59 lines
2.1 KiB
Bash
59 lines
2.1 KiB
Bash
mrepo=https://git.bprieshof.nl/Work/BCK-ServTest
|
|
mbranch=master
|
|
|
|
#install needed packages
|
|
apt install rssh vsftpd -y
|
|
|
|
#Setup groups
|
|
groupadd sftpusers
|
|
groupadd ftpusers
|
|
groupadd BCKviewer
|
|
groupadd BCKadmin
|
|
|
|
#setup Folders
|
|
mkdir -p /backups/ftp/
|
|
mkdir -p /backups/sftp/
|
|
mkdir -p /vhome
|
|
|
|
#setup tools
|
|
wget -q -t7 "$repo"/raw/branch/"$branch"/Tools/aclutil -O /tools/aclutil
|
|
wget -q -t7 "$repo"/raw/branch/"$branch"/Tools/adduserutil -O /tools/adduserutil
|
|
wget -q -t7 "$repo"/raw/branch/"$branch"/Tools/deluserutil -O /tools/deluserutil
|
|
wget -q -t7 "$repo"/raw/branch/"$branch"/Tools/ez-aclutil -O /tools/ez-aclutil
|
|
chmod 700 /tools/deluserutil
|
|
chmod 700 /tools/adduserutil
|
|
chmod 700 /tools/aclutil
|
|
chmod 700 /tools/ez-aclutil
|
|
|
|
#SSH Config
|
|
sed -i -e '/Subsystem\ssftp/c\Subsystem sftp internal-sftp' sshd_config
|
|
curl --silent --show-error "$repo"/raw/branch/"$branch"/config/sshd_append.conf >>/etc/ssh/sshd_config
|
|
|
|
#rssh Config
|
|
curl --silent --show-error "$repo"/raw/branch/"$branch"/config/rssh_append.conf >>/etc/rssh.conf
|
|
|
|
#vsftp Config
|
|
openssl req -new -x509 -nodes -days 3650 -newkey rsa:2048 -keyout /etc/ssl/private/vsftpd.pem -out /etc/ssl/private/vsftpd.pem -subj "/C=NL/ST=Gelderland/L=Arnhem/O=ICT Maatwerk B.V./CN=$(hostname -f)"
|
|
wget -q -t7 "$repo"/raw/branch/"$branch"/config/vsftpd.conf -O /etc/vsftpd.conf
|
|
|
|
#sudo Config
|
|
wget -q -t7 "$repo"/raw/branch/"$branch"/config/sudo.conf -O ~/
|
|
|
|
#Setup grequalizer
|
|
git clone https://github.com/lpirl/grequalizer.git /opt/grequalizer
|
|
mkdir /opt/grequalizer/conf/
|
|
echo "/opt/grequalizer" > /opt/grequalizer/conf/files_to_chroots.txt
|
|
echo "/usr/bin/rsync" > /opt/grequalizer/conf/binaries_to_chroots.txt
|
|
echo "/usr/bin/rssh" >> /opt/grequalizer/conf/binaries_to_chroots.txt
|
|
wget -q -t7 "$repo"/raw/branch/"$branch"/config/grequalizer-sftp.conf -O /opt/grequalizer/conf/grequalizer-sftp.conf
|
|
wget -q -t7 "$repo"/raw/branch/"$branch"/config/grequalizer-ftp.conf -O /opt/grequalizer/conf/grequalizer-ftp.conf
|
|
|
|
#UFW Config
|
|
##FTP
|
|
ufw allow 20:21/tcp
|
|
ufw allow 30000:31000/tcp
|
|
#SSH/SFTP
|
|
ufw limit 22/tcp
|
|
echo "y" | ufw enable
|
|
#Restart services
|
|
systemctl restart vsftpd sshd |