Got attack box and c2-redirector working
This commit is contained in:
@@ -0,0 +1,302 @@
|
||||
#!/bin/bash
|
||||
# post_install_c2.sh - Post-installation setup for C2 server
|
||||
|
||||
# ANSI color codes
|
||||
GREEN='\033[0;32m'
|
||||
YELLOW='\033[1;33m'
|
||||
RED='\033[0;31m'
|
||||
BLUE='\033[0;34m'
|
||||
NC='\033[0m' # No Color
|
||||
|
||||
# Default settings
|
||||
DEBUG=false
|
||||
RUN_ON_REDIRECTOR=false
|
||||
|
||||
# Show usage information
|
||||
function show_usage() {
|
||||
echo "Usage: $0 [options]"
|
||||
echo ""
|
||||
echo "Options:"
|
||||
echo " -d, --debug Enable debug/verbose output"
|
||||
echo " -r, --run-on-redirector Run post-install script on redirector"
|
||||
echo " -h, --help Show this help message"
|
||||
echo ""
|
||||
}
|
||||
|
||||
# Process command line arguments
|
||||
while [[ $# -gt 0 ]]; do
|
||||
case $1 in
|
||||
-d|--debug)
|
||||
DEBUG=true
|
||||
shift
|
||||
;;
|
||||
-r|--run-on-redirector)
|
||||
RUN_ON_REDIRECTOR=true
|
||||
shift
|
||||
;;
|
||||
-h|--help)
|
||||
show_usage
|
||||
exit 0
|
||||
;;
|
||||
*)
|
||||
echo "Unknown option: $1"
|
||||
show_usage
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
done
|
||||
|
||||
# Debug function - only prints if DEBUG is true
|
||||
function debug() {
|
||||
if [ "$DEBUG" = true ]; then
|
||||
echo -e "${BLUE}[DEBUG] $1${NC}"
|
||||
fi
|
||||
}
|
||||
|
||||
echo -e "${BLUE}==================================================${NC}"
|
||||
echo -e "${BLUE} C2ingRed Post-Installation Setup - C2 Server ${NC}"
|
||||
echo -e "${BLUE}==================================================${NC}"
|
||||
|
||||
# Function to check if domain resolves to current IP
|
||||
check_dns() {
|
||||
domain=$1
|
||||
current_ip=$(curl -s ifconfig.me)
|
||||
resolved_ip=$(dig +short $domain)
|
||||
|
||||
debug "Checking DNS for $domain"
|
||||
debug "Current IP: $current_ip"
|
||||
debug "Resolved IP: $resolved_ip"
|
||||
|
||||
if [ "$resolved_ip" = "$current_ip" ]; then
|
||||
echo -e "${GREEN}DNS check passed for $domain!${NC}"
|
||||
return 0
|
||||
else
|
||||
echo -e "${YELLOW}DNS check failed for $domain${NC}"
|
||||
echo -e "Current IP: $current_ip"
|
||||
echo -e "Resolved IP: $resolved_ip or not set"
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Function to set up Let's Encrypt
|
||||
setup_letsencrypt() {
|
||||
domain=$1
|
||||
email=$2
|
||||
|
||||
echo -e "\n${BLUE}Setting up Let's Encrypt for $domain${NC}"
|
||||
debug "Domain: $domain, Email: $email"
|
||||
|
||||
# Stop Havoc service temporarily to free port 80
|
||||
systemctl stop havoc 2>/dev/null
|
||||
debug "Stopped Havoc service"
|
||||
|
||||
# Get certificate
|
||||
debug "Running certbot to obtain certificate"
|
||||
if [ "$DEBUG" = true ]; then
|
||||
certbot certonly --standalone -d $domain -m $email --agree-tos --non-interactive
|
||||
else
|
||||
certbot certonly --standalone -d $domain -m $email --agree-tos --non-interactive >/dev/null 2>&1
|
||||
fi
|
||||
|
||||
cert_result=$?
