###############################################################################
# #
# IPFire.org - A linux based firewall #
-# Copyright (C) 2007 Michael Tremer & Christian Schmidt #
+# Copyright (C) 2007-2020 IPFire Team <info@ipfire.org> #
# #
# This program is free software: you can redistribute it and/or modify #
# it under the terms of the GNU General Public License as published by #
#use warnings;
#use CGI::Carp 'fatalsToBrowser';
+use IO::Socket;
+
require '/var/ipfire/general-functions.pl';
+require "${General::swroot}/location-functions.pl";
require "${General::swroot}/lang.pl";
require "${General::swroot}/header.pl";
+my %color = ();
+my %mainsettings = ();
my %remotesettings=();
my %checked=();
my $errormessage='';
my $counter = 0;
+&General::readhash("${General::swroot}/main/settings", \%mainsettings);
+&General::readhash("/srv/web/ipfire/html/themes/ipfire/include/colors.txt", \%color);
+
&Header::showhttpheaders();
$remotesettings{'ENABLE_SSH'} = 'off';
-$remotesettings{'ENABLE_SSH_PORTOCOL1'} = 'off';
$remotesettings{'ENABLE_SSH_PORTFW'} = 'off';
$remotesettings{'ACTION'} = '';
&Header::getcgihash(\%remotesettings);
&General::log($Lang::tr{'ssh is disabled'});
unlink "${General::swroot}/remote/enablessh";
}
-
- if ($remotesettings{'ENABLE_SSH_PORTOCOL1'} eq 'on')
- {
- &General::log($Lang::tr{'ssh1 enabled'});
- }
- else
- {
- &General::log($Lang::tr{'ssh1 disabled'});
- }
if ($remotesettings{'SSH_PORT'} eq 'on')
{
# used
$remotesettings{'ENABLE_SSH_PASSWORDS'} = 'on' unless exists $remotesettings{'ENABLE_SSH_PASSWORDS'};
$remotesettings{'ENABLE_SSH_KEYS'} = 'on' unless exists $remotesettings{'ENABLE_SSH_KEYS'};
+ $remotesettings{'SSH_AGENT_FORWARDING'} = 'off' unless exists $remotesettings{'SSH_AGENT_FORWARDING'};
$checked{'ENABLE_SSH'}{'off'} = '';
$checked{'ENABLE_SSH'}{'on'} = '';
$checked{'ENABLE_SSH'}{$remotesettings{'ENABLE_SSH'}} = "checked='checked'";
-$checked{'ENABLE_SSH_PORTOCOL1'}{'off'} = '';
-$checked{'ENABLE_SSH_PORTOCOL1'}{'on'} = '';
-$checked{'ENABLE_SSH_PORTOCOL1'}{$remotesettings{'ENABLE_SSH_PORTOCOL1'}} = "checked='checked'";
$checked{'ENABLE_SSH_PORTFW'}{'off'} = '';
$checked{'ENABLE_SSH_PORTFW'}{'on'} = '';
$checked{'ENABLE_SSH_PORTFW'}{$remotesettings{'ENABLE_SSH_PORTFW'}} = "checked='checked'";
$checked{'SSH_PORT'}{'off'} = '';
$checked{'SSH_PORT'}{'on'} = '';
$checked{'SSH_PORT'}{$remotesettings{'SSH_PORT'}} = "checked='checked'";
+$checked{'SSH_AGENT_FORWARDING'}{'off'} = '';
+$checked{'SSH_AGENT_FORWARDING'}{'on'} = '';
+$checked{'SSH_AGENT_FORWARDING'}{$remotesettings{'SSH_AGENT_FORWARDING'}} = "checked='checked'";
&Header::openpage($Lang::tr{'remote access'}, 1, '');
if ($errormessage) {
&Header::openbox('100%', 'left', $Lang::tr{'error messages'});
- print "<FONT CLASS='base'>$errormessage </FONT>\n";
+ print "<font class='base'>$errormessage </font>\n";
&Header::closebox();
}
print "<form method='post' action='$ENV{'SCRIPT_NAME'}'>\n";
-&Header::openbox('100%', 'left', 'SSH:');
+&Header::openbox('100%', 'left', $Lang::tr{'ssh'});
print <<END
<table width='100%'>
<tr>
</tr>
<tr>
<td> </td>
- <td><input type='checkbox' name='ENABLE_SSH_PORTOCOL1' $checked{'ENABLE_SSH_PORTOCOL1'}{'on'} /></td>
- <td width='100%' class='base'>$Lang::tr{'ssh1 support'}</td>
+ <td><input type='checkbox' name='SSH_AGENT_FORWARDING' $checked{'SSH_AGENT_FORWARDING'}{'on'} /></td>
+ <td width='100%' class='base'>$Lang::tr{'ssh agent forwarding'}</td>
</tr>
<tr>
<td> </td>
<td width='100%' class='base'>$Lang::tr{'ssh port'}</td>
</tr>
<tr>
- <td align='center' colspan='3'><hr />
+ <td align='right' colspan='3'>
<input type='submit' name='ACTION' value='$Lang::tr{'ssh tempstart15'}' />
