diff options
Diffstat (limited to 'modules/security')
| -rw-r--r-- | modules/security/gopass/gopass-ssh-load.sh | 13 | ||||
| -rw-r--r-- | modules/security/gopass/gopass-sync-init.sh | 13 | ||||
| -rw-r--r-- | modules/security/gpg/gpg-backup.sh | 63 |
3 files changed, 50 insertions, 39 deletions
diff --git a/modules/security/gopass/gopass-ssh-load.sh b/modules/security/gopass/gopass-ssh-load.sh index b9a06e9..8c1b11f 100644 --- a/modules/security/gopass/gopass-ssh-load.sh +++ b/modules/security/gopass/gopass-ssh-load.sh @@ -28,11 +28,15 @@ set -o pipefail export GNUPGHOME="@@GNUPGHOME@@" export GOPASS_SSH_KEYS="@@GOPASS_SSH_KEYS@@" +info() { printf '\033[1;34m==>\033[0m %s\n' "$*"; } +warn() { printf '\033[1;33m==> warning:\033[0m %s\n' "$*" >&2; } +error() { printf '\033[1;31m==> error:\033[0m %s\n' "$*" >&2; } +die() { error "$*"; exit 1; } + SSH_AUTH_SOCK="$(gpgconf --list-dirs agent-ssh-socket)" export SSH_AUTH_SOCK if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then - echo "Error: SSH_AUTH_SOCK is not set or valid." >&2 - exit 1 + die "SSH_AUTH_SOCK is not set or valid." fi if ssh-add -l 2>/dev/null | grep -qE "(ED25519|RSA|ECDSA)"; then @@ -41,8 +45,7 @@ fi # GOPASS_SSH_KEYS holds a space-separated list of gopass entry names under ssh if [ -z "${GOPASS_SSH_KEYS:-}" ]; then - echo "Error: GOPASS_SSH_KEYS is not set. Example: GOPASS_SSH_KEYS=\"github gitlab\"" >&2 - exit 1 + die "GOPASS_SSH_KEYS is not set. Example: GOPASS_SSH_KEYS=\"github gitlab\"" fi # shellcheck disable=SC2086 @@ -63,6 +66,6 @@ for key in "${keys[@]}"; do ssh-add "$keyfile" 2>/dev/null rm -rf "$tmpdir" else - echo "Warning: no gopass entry ssh/$key" >&2 + warn "no gopass entry ssh/$key" fi done diff --git a/modules/security/gopass/gopass-sync-init.sh b/modules/security/gopass/gopass-sync-init.sh index c7767f9..e00ce73 100644 --- a/modules/security/gopass/gopass-sync-init.sh +++ b/modules/security/gopass/gopass-sync-init.sh @@ -11,19 +11,24 @@ STORE_DIR="@@PASSWORD_STORE_DIR@@" +info() { printf '\033[1;34m==>\033[0m %s\n' "$*"; } +warn() { printf '\033[1;33m==> warning:\033[0m %s\n' "$*" >&2; } +error() { printf '\033[1;31m==> error:\033[0m %s\n' "$*" >&2; } +die() { error "$*"; exit 1; } + mkdir -p "$STORE_DIR" -cd "$STORE_DIR" || { echo "Failed to enter $STORE_DIR"; exit 1; } +cd "$STORE_DIR" || die "Failed to enter $STORE_DIR" # Check if the directory is already a git repository; initialize if not if ! git rev-parse --is-inside-work-tree >/dev/null 2>&1; then - echo "Initializing git repository in $STORE_DIR..." + info "Initializing git repository in $STORE_DIR..." git init fi # Check if the remote 'origin' is set; add it if not if ! git remote | grep -q "^origin$"; then - echo "Adding remote origin..." + info "Adding remote origin..." git remote add origin "@@REMOTE_REPO_URL@@" fi -echo "Password store git setup complete." +info "Password store git setup complete." diff --git a/modules/security/gpg/gpg-backup.sh b/modules/security/gpg/gpg-backup.sh index 57c216b..c1b6c25 100644 --- a/modules/security/gpg/gpg-backup.sh +++ b/modules/security/gpg/gpg-backup.sh @@ -1,6 +1,11 @@ #!/usr/bin/env bash set -euo pipefail +info() { printf '\033[1;34m==>\033[0m %s\n' "$*"; } +warn() { printf '\033[1;33m==> warning:\033[0m %s\n' "$*" >&2; } +error() { printf '\033[1;31m==> error:\033[0m %s\n' "$*" >&2; } +die() { error "$*"; exit 1; } + WORKDIR="$(mktemp -d)" cleanup() { @@ -12,9 +17,11 @@ cleanup() { trap cleanup EXIT usage() { - echo "Usage:" - echo " $0 export <filename> Export all GPG keys to an encrypted file" - echo " $0 import <filename> Decrypt and import keys from a backup file" + echo "Usage: $0 <export|import> <filename>" + echo "" + echo "Commands:" + echo " export Export all GPG keys to an encrypted file" + echo " import Decrypt and import keys from a backup file" exit 1 } @@ -22,29 +29,28 @@ do_export() { local outfile="$1" if [[ -e "$outfile" ]]; then - echo "!! Refusing to overwrite existing file: $outfile" >&2 - exit 1 + die "Refusing to overwrite existing file: $outfile" fi - echo "==> Exporting public keys..." + info "Exporting public keys..." gpg --export --armor > "$WORKDIR/public-keys.asc" - echo "==> Exporting secret keys..." + info "Exporting secret keys..." gpg --export-secret-keys --armor > "$WORKDIR/secret-keys.asc" - echo "==> Exporting secret subkeys (if any)..." + info "Exporting secret subkeys (if any)..." gpg --export-secret-subkeys --armor > "$WORKDIR/secret-subkeys.asc" || true - echo "==> Exporting owner trust database..." + info "Exporting owner trust database..." gpg --export-ownertrust > "$WORKDIR/ownertrust.txt" - echo "==> Exporting revocation certificates..." + info "Exporting revocation certificates..." mkdir -p "$WORKDIR/revocation-certs" if [[ -d "$HOME/.gnupg/openpgp-revocs.d" ]]; then cp "$HOME"/.gnupg/openpgp-revocs.d/*.rev "$WORKDIR/revocation-certs/" 2>/dev/null || true fi - echo "==> Bundling everything into a single archive..." + info "Bundling everything into a single archive..." tar -C "$WORKDIR" -cf "$WORKDIR/gpg-full-backup.tar" \ public-keys.asc \ secret-keys.asc \ @@ -52,7 +58,7 @@ do_export() { ownertrust.txt \ revocation-certs - echo "==> Encrypting with GPG (AES256, SHA512, max S2K iteration count)..." + info "Encrypting with GPG (AES256, SHA512, max S2K iteration count)..." echo " You will be prompted for a passphrase — use a strong one." gpg --symmetric \ --cipher-algo AES256 \ @@ -63,21 +69,19 @@ do_export() { --output "$outfile" \ "$WORKDIR/gpg-full-backup.tar" - echo "==> Verifying: attempting decryption to confirm it works..." + info "Verifying: attempting decryption to confirm it works..." if gpg --decrypt "$outfile" > "$WORKDIR/verify.tar" 2>/dev/null; then if cmp -s "$WORKDIR/gpg-full-backup.tar" "$WORKDIR/verify.tar"; then - echo "==> Verification succeeded: backup decrypts correctly." + info "Verification succeeded: backup decrypts correctly." else - echo "!! WARNING: decrypted content does not match original. Investigate before trusting this backup." >&2 - exit 1 + die "Decrypted content does not match original. Investigate before trusting this backup." fi else - echo "!! WARNING: decryption test failed." >&2 - exit 1 + die "Decryption test failed." fi echo - echo "==> Done." + info "Done." echo " Encrypted backup: $outfile" echo " Store this file somewhere safe (offline media, encrypted drive)." echo " The S2K iteration count only helps if your passphrase itself" @@ -88,42 +92,41 @@ do_import() { local infile="$1" if [[ ! -f "$infile" ]]; then - echo "!! File not found: $infile" >&2 - exit 1 + die "File not found: $infile" fi - echo "==> Decrypting $infile ..." + info "Decrypting $infile ..." echo " You will be prompted for the backup's passphrase." echo " Note: this may take a while due to the high S2K iteration count." gpg --decrypt "$infile" > "$WORKDIR/gpg-full-backup.tar" - echo "==> Extracting archive..." + info "Extracting archive..." tar -C "$WORKDIR" -xf "$WORKDIR/gpg-full-backup.tar" - echo "==> Importing public keys..." + info "Importing public keys..." gpg --import "$WORKDIR/public-keys.asc" - echo "==> Importing secret keys..." + info "Importing secret keys..." gpg --import "$WORKDIR/secret-keys.asc" if [[ -s "$WORKDIR/secret-subkeys.asc" ]]; then - echo "==> Importing secret subkeys..." + info "Importing secret subkeys..." gpg --import "$WORKDIR/secret-subkeys.asc" || true fi if [[ -f "$WORKDIR/ownertrust.txt" ]]; then - echo "==> Importing owner trust database..." + info "Importing owner trust database..." gpg --import-ownertrust "$WORKDIR/ownertrust.txt" fi if [[ -d "$WORKDIR/revocation-certs" ]] && [[ -n "$(ls -A "$WORKDIR/revocation-certs" 2>/dev/null)" ]]; then - echo "==> Restoring revocation certificates..." + info "Restoring revocation certificates..." mkdir -p "$HOME/.gnupg/openpgp-revocs.d" cp "$WORKDIR"/revocation-certs/*.rev "$HOME/.gnupg/openpgp-revocs.d/" 2>/dev/null || true fi echo - echo "==> Done. Keys imported into your GPG keyring." + info "Done. Keys imported into your GPG keyring." echo " Run 'gpg --list-secret-keys' to confirm." } @@ -146,4 +149,4 @@ case "$command" in *) usage ;; -esac +esac
\ No newline at end of file |
