199 lines
6.8 KiB
Bash
Executable File
199 lines
6.8 KiB
Bash
Executable File
#!/bin/bash
|
|
|
|
# ap-setup.sh
|
|
# OpenDRS Online Discrepancy Reporting System
|
|
# Copyright (C) 2022 Rod Wright
|
|
|
|
# SPDX-License-Identifier: GPL-2.0
|
|
|
|
# Wireless Access Point Raspberry Pi Setup
|
|
|
|
function get_ap_params() {
|
|
echo ""
|
|
wapssidok="no"
|
|
while [[ "$wapssidok" == "no" ]]
|
|
do
|
|
echo "This access point will need an SSID. This is what will appear"
|
|
echo "as the name of this terminal when other devices connect."
|
|
echo -n "Please enter the desired SSID for this access point: "
|
|
read wapssid
|
|
if [[ "$wapssid" = "" ]]
|
|
then
|
|
echo "SSID cannot be blank. Try again."
|
|
else
|
|
wapssidok="yes"
|
|
fi
|
|
done
|
|
wappassok="no"
|
|
while [[ "$wappassok" == "no" ]]
|
|
do
|
|
echo "You will need to set a passphrase for this access point. It should"
|
|
echo "be at least 8 characters in length and cannot be blank."
|
|
echo -n "Please enter the desired passphrase for this access point: "
|
|
read wappass
|
|
wappasslen=$(echo -n $wappass | wc -m)
|
|
if [[ "$wappass" == "" || $wappasslen -lt 8 ]]
|
|
then
|
|
echo "Passphrase doesn't satisfy requirements above. Try again."
|
|
else
|
|
wappassok="yes"
|
|
fi
|
|
done
|
|
# Save parameters in config file
|
|
sed -i 's|'wapssid=.*'|'wapssid="\'$wapssid\'"'|' /etc/piwifiap/piwifiap.conf
|
|
sed -i 's|'wappass=.*'|'wappass="\'$wappass\'"'|' /etc/piwifiap/piwifiap.conf
|
|
sed -i 's|'802-11-wireless-security.psk:.*'|'802-11-wireless-security.psk:$wappass'|' /etc/piwifiap/piwifiap.secret
|
|
}
|
|
|
|
function config_systemd-networkd() {
|
|
echo "Configuring as wireless access point using systemd-networkd."
|
|
get_ap_params
|
|
# Save network system type in config file
|
|
sed -i 's,'network_system=.*','network_system="\"systemd-networkd\""',' /etc/piwifiap/piwifiap.conf
|
|
|
|
apt install hostapd
|
|
systemctl unmask hostapd
|
|
systemctl enable hostapd
|
|
echo "[NetDev]" >/etc/systemd/network/bridge-br0.netdev
|
|
echo "Name=br0" >>/etc/systemd/network/bridge-br0.netdev
|
|
echo "Kind=bridge" >>/etc/systemd/network/bridge-br0.netdev
|
|
echo "[Match]" >/etc/systemd/network/br0-member-eth0.network
|
|
echo "Name=eth0" >>/etc/systemd/network/br0-member-eth0.network
|
|
echo "" >>/etc/systemd/network/br0-member-eth0.network
|
|
echo "[Network]" >>/etc/systemd/network/br0-member-eth0.network
|
|
echo "Bridge=br0" >>/etc/systemd/network/br0-member-eth0.network
|
|
systemctl enable systemd-networkd
|
|
mv /etc/dhcpcd.conf /etc/dhcpcd.conf.old
|
|
echo "denyinterfaces wlan0 eth0" >/etc/dhcpcd.conf
|
|
cat /etc/dhcpcd.conf.old >>/etc/dhcpcd.conf
|
|
echo "interface br0" >>/etc/dhcpcd.conf
|
|
rfkill unblock wlan
|
|
echo "country_code=US" >/etc/hostapd/hostapd.conf
|
|
echo "interface=wlan0" >>/etc/hostapd/hostapd.conf
|
|
echo "bridge=br0" >>/etc/hostapd/hostapd.conf
|
|
echo "ssid=$wapssid" >>/etc/hostapd/hostapd.conf
|
|
echo "hw_mode=g" >>/etc/hostapd/hostapd.conf
|
|
echo "channel=7" >>/etc/hostapd/hostapd.conf
|
|
echo "macaddr_acl=0" >>/etc/hostapd/hostapd.conf
|
|
echo "auth_algs=1" >>/etc/hostapd/hostapd.conf
|
|
echo "ignore_broadcast_ssid=0" >>/etc/hostapd/hostapd.conf
|
|
echo "wpa=2" >>/etc/hostapd/hostapd.conf
|
|
echo "wpa_passphrase=$wappass" >>/etc/hostapd/hostapd.conf
|
|
echo "wpa_key_mgmt=WPA-PSK" >>/etc/hostapd/hostapd.conf
|
|
echo "wpa_pairwise=TKIP" >>/etc/hostapd/hostapd.conf
|
|
echo "rsn_pairwise=CCMP" >>/etc/hostapd/hostapd.conf
|
|
if dpkg -l|grep webmin >/dev/null 2>&1
|
|
then
|
|
wget -c http://github.com/pjz/webmin-modules/releases/download/v1.0/hostap.wbm.gz
|
|
gzip -d hostap.wbm.gz
|
|
/usr/share/webmin/install-module.pl hostap.wbm
|
|
fi
|
|
echo ""
|
|
echo ""
|
|
}
|
|
|
|
function config_NetworkManager() {
|
|
echo "Configuring as wireless access point using NetworkManager."
