aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security
diff options
context:
space:
mode:
Diffstat (limited to 'modules/security')
-rw-r--r--modules/security/gopass/gopass-sync-init.sh17
-rw-r--r--modules/security/gpg/gpg-backup.sh47
-rw-r--r--modules/security/ssh/gpg-ssh-key-load.sh33
3 files changed, 53 insertions, 44 deletions
diff --git a/modules/security/gopass/gopass-sync-init.sh b/modules/security/gopass/gopass-sync-init.sh
index 5d5e423..8250458 100644
--- a/modules/security/gopass/gopass-sync-init.sh
+++ b/modules/security/gopass/gopass-sync-init.sh
@@ -8,24 +8,27 @@
STORE_DIR="@@PASSWORD_STORE_DIR@@"
-info() { printf '\033[1;34m==>\033[0m %s\n' "$*"; }
-warn() { printf '\033[1;33m==> warning:\033[0m %s\n' "$*" >&2; }
+info() { printf '\033[1;34m==>\033[0m %s\n' "$*"; }
+warn() { printf '\033[1;33m==> warning:\033[0m %s\n' "$*" >&2; }
error() { printf '\033[1;31m==> error:\033[0m %s\n' "$*" >&2; }
-die() { error "$*"; exit 1; }
+die() {
+ error "$*"
+ exit 1
+}
mkdir -p "$STORE_DIR"
cd "$STORE_DIR" || die "Failed to enter $STORE_DIR"
# Check if the directory is already a git repository; initialize if not
if ! git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
- info "Initializing git repository in $STORE_DIR..."
- git init
+ info "Initializing git repository in $STORE_DIR..."
+ git init
fi
# Check if the remote 'origin' is set; add it if not
if ! git remote | grep -q "^origin$"; then
- info "Adding remote origin..."
- git remote add origin "@@REMOTE_REPO_URL@@"
+ info "Adding remote origin..."
+ git remote add origin "@@REMOTE_REPO_URL@@"
fi
info "Password store git setup complete."
diff --git a/modules/security/gpg/gpg-backup.sh b/modules/security/gpg/gpg-backup.sh
index 685c4a3..41c7524 100644
--- a/modules/security/gpg/gpg-backup.sh
+++ b/modules/security/gpg/gpg-backup.sh
@@ -4,15 +4,18 @@
set -euo pipefail
-info() { printf '\033[1;34m==>\033[0m %s\n' "$*"; }
-warn() { printf '\033[1;33m==> warning:\033[0m %s\n' "$*" >&2; }
+info() { printf '\033[1;34m==>\033[0m %s\n' "$*"; }
+warn() { printf '\033[1;33m==> warning:\033[0m %s\n' "$*" >&2; }
error() { printf '\033[1;31m==> error:\033[0m %s\n' "$*" >&2; }
-die() { error "$*"; exit 1; }
+die() {
+ error "$*"
+ exit 1
+}
WORKDIR="$(mktemp -d)"
cleanup() {
- if [[ -d "$WORKDIR" ]]; then
+ if [[ -d $WORKDIR ]]; then
find "$WORKDIR" -type f -exec shred -u -z {} \; 2>/dev/null || true
rm -rf "$WORKDIR"
fi
@@ -31,21 +34,21 @@ usage() {
do_export() {
local outfile="$1"
- if [[ -e "$outfile" ]]; then
+ if [[ -e $outfile ]]; then
die "Refusing to overwrite existing file: $outfile"
fi
info "Exporting public keys..."
- gpg --export --armor > "$WORKDIR/public-keys.asc"
+ gpg --export --armor >"$WORKDIR/public-keys.asc"
info "Exporting secret keys..."
- gpg --export-secret-keys --armor > "$WORKDIR/secret-keys.asc"
+ gpg --export-secret-keys --armor >"$WORKDIR/secret-keys.asc"
info "Exporting secret subkeys (if any)..."
- gpg --export-secret-subkeys --armor > "$WORKDIR/secret-subkeys.asc" || true
+ gpg --export-secret-subkeys --armor >"$WORKDIR/secret-subkeys.asc" || true
info "Exporting owner trust database..."
- gpg --export-ownertrust > "$WORKDIR/ownertrust.txt"
+ gpg --export-ownertrust >"$WORKDIR/ownertrust.txt"
info "Exporting revocation certificates..."
mkdir -p "$WORKDIR/revocation-certs"
@@ -73,7 +76,7 @@ do_export() {
"$WORKDIR/gpg-full-backup.tar"
info "Verifying: attempting decryption to confirm it works..."
