aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security
diff options
context:
space:
mode:
Diffstat (limited to 'modules/security')
-rw-r--r--modules/security/gopass/gopass-ssh-load.sh13
-rw-r--r--modules/security/gopass/gopass-sync-init.sh13
-rw-r--r--modules/security/gpg/gpg-backup.sh63
3 files changed, 50 insertions, 39 deletions
diff --git a/modules/security/gopass/gopass-ssh-load.sh b/modules/security/gopass/gopass-ssh-load.sh
index b9a06e9..8c1b11f 100644
--- a/modules/security/gopass/gopass-ssh-load.sh
+++ b/modules/security/gopass/gopass-ssh-load.sh
@@ -28,11 +28,15 @@ set -o pipefail
export GNUPGHOME="@@GNUPGHOME@@"
export GOPASS_SSH_KEYS="@@GOPASS_SSH_KEYS@@"
+info() { printf '\033[1;34m==>\033[0m %s\n' "$*"; }
+warn() { printf '\033[1;33m==> warning:\033[0m %s\n' "$*" >&2; }
+error() { printf '\033[1;31m==> error:\033[0m %s\n' "$*" >&2; }
+die() { error "$*"; exit 1; }
+
SSH_AUTH_SOCK="$(gpgconf --list-dirs agent-ssh-socket)"
export SSH_AUTH_SOCK
if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then
- echo "Error: SSH_AUTH_SOCK is not set or valid." >&2
- exit 1
+ die "SSH_AUTH_SOCK is not set or valid."
fi
if ssh-add -l 2>/dev/null | grep -qE "(ED25519|RSA|ECDSA)"; then
@@ -41,8 +45,7 @@ fi
# GOPASS_SSH_KEYS holds a space-separated list of gopass entry names under ssh
if [ -z "${GOPASS_SSH_KEYS:-}" ]; then
- echo "Error: GOPASS_SSH_KEYS is not set. Example: GOPASS_SSH_KEYS=\"github gitlab\"" >&2
- exit 1
+ die "GOPASS_SSH_KEYS is not set. Example: GOPASS_SSH_KEYS=\"github gitlab\""
fi
# shellcheck disable=SC2086
@@ -63,6 +66,6 @@ for key in "${keys[@]}"; do
ssh-add "$keyfile" 2>/dev/null
rm -rf "$tmpdir"
else
- echo "Warning: no gopass entry ssh/$key" >&2
+ warn "no gopass entry ssh/$key"
fi
done
diff --git a/modules/security/gopass/gopass-sync-init.sh b/modules/security/gopass/gopass-sync-init.sh
index c7767f9..e00ce73 100644
--- a/modules/security/gopass/gopass-sync-init.sh
+++ b/modules/security/gopass/gopass-sync-init.sh
@@ -11,19 +11,24 @@
STORE_DIR="@@PASSWORD_STORE_DIR@@"
+info() { printf '\033[1;34m==>\033[0m %s\n' "$*"; }
+warn() { printf '\033[1;33m==> warning:\033[0m %s\n' "$*" >&2; }
+error() { printf '\033[1;31m==> error:\033[0m %s\n' "$*" >&2; }
+die() { error "$*"; exit 1; }
+
mkdir -p "$STORE_DIR"
-cd "$STORE_DIR" || { echo "Failed to enter $STORE_DIR"; exit 1; }
+cd "$STORE_DIR" || die "Failed to enter $STORE_DIR"
# Check if the directory is already a git repository; initialize if not
if ! git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
- echo "Initializing git repository in $STORE_DIR..."
+ info "Initializing git repository in $STORE_DIR..."
git init
fi
# Check if the remote 'origin' is set; add it if not
if ! git remote | grep -q "^origin$"; then
- echo "Adding remote origin..."
+ info "Adding remote origin..."
git remote add origin "@@REMOTE_REPO_URL@@"
fi
-echo "Password store git setup complete."
+info "Password store git setup complete."
diff --git a/modules/security/gpg/gpg-backup.sh b/modules/security/gpg/gpg-backup.sh
index 57c216b..c1b6c25 100644
--- a/modules/security/gpg/gpg-backup.sh
+++ b/modules/security/gpg/gpg-backup.sh
@@ -1,6 +1,11 @@
#!/usr/bin/env bash
set -euo pipefail
+info() { printf '\033[1;34m==>\033[0m %s\n' "$*"; }
+warn() { printf '\033[1;33m==> warning:\033[0m %s\n' "$*" >&2; }
+error() { printf '\033[1;31m==> error:\033[0m %s\n' "$*" >&2; }
+die() { error "$*"; exit 1; }
+
WORKDIR="$(mktemp -d)"
cleanup() {
@@ -12,9 +17,11 @@ cleanup() {
trap cleanup EXIT
usage() {
- echo "Usage:"
- echo " $0 export <filename> Export all GPG keys to an encrypted file"
- echo " $0 import <filename> Decrypt and import keys from a backup file"
+ echo "Usage: $0 <export|import> <filename>"
+ echo ""
+ echo "Commands:"
+ echo " export Export all GPG keys to an encrypted file"
+ echo " import Decrypt and import keys from a backup file"
exit 1
}
@@ -22,29 +29,28 @@ do_export() {
local outfile="$1"
if [[ -e "$outfile" ]]; then
- echo "!! Refusing to overwrite existing file: $outfile" >&2
- exit 1
+ die "Refusing to overwrite existing file: $outfile"
fi
- echo "==> Exporting public keys..."
