mirror of
https://github.com/trailofbits/algo.git
synced 2026-09-30 13:35:00 +02:00
- Obviate need to copy separate script and certificate files - Allow execution from any directory, not just the script's parent directory (no assumption of any particular working directory) - Fix docs that neglected to mention copying cacert.pem - Fix docs that incorrectly referred to