2007-11-14 14:32:08 -06:00
|
|
|
#! /usr/bin/python -E
|
|
|
|
# Authors: John Dennis <jdennis@redhat.com>
|
|
|
|
#
|
|
|
|
# Copyright (C) 2007 Red Hat
|
|
|
|
# see file 'COPYING' for use and warranty information
|
|
|
|
#
|
|
|
|
# This program is free software; you can redistribute it and/or
|
|
|
|
# modify it under the terms of the GNU General Public License as
|
|
|
|
# published by the Free Software Foundation; version 2 only
|
|
|
|
#
|
|
|
|
# This program is distributed in the hope that it will be useful,
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
# GNU General Public License for more details.
|
|
|
|
#
|
|
|
|
# You should have received a copy of the GNU General Public License
|
|
|
|
# along with this program; if not, write to the Free Software
|
|
|
|
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
|
|
|
#
|
|
|
|
|
2007-11-23 09:35:22 -06:00
|
|
|
import os
|
2007-11-14 14:32:08 -06:00
|
|
|
import sys
|
|
|
|
from optparse import OptionParser
|
|
|
|
import ipa
|
Add radius profile implementations:
get_radius_profile_by_uid
add_radius_profile
update_radius_profile
delete_radius_profile
find_radius_profiles
Rewrite command line arg handling, now support pair entry, interactive
mode with auto completion, reading pairs from a file, better handling
of mandatory values, better help, long arg names now match attribute
name in pairs
Establish mappings for all attributes and names used in clients and
profiles
Add notion of containers to radius clients and profiles in LDAP
Move common code, variables, constants, and strings into the files
radius_client.py, radius_util.py, ipautil.py to eliminate redundant
elements which could get out of sync if modified and to provide access
to other code which might benefit from using these items in the
future.
Add utility functions:
format_list()
parse_key_value_pairs()
Add utility class:
AttributeValueCompleter
Unify attribute usage in radius ldap schema
2007-11-21 12:11:10 -06:00
|
|
|
from ipa import radius_util
|
2007-11-14 14:32:08 -06:00
|
|
|
import ipa.ipaclient as ipaclient
|
|
|
|
import ipa.ipavalidate as ipavalidate
|
|
|
|
import ipa.config
|
|
|
|
import ipa.ipaerror
|
2007-11-14 15:01:27 -06:00
|
|
|
import ipa.ipautil
|
2007-11-14 14:32:08 -06:00
|
|
|
|
|
|
|
import xmlrpclib
|
|
|
|
import kerberos
|
|
|
|
import ldap
|
|
|
|
|
|
|
|
#------------------------------------------------------------------------------
|
|
|
|
|
2007-11-24 10:20:28 -06:00
|
|
|
attrs = radius_util.radius_client_ldap_attr_to_radius_attr.keys()
|
2007-11-23 09:35:22 -06:00
|
|
|
|
|
|
|
#------------------------------------------------------------------------------
|
2007-11-14 14:32:08 -06:00
|
|
|
|
2007-11-23 09:35:22 -06:00
|
|
|
def parse_options():
|
2007-11-14 14:32:08 -06:00
|
|
|
return options, args
|
|
|
|
|
|
|
|
#------------------------------------------------------------------------------
|
|
|
|
|
|
|
|
# FIXME
|
2007-11-23 09:35:22 -06:00
|
|
|
def help_option_callback(option, opt_str, value, parser, *args, **kwargs):
|
|
|
|
parser.print_help()
|
|
|
|
print
|
|
|
|
print "Note: Client-IP-Address may contain wildcards, to get all clients use '*'"
|
|
|
|
sys.exit(0)
|
2007-11-14 14:32:08 -06:00
|
|
|
|
|
|
|
def main():
|
2007-11-23 09:35:22 -06:00
|
|
|
opt_parser = OptionParser(add_help_option=False)
|
|
|
|
opt_parser.add_option("-h", "--help", action="callback", callback=help_option_callback,
|
|
|
|
help="detailed help information")
|
|
|
|
|
2008-08-15 11:08:01 -05:00
|
|
|
ipa.config.add_standard_options(opt_parser)
|
|
|
|
options, args = opt_parser.parse_args()
|
2007-11-14 14:32:08 -06:00
|
|
|
|
2007-11-23 09:35:22 -06:00
|
|
|
opt_parser.set_usage("Usage: %s [options] Client-IP-Address [Client-IP-Address ...]" % (os.path.basename(sys.argv[0])))
|
2007-11-14 14:32:08 -06:00
|
|
|
|
2008-08-15 11:08:01 -05:00
|
|
|
if len(args) < 1:
|
2007-11-23 09:35:22 -06:00
|
|
|
opt_parser.error("missing Client-IP-Address(es)")
|
2007-11-14 14:32:08 -06:00
|
|
|
|
2008-08-15 11:08:01 -05:00
|
|
|
ipa.config.init_config(options)
|
|
|
|
|
|
|
|
ip_addrs = args
|
2007-11-14 14:32:08 -06:00
|
|
|
|
|
|
|
try:
|
|
|
|
ipa_client = ipaclient.IPAClient()
|
|
|
|
radius_clients = ipa_client.find_radius_clients(ip_addrs, sattrs=attrs)
|
|
|
|
counter = radius_clients[0]
|
|
|
|
radius_clients = radius_clients[1:]
|
|
|
|
|
|
|
|
if counter == 0:
|
|
|
|
print "No entries found for", ip_addrs
|
|
|
|
return 2
|
|
|
|
|
|
|
|
for radius_client in radius_clients:
|
2007-11-23 09:35:22 -06:00
|
|
|
client_attrs = radius_client.attrList()
|
|
|
|
client_attrs.sort()
|
2007-11-14 14:32:08 -06:00
|
|
|
|
2007-11-24 10:20:28 -06:00
|
|
|
print "%s:" % radius_client.getValues(radius_util.radius_client_attr_to_ldap_attr['Client-IP-Address'])
|
2007-11-23 09:35:22 -06:00
|
|
|
for attr in client_attrs:
|
2007-11-14 14:32:08 -06:00
|
|
|
value = radius_client.getValues(attr)
|
2007-11-24 10:20:28 -06:00
|
|
|
print "\t%s = %s" % (radius_util.radius_client_ldap_attr_to_radius_attr[attr], value)
|
2007-11-14 14:32:08 -06:00
|
|
|
|
|
|
|
except xmlrpclib.Fault, f:
|
|
|
|
print f.faultString
|
|
|
|
return 1
|
|
|
|
except kerberos.GSSError, e:
|
|
|
|
print "Could not initialize GSSAPI: %s/%s" % (e[0][0][0], e[0][1][0])
|
|
|
|
return 1
|
|
|
|
except xmlrpclib.ProtocolError, e:
|
|
|
|
print "Unable to connect to IPA server: %s" % (e.errmsg)
|
|
|
|
return 1
|
|
|
|
except ipa.ipaerror.IPAError, e:
|
|
|
|
print "%s" % (e.message)
|
|
|
|
return 1
|
|
|
|
|
|
|
|
return 0
|
|
|
|
|
|
|
|
if __name__ == "__main__":
|
|
|
|
sys.exit(main())
|