|
||||
debug "Certbot result code: $cert_result"
|
||||
|
||||
if [ $cert_result -eq 0 ]; then
|
||||
echo -e "${GREEN}Successfully obtained certificate for $domain${NC}"
|
||||
|
||||
# Configure applications to use the certificate if needed
|
||||
if [ -f "/etc/postfix/main.cf" ]; then
|
||||
debug "Updating Postfix configuration with new certificate"
|
||||
sed -i "s|^smtpd_tls_cert_file =.*|smtpd_tls_cert_file = /etc/letsencrypt/live/$domain/fullchain.pem|" /etc/postfix/main.cf
|
||||
sed -i "s|^smtpd_tls_key_file =.*|smtpd_tls_key_file = /etc/letsencrypt/live/$domain/privkey.pem|" /etc/postfix/main.cf
|
||||
fi
|
||||
|
||||
# Restart Havoc
|
||||
debug "Restarting Havoc service"
|
||||
systemctl start havoc
|
||||
|
||||
return 0
|
||||
else
|
||||
echo -e "${RED}Failed to obtain certificate for $domain${NC}"
|
||||
|
||||
# Restart Havoc
|
||||
debug "Restarting Havoc service"
|
||||
systemctl start havoc
|
||||
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Function to display DKIM/DMARC records
|
||||
show_dns_records() {
|
||||
domain=$1
|
||||
|
||||
debug "Showing DNS records for $domain"
|
||||
|
||||
if [ -f "/etc/opendkim/keys/$domain/mail.txt" ]; then
|
||||
echo -e "\n${BLUE}DKIM DNS Record Information for $domain${NC}"
|
||||
echo -e "${YELLOW}Add the following TXT record to your DNS:${NC}"
|
||||
echo -e "${GREEN}=================================================${NC}"
|
||||
echo -e "Name: mail._domainkey.$domain"
|
||||
echo -e "Value:"
|
||||
cat /etc/opendkim/keys/$domain/mail.txt | grep -v "^;" | tr -d '\n'
|
||||
echo -e "\n${GREEN}=================================================${NC}"
|
||||
fi
|
||||
|
||||
echo -e "\n${BLUE}DMARC Record Recommendation for $domain${NC}"
|
||||
echo -e "${YELLOW}Add the following TXT record to your DNS:${NC}"
|
||||
echo -e "${GREEN}=================================================${NC}"
|
||||
echo -e "Name: _dmarc.$domain"
|
||||
echo -e "Value: v=DMARC1; p=reject; rua=mailto:admin@$domain; ruf=mailto:admin@$domain; pct=100"
|
||||
echo -e "${GREEN}=================================================${NC}"
|
||||
}
|
||||
|
||||
# Function to test redirector connection
|
||||
test_redirector() {
|
||||
# Check if SSH to redirector is configured
|
||||
debug "Testing redirector connection"
|
||||
|
||||
if [ -f "/root/.ssh/config" ] && grep -q "Host redirector" /root/.ssh/config; then
|
||||
echo -e "\n${BLUE}Testing SSH connection to redirector...${NC}"
|
||||
if [ "$DEBUG" = true ]; then
|
||||
ssh -o ConnectTimeout=5 redirector "echo 'Connection successful'"
|
||||
else
|
||||
ssh -o ConnectTimeout=5 redirector "echo 'Connection successful'" >/dev/null 2>&1
|
||||
fi
|
||||
|
||||
ssh_result=$?
|
||||
debug "SSH connection result: $ssh_result"
|
||||
|
||||
if [ $ssh_result -eq 0 ]; then
|
||||
echo -e "${GREEN}SSH connection to redirector successful!${NC}"
|
||||
echo -e "You can access the redirector with: ${YELLOW}ssh redirector${NC}"
|
||||
return 0
|
||||
else
|
||||
echo -e "${RED}Could not connect to redirector.${NC}"
|
||||
echo -e "${YELLOW}Please verify SSH configuration and firewall rules.${NC}"
|
||||
return 1
|
||||
fi
|
||||
else
|
||||
echo -e "\n${YELLOW}Redirector SSH configuration not found.${NC}"
|
||||
echo -e "If you need to access the redirector, please check deployment logs."
