DSP_test.git
|
||||
dest: DSP_test
|
||||
version: master
|
||||
|
||||
tests:
|
||||
- DSP_test
|
||||
environment:
|
||||
# RPM package containing the policy module
|
||||
TEST_RPM: openwsman-selinux
|
||||
# policy module name
|
||||
TEST_POLICY: openwsman
|
||||
# policy sources will be extracted from corresponding .src.rpm
|
||||
# policy tar filename regexp (e.g. "usbguard-selinux*.tar.gz")
|
||||
# or empty string if policy sources are not inside a tar archive
|
||||
POLICY_TAR: ''
|
||||
# path to policy sources (in of the tar archive) -- <POLICY_TAR>/<POLICY_PATH>/<TEST_POLICY>.(te|if|fc)
|
||||
# or path in the src.rpm if there is no tar archive -- <src.rpm>/<POLICY_PATH>/<TEST_POLICY>.(te|if|fc)
|
||||
# can contain wildcards (e.g. for versions etc.)
|
||||
POLICY_PATH: .
|
||||
|
||||
required_packages:
|
||||
- policycoreutils
|
||||
- selinux-policy
|
||||
- selinux-policy-targeted
|
||||
- setools-console
|
||||
- libselinux-utils
|
||||
- rpm
|
||||
- tar
|
||||
- git
|
||||
- openwsman-server
|
||||
Reference in New Issue
Block a user