Subversion Repositories ALCASAR

Rev

Rev 1744 | Rev 1764 | Go to most recent revision | Details | Compare with Previous | Last modification | View Log

Rev Author Line No. Line
318 richard 1
<?php
838 richard 2
/* written by steweb57 & Rexy */
318 richard 3
 
861 richard 4
/********************
1748 richard 5
* READ CONF FILES   *
861 richard 6
*********************/
841 richard 7
define ("CONF_FILE", "/usr/local/etc/alcasar.conf");
8
define ("ETHERS_FILE", "/usr/local/etc/alcasar-ethers");
1578 richard 9
$conf_files=array(CONF_FILE,ETHERS_FILE);
861 richard 10
foreach ($conf_files as $file){
11
if (!file_exists($file)){
12
	exit("Requested file ".$file." isn't present");}
13
if (!is_readable($file)){
14
	exit("Can't read the file ".$file);}
841 richard 15
}
16
 
318 richard 17
# Choice of language
18
$Language = 'en';
19
if(isset($_SERVER['HTTP_ACCEPT_LANGUAGE'])){
20
	$Langue		= explode(",",$_SERVER['HTTP_ACCEPT_LANGUAGE']);
21
	$Language	= strtolower(substr(chop($Langue[0]),0,2)); }
22
if($Language == 'fr'){
23
	$l_network_title	= "Configuration réseau";
1478 richard 24
	$l_extif_legend		= " (Interface connectée à Internet)";
25
	$l_intif_legend		= " (Réseau de consultation)";
318 richard 26
	$l_internet_legend	= "INTERNET";
1733 richard 27
	$l_ip_adr		= "Adresse IP";
28
	$l_ip_mask		= "Masque";
318 richard 29
	$l_ip_router		= "Passerelle";
736 franck 30
	$l_ip_public		= "Adresse IP publique";
1733 richard 31
	$l_ip_dns1		= "DNS1";
32
	$l_ip_dns2		= "DNS2";
861 richard 33
	$l_dhcp_title		= "Service DHCP";
862 richard 34
	$l_dhcp_state		= "Mode actuel";
1484 richard 35
	$l_DHCP_on		= "actif";
36
	$l_DHCP_off		= "inactif";
1493 franck 37
	$l_DHCP_off_explain	= "! Avant d'arrêter le serveur DHCP, vous devez renseigner les paramètres d'un serveur externe (cf. documentation).";
841 richard 38
	$l_static_dhcp_title	= "Réservation d'adresses IP statiques";
39
	$l_mac_address		= "Adresse MAC";
40
	$l_ip_address		= "Adresse IP";
1733 richard 41
	$l_mac_del		= "Supprimer de la liste";
841 richard 42
	$l_add_to_list		= "Ajouter";
1733 richard 43
	$l_apply		= "Appliquer les changements";
44
	$l_import_cert		= "Import de certificat";
45
	$l_private_key		= "Clé privée (.key) :";
46
	$l_certificate		= "Certificat (.crt) :";
1740 richard 47
	$l_server_chain		= "Chaîne de certification (si nécéssaire : .crt) :";
48
	$l_default_cert		= "Revenir au certificat d'origine";
49
	$l_import		= "Importer";
1743 clement.si 50
	$l_current_certificate  = "Certificat actuel";
51
	$l_validated		= "Validé par :";
841 richard 52
 
318 richard 53
} else {
54
	$l_network_title	= "Network configuration";
1478 richard 55
	$l_extif_legend		= " (Internet connected interface)";
56
	$l_intif_legend		= " (Private network)";
318 richard 57
	$l_internet_legend	= "INTERNET";
1733 richard 58
	$l_ip_adr		= "IP Address";
59
	$l_ip_mask		= "Mask";
841 richard 60
	$l_ip_router		= "Gateway";
318 richard 61
	$l_ip_public		= "Public IP address";
1733 richard 62
	$l_ip_dns1		= "DNS1";
63
	$l_ip_dns2		= "DNS2";
861 richard 64
	$l_dhcp_title		= "DHCP service";
862 richard 65
	$l_dhcp_state		= "Current mode";
1484 richard 66
	$l_DHCP_on		= "enabled";
67
	$l_DHCP_off		= "disabled";
68
	$l_DHCP_off_explain	= "! Before disabling the DHCP server, you must write the extern DHCP parameters in the config file (see Documentation)";
841 richard 69
	$l_static_dhcp_title	= "Static IP addresses reservation";
70
	$l_mac_address		= "MAC Address";
71
	$l_ip_address		= "IP Address";
1733 richard 72
	$l_mac_del		= "Delete from list";
841 richard 73
	$l_add_to_list		= "Add";
1733 richard 74
	$l_apply		= "Apply changes";
75
	$l_import_cert		= "Certificate import";
76
	$l_private_key		= "Private key (.key) :";
77
	$l_certificate		= "Certificate (.crt) :";
1740 richard 78
	$l_server_chain		= "Server-chain (if necessary : .crt) :";
1733 richard 79
	$l_default_cert		= "Back to default certificate";
1740 richard 80
	$l_import		= "Import";
1743 clement.si 81
	$l_current_certificate  = "Current certificate";
82
	$l_validated		= "Validated by :";
83
 