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Function to synchronize payloads with redirector
|
||||
sync_payloads() {
|
||||
# Check if sync script exists
|
||||
debug "Attempting to synchronize payloads with redirector"
|
||||
|
||||
if [ -f "/root/Tools/secure_payload_sync.sh" ]; then
|
||||
echo -e "\n${BLUE}Synchronizing payloads with redirector...${NC}"
|
||||
if [ "$DEBUG" = true ]; then
|
||||
/root/Tools/secure_payload_sync.sh
|
||||
else
|
||||
/root/Tools/secure_payload_sync.sh >/dev/null 2>&1
|
||||
fi
|
||||
|
||||
sync_result=$?
|
||||
debug "Payload sync result: $sync_result"
|
||||
|
||||
if [ $sync_result -eq 0 ]; then
|
||||
echo -e "${GREEN}Payload synchronization successful${NC}"
|
||||
return 0
|
||||
else
|
||||
echo -e "${RED}Payload synchronization failed${NC}"
|
||||
echo -e "${YELLOW}Check /root/Tools/logs/payload_sync.log for details${NC}"
|
||||
return 1
|
||||
fi
|
||||
else
|
||||
echo -e "\n${YELLOW}Payload sync script not found${NC}"
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Function to run redirector post-install script
|
||||
run_redirector_setup() {
|
||||
echo -e "\n${BLUE}Running post-installation setup on redirector...${NC}"
|
||||
debug "Checking if we can connect to redirector"
|
||||
|
||||
# First, test the connection
|
||||
if [ -f "/root/.ssh/config" ] && grep -q "Host redirector" /root/.ssh/config; then
|
||||
# Check if post_install_redirector.sh exists on the redirector
|
||||
debug "Checking for post_install_redirector.sh on redirector"
|
||||
ssh -o ConnectTimeout=5 redirector "test -f /root/Tools/post_install_redirector.sh" >/dev/null 2>&1
|
||||
|
||||
check_result=$?
|
||||
debug "Script check result: $check_result"
|
||||
|
||||
if [ $check_result -eq 0 ]; then
|
||||
echo -e "${BLUE}Running post-install script on redirector...${NC}"
|
||||
# Pass the debug flag if it's enabled here
|
||||
if [ "$DEBUG" = true ]; then
|
||||
ssh -o ConnectTimeout=10 redirector "/root/Tools/post_install_redirector.sh --debug"
|
||||
else
|
||||
ssh -o ConnectTimeout=10 redirector "/root/Tools/post_install_redirector.sh"
|
||||
fi
|
||||
|
||||
redir_setup_result=$?
|
||||
debug "Redirector setup result: $redir_setup_result"
|
||||
|
||||
if [ $redir_setup_result -eq 0 ]; then
|
||||
echo -e "${GREEN}Redirector post-installation completed successfully${NC}"
|
||||
return 0
|
||||
else
|
||||
echo -e "${RED}Redirector post-installation failed${NC}"
|
||||
return 1
|
||||
fi
|
||||
else
|
||||
echo -e "${RED}post_install_redirector.sh not found on redirector${NC}"
|
||||
return 1
|
||||
fi
|
||||
else
|
||||
echo -e "${RED}SSH configuration for redirector not found${NC}"
|
||||
echo -e "${YELLOW}Cannot run post-installation on redirector${NC}"
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Main execution
|
||||
debug "Starting post-installation process with debug mode: $DEBUG"
|
||||
debug "Run on redirector flag: $RUN_ON_REDIRECTOR"
|
||||
|
||||
echo -e "\n${BLUE}Running post-installation checks...${NC}"
|
||||
|
||||
# Get domain information
|
||||
read -p "Enter primary domain: " domain
|
||||
read -p "Enter email for Let's Encrypt: " email
|
||||
|
||||
# Check DNS configuration
|
||||
echo -e "\n${BLUE}Checking DNS configuration...${NC}"
|
||||
check_dns $domain
|
||||
|
||||
# Ask if user wants to set up Let's Encrypt certificates
|
||||
read -p "Set up Let's Encrypt SSL certificate? (y/n): " setup_ssl
|
||||
if [ "$setup_ssl" = "y" ]; then
|
||||
setup_letsencrypt $domain $email
|
||||
fi
|
||||
|
||||
# Show DNS records to configure
|
||||
show_dns_records $domain
|
||||
|
||||
# Test redirector connection
|
