This repository has been archived by the owner on Jun 19, 2020. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 24
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
(FACT-2330) Add ssh fact for Windows OpenSSH feature
- Loading branch information
Oana Tanasoiu
committed
Apr 8, 2020
1 parent
43fc506
commit 8aad8c3
Showing
10 changed files
with
338 additions
and
97 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,27 @@ | ||
# frozen_string_literal: true | ||
|
||
module Facts | ||
module Windows | ||
class Ssh | ||
FACT_NAME = 'ssh' | ||
|
||
def call_the_resolver | ||
privileged = Facter::Resolvers::Identity.resolve(:privileged) | ||
ssh_info = Facter::Resolvers::Windows::Ssh.resolve(:ssh) if privileged | ||
ssh_facts = {} | ||
ssh_info&.each { |ssh| ssh_facts.merge!(create_ssh_fact(ssh)) } | ||
Facter::ResolvedFact.new(FACT_NAME, ssh_facts.empty? ? nil : ssh_facts) | ||
end | ||
|
||
private | ||
|
||
def create_ssh_fact(ssh) | ||
{ ssh.name.to_sym => | ||
{ fingerprints: { sha1: ssh.fingerprint.sha1, | ||
sha256: ssh.fingerprint.sha256 }, | ||
key: ssh.key, | ||
type: ssh.type } } | ||
end | ||
end | ||
end | ||
end |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,25 @@ | ||
# frozen_string_literal: true | ||
|
||
require 'base64' | ||
require 'digest/sha1' | ||
|
||
module Facter | ||
class SshHelper | ||
class << self | ||
SSH_NAME = { 'ssh-dss' => 'dsa', 'ecdsa-sha2-nistp256' => 'ecdsa', | ||
'ssh-ed25519' => 'ed25519', 'ssh-rsa' => 'rsa' }.freeze | ||
SSH_FINGERPRINT = { 'rsa' => 1, 'dsa' => 2, 'ecdsa' => 3, 'ed25519' => 4 }.freeze | ||
|
||
def create_ssh(key_type, key) | ||
key_name = SSH_NAME[key] | ||
decoded_key = Base64.decode64(key) | ||
ssh_fp = SSH_FINGERPRINT[key_name] | ||
sha1 = "SSHFP #{ssh_fp} 1 #{Digest::SHA1.new.update(decoded_key)}" | ||
sha256 = "SSHFP #{ssh_fp} 2 #{Digest::SHA2.new.update(decoded_key)}" | ||
|
||
fingerprint = FingerPrint.new(sha1, sha256) | ||
Ssh.new(fingerprint, key_type, key, key_name) | ||
end | ||
end | ||
end | ||
end |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,46 @@ | ||
# frozen_string_literal: true | ||
|
||
module Facter | ||
module Resolvers | ||
module Windows | ||
class Ssh < BaseResolver | ||
@log = Facter::Log.new(self) | ||
@semaphore = Mutex.new | ||
@fact_list ||= {} | ||
FILE_NAMES = %w[ssh_host_rsa_key.pub ssh_host_dsa_key.pub | ||
ssh_host_ecdsa_key.pub ssh_host_ed25519_key.pub].freeze | ||
class << self | ||
private | ||
|
||
def post_resolve(fact_name) | ||
@fact_list.fetch(fact_name) { retrieve_info(fact_name) } | ||
end | ||
|
||
def retrieve_info(fact_name) | ||
ssh_dir = determine_ssh_dir | ||
return unless ssh_dir && File.directory?(ssh_dir) | ||
|
||
ssh_list = [] | ||
|
||
FILE_NAMES.each do |file_name| | ||
next unless File.readable?(File.join(ssh_dir, file_name)) | ||
|
||
key_type, key = File.read(File.join(ssh_dir, file_name)).split(' ') | ||
ssh_list << SshHelper.create_ssh(key_type, key) | ||
end | ||
@fact_list[:ssh] = ssh_list.empty? ? nil : ssh_list | ||
@fact_list[fact_name] | ||
end | ||
|
||
def determine_ssh_dir | ||
progdata_dir = ENV['programdata'] | ||
|
||
return if !progdata_dir || progdata_dir.empty? | ||