318 richard 84
}
841 richard 85
if (isset($_POST['choix'])){$choix=$_POST['choix'];} else {$choix="";}
86
switch ($choix)
87
{
1484 richard 88
case 'DHCP_On' :
89
	exec ("sudo /usr/local/sbin/alcasar-dhcp.sh -on");
841 richard 90
	break;
91
case 'DHCP_Off' :
92
	exec ("sudo /usr/local/sbin/alcasar-dhcp.sh -off");
93
	break;
94
case 'new_mac' :
95
	if ((trim($_POST['add_mac']) != "") and (trim($_POST['add_ip']) != ""))
96
		{
97
		$tab=file(ETHERS_FILE);
98
		$insert="True";
1710 richard 99
		if ($tab)  # the file isn't empty
841 richard 100
			{
859 richard 101
			foreach ($tab as $line)  # verify that MAC or IP addresses doesn't exist
841 richard 102
				{
103
				$field=explode(" ", $line);
104
				$mac_addr=trim($field[0]);$ip_addr=trim($field[1]);
859 richard 105
				if (strcasecmp(trim($_POST['add_mac']),trim($mac_addr)) == 0)
841 richard 106
					{
107
					$insert="False";
108
					break;
109
					}
859 richard 110
				if (strcasecmp(trim($_POST['add_ip']), trim($ip_addr)) == 0)
841 richard 111
					{
112
					$insert="False";
113
					break;
114
					}
115
				}
116
			}
1733 richard 117
		if ($insert == "True")
841 richard 118
			{
119
			$line = trim($_POST['add_mac']) . " " . trim($_POST['add_ip']) . "\n";
120
			$pointeur=fopen(ETHERS_FILE,"a");
121
			fwrite ($pointeur, $line);
122
			fclose ($pointeur);
1707 richard 123
			exec ("sudo /usr/bin/systemctl reload chilli");
841 richard 124
			}
125
		}
126
	break;
127
case 'del_mac' :
128
	$tab=file(ETHERS_FILE);
129
	if ($tab)
130
		{
131
		$pointeur=fopen(ETHERS_FILE,"w+");
132
		foreach ($tab as $line)
133
			{
134
			$field=explode(" ", $line);
135
			$mac_addr=trim($field[0]);
136
			$remove_line = False;
137
			foreach ($_POST as $key => $value)
138
				{
139
				if ($mac_addr == $key)
140
			       		{
141
					$remove_line = True;
142
					break;
143
					}
144
				}
145
			if (! $remove_line) {fwrite($pointeur,$line);}
146
			}
147
		fclose($pointeur);
1578 richard 148
		exec ("sudo /usr/bin/systemctl reload chilli");
841 richard 149
		}
150
	break;
318 richard 151
}
152
 
153
// Fonction de test de connectivité internet
154
function internetTest(){
696 franck 155
	$host = "www.google.fr"; # Google Test
318 richard 156
	$port = "80";
1710 richard 157
	//var $num;	//not used
158
	//var $error;	//not used
1733 richard 159
 
318 richard 160
	if (! $sock = @fsockopen($host, $port, $num, $error, 5)) {
161
		return false;
162
	} else {
163
		fclose($sock);
164
		return true;
165
	}
166
}
167
 
861 richard 168
/***********************************
169
*	Read ALCASAR_CONF_FILE     *
170
************************************/
654 richard 171
$ouvre=fopen(CONF_FILE,"r");
318 richard 172
if ($ouvre){
173
	while (!feof ($ouvre))
174
	{
175
		$tampon = fgets($ouvre, 4096);
176
		if (strpos($tampon,"=")!==false){
177
			$tmp = explode("=",$tampon);
654 richard 178
			$conf[$tmp[0]] = $tmp[1];
318 richard 179
		}
180
	}
1748 richard 181
	fclose($ouvre);
318 richard 182
}
183
 
184
/************************
185
*	TO DO		*
186
*************************/
838 richard 187
//modification de la conf réseau  --> V3.0
318 richard 188
 