||||
test_redirector
|
||||
|
||||
# Ask if user wants to sync payloads
|
||||
read -p "Synchronize payloads with redirector? (y/n): " sync_payload
|
||||
if [ "$sync_payload" = "y" ]; then
|
||||
sync_payloads
|
||||
fi
|
||||
|
||||
# Ask if user wants to run post-install on redirector
|
||||
if [ "$RUN_ON_REDIRECTOR" = true ] || test_redirector; then
|
||||
read -p "Run post-installation setup on redirector? (y/n): " run_on_redir
|
||||
if [ "$run_on_redir" = "y" ]; then
|
||||
run_redirector_setup
|
||||
fi
|
||||
fi
|
||||
|
||||
echo -e "\n${GREEN}Post-installation checks complete!${NC}"
|
||||
echo -e "${YELLOW}Ensure your DNS records are properly configured.${NC}"
|
||||
echo -e "${YELLOW}See your deployment log for complete infrastructure details.${NC}"
|
||||
@@ -0,0 +1,158 @@
|
||||
#!/bin/bash
|
||||
# post_install_redirector.sh - Post-installation setup for redirector
|
||||
|
||||
# ANSI color codes
|
||||
GREEN='\033[0;32m'
|
||||
YELLOW='\033[1;33m'
|
||||
RED='\033[0;31m'
|
||||
BLUE='\033[0;34m'
|
||||
NC='\033[0m' # No Color
|
||||
|
||||
echo -e "${BLUE}==================================================${NC}"
|
||||
echo -e "${BLUE} C2ingRed Post-Installation Setup - Redirector ${NC}"
|
||||
echo -e "${BLUE}==================================================${NC}"
|
||||
|
||||
# Function to check if domain resolves to current IP
|
||||
check_dns() {
|
||||
domain=$1
|
||||
current_ip=$(curl -s ifconfig.me)
|
||||
resolved_ip=$(dig +short $domain)
|
||||
|
||||
if [ "$resolved_ip" = "$current_ip" ]; then
|
||||
echo -e "${GREEN}DNS check passed for $domain!${NC}"
|
||||
return 0
|
||||
else
|
||||
echo -e "${YELLOW}DNS check failed for $domain${NC}"
|
||||
echo -e "Current IP: $current_ip"
|
||||
echo -e "Resolved IP: $resolved_ip or not set"
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Function to set up Let's Encrypt
|
||||
setup_letsencrypt() {
|
||||
domain=$1
|
||||
email=$2
|
||||
|
||||
echo -e "\n${BLUE}Setting up Let's Encrypt for $domain${NC}"
|
||||
|
||||
# Check if certificate already exists
|
||||
if [ -d "/etc/letsencrypt/live/$domain" ]; then
|
||||
echo -e "${YELLOW}Certificate already exists for $domain${NC}"
|
||||
read -p "Do you want to renew it? (y/n): " renew
|
||||
if [ "$renew" != "y" ]; then
|
||||
echo -e "${YELLOW}Skipping certificate renewal${NC}"
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
# Stop nginx if running to free up port 80
|
||||
systemctl stop nginx 2>/dev/null
|
||||
|
||||
# Get certificate
|
||||
certbot certonly --standalone -d $domain -m $email --agree-tos --non-interactive
|
||||
|
||||
if [ $? -eq 0 ]; then
|
||||
echo -e "${GREEN}Successfully obtained certificate for $domain${NC}"
|
||||
return 0
|
||||
else
|
||||
echo -e "${RED}Failed to obtain certificate for $domain${NC}"
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Function to update NGINX configuration
|
||||
update_nginx_config() {
|
||||
domain=$1
|
||||
|
||||
# Check if NGINX config exists and contains the domain
|
||||
if [ -f "/etc/nginx/sites-available/default" ]; then
|
||||
if grep -q "$domain" "/etc/nginx/sites-available/default"; then
|
||||
echo -e "\n${BLUE}Updating NGINX configuration to use SSL certificate${NC}"
|
||||
|
||||
# Update SSL certificate paths
|
||||
sed -i "s|ssl_certificate .*|ssl_certificate /etc/letsencrypt/live/$domain/fullchain.pem;|" /etc/nginx/sites-available/default
|
||||
sed -i "s|ssl_certificate_key .*|ssl_certificate_key /etc/letsencrypt/live/$domain/privkey.pem;|" /etc/nginx/sites-available/default
|
||||
|
||||
echo -e "${GREEN}NGINX configuration updated${NC}"
