#!/bin/sh
#
# Copyright 2001-2003 Sun Microsystems, Inc.  All rights reserved.
# Use is subject to license terms.
#
#ident	"@(#)postinstall	1.55	03/04/16 SMI"
#
# Generate security certificates, start Apache, print startup message.

##############################################################################
#
# Default settings
#
##############################################################################
PERL=/usr/perl5/bin/perl
PERLINC=${BASEDIR}/SUNWscvw/lib/perl
HOSTNAME=`hostname`

PASSWORD=sPm30c9o # Must match server-request.conf
PROG=`basename $0`
PKGROOT=${BASEDIR}/SUNWscvw
PKGCONF=${PKGROOT}/conf
PKGSSL=${PKGCONF}/ssl
LOGDIR=${PKG_INSTALL_ROOT}/var/cluster/spm
PERL=/usr/perl5/bin/perl
OPENSSL=${BASEDIR}/SUNWscva/bin/openssl
LOGFILE=${LOGDIR}/messages
ROOTCERT=${PKGSSL}/sun-ca.crt
SERVER_SIGN_CONF=${PKGSSL}/server-sign.conf
RANDFILE=${PKGSSL}/random-bits; export RANDFILE
SERVER_REQUEST_CONF=${PKGSSL}/server-request.conf

##############################################################################
#
# set_hostname
#
# Attempt to get the fully qualified domain name for the host. If this
# succeeds, reset the parameters which rely upon it.
#
##############################################################################

set_hostname()
{
    TEMP=`${PERL} -I${PERLINC} -e "use Net::Domain qw(hostfqdn); print hostfqdn();"`

    if [ "$TEMP" != "" ]
    then
	HOSTNAME=${TEMP}
    fi

    SERVER_KEY=${PKGSSL}/${HOSTNAME}.key
    SERVER_REQUEST=${PKGSSL}/${HOSTNAME}.csr
    SERVER_CERT=${PKGSSL}/${HOSTNAME}.crt
}

##############################################################################
#
# Print internationalized error message
#
##############################################################################
error()
{
    echo "${PROG}: $@"
}

##############################################################################
#
# Generate the server key
#
##############################################################################
generate_server_key()
{
    ${OPENSSL} genrsa -out ${SERVER_KEY} 1024 > ${LOGFILE} 2>&1

    if [ $? -ne 0 ]
    then
	error `gettext "generate server key failed"`
    fi
}

##############################################################################
#
# Generate the certificate request
#
##############################################################################
generate_certificate_request()
{
    ${OPENSSL} req -new -config ${SERVER_REQUEST_CONF} \
		   -key ${SERVER_KEY} -out ${SERVER_REQUEST} \
		   >> ${LOGFILE} 2>&1
    
    if [ $? -ne 0 ]
    then
	error `gettext "generate certificate request failed"`
    fi
}

##############################################################################
#
# Sign the certificate request
#
##############################################################################
sign_server_certificate()
{
    # Generate a random certificate serial number
    RANDVAL=`generate_serial_number`

    # Create the necessary support directories
    mkdir -p ${PKGSSL}/ca.db.certs

    if [ $? -ne 0 ]
    then
	error `gettext "failed to created ca.db.certs directory"`
    fi

    echo ${RANDVAL} > ${PKGSSL}/ca.db.serial

    if [ $? -ne 0 ]
    then
	error `gettext "failed to created ca.db.serial file"`
    fi

    touch $PKGSSL/ca.db.index

    if [ $? -ne 0 ]
    then
	error `gettext "failed to created ca.db.index file"`
    fi

    # Sign the certificate
    ${OPENSSL} ca -config ${SERVER_SIGN_CONF} \
		  -key ${PASSWORD} -out ${SERVER_CERT} \
		  -batch -infiles ${SERVER_REQUEST} \
		  >> ${LOGFILE} 2>&1
    
    if [ $? -ne 0 ]
    then
	error `gettext "sign server certificate failed"`
    fi

