mirror of
https://github.com/angristan/openvpn-install.git
synced 2024-12-04 22:45:32 +01:00
chown/chmod client file when name match system user (#961)
This commit is contained in:
parent
8c6266053b
commit
610d42e6b2
@ -1097,6 +1097,7 @@ function newClient() {
|
|||||||
if [ -e "/home/${CLIENT}" ]; then
|
if [ -e "/home/${CLIENT}" ]; then
|
||||||
# if $1 is a user name
|
# if $1 is a user name
|
||||||
homeDir="/home/${CLIENT}"
|
homeDir="/home/${CLIENT}"
|
||||||
|
CLIENT_OWNER="$CLIENT"
|
||||||
elif [ "${SUDO_USER}" ]; then
|
elif [ "${SUDO_USER}" ]; then
|
||||||
# if not, use SUDO_USER
|
# if not, use SUDO_USER
|
||||||
if [ "${SUDO_USER}" == "root" ]; then
|
if [ "${SUDO_USER}" == "root" ]; then
|
||||||
@ -1105,11 +1106,14 @@ function newClient() {
|
|||||||
else
|
else
|
||||||
homeDir="/home/${SUDO_USER}"
|
homeDir="/home/${SUDO_USER}"
|
||||||
fi
|
fi
|
||||||
|
CLIENT_OWNER="$SUDO_USER"
|
||||||
else
|
else
|
||||||
# if not SUDO_USER, use /root
|
# if not SUDO_USER, use /root
|
||||||
homeDir="/root"
|
homeDir="/root"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
CLIENT_FILEPATH="$homeDir/$CLIENT.ovpn"
|
||||||
|
|
||||||
# Determine if we use tls-auth or tls-crypt
|
# Determine if we use tls-auth or tls-crypt
|
||||||
if grep -qs "^tls-crypt" /etc/openvpn/server.conf; then
|
if grep -qs "^tls-crypt" /etc/openvpn/server.conf; then
|
||||||
TLS_SIG="1"
|
TLS_SIG="1"
|
||||||
@ -1118,7 +1122,7 @@ function newClient() {
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
# Generates the custom client.ovpn
|
# Generates the custom client.ovpn
|
||||||
cp /etc/openvpn/client-template.txt "$homeDir/$CLIENT.ovpn"
|
cp /etc/openvpn/client-template.txt "$CLIENT_FILEPATH"
|
||||||
{
|
{
|
||||||
echo "<ca>"
|
echo "<ca>"
|
||||||
cat "/etc/openvpn/easy-rsa/pki/ca.crt"
|
cat "/etc/openvpn/easy-rsa/pki/ca.crt"
|
||||||
@ -1145,10 +1149,18 @@ function newClient() {
|
|||||||
echo "</tls-auth>"
|
echo "</tls-auth>"
|
||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
} >>"$homeDir/$CLIENT.ovpn"
|
} >>"$CLIENT_FILEPATH"
|
||||||
|
|
||||||
|
if [[ -n "$CLIENT_OWNER" ]]; then
|
||||||
|
echo "Setting owner permission for $CLIENT_FILEPATH"
|
||||||
|
CLIENT_OWNER_GROUP=$(id -gn "$CLIENT_OWNER")
|
||||||
|
|
||||||
|
chmod go-rw "$CLIENT_FILEPATH"
|
||||||
|
chown "$CLIENT_OWNER:$CLIENT_OWNER_GROUP" "$CLIENT_FILEPATH"
|
||||||
|
fi
|
||||||
|
|
||||||
echo ""
|
echo ""
|
||||||
echo "The configuration file has been written to $homeDir/$CLIENT.ovpn."
|
echo "The configuration file has been written to $CLIENT_FILEPATH."
|
||||||
echo "Download the .ovpn file and import it in your OpenVPN client."
|
echo "Download the .ovpn file and import it in your OpenVPN client."
|
||||||
|
|
||||||
exit 0
|
exit 0
|
||||||
|
Loading…
Reference in New Issue
Block a user