|
||||
else
|
||||
echo -e "${YELLOW}Domain $domain not found in NGINX configuration${NC}"
|
||||
fi
|
||||
else
|
||||
echo -e "${RED}NGINX configuration file not found${NC}"
|
||||
fi
|
||||
}
|
||||
|
||||
# Function to start services
|
||||
start_services() {
|
||||
echo -e "\n${BLUE}Starting required services${NC}"
|
||||
|
||||
# Start nginx
|
||||
systemctl start nginx
|
||||
if [ $? -eq 0 ]; then
|
||||
echo -e "${GREEN}NGINX started successfully${NC}"
|
||||
systemctl enable nginx
|
||||
else
|
||||
echo -e "${RED}Failed to start NGINX${NC}"
|
||||
fi
|
||||
|
||||
# Start shell handler
|
||||
systemctl start shell-handler
|
||||
if [ $? -eq 0 ]; then
|
||||
echo -e "${GREEN}Shell handler started successfully${NC}"
|
||||
systemctl enable shell-handler
|
||||
else
|
||||
echo -e "${RED}Failed to start shell handler${NC}"
|
||||
fi
|
||||
}
|
||||
|
||||
# Function to display port information
|
||||
show_port_info() {
|
||||
# Display shell handler port
|
||||
if [ -f "/etc/systemd/system/shell-handler.service" ]; then
|
||||
SHELL_PORT=$(grep "LISTEN_PORT=" /root/Tools/shell-handler/persistent-listener.sh | cut -d'=' -f2)
|
||||
echo -e "\n${BLUE}Shell Handler Port Information:${NC}"
|
||||
echo -e "Shell Handler is using port: ${GREEN}$SHELL_PORT${NC}"
|
||||
fi
|
||||
|
||||
# Display nginx listening ports
|
||||
echo -e "\n${BLUE}NGINX Listening Ports:${NC}"
|
||||
netstat -tulnp | grep nginx
|
||||
}
|
||||
|
||||
# Main execution
|
||||
echo -e "\n${BLUE}Beginning redirector setup process...${NC}"
|
||||
|
||||
# Get domain information
|
||||
read -p "Enter redirector domain (e.g., cdn.example.com): " redirector_domain
|
||||
read -p "Enter email for Let's Encrypt: " email
|
||||
|
||||
# Check if DNS is properly configured
|
||||
echo -e "\n${BLUE}Checking DNS configuration...${NC}"
|
||||
check_dns $redirector_domain
|
||||
|
||||
# Confirm proceeding even if DNS check fails
|
||||
if [ $? -ne 0 ]; then
|
||||
echo -e "${YELLOW}DNS check failed but we can proceed anyway.${NC}"
|
||||
echo -e "${YELLOW}Make sure to set up DNS records before trying to obtain certificates.${NC}"
|
||||
read -p "Do you want to proceed anyway? (y/n): " proceed
|
||||
if [ "$proceed" != "y" ]; then
|
||||
echo -e "${RED}Setup aborted.${NC}"
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
# Set up Let's Encrypt
|
||||
setup_letsencrypt $redirector_domain $email
|
||||
|
||||
# Update NGINX configuration
|
||||
update_nginx_config $redirector_domain
|
||||
|
||||
# Start services
|
||||
start_services
|
||||
|
||||
# Show port information
|
||||
show_port_info
|
||||
|
||||
echo -e "\n${GREEN}Redirector setup complete!${NC}"
|
||||
echo -e "${YELLOW}Make sure DNS records are properly configured for continued operation.${NC}"
|
||||
+194
-12
@@ -2,6 +2,11 @@
|
||||
# Common task for configuring mail server
|
||||
# Shared across all providers
|
||||
|
||||
- name: Set default SMTP auth credentials if not defined
|
||||
set_fact:
|
||||
smtp_auth_user: "{{ smtp_auth_user | default('admin') }}"
|
||||
smtp_auth_pass: "{{ smtp_auth_pass | default(lookup('password', '/tmp/smtp_auth_pass_' + deployment_id + ' length=16 chars=ascii_letters,digits')) }}"
|
||||
|
||||
- name: Configure Postfix main.cf
|
||||
lineinfile:
|
||||
path: /etc/postfix/main.cf
|
||||
@@ -16,18 +21,41 @@
|
||||
- { regexp: '^smtpd_banner', line: "smtpd_banner = $myhostname ESMTP $mail_name" }
|
||||
- { regexp: '^mynetworks', line: "mynetworks = 127.0.0.0/8 [::1]/128" }
|
||||
- { regexp: '^relay_domains', line: "relay_domains = $mydestination" }
|
||||