1740 richard 189
?>
190
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
841 richard 191
<html><!-- written by steweb57 & rexy -->
318 richard 192
<head>
193
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
194
<title><?php echo $l_network_title; ?></title>
335 richard 195
<link rel="stylesheet" href="/css/style.css" type="text/css">
1578 richard 196
<script type="text/javascript">
197
function MAC_Control(formulaire){
198
/*MAC control (upper case and '-' separator*/
199
	var regex1 = /^([0-9a-fA-F]{2}(-|:)){5}[0-9a-fA-F]{2}$/; //vérification adresse mac
200
	if (regex1.test(document.forms[formulaire].add_mac.value)){
201
		document.forms[formulaire].add_mac.value=document.forms[formulaire].add_mac.value.toUpperCase().replace(/:/g, '-');
202
		return true;
203
	} else {
204
		alert("Invalid MAC address");//non internationnalisé
205
		return false;
206
	}
207
}
208
</script>
318 richard 209
</head>
210
<body>
211
<table width="100%" border="0" cellspacing="0" cellpadding="0">
353 richard 212
	<tr><th><?php echo $l_network_title; ?></th></tr>
318 richard 213
	<tr bgcolor="#FFCC66"><td><img src="/images/pix.gif" width="1" height="2"></td></tr>
214
</table>
215
<TABLE width="100%" border=1 cellspacing=0 cellpadding=1>
216
	<tr><td valign="middle" align="left">
217
	<fieldset>
218
	<legend><?php echo $l_internet_legend;
219
 	if (InternetTest()){
841 richard 220
		echo " <img src='/images/state_ok.gif'>";
318 richard 221
		$IP_PUB = exec ("wget http://checkip.dyndns.org/ -O - -o /dev/null | cut -d: -f 2 | cut -d\< -f 1");}
222
	else 	{
841 richard 223
		echo " <img src='/images/state_error.gif'>";
318 richard 224
		$IP_PUB = "-.-.-.-";}
225
	?></legend>
226
	<table>
227
		<tr><td><?php echo $l_ip_public." : </td><td>".$IP_PUB;?></td></tr>
654 richard 228
		<tr><td><?php echo $l_ip_dns1." : </td><td>".$conf["DNS1"];?></td></tr>
229
		<tr><td><?php echo $l_ip_dns2." : </td><td>".$conf["DNS2"];?></td></tr>
318 richard 230
	</table>
231
	</fieldset>
232
	</td><td>
233
	<fieldset>
1478 richard 234
	<legend><?php echo $conf["EXTIF"].$l_extif_legend; ?></legend>
318 richard 235
	<table>
654 richard 236
		<tr><td><?php echo $l_ip_adr." : </td><td>".$conf["PUBLIC_IP"];?></td></tr>
237
		<tr><td><?php echo $l_ip_router." : </td><td>".$conf["GW"];?></td></tr>
318 richard 238
	</table>
239
	</fieldset>
240
	</td><td>
241
	<fieldset>
1478 richard 242
	<legend><?php echo $conf["INTIF"].$l_intif_legend; ?></legend>
318 richard 243
	<table>
654 richard 244
		<tr><td><?php echo $l_ip_adr." : </td><td>".$conf["PRIVATE_IP"];?></td></tr>
318 richard 245
	</table>
246
	</fieldset>
247
	</td></tr>
248
</table>
353 richard 249
<table width="100%" border="0" cellspacing="0" cellpadding="0">
841 richard 250
	<tr><th><?php echo $l_dhcp_title;?></th></tr>
353 richard 251
	<tr bgcolor="#FFCC66"><td><img src="/images/pix.gif" width="1" height="2"></td></tr>
318 richard 252
</table>
841 richard 253
<table width="100%" border=1 cellspacing=0 cellpadding=0>
1484 richard 254
<tr><td colspan="2" valign="middle" align="left">
841 richard 255
<?
861 richard 256
$dhcp_state=trim($conf["DHCP"]);
862 richard 257
echo "<CENTER><H3>$l_dhcp_state : ${"l_DHCP_".$dhcp_state}</H3></CENTER>";
861 richard 258
echo "<FORM action='$_SERVER[PHP_SELF]' method=POST>";
259
echo "<select name='choix'>";
260
echo "<option value=\"DHCP_Off\" ";if (!strcmp($dhcp_state,"off")) echo "selected";echo ">$l_DHCP_off";
1484 richard 261
echo "<option value=\"DHCP_On\" ";if (!strcmp($dhcp_state,"on")) echo "selected";echo ">$l_DHCP_on";
861 richard 262
echo "</select>";
263
echo "<input type=submit value='$l_apply'>";
1484 richard 264
echo "<br>$l_DHCP_off_explain";
841 richard 265
echo "</FORM>";
266
echo "</td></tr>";
1484 richard 267
if (strncmp($conf["DHCP"],"on",2) == 0) { require ('network2.php');}
861 richard 268
else { echo "</TABLE>"; }
1710 richard 269
$maxsize=100000;
841 richard 270
?>
1710 richard 271
 