<input type='submit' name='ACTION' value='$Lang::tr{'ssh tempstart30'}' />
<input type='submit' name='ACTION' value='$Lang::tr{'save'}' /></td>
print "</form>\n";
-&Header::openbox('100%', 'left', $Lang::tr{'ssh host keys'});
+&Header::openbox('100%', 'center', $Lang::tr{'ssh host keys'});
-print "<table>\n";
+print "<table class='tbl' width='100%'>\n";
print <<END
-<tr><td class='boldbase'><b>$Lang::tr{'ssh key'}</b></td>
- <td class='boldbase'><b>$Lang::tr{'ssh fingerprint'}</b></td>
- <td class='boldbase'><b>$Lang::tr{'ssh key size'}</b></td></tr>
+<thead>
+ <tr>
+ <th align="center"><strong>$Lang::tr{'ssh key'}</strong></th>
+ <th align="center"><strong>$Lang::tr{'type'}</strong></th>
+ <th align="center"><strong>$Lang::tr{'ssh fingerprint'}</strong></th>
+ <th align="center"><strong>$Lang::tr{'ssh key size'}</strong></th>
+ </tr>
+</thead>
+<tbody>
END
;
&viewkey("/etc/ssh/ssh_host_key.pub","RSA1");
&viewkey("/etc/ssh/ssh_host_rsa_key.pub","RSA2");
&viewkey("/etc/ssh/ssh_host_dsa_key.pub","DSA");
+&viewkey("/etc/ssh/ssh_host_ecdsa_key.pub","ECDSA");
+&viewkey("/etc/ssh/ssh_host_ed25519_key.pub","ED25519");
-print "</table>\n";
+print "</tbody>\n</table>\n";
+
+&Header::closebox();
+
+&Header::openbox('100%', 'center', $Lang::tr{'ssh active sessions'});
+
+print <<END;
+ <table class="tbl" width="100%">
+ <thead>
+ <tr>
+ <th align="center">
+ <strong>$Lang::tr{'ssh username'}</strong>
+ </th>
+ <th align="center">
+ <strong>$Lang::tr{'ssh login time'}</strong>
+ </th>
+ <th align="center">
+ <strong>$Lang::tr{'ip address'}</strong>
+ </th>
+ <th align="center">
+ <strong>$Lang::tr{'country'}</strong>
+ </th>
+ <th align="center">
+ <strong>$Lang::tr{'rdns'}</strong>
+ </th>
+ </tr>
+ </thead>
+ <tbody>
+END
+
+&printactivelogins();
+
+print "</tbody>\n</table>\n";
&Header::closebox();
my @temp = split(/ /,`/usr/bin/ssh-keygen -l -f $key`);
my $keysize = &Header::cleanhtml($temp[0],"y");
my $fingerprint = &Header::cleanhtml($temp[1],"y");
- print "<tr><td>$key ($name)</td><td><code>$fingerprint</code></td><td align='center'>$keysize</td></tr>\n";
+ print "<tr><td><code>$key</code></td><td align='center'>$name</td><td><code>$fingerprint</code></td><td align='center'>$keysize</td></tr>\n";
}
}
+
+sub printactivelogins()
+{
+ # print active SSH logins (grep outpout of "who -s")
+ my $command = "who -s";
+ my @output = `$command`;
+ chomp(@output);
+
+ my $id = 0;
+
+ if ( scalar(@output) == 0 )
+ {
+ # no logins appeared
+ my $table_colour = ($id++ % 2) ? $color{'color20'} : $color{'color22'};
+ print "<tr bgcolor='$table_colour'><td colspan='5'>$Lang::tr{'ssh no active logins'}</td></tr>\n";
+ } else {
+ # list active logins...
+ foreach my $line (@output)
+ {
+ my @arry = split(/\ +/, $line);
+
+ my $username = @arry[0];
+ my $logintime = join(' ', @arry[2..4]);
+ my $remoteip = @arry[5];
+ $remoteip =~ s/[()]//g;
+
+ # display more information about that IP adress...
+ my $ccode = &Location::Functions::lookup_country_code($remoteip);
+ my $flag_icon = &Location::Functions::get_flag_icon($ccode);
+
+ # get rDNS...
+ my $iaddr = inet_aton($remoteip);
+ my $rdns = gethostbyaddr($iaddr, AF_INET);
+ if (!$rdns) { $rdns = $Lang::tr{'ptr lookup failed'}; };
+
+ my $table_colour = ($id++ % 2) ? $color{'color20'} : $color{'color22'};
+
+ print <<END;
+ <tr bgcolor='$table_colour'>
+ <td>$username</td>
+ <td>$logintime</td>
+ <td align='center'><a href='ipinfo.cgi?ip=$remoteip'>$remoteip</a></td>
+ <td align='center'><a href='country.cgi#$ccode'><img src='$flag_icon' border='0' alt='$ccode' title='$ccode' /></a></td>
+ <td>$rdns</td>
+ </tr>
+END
+;
+ }
+ }
+}