- { regexp: '^smtpd_tls_cert_file', line: "smtpd_tls_cert_file = /etc/letsencrypt/live/{{ domain }}/fullchain.pem" }
|
||||
- { regexp: '^smtpd_tls_key_file', line: "smtpd_tls_key_file = /etc/letsencrypt/live/{{ domain }}/privkey.pem" }
|
||||
- { regexp: '^smtpd_tls_security_level', line: "smtpd_tls_security_level = encrypt" }
|
||||
- { regexp: '^smtpd_use_tls', line: "smtpd_use_tls = yes" }
|
||||
- { regexp: '^smtpd_tls_session_cache_database', line: "smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache" }
|
||||
- { regexp: '^smtp_tls_session_cache_database', line: "smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache" }
|
||||
- { regexp: '^smtpd_use_tls', line: "smtpd_use_tls = yes" }
|
||||
- { regexp: '^smtpd_tls_auth_only', line: "smtpd_tls_auth_only = yes" }
|
||||
- { regexp: '^milter_default_action', line: "milter_default_action = accept" }
|
||||
- { regexp: '^milter_protocol', line: "milter_protocol = 6" }
|
||||
- { regexp: '^smtpd_milters', line: "smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock" }
|
||||
- { regexp: '^non_smtpd_milters', line: "non_smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock" }
|
||||
|
||||
- name: Check if SSL certificates exist
|
||||
stat:
|
||||
path: "/etc/letsencrypt/live/{{ domain }}/fullchain.pem"
|
||||
register: ssl_cert_exists
|
||||
|
||||
- name: Configure Postfix SSL settings (if certificates exist)
|
||||
lineinfile:
|
||||
path: /etc/postfix/main.cf
|
||||
regexp: "{{ item.regexp }}"
|
||||
line: "{{ item.line }}"
|
||||
with_items:
|
||||
- { regexp: '^smtpd_tls_cert_file', line: "smtpd_tls_cert_file = /etc/letsencrypt/live/{{ domain }}/fullchain.pem" }
|
||||
- { regexp: '^smtpd_tls_key_file', line: "smtpd_tls_key_file = /etc/letsencrypt/live/{{ domain }}/privkey.pem" }
|
||||
- { regexp: '^smtpd_tls_security_level', line: "smtpd_tls_security_level = encrypt" }
|
||||
- { regexp: '^smtpd_tls_auth_only', line: "smtpd_tls_auth_only = yes" }
|
||||
when: ssl_cert_exists.stat.exists
|
||||
|
||||
- name: Configure Postfix SSL settings (if certificates don't exist - use opportunistic TLS)
|
||||
lineinfile:
|
||||
path: /etc/postfix/main.cf
|
||||
regexp: "{{ item.regexp }}"
|
||||
line: "{{ item.line }}"
|
||||
with_items:
|
||||
- { regexp: '^smtpd_tls_security_level', line: "smtpd_tls_security_level = may" }
|
||||
- { regexp: '^smtpd_tls_auth_only', line: "smtpd_tls_auth_only = no" }
|
||||
when: not ssl_cert_exists.stat.exists
|
||||
|
||||
- name: Configure OpenDKIM
|
||||
lineinfile:
|
||||
path: /etc/opendkim.conf
|
||||
@@ -42,6 +70,14 @@
|
||||
- { regexp: '^UMask', line: "UMask 002" }
|
||||
- { regexp: '^Mode', line: "Mode sv" }
|
||||
|
||||
- name: Create OpenDKIM socket directory
|
||||
file:
|
||||
path: /var/spool/postfix/opendkim
|
||||
state: directory
|
||||
owner: opendkim
|
||||
group: postfix
|
||||
mode: 0755
|
||||
|
||||
- name: Create DKIM directory
|
||||
file:
|
||||
path: /etc/opendkim/keys/{{ domain }}
|
||||
@@ -75,7 +111,7 @@
|
||||
group: opendkim
|
||||
mode: 0644
|
||||
|
||||
- name: Enable submission port (587) in master.cf
|
||||
- name: Enable submission port (587) in master.cf (with SSL)
|
||||
blockinfile:
|
||||
path: /etc/postfix/master.cf
|
||||
insertafter: '^#submission'
|
||||
@@ -86,6 +122,20 @@
|
||||
-o smtpd_sasl_auth_enable=yes
|
||||
-o smtpd_recipient_restrictions=permit_sasl_authenticated,reject
|
||||
-o smtpd_relay_restrictions=permit_sasl_authenticated,reject
|
||||
when: ssl_cert_exists.stat.exists
|
||||
|
||||
- name: Enable submission port (587) in master.cf (without SSL requirements)
|
||||
blockinfile:
|
||||
path: /etc/postfix/master.cf
|
||||
