1 | #!/usr/bin/perl |
---|
2 | |
---|
3 | use strict; |
---|
4 | |
---|
5 | use gateway_lib; |
---|
6 | |
---|
7 | use IO::File; |
---|
8 | |
---|
9 | use Getopt::Long; |
---|
10 | |
---|
11 | my $ssh_pubkey; |
---|
12 | my $ssh_privkey; |
---|
13 | my $active; |
---|
14 | my $tunnelip; |
---|
15 | my $peer; |
---|
16 | my $fedkit_dir= "/usr/local/federation"; |
---|
17 | my $perl = "/usr/bin/perl"; |
---|
18 | my $iface_file = "/var/emulab/boot/ifmap"; |
---|
19 | my $ssh = "/usr/bin/ssh"; |
---|
20 | my $seer; |
---|
21 | my $ssh_port = 22; |
---|
22 | my @ports; |
---|
23 | my $use_file; |
---|
24 | |
---|
25 | my %opts = ( |
---|
26 | 'ssh_pubkey=s' => \$ssh_pubkey, |
---|
27 | 'ssh_privkey=s' => \$ssh_privkey, |
---|
28 | 'tunnelip' => \$tunnelip, |
---|
29 | 'peer=s' => \$peer, |
---|
30 | 'fedkit=s' => \$fedkit_dir, |
---|
31 | 'perl=s' => \$perl, |
---|
32 | 'interfaces=s' => \$iface_file, |
---|
33 | 'ssh=s' => \$ssh, |
---|
34 | 'port=s' => \@ports, |
---|
35 | 'active' => \$active, |
---|
36 | 'ssh_port=s' => \$ssh_port, |
---|
37 | 'use_file' => \$use_file, |
---|
38 | 'seer' => \$seer, |
---|
39 | ); |
---|
40 | |
---|
41 | exit(20) unless GetOptions(%opts); |
---|
42 | |
---|
43 | if ($use_file) { |
---|
44 | gateway_lib::read_config(gateway_lib::config_filename(), \%opts) |
---|
45 | } |
---|
46 | |
---|
47 | my $tunnelparam = $tunnelip ? '--tunnelip' : ''; |
---|
48 | |
---|
49 | # Private keys need to have restrictive permissions |
---|
50 | chmod(0600, $ssh_privkey); |
---|
51 | if ($active) { |
---|
52 | my $portparam = join(" --port=", @ports); |
---|
53 | |
---|
54 | # join doesn't prefix the first one |
---|
55 | $portparam="--port=$portparam" if $portparam; |
---|
56 | |
---|
57 | system("$perl -I$fedkit_dir/lib $fedkit_dir/bin/active_config.pl " . |
---|
58 | "--peer=$peer --ssh_pubkey=$ssh_pubkey --ssh_privkey=$ssh_privkey " . |
---|
59 | " $tunnelparam --fedkit=$fedkit_dir --perl=$perl " . |
---|
60 | "--ssh_port=$ssh_port --ssh=$ssh --interfaces=$iface_file"); |
---|
61 | exit(20) if $?; |
---|
62 | |
---|
63 | system("$perl -I$fedkit_dir/lib $fedkit_dir/bin/port_forward.pl " . |
---|
64 | "--peer=$peer --ssh_pubkey=$ssh_pubkey --ssh_privkey=$ssh_privkey " . |
---|
65 | " $tunnelparam --fedkit=$fedkit_dir --perl=$perl " . |
---|
66 | "--ssh=$ssh --ssh_port=$ssh_port $portparam"); |
---|
67 | exit(20) if $?; |
---|
68 | |
---|
69 | if ($seer ) { |
---|
70 | system("$perl -I$fedkit_dir/lib $fedkit_dir/bin/start_seer.pl " . |
---|
71 | "--peer=$peer --seer --fedkit=$fedkit_dir --perl=$perl " . |
---|
72 | "--ssh=$ssh --ssh_privkey=$ssh_privkey"); |
---|
73 | exit(20) if $?; |
---|
74 | } |
---|
75 | |
---|
76 | } |
---|
77 | else { |
---|
78 | system("$perl -I$fedkit_dir/lib $fedkit_dir/bin/prep_gateway.pl " . |
---|
79 | "--peer=$peer --ssh_pubkey=$ssh_pubkey $tunnelparam"); |
---|
80 | exit(20) if $?; |
---|
81 | } |
---|
82 | |
---|
83 | =pod |
---|
84 | |
---|
85 | =head1 NAME |
---|
86 | |
---|
87 | B<combo_active.pl> - Do both the active configuration of a connectiveity gateway and service port forwarding. |
---|
88 | |
---|
89 | =head1 OPTIONS |
---|
90 | |
---|
91 | =over 8 |
---|
92 | |
---|
93 | =item B<fedkit=>I<install_dir> |
---|
94 | |
---|
95 | Directory in which this software is installed. Generally not needed. |
---|
96 | |
---|
97 | =item B<interfaces=>I<interface table> |
---|
98 | |
---|
99 | A list of interfaces to forward data on of the form: |
---|
100 | |
---|
101 | =begin text |
---|
102 | |
---|
103 | iface ip_addr |
---|
104 | |
---|
105 | =end text |
---|
106 | |
---|
107 | The interface is the operating system name of the interface and the IP address |
---|
108 | is given in standard dotted decimal notation. Other characters on a line are |
---|
109 | ignored. |
---|
110 | |
---|
111 | =item B<peer=>I<hostname> |
---|
112 | |
---|
113 | The other gateway providing forwarding. |
---|
114 | |
---|
115 | =item B<perl=>I<perl_binary> |
---|
116 | |
---|
117 | Location of the perl binary. Usually unneeded. |
---|
118 | |
---|
119 | =item B<port=>I<port_spec> |
---|
120 | |
---|
121 | Forward the given port. The port is specified as |
---|
122 | for B<port_forward.pl> |
---|
123 | |
---|
124 | =item B<ssh=>I<ssh_binary> |
---|
125 | |
---|
126 | The pathname of the ssh binary. Unusally unnecessary. |
---|
127 | |
---|
128 | =item B<ssh_pubkey=>I<keyfile> |
---|
129 | |
---|
130 | A public to install as authorized. |
---|
131 | |
---|
132 | =item B<ssh_privkey=>I<identity_file> |
---|
133 | |
---|
134 | The identity to use for remote access |
---|
135 | |
---|
136 | =item B<tunnelip> |
---|
137 | |
---|
138 | True if the testbed uses the DETER tunnelip extension to provide external |
---|
139 | connectivity information |
---|
140 | |
---|
141 | =item B<use_file> |
---|
142 | |
---|
143 | If given read additional parameters from the file in |
---|
144 | /proj/I<project>/exp/I<experiment/tmp/I<hostname>.gw/conf where those are the |
---|
145 | current testbed project and experiment and the hostname is before the first |
---|
146 | dot. The file is option: value. |
---|
147 | |
---|
148 | =back |
---|
149 | |
---|
150 | =head1 SYNOPSIS |
---|
151 | |
---|
152 | Call B<active_config.pl> and B<port_forward.pl> with the relevant parameters. |
---|
153 | |
---|
154 | |
---|
155 | =head1 AUTHORS |
---|
156 | |
---|
157 | Ted Faber <faber@isi.edu> |
---|
158 | |
---|
159 | =cut |
---|