sshd revision 136224
1169691Skan#!/bin/sh 2169691Skan# 3169691Skan# $NetBSD: sshd,v 1.18 2002/04/29 08:23:34 lukem Exp $ 4169691Skan# $FreeBSD: head/etc/rc.d/sshd 136224 2004-10-07 13:55:26Z mtm $ 5169691Skan# 6169691Skan 7169691Skan# PROVIDE: sshd 8169691Skan# REQUIRE: LOGIN 9169691Skan 10169691Skan. /etc/rc.subr 11169691Skan 12169691Skanname="sshd" 13169691Skanrcvar=`set_rcvar` 14169691Skankeygen_cmd="sshd_keygen" 15169691Skanstart_precmd="sshd_precmd" 16169691Skanpidfile="/var/run/${name}.pid" 17169691Skanextra_commands="keygen reload" 18169691Skan 19169691Skantimeout=300 20169691Skan 21169691Skanuser_reseed() 22169691Skan{ 23169691Skan ( 24169691Skan seeded=`sysctl -n kern.random.sys.seeded 2>/dev/null` 25169691Skan if [ "${seeded}" != "" ] ; then 26169691Skan warn "Setting entropy source to blocking mode." 27169691Skan echo "====================================================" 28169691Skan echo "Type a full screenful of random junk to unblock" 29169691Skan echo "it and remember to finish with <enter>. This will" 30169691Skan echo "timeout in ${timeout} seconds, but waiting for" 31169691Skan echo "the timeout without typing junk may make the" 32169691Skan echo "entropy source deliver predictable output." 33169691Skan echo "" 34169691Skan echo "Just hit <enter> for fast+insecure startup." 35169691Skan echo "====================================================" 36169691Skan sysctl kern.random.sys.seeded=0 2>/dev/null 37169691Skan read -t ${timeout} junk 38169691Skan echo "${junk}" `sysctl -a` `date` > /dev/random 39169691Skan fi 40169691Skan ) 41169691Skan} 42169691Skan 43169691Skansshd_keygen() 44169691Skan{ 45169691Skan ( 46169691Skan umask 022 47169691Skan 48169691Skan # Can't do anything if ssh is not installed 49169691Skan [ -x /usr/bin/ssh-keygen ] || { 50169691Skan warn "/usr/bin/ssh-keygen does not exist." 51169691Skan return 1 52169691Skan } 53169691Skan 54169691Skan if [ -f /etc/ssh/ssh_host_key ]; then 55169691Skan echo "You already have an RSA host key" \ 56169691Skan "in /etc/ssh/ssh_host_key" 57169691Skan echo "Skipping protocol version 1 RSA Key Generation" 58169691Skan else 59169691Skan /usr/bin/ssh-keygen -t rsa1 -b 1024 \ 60169691Skan -f /etc/ssh/ssh_host_key -N '' 61169691Skan fi 62169691Skan 63169691Skan if [ -f /etc/ssh/ssh_host_dsa_key ]; then 64169691Skan echo "You already have a DSA host key" \ 65169691Skan "in /etc/ssh/ssh_host_dsa_key" 66169691Skan echo "Skipping protocol version 2 DSA Key Generation" 67169691Skan else 68169691Skan /usr/bin/ssh-keygen -t dsa -f /etc/ssh/ssh_host_dsa_key -N '' 69169691Skan fi 70169691Skan 71169691Skan if [ -f /etc/ssh/ssh_host_rsa_key ]; then 72169691Skan echo "You already have a RSA host key" \ 73169691Skan "in /etc/ssh/ssh_host_rsa_key" 74169691Skan echo "Skipping protocol version 2 RSA Key Generation" 75 else 76 /usr/bin/ssh-keygen -t rsa -f /etc/ssh/ssh_host_rsa_key -N '' 77 fi 78 ) 79} 80 81sshd_precmd() 82{ 83 if [ ! -f /etc/ssh/ssh_host_key -o \ 84 ! -f /etc/ssh/ssh_host_dsa_key -o \ 85 ! -f /etc/ssh/ssh_host_rsa_key ]; then 86 user_reseed 87 run_rc_command keygen 88 fi 89} 90 91load_rc_config $name 92run_rc_command "$1" 93