272
<table width="100%" border="0" cellspacing="0" cellpadding="0">
1733 richard 273
	<tr><th><?php echo $l_import_cert;?></th></tr>
1710 richard 274
	<tr bgcolor="#FFCC66"><td><img src="/images/pix.gif" width="1" height="2"></td></tr>
275
</table>
276
<table width="100%" border="1" cellspacing="0" cellpadding="0">
277
	<tr><td>
278
	<form method="post" action="network.php" enctype="multipart/form-data">
1740 richard 279
	<?php echo $l_private_key;?><input type="file" name="key"><br>
280
	<?php echo $l_certificate;?><input type="file" name="crt"><br>
281
	<?php echo $l_server_chain;?><input type="file" name="sc">
282
	<input type="hidden" name="MAX_FILE_SIZE" value=<?php echo $maxsize;?>><br>
283
	<input type="submit" <?php echo "value=\"".$l_import."\""?>>
1710 richard 284
	</form>
1743 clement.si 285
<?php
1744 clement.si 286
$domain = exec("/bin/openssl x509 -noout -subject -in /etc/pki/tls/certs/alcasar.crt | sed -n '/^subject/s/^.*CN=//p' | cut -d'/' -f 1");
287
$organization = exec("/bin/openssl x509 -noout -subject -in /etc/pki/tls/certs/alcasar.crt | sed -n '/^subject/s/^.*O=//p' | cut -d'/' -f 1");
288
$CAdomain = exec("/bin/openssl x509 -noout -issuer -in /etc/pki/tls/certs/alcasar.crt | sed -n '/^issuer/s/^.*CN=//p' | cut -d'/' -f 1");
289
$CAorganization = exec("/bin/openssl x509 -noout -issuer -in /etc/pki/tls/certs/alcasar.crt | sed -n '/^issuer/s/^.*O=//p' | cut -d'/' -f 1");
1743 clement.si 290
 
291
	echo "<br><br>\n";
292
	echo "<h3>".$l_current_certificate."</h3>\n";
293
	echo "Common name : ".$domain."<br>\n";
294
	echo "Organization : ".$organization."<br/>\n";
295
	echo "<h4>". $l_validated ."</h4>\n";
296
	echo "Common name : ".$CAdomain."<br>\n";
297
	echo "Organization : ".$CAorganization."<br>\n";
298
?>
1710 richard 299
	</td><td>
300
	<form method="post" action="network.php">
1740 richard 301
	<input type="hidden" name="default">
1743 clement.si 302
	<input type="submit" <?php echo "value=\"".$l_default_cert."\""; if(!file_exists("/etc/pki/tls/certs/alcasar.crt.old") || !file_exists("/etc/pki/tls/private/alcasar.key.old")){ echo "disabled";}?> >
1710 richard 303
	</form>
304
	</td>
305
	</tr>
306
</table>
307
 
318 richard 308
</body>
309
</html>
1710 richard 310
 
311
<?php
312
if(isset($_POST['default'])){
1740 richard 313
	echo "$l_default_cert";
1733 richard 314
	exec("sudo alcasar-importcert.sh -d");
1710 richard 315
}
316
if(isset($_POST['MAX_FILE_SIZE'])){
317
	echo "changement";
318
	$maxsize = 100000;
319
	if(isset($_FILES['key']) && isset($_FILES['crt']) && $_FILES['key']['error'] == 0 && $_FILES['crt']['error'] == 0){
320
		$dest = "/tmp/";
321
		if($_FILES['key']['size'] <= $maxsize && $_FILES['crt']['size'] <= $maxsize)
322
		{
323
			if(pathinfo($_FILES['key']['name'])['extension'] == 'key' && pathinfo($_FILES['crt']['name'])['extension'] == 'crt')
324
			{
325
				$scpath = "";
326
				if(isset($_FILES['sc']) && pathinfo($_FILES['sc']['name'])['extension'] == 'crt')
327
				{
328
					$scpath = $dest."server-chain.crt";
1740 richard 329
					move_uploaded_file($_FILES['sc']['tmp_name'], $scpath);
1710 richard 330
				}
331
				$keypath = $dest."alcasar.key";
332
				$crtpath = $dest."alcasar.crt";
333
				move_uploaded_file($_FILES['key']['tmp_name'], $keypath);
334
				move_uploaded_file($_FILES['crt']['tmp_name'], $crtpath);
335
				exec("sudo alcasar-importcert.sh -i $crtpath -k $keypath -c $scpath");
336
			}
337
		}
338
	}
339
}
340
?>