|
||
File.join(progdata_dir, 'ssh') | ||
end | ||
end | ||
end | ||
end | ||
end | ||
end |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,87 @@ | ||
# frozen_string_literal: true | ||
|
||
describe Facts::Windows::Ssh do | ||
describe '#call_the_resolver' do | ||
subject(:fact) { Facts::Windows::Ssh.new } | ||
|
||
context 'when user is privileged' do | ||
let(:ssh) do | ||
[Facter::Ssh.new(Facter::FingerPrint.new('test', 'test'), 'ecdsa', 'test', 'ecdsa')] | ||
end | ||
let(:value) do | ||
{ 'ecdsa' => { 'fingerprints' => | ||
{ 'sha1' => 'test', 'sha256' => 'test' }, | ||
'key' => 'test', | ||
'type' => 'ecdsa' } } | ||
end | ||
|
||
before do | ||
allow(Facter::Resolvers::Identity).to receive(:resolve).with(:privileged).and_return(true) | ||
allow(Facter::Resolvers::Windows::Ssh).to receive(:resolve).with(:ssh).and_return(ssh) | ||
end | ||
|
||
it 'calls Facter::Resolvers::Windows::Ssh' do | ||
fact.call_the_resolver | ||
expect(Facter::Resolvers::Windows::Ssh).to have_received(:resolve).with(:ssh) | ||
end | ||
|
||
it 'calls Facter::Resolvers::Windows::Identity' do | ||
fact.call_the_resolver | ||
expect(Facter::Resolvers::Identity).to have_received(:resolve).with(:privileged) | ||
end | ||
|
||
it 'returns ssh fact' do | ||
expect(fact.call_the_resolver).to be_an_instance_of(Facter::ResolvedFact).and \ | ||
have_attributes(name: 'ssh', value: value) | ||
end | ||
end | ||
|
||
context 'when user is privileged but no ssh key found' do | ||
let(:value) { nil } | ||
|
||
before do | ||
allow(Facter::Resolvers::Identity).to receive(:resolve).with(:privileged).and_return(true) | ||
allow(Facter::Resolvers::Windows::Ssh).to receive(:resolve).with(:ssh).and_return({}) | ||
end | ||
|
||
it 'calls Facter::Resolvers::Windows::Ssh' do | ||
fact.call_the_resolver | ||
expect(Facter::Resolvers::Windows::Ssh).to have_received(:resolve).with(:ssh) | ||
end | ||
|
||
it 'calls Facter::Resolvers::Windows::Identity' do | ||
fact.call_the_resolver | ||
expect(Facter::Resolvers::Identity).to have_received(:resolve).with(:privileged) | ||
end | ||
|
||
it 'returns ssh fact' do | ||
expect(fact.call_the_resolver).to be_an_instance_of(Facter::ResolvedFact).and \ | ||
have_attributes(name: 'ssh', value: value) | ||
end | ||
end | ||
|
||
context 'when user is not privileged' do | ||
let(:value) { nil } | ||
|
||
before do | ||
allow(Facter::Resolvers::Identity).to receive(:resolve).with(:privileged).and_return(false) | ||
allow(Facter::Resolvers::Windows::Ssh).to receive(:resolve).with(:ssh).and_return(value) | ||
end | ||
|
||
it "doesn't call Facter::Resolvers::Windows::Ssh" do | ||
fact.call_the_resolver | ||
expect(Facter::Resolvers::Windows::Ssh).not_to have_received(:resolve).with(:ssh) | ||
end | ||
|
||
it 'calls Facter::Resolvers::Windows::Identity' do | ||
fact.call_the_resolver | ||
expect(Facter::Resolvers::Identity).to have_received(:resolve).with(:privileged) | ||
end | ||
|
||
it 'returns ssh fact' do | ||
expect(fact.call_the_resolver).to be_an_instance_of(Facter::ResolvedFact).and \ | ||
have_attributes(name: 'ssh', value: value) | ||
end | ||
end | ||
end | ||
end |
Oops, something went wrong.