sshd revision 136224
1169691Skan#!/bin/sh
2169691Skan#
3169691Skan# $NetBSD: sshd,v 1.18 2002/04/29 08:23:34 lukem Exp $
4169691Skan# $FreeBSD: head/etc/rc.d/sshd 136224 2004-10-07 13:55:26Z mtm $
5169691Skan#
6169691Skan
7169691Skan# PROVIDE: sshd
8169691Skan# REQUIRE: LOGIN
9169691Skan
10169691Skan. /etc/rc.subr
11169691Skan
12169691Skanname="sshd"
13169691Skanrcvar=`set_rcvar`
14169691Skankeygen_cmd="sshd_keygen"
15169691Skanstart_precmd="sshd_precmd"
16169691Skanpidfile="/var/run/${name}.pid"
17169691Skanextra_commands="keygen reload"
18169691Skan
19169691Skantimeout=300
20169691Skan
21169691Skanuser_reseed()
22169691Skan{
23169691Skan	(
24169691Skan	seeded=`sysctl -n kern.random.sys.seeded 2>/dev/null`
25169691Skan	if [ "${seeded}" != "" ] ; then
26169691Skan		warn "Setting entropy source to blocking mode."
27169691Skan		echo "===================================================="
28169691Skan		echo "Type a full screenful of random junk to unblock"
29169691Skan		echo "it and remember to finish with <enter>. This will"
30169691Skan		echo "timeout in ${timeout} seconds, but waiting for"
31169691Skan		echo "the timeout without typing junk may make the"
32169691Skan		echo "entropy source deliver predictable output."
33169691Skan		echo ""
34169691Skan		echo "Just hit <enter> for fast+insecure startup."
35169691Skan		echo "===================================================="
36169691Skan		sysctl kern.random.sys.seeded=0 2>/dev/null
37169691Skan		read -t ${timeout} junk
38169691Skan		echo "${junk}" `sysctl -a` `date` > /dev/random
39169691Skan	fi
40169691Skan	)
41169691Skan}
42169691Skan
43169691Skansshd_keygen()
44169691Skan{
45169691Skan	(
46169691Skan	umask 022
47169691Skan
48169691Skan	# Can't do anything if ssh is not installed
49169691Skan	[ -x /usr/bin/ssh-keygen ] || {
50169691Skan		warn "/usr/bin/ssh-keygen does not exist."
51169691Skan		return 1
52169691Skan	}
53169691Skan
54169691Skan	if [ -f /etc/ssh/ssh_host_key ]; then
55169691Skan		echo "You already have an RSA host key" \
56169691Skan		    "in /etc/ssh/ssh_host_key"
57169691Skan		echo "Skipping protocol version 1 RSA Key Generation"
58169691Skan	else
59169691Skan		/usr/bin/ssh-keygen -t rsa1 -b 1024 \
60169691Skan		    -f /etc/ssh/ssh_host_key -N ''
61169691Skan	fi
62169691Skan
63169691Skan	if [ -f /etc/ssh/ssh_host_dsa_key ]; then
64169691Skan		echo "You already have a DSA host key" \
65169691Skan		    "in /etc/ssh/ssh_host_dsa_key"
66169691Skan		echo "Skipping protocol version 2 DSA Key Generation"
67169691Skan	else
68169691Skan		/usr/bin/ssh-keygen -t dsa -f /etc/ssh/ssh_host_dsa_key -N ''
69169691Skan	fi
70169691Skan
71169691Skan	if [ -f /etc/ssh/ssh_host_rsa_key ]; then
72169691Skan		echo "You already have a RSA host key" \
73169691Skan		    "in /etc/ssh/ssh_host_rsa_key"
74169691Skan		echo "Skipping protocol version 2 RSA Key Generation"
75	else
76		/usr/bin/ssh-keygen -t rsa -f /etc/ssh/ssh_host_rsa_key -N ''
77	fi
78	)
79}
80
81sshd_precmd()
82{
83	if [ ! -f /etc/ssh/ssh_host_key -o \
84	    ! -f /etc/ssh/ssh_host_dsa_key -o \
85	    ! -f /etc/ssh/ssh_host_rsa_key ]; then
86		user_reseed
87		run_rc_command keygen
88	fi
89}
90
91load_rc_config $name
92run_rc_command "$1"
93