insertafter: '^#submission'
|
||||
block: |
|
||||
submission inet n - y - - smtpd
|
||||
-o syslog_name=postfix/submission
|
||||
-o smtpd_tls_security_level=may
|
||||
-o smtpd_sasl_auth_enable=yes
|
||||
-o smtpd_recipient_restrictions=permit_sasl_authenticated,reject
|
||||
-o smtpd_relay_restrictions=permit_sasl_authenticated,reject
|
||||
when: not ssl_cert_exists.stat.exists
|
||||
|
||||
- name: Configure Dovecot for Postfix SASL
|
||||
blockinfile:
|
||||
@@ -118,25 +168,44 @@
|
||||
path: /etc/dovecot/passwd
|
||||
line: "{{ smtp_auth_user }}:{{ smtp_auth_pass | password_hash('sha512_crypt') }}"
|
||||
|
||||
- name: Display SMTP authentication credentials (if generated)
|
||||
debug:
|
||||
msg: |
|
||||
SMTP Authentication Credentials (Generated):
|
||||
Username: {{ smtp_auth_user }}
|
||||
Password: {{ smtp_auth_pass }}
|
||||
|
||||
Save these credentials for email client configuration.
|
||||
when: smtp_auth_pass is defined and smtp_auth_pass != ""
|
||||
|
||||
- name: Disable system auth and use passwd-file
|
||||
lineinfile:
|
||||
path: /etc/dovecot/conf.d/10-auth.conf
|
||||
regexp: '^!include auth-system.conf.ext'
|
||||
line: '#!include auth-system.conf.ext'
|
||||
|
||||
- name: Add auth-passwdfile configuration
|
||||
blockinfile:
|
||||
path: /etc/dovecot/conf.d/10-auth.conf
|
||||
insertafter: '^auth_mechanisms ='
|
||||
block: |
|
||||
- name: Create custom auth configuration file
|
||||
copy:
|
||||
dest: /etc/dovecot/conf.d/auth-c2itall.conf.ext
|
||||
content: |
|
||||
passdb {
|
||||
driver = passwd-file
|
||||
args = scheme=sha512_crypt /etc/dovecot/passwd
|
||||
}
|
||||
|
||||
userdb {
|
||||
driver = static
|
||||
args = uid=vmail gid=vmail home=/var/vmail/%u
|
||||
}
|
||||
mode: '0644'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Include custom auth configuration
|
||||
lineinfile:
|
||||
path: /etc/dovecot/conf.d/10-auth.conf
|
||||
insertafter: 'auth_mechanisms = plain login'
|
||||
line: '!include auth-c2itall.conf.ext'
|
||||
|
||||
- name: Create vmail group
|
||||
group:
|
||||
@@ -159,12 +228,125 @@
|
||||
group: vmail
|
||||
mode: 0700
|
||||
|
||||
- name: Start and enable OpenDKIM service
|
||||
service:
|
||||
name: opendkim
|
||||
state: started
|
||||
enabled: yes
|
||||
ignore_errors: true
|
||||
|
||||
- name: Check Postfix configuration syntax
|
||||
command: postfix check
|
||||
register: postfix_config_check
|
||||
failed_when: false
|
||||
|
||||
- name: Display Postfix configuration errors if any
|
||||
debug:
|
||||
msg: "Postfix configuration check result: {{ postfix_config_check.stdout_lines }}"
|
||||
when: postfix_config_check.rc != 0
|
||||
|
||||
- name: Restart Postfix
|
||||
service:
|
||||
name: postfix
|
||||
state: restarted
|
||||
ignore_errors: true
|
||||
register: postfix_restart_result
|
||||
|
||||
- name: Display Postfix restart error details
|
||||
block:
|
||||
- name: Get systemctl status for Postfix
|
||||
command: systemctl status postfix.service
|
||||
register: postfix_status
|
||||
failed_when: false
|
||||
|
||||
- name: Get journal logs for Postfix
|
||||
command: journalctl -xeu postfix.service --no-pager -n 20
|
||||
register: postfix_logs
|
||||
failed_when: false
|
||||
|
||||
- name: Display Postfix status and logs
|
||||
debug:
|
||||
msg: |
|
||||
Postfix Status:
|
||||
{{ postfix_status.stdout }}
|
||||
|
||||
Postfix Logs:
|
||||
{{ postfix_logs.stdout }}
|
||||
when: postfix_restart_result.failed
|
||||
|
||||
- name: Continue without Postfix if restart fails
|
||||
debug:
|
||||
msg: "Postfix failed to start but continuing deployment. Email services may not be available."