|
|
rfkill unblock wlan
|
|
get_ap_params
|
|
|
|
# Clean up a possible failed previous attempt
|
|
nmcli con del piwifi-hotspot >/dev/null 2>&1
|
|
nmcli con del piwifi-ethernet >/dev/null 2>&1
|
|
nmcli con del piwifi-bridge >/dev/null 2>&1
|
|
|
|
|
|
# Save network system type in config file
|
|
sed -i 's|'network_system=.*'|'network_system="\"NetworkManager\""'|' /etc/piwifiap/piwifiap.conf
|
|
|
|
# create bridge interface
|
|
nmcli con add type bridge con-name piwifi-bridge ifname bridge0
|
|
|
|
# add ethernet to bridge
|
|
nmcli con add type ethernet slave-type bridge con-name piwifi-ethernet ifname eth0 master bridge0
|
|
|
|
# create access point
|
|
nmcli con add type wifi ifname wlan0 mode ap con-name piwifi-hotspot ssid $wapssid
|
|
nmcli con modify piwifi-hotspot wifi-sec.key-mgmt wpa-psk
|
|
nmcli con modify piwifi-hotspot 802-11-wireless.band bg
|
|
# disable protected management frames for wpa_supplicant bug in trixie
|
|
nmcli con modify piwifi-hotspot 802-11-wireless-security.pmf 1
|
|
|
|
# add wifi to bridge
|
|
nmcli con modify piwifi-hotspot master bridge0 slave-type bridge
|
|
|
|
# activate bridge
|
|
nmcli con up piwifi-bridge
|
|
|
|
# activite wifi
|
|
nmcli con up piwifi-hotspot passwd-file /etc/piwifiap/piwifiap.secret
|
|
|
|
}
|
|
|
|
current_user=$(whoami)
|
|
if [[ "$current_user" != "root" ]]
|
|
then
|
|
echo "You must have root privileges to run this setup."
|
|
echo "Try 'sudo $0'"
|
|
exit 1
|
|
fi
|
|
echo ""
|
|
echo ""
|
|
echo "If this system connects to a network using ethernet, it can be configured"
|
|
echo "as a wireless access point for other systems. Would you like to configure"
|
|
echo -n "this system as an access point? [y/N]: "
|
|
read wapconf
|
|
if [[ "$wapconf" == "Y" || "$wapconf" == "y" ]]
|
|
then
|
|
# Determine if we are using NetworkManager or systemd-networkd
|
|
echo ""
|
|
echo "Copying files..."
|
|
chmod +x apsetup/usr/local/bin/wap-*
|
|
cp -R apsetup/usr/local/bin/* /usr/local/bin/
|
|
cp -R apsetup/etc/* /etc/
|
|
chown -R root:root /etc/piwifiap
|
|
chmod 600 /etc/piwifiap/*
|
|
if systemctl status dhcpcd.service|grep -q "Active: active (running)"
|
|
then
|
|
config_systemd-networkd
|
|
elif systemctl status NetworkManager.service|grep -q "Active: active (running)"
|
|
then
|
|
config_NetworkManager
|
|
else
|
|
echo "Unable to determine what type of network configuration (systemd-networkd"
|
|
echo "or NetworkManager) your system uses. Automatic setup cannot continue."
|
|
exit 1
|
|
fi
|
|
|
|
echo "Wireless access point setup is complete. It will be"
|
|
echo "automatically enabled after reboot. To change the SSID or"
|
|
echo "passphrase in the future, run:"
|
|
echo " sudo wap-setssid"
|
|
echo "or:"
|
|
echo " sudo wap-setpassphrase"
|
|
echo "at a command prompt."
|
|
echo ""
|
|
echo "To disable the access point altogether in the future, run:"
|
|
echo " sudo wap-disable"
|
|
echo "at a command prompt and reboot. To re-enable it, run:"
|
|
echo " sudo wap-enable"
|
|
echo "at a command prompt and reboot."
|
|
echo ""
|
|
echo "The system must be rebooted for the configuration to take effect."
|
|
echo ""
|
|
read -p "Would you like to reboot now? [Y/n]: " -r rebootok
|
|
case "$rebootok" in
|
|
"y" | "Y" | "")
|
|
reboot
|
|
;;
|
|
*)
|
|
echo "You may continue to use the system, but the access point will not be"
|
|
echo "functional until you reboot."
|
|
exit 0
|
|
;;
|
|
esac
|
|
else
|
|
exit 2
|
|
fi
|
|
|