+ info "Exporting public keys..."
gpg --export --armor > "$WORKDIR/public-keys.asc"
- echo "==> Exporting secret keys..."
+ info "Exporting secret keys..."
gpg --export-secret-keys --armor > "$WORKDIR/secret-keys.asc"
- echo "==> Exporting secret subkeys (if any)..."
+ info "Exporting secret subkeys (if any)..."
gpg --export-secret-subkeys --armor > "$WORKDIR/secret-subkeys.asc" || true
- echo "==> Exporting owner trust database..."
+ info "Exporting owner trust database..."
gpg --export-ownertrust > "$WORKDIR/ownertrust.txt"
- echo "==> Exporting revocation certificates..."
+ info "Exporting revocation certificates..."
mkdir -p "$WORKDIR/revocation-certs"
if [[ -d "$HOME/.gnupg/openpgp-revocs.d" ]]; then
cp "$HOME"/.gnupg/openpgp-revocs.d/*.rev "$WORKDIR/revocation-certs/" 2>/dev/null || true
fi
- echo "==> Bundling everything into a single archive..."
+ info "Bundling everything into a single archive..."
tar -C "$WORKDIR" -cf "$WORKDIR/gpg-full-backup.tar" \
public-keys.asc \
secret-keys.asc \
@@ -52,7 +58,7 @@ do_export() {
ownertrust.txt \
revocation-certs
- echo "==> Encrypting with GPG (AES256, SHA512, max S2K iteration count)..."
+ info "Encrypting with GPG (AES256, SHA512, max S2K iteration count)..."
echo " You will be prompted for a passphrase — use a strong one."
gpg --symmetric \
--cipher-algo AES256 \
@@ -63,21 +69,19 @@ do_export() {
--output "$outfile" \
"$WORKDIR/gpg-full-backup.tar"
- echo "==> Verifying: attempting decryption to confirm it works..."
+ info "Verifying: attempting decryption to confirm it works..."
if gpg --decrypt "$outfile" > "$WORKDIR/verify.tar" 2>/dev/null; then
if cmp -s "$WORKDIR/gpg-full-backup.tar" "$WORKDIR/verify.tar"; then
- echo "==> Verification succeeded: backup decrypts correctly."
+ info "Verification succeeded: backup decrypts correctly."
else
- echo "!! WARNING: decrypted content does not match original. Investigate before trusting this backup." >&2
- exit 1
+ die "Decrypted content does not match original. Investigate before trusting this backup."
fi
else
- echo "!! WARNING: decryption test failed." >&2
- exit 1
+ die "Decryption test failed."
fi
echo
- echo "==> Done."
+ info "Done."
echo " Encrypted backup: $outfile"
echo " Store this file somewhere safe (offline media, encrypted drive)."
echo " The S2K iteration count only helps if your passphrase itself"
@@ -88,42 +92,41 @@ do_import() {
local infile="$1"
if [[ ! -f "$infile" ]]; then
- echo "!! File not found: $infile" >&2
- exit 1
+ die "File not found: $infile"
fi
- echo "==> Decrypting $infile ..."
+ info "Decrypting $infile ..."
echo " You will be prompted for the backup's passphrase."
echo " Note: this may take a while due to the high S2K iteration count."
gpg --decrypt "$infile" > "$WORKDIR/gpg-full-backup.tar"
- echo "==> Extracting archive..."
+ info "Extracting archive..."
tar -C "$WORKDIR" -xf "$WORKDIR/gpg-full-backup.tar"
- echo "==> Importing public keys..."
+ info "Importing public keys..."
gpg --import "$WORKDIR/public-keys.asc"
- echo "==> Importing secret keys..."
+ info "Importing secret keys..."
gpg --import "$WORKDIR/secret-keys.asc"
if [[ -s "$WORKDIR/secret-subkeys.asc" ]]; then
- echo "==> Importing secret subkeys..."
+ info "Importing secret subkeys..."
gpg --import "$WORKDIR/secret-subkeys.asc" || true
fi
if [[ -f "$WORKDIR/ownertrust.txt" ]]; then
- echo "==> Importing owner trust database..."
+ info "Importing owner trust database..."
gpg --import-ownertrust "$WORKDIR/ownertrust.txt"
fi
if [[ -d "$WORKDIR/revocation-certs" ]] && [[ -n "$(ls -A "$WORKDIR/revocation-certs" 2>/dev/null)" ]]; then
- echo "==> Restoring revocation certificates..."
+ info "Restoring revocation certificates..."
mkdir -p "$HOME/.gnupg/openpgp-revocs.d"
cp "$WORKDIR"/revocation-certs/*.rev "$HOME/.gnupg/openpgp-revocs.d/" 2>/dev/null || true
fi
echo
- echo "==> Done. Keys imported into your GPG keyring."
+ info "Done. Keys imported into your GPG keyring."
echo " Run 'gpg --list-secret-keys' to confirm."
}
@@ -146,4 +149,4 @@ case "$command" in
*)
usage
;;
-esac
+esac \ No newline at end of file