|
From: Heiko Z. <smi...@us...> - 2005-10-17 19:16:28
|
Update of /cvsroot/devil-linux/build/scripts/scripts In directory sc8-pr-cvs1.sourceforge.net:/tmp/cvs-serv31171/scripts/scripts Modified Files: ipsec Log Message: - updated acl to 2.2.32 - updated attr to 2.4.24 - updated bind to 9.3.1 - updated bison to 2.1 - updated iproute2 to 051007 - updated less to 382 - updated openswan to 2.4.2dr2 - updated openvpn to 2.0.2 - updated pci.ids - updated pciutils to 2.2.0 - updated usb.ids - updated usbutils to 0.71 - updated vim to 6.4 - updated xfsprogs to 2.7.3 Index: ipsec =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/scripts/ipsec,v retrieving revision 1.4 retrieving revision 1.5 diff -u -d -r1.4 -r1.5 --- ipsec 25 Jul 2005 17:16:58 -0000 1.4 +++ ipsec 17 Oct 2005 19:16:16 -0000 1.5 @@ -1,12 +1,13 @@ #!/bin/sh # IPsec startup and shutdown script # Copyright (C) 1998, 1999, 2001 Henry Spencer. -# +# Copyright (C) 2002 Michael Richardson <mc...@fr...> +# # This program is free software; you can redistribute it and/or modify it # under the terms of the GNU General Public License as published by the # Free Software Foundation; either version 2 of the License, or (at your # option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>. -# +# # This program is distributed in the hope that it will be useful, but # WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY # or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License @@ -26,7 +27,7 @@ # times of NFS filesystem startup/shutdown). Startup is after startup of # syslog and pcmcia support; shutdown is just before shutdown of syslog. # -# chkconfig: 2345 47 68 +# chkconfig: 2345 47 76 # description: IPsec provides encrypted and authenticated communications; \ # KLIPS is the kernel half of it, Pluto is the user-level management daemon. @@ -63,11 +64,20 @@ me='ipsec setup' # for messages +# where the private directory and the config files are +IPSEC_EXECDIR="${IPSEC_EXECDIR-/usr/libexec/ipsec}" +IPSEC_LIBDIR="${IPSEC_LIBDIR-/usr/lib/ipsec}" +IPSEC_SBINDIR="${IPSEC_SBINDIR-/usr/sbin}" +IPSEC_CONFS="${IPSEC_CONFS-/etc}" + if test " $IPSEC_DIR" = " " # if we were not called by the ipsec command then - # we must establish a suitable PATH ourselves - PATH=/usr/local/sbin:/sbin:/usr/sbin:/usr/local/bin:/bin:/usr/bin - export PATH + # we must establish a suitable PATH ourselves + PATH="${IPSEC_SBINDIR}":/sbin:/usr/sbin:/usr/local/bin:/bin:/usr/bin + export PATH + + IPSEC_DIR="$IPSEC_LIBDIR" + export IPSEC_DIR IPSEC_CONFS IPSEC_LIBDIR IPSEC_EXECDIR fi # Check that the ipsec command is available. @@ -87,22 +97,52 @@ exit 1 fi +# accept a few flags + +export IPSEC_setupflags +IPSEC_setupflags="" + +config="" + +for dummy +do + case "$1" in + --showonly|--show) IPSEC_setupflags="$1" ;; + --config) config="--config $2" ; shift ;; + *) break ;; + esac + shift +done + + # Pick up IPsec configuration (until we have done this, successfully, we # do not know where errors should go, hence the explicit "daemon.error"s.) # Note the "--export", which exports the variables created. -eval `ipsec _confread --varprefix IPSEC --export --type config setup` +eval `ipsec _confread $config --optional --varprefix IPSEC --export --type config setup` + if test " $IPSEC_confreadstatus" != " " then - echo "$IPSEC_confreadstatus -- \`$1' aborted" | - logger -s -p daemon.error -t ipsec_setup - exit 1 + case $1 in + stop|--stop|_autostop) + echo "$IPSEC_confreadstatus -- \`$1' may not work" | + logger -s -p daemon.error -t ipsec_setup;; + + *) echo "$IPSEC_confreadstatus -- \`$1' aborted" | + logger -s -p daemon.error -t ipsec_setup; + exit 1;; + esac fi + +IPSEC_confreadsection=${IPSEC_confreadsection:-setup} +export IPSEC_confreadsection + IPSECsyslog=${IPSECsyslog-daemon.error} export IPSECsyslog # misc setup umask 022 +mkdir -p /var/run/pluto # do it @@ -114,24 +154,33 @@ logger -s -p $IPSECsyslog -t ipsec_setup 2>&1 exit 1 fi - tmp=/var/run/ipsec_setup.st + tmp=/var/run/pluto/ipsec_setup.st + outtmp=/var/run/pluto/ipsec_setup.out ( ipsec _realsetup $1 echo "$?" >$tmp - ) 2>&1 | logger -s -p $IPSECsyslog -t ipsec_setup 2>&1 - st=`cat $tmp` - rm -f $tmp + ) > ${outtmp} 2>&1 + st=$? + if test -f $tmp + then + st=`cat $tmp` + rm -f $tmp + fi + if [ -f ${outtmp} ]; then + cat ${outtmp} | logger -s -p $IPSECsyslog -t ipsec_setup 2>&1 + rm -f ${outtmp} + fi exit $st ;; - restart|--restart) - $0 stop - $0 start + restart|--restart|force-reload) + $0 $IPSEC_setupflags stop + $0 $IPSEC_setupflags start ;; _autorestart) # for internal use only - $0 _autostop - $0 _autostart + $0 $IPSEC_setupflags _autostop + $0 $IPSEC_setupflags _autostart ;; status|--status) |