-
Notifications
You must be signed in to change notification settings - Fork 174
Expand file tree
/
Copy pathsshpublickeys.py
More file actions
83 lines (62 loc) · 3.02 KB
/
sshpublickeys.py
File metadata and controls
83 lines (62 loc) · 3.02 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
# Copyright 2012 Cloudbase Solutions Srl
#
# Licensed under the Apache License, Version 2.0 (the "License"); you may
# not use this file except in compliance with the License. You may obtain
# a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
# License for the specific language governing permissions and limitations
# under the License.
import os
from oslo_log import log as oslo_logging
from cloudbaseinit import conf as cloudbaseinit_conf
from cloudbaseinit import exception
from cloudbaseinit.osutils import factory as osutils_factory
from cloudbaseinit.plugins.common import base
CONF = cloudbaseinit_conf.CONF
LOG = oslo_logging.getLogger(__name__)
# The default Win32-OpenSSH config assumes that the built-in Administrators
# group with SID S-1-5-32-544 does not have an internationalized name.
ADMINISTRATORS = "Administrators"
class SetUserSSHPublicKeysPlugin(base.BasePlugin):
def execute(self, service, shared_data):
public_keys = service.get_public_keys()
if not public_keys:
LOG.debug('Public keys not found in metadata')
return base.PLUGIN_EXECUTION_DONE, False
username = service.get_admin_username() or CONF.username
osutils = osutils_factory.get_os_utils()
user_home = osutils.get_user_home(username)
if not user_home:
raise exception.CloudbaseInitException("User profile not found!")
LOG.debug("User home: %s" % user_home)
user_ssh_dir = os.path.join(user_home, '.ssh')
if not os.path.exists(user_ssh_dir):
os.makedirs(user_ssh_dir)
authorized_keys_path = os.path.join(user_ssh_dir, "authorized_keys")
authorized_keys_files = [authorized_keys_path]
admin_membership_conditions = (
osutils.group_exists(ADMINISTRATORS),
ADMINISTRATORS in CONF.groups
)
if all(admin_membership_conditions):
program_data_dir = os.getenv("PROGRAMDATA", "C:\ProgramData")
LOG.debug("Program Data: %s" % program_data_dir)
program_data_ssh_dir = os.path.join(program_data_dir, "ssh")
if not os.path.exists(program_data_ssh_dir):
os.makedirs(program_data_ssh_dir)
administrators_authorized_keys_path = os.path.join(
program_data_ssh_dir, "administrators_authorized_keys"
)
authorized_keys_files.append(administrators_authorized_keys_path)
for filepath in authorized_keys_files:
LOG.info("Writing SSH public keys in: %s" % filepath)
with open(filepath, 'w') as f:
for public_key in public_keys:
# All public keys are space-stripped.
f.write(public_key + "\n")
return base.PLUGIN_EXECUTION_DONE, False