|
||||
when: postfix_restart_result.failed
|
||||
|
||||
- name: Remove OpenDKIM configuration from Postfix if restart failed
|
||||
lineinfile:
|
||||
path: /etc/postfix/main.cf
|
||||
regexp: "{{ item }}"
|
||||
state: absent
|
||||
with_items:
|
||||
- '^smtpd_milters'
|
||||
- '^non_smtpd_milters'
|
||||
- '^milter_default_action'
|
||||
- '^milter_protocol'
|
||||
when: postfix_restart_result.failed
|
||||
ignore_errors: true
|
||||
|
||||
- name: Retry Postfix restart without OpenDKIM
|
||||
service:
|
||||
name: postfix
|
||||
state: restarted
|
||||
when: postfix_restart_result.failed
|
||||
ignore_errors: true
|
||||
register: postfix_retry_result
|
||||
|
||||
- name: Display final Postfix status
|
||||
debug:
|
||||
msg: |
|
||||
Postfix final status: {{ 'Running' if not postfix_retry_result.failed else 'Failed' }}
|
||||
Email services: {{ 'Limited functionality' if postfix_restart_result.failed else 'Fully operational' }}
|
||||
when: postfix_restart_result.failed
|
||||
|
||||
- name: Check Dovecot configuration syntax
|
||||
command: dovecot -n
|
||||
register: dovecot_config_check
|
||||
failed_when: false
|
||||
|
||||
- name: Display Dovecot configuration errors if any
|
||||
debug:
|
||||
msg: "Dovecot configuration check result: {{ dovecot_config_check.stdout_lines }}"
|
||||
when: dovecot_config_check.rc != 0
|
||||
|
||||
- name: Restart Dovecot
|
||||
service:
|
||||
name: dovecot
|
||||
state: restarted
|
||||
state: restarted
|
||||
ignore_errors: true
|
||||
register: dovecot_restart_result
|
||||
|
||||
- name: Display Dovecot restart error details
|
||||
block:
|
||||
- name: Get systemctl status for Dovecot
|
||||
command: systemctl status dovecot.service
|
||||
register: dovecot_status
|
||||
failed_when: false
|
||||
|
||||
- name: Get journal logs for Dovecot
|
||||
command: journalctl -xeu dovecot.service --no-pager -n 20
|
||||
register: dovecot_logs
|
||||
failed_when: false
|
||||
|
||||
- name: Display Dovecot status and logs
|
||||
debug:
|
||||
msg: |
|
||||
Dovecot Status:
|
||||
{{ dovecot_status.stdout }}
|
||||
|
||||
Dovecot Logs:
|
||||
{{ dovecot_logs.stdout }}
|
||||
when: dovecot_restart_result.failed
|
||||
|
||||
- name: Continue without Dovecot if restart fails
|
||||
debug:
|
||||
msg: "Dovecot failed to start but continuing deployment. Email services may not be available."
|
||||
when: dovecot_restart_result.failed
|
||||
Reference in New Issue
Block a user