X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?a=blobdiff_plain;f=debian%2Fpostinst;h=2254b3819caa663a267b51d13be2fe5ad6a55a53;hb=HEAD;hp=cbd1e674dada34789a31c75c3c966a3c0582c346;hpb=7ace5424b7711c90d37117b174754cea041dc677;p=fail2ban-cn.git diff --git a/debian/postinst b/debian/postinst index cbd1e67..a669349 100755 --- a/debian/postinst +++ b/debian/postinst @@ -1,53 +1,66 @@ #!/bin/sh -# postinst script for bind9-cn -# -# see: dh_installdeb(1) set -e +[ "$1" = "configure" ] || exit 0 +[ "$DEBIAN_SCRIPT_DEBUG" ] && set -vx -# summary of how this script can be called: -# * `configure' -# * `abort-upgrade' -# * `abort-remove' `in-favour' -# -# * `abort-deconfigure' `in-favour' -# `removing' -# -# for details, see http://www.debian.org/doc/debian-policy/ or -# the debian-policy package -# - -case "$1" in - configure|reconfigure) - # continue below - ;; - - *) - exit 0 - ;; -esac - -# import CN-functions +# Load CARNET Tools . /usr/share/carnet-tools/functions.sh CONF="/etc/fail2ban/jail.conf" if [ -e "$CONF" ]; then # enable ssh, pam-generic, sasl, proftpd and vsftpd service - echo "CN: Enabling SSH, PAM-generic, SASL, ProFTPD, vsftpd and Dovecot support..." - perl -ne 'if (/^\[(ssh|pam-generic|sasl|proftpd|vsftpd|dovecot)\]/ .. /^enabled/) { $_ =~ s/^enabled\s+=\s+false/enabled = true/gi }; print $_' "$CONF" > "$CONF.$$" && \ + echo "CN: Enabling SSH, PAM-generic, SASL and Dovecot support..." + perl -ne 'if (/^\[(ssh|pam-generic|sasl|dovecot)\]/ .. /^enabled/) { $_ =~ s/^enabled\s+=\s+false/enabled = true/gi }; print $_' "$CONF" > "$CONF.$$" && \ cp_mv "$CONF.$$" "$CONF" rm -f "$CONF.$$" + if [ -f /var/log/vsftpd.log ]; then + echo "CN: Enabling vsftpd support..." + perl -ne 'if (/^\[vsftpd\]/ .. /^enabled/) { $_ =~ s/^enabled\s+=\s+false/enabled = true/gi }; print $_' "$CONF" > "$CONF.$$" && \ + cp_mv "$CONF.$$" "$CONF" + rm -f "$CONF.$$" + else + echo "CN: Disabling vsftpd support..." + perl -ne 'if (/^\[vsftpd\]/ .. /^enabled/) { $_ =~ s/^enabled\s+=\s+true/enabled = false/gi }; print $_' "$CONF" > "$CONF.$$" && \ + cp_mv "$CONF.$$" "$CONF" + rm -f "$CONF.$$" + fi + + if [ -f /var/log/proftpd/proftpd.log ]; then + echo "CN: Enabling ProFTPD support..." + perl -ne 'if (/^\[proftpd\]/ .. /^enabled/) { $_ =~ s/^enabled\s+=\s+false/enabled = true/gi }; print $_' "$CONF" > "$CONF.$$" && \ + cp_mv "$CONF.$$" "$CONF" + rm -f "$CONF.$$" + else + echo "CN: Disabling ProFTPD support..." + perl -ne 'if (/^\[proftpd\]/ .. /^enabled/) { $_ =~ s/^enabled\s+=\s+true/enabled = false/gi }; print $_' "$CONF" > "$CONF.$$" && \ + cp_mv "$CONF.$$" "$CONF" + rm -f "$CONF.$$" + fi + + # postfix-sasl in jessie, not sasl anymore + cp_check_and_sed 'filter[ ]*=[ ]*sasl' \ + 's/^filter[ ]*=[ ]*sasl/filter = postfix-sasl/gi' \ + "$CONF" && echo "CN: Fixing sasl to postfix-sasl..." || true + # add network address and class if needed cp_get_netaddr || true NETADDR="$RET" - IGNOREIP=$(grep '^ignoreip' "$CONF") - if ! echo "$IGNOREIP" | grep -q "$NETADDR"; then - echo "CN: Enabling local IP ranges exclusion..." - cp_check_and_sed '^ignoreip' \ - "s;^\(ignoreip.*\)$;\1 $NETADDR;g" "$CONF" || true - fi + IGNOREIP=$(grep '^ignoreip' "$CONF" || true) + if grep -q '^ignoreip' "$CONF"; then + IGNOREIP=$(grep '^ignoreip' "$CONF") + if ! echo "$IGNOREIP" | grep -q "$NETADDR"; then + echo "CN: Enabling local IP ranges exclusion..." + cp_check_and_sed '^ignoreip' \ + "s;^\(ignoreip.*\)$;\1 $NETADDR;g" "$CONF" || true + fi + elif grep -q '^#ignoreip' "$CONF"; then + echo "CN: Enabling local IP ranges exclusion..." + cp_check_and_sed '^#ignoreip' \ + "s;^#ignoreip.*$;ignoreip = $NETADDR;g" "$CONF" || true + fi fi # restart the services