- if gpg --decrypt "$outfile" > "$WORKDIR/verify.tar" 2>/dev/null; then
+ if gpg --decrypt "$outfile" >"$WORKDIR/verify.tar" 2>/dev/null; then
if cmp -s "$WORKDIR/gpg-full-backup.tar" "$WORKDIR/verify.tar"; then
info "Verification succeeded: backup decrypts correctly."
else
@@ -94,14 +97,14 @@ do_export() {
do_import() {
local infile="$1"
- if [[ ! -f "$infile" ]]; then
+ if [[ ! -f $infile ]]; then
die "File not found: $infile"
fi
info "Decrypting $infile ..."
echo " You will be prompted for the backup's passphrase."
echo " Note: this may take a while due to the high S2K iteration count."
- gpg --decrypt "$infile" > "$WORKDIR/gpg-full-backup.tar"
+ gpg --decrypt "$infile" >"$WORKDIR/gpg-full-backup.tar"
info "Extracting archive..."
tar -C "$WORKDIR" -xf "$WORKDIR/gpg-full-backup.tar"
@@ -143,13 +146,13 @@ command="$1"
filename="$2"
case "$command" in
- export)
- do_export "$filename"
- ;;
- import)
- do_import "$filename"
- ;;
- *)
- usage
- ;;
-esac \ No newline at end of file
+export)
+ do_export "$filename"
+ ;;
+import)
+ do_import "$filename"
+ ;;
+*)
+ usage
+ ;;
+esac
diff --git a/modules/security/ssh/gpg-ssh-key-load.sh b/modules/security/ssh/gpg-ssh-key-load.sh
index 02dda1d..b9567f8 100644
--- a/modules/security/ssh/gpg-ssh-key-load.sh
+++ b/modules/security/ssh/gpg-ssh-key-load.sh
@@ -15,10 +15,13 @@ export GNUPGHOME="@@GNUPGHOME@@"
GOPASS_SSH_KEY="@@GOPASS_SSH_KEY@@"
-info() { printf '\033[1;34m==>\033[0m %s\n' "$*"; }
-warn() { printf '\033[1;33m==> warning:\033[0m %s\n' "$*" >&2; }
+info() { printf '\033[1;34m==>\033[0m %s\n' "$*"; }
+warn() { printf '\033[1;33m==> warning:\033[0m %s\n' "$*" >&2; }
error() { printf '\033[1;31m==> error:\033[0m %s\n' "$*" >&2; }
-die() { error "$*"; exit 1; }
+die() {
+ error "$*"
+ exit 1
+}
usage() {
cat <<EOF
@@ -34,15 +37,15 @@ EOF
while [[ $# -gt 0 ]]; do
case "$1" in
- --help | -h)
- usage
- exit 0
- ;;
- *)
- error "Unknown option: $1"
- usage
- exit 1
- ;;
+ --help | -h)
+ usage
+ exit 0
+ ;;
+ *)
+ error "Unknown option: $1"
+ usage
+ exit 1
+ ;;
esac
done
@@ -60,14 +63,14 @@ if ssh-add -l 2>/dev/null | grep -qE "(ED25519|RSA|ECDSA)"; then
exit 0
fi
-if ! gopass show -o "$GOPASS_SSH_KEY" > /dev/null 2>&1; then
+if ! gopass show -o "$GOPASS_SSH_KEY" >/dev/null 2>&1; then
die "no gopass entry $GOPASS_SSH_KEY"
fi
tmpdir=$(mktemp -d)
trap 'rm -rf "$tmpdir"' EXIT
keyfile="$tmpdir/key"
-gopass show -o "$GOPASS_SSH_KEY" > "$keyfile" 2>/dev/null
+gopass show -o "$GOPASS_SSH_KEY" >"$keyfile" 2>/dev/null
chmod 600 "$keyfile"
passphrase=$(gopass show -o "$GOPASS_SSH_KEY/passphrase" 2>/dev/null || true)
@@ -82,4 +85,4 @@ if ! timeout 60 ssh-add "$keyfile"; then
exit 1
fi
-info "SSH key loaded into gpg-agent." \ No newline at end of file
+info "SSH key loaded into gpg-agent."