    # Remove the support directories
    rm -rf $PKGSSL/ca.db.*

    if [ $? -ne 0 ]
    then
	error `gettext "ca support file removal failed"`
    fi
}

##############################################################################
#
# Verify the server certificate
#
##############################################################################
verify_server_certificate()
{
    ${OPENSSL} verify -CAfile ${ROOTCERT} ${SERVER_CERT} >> ${LOGFILE} 2>&1

    if [ $? -ne 0 ]
    then
	error `gettext "verify server certificate failed"`
    fi
}

##############################################################################
#
# Generate the serial number
#
##############################################################################
generate_serial_number() {
    SER=`${PERL} -e 'srand(time()^($$+($$<<15))); print int(rand 64000) + 1;'`
    NUMCHAR=`echo ${SER} | wc -m`
    ODDCHAR=`echo "(${NUMCHAR} - 1) % 2" | bc`

    if [ ${ODDCHAR} = 1 ]
    then
	echo "0${SER}"
    else
	echo $SER
    fi
}

##############################################################################
#
# Start or restart the server if we're not jumpstarting and if the 
#
##############################################################################
start_apache()
{
    if [ -f /var/cluster/spm/httpd.pid ]
    then
	/opt/SUNWscvw/bin/apachectl restart > /dev/null
    elif [ -f /usr/apache/bin/httpd ]
    then
	/opt/SUNWscvw/bin/apachectl startssl > /dev/null
    fi
    
    if [ $? -ne 0 ]
    then
	error `gettext "Apache start failed"`
	exit 0
    fi
}

##############################################################################
#
# Print out the final message if we're not jumpstarting
#
##############################################################################
print_final_message()
{
    echo
    echo "######################################################################"

    # If the Apache packages are not installed, print out a message telling the
    # user to install them
    if [ ! -f ${PKG_INSTALL_ROOT}/usr/apache/bin/httpd ]
    then
	echo "NOTE: To finish installing the SunPlex Manager, you must install"
	echo "the SUNWapchr and SUNWapchu Solaris packages and any associated"
	echo "patches. Then run '/etc/init.d/initspm start' to start the server."
	echo
    fi
    echo "Welcome to the SunPlex Manager. Your cluster is now ready to be"
    echo "installed or administered from a web browser. You may access the"
    echo "SunPlex Manager through your web browser by securely connecting"
    echo "to port 3000 on any node of your cluster, such as:"
    echo " "
    echo "	  https://${HOSTNAME}:3000"
    echo " "
    echo "If you are using the SunPlex Manager to install Sun Cluster, you"
    echo "must login as root or any other user which has a user id (uid) of"
    echo "0. If this cluster has already been installed, you must login as a"
    echo "user or role which has the solaris.cluster.gui RBAC authorization."
    echo "The user must have the same password on each node. For further "
    echo "instructions about configuring the SunPlex Manager to install or "
    echo "administer your cluster, see the Sun Cluster 3.1 System "
    echo "Administration Guide."
    echo "######################################################################"
}

##############################################################################
#
# Main function
#
##############################################################################

# Set the hostname and related parameters
set_hostname

# Generate the server certificate 
generate_server_key
generate_certificate_request
sign_server_certificate
verify_server_certificate

# Change the ownership of the messages file
chroot ${PKG_INSTALL_ROOT:-/} /usr/bin/chown spmadmin /var/cluster/spm/messages

# Start the server if we're not jumpstarting
if [ "$PKG_INSTALL_ROOT" = "/" ] || [ "$PKG_INSTALL_ROOT" = "" ]
then
    start_apache

    # Start event daemon if in clustered mode
    if [ -x /usr/sbin/clinfo ]; then
	/usr/sbin/clinfo >/dev/null 2>&1
	if [ $? -eq 0 ]; then
	    /var/cluster/spm/bin/scguieventd -d
	fi
    fi
fi

# Print the final message
print_final_message

# Exit 0 so that scinstall will succeed even if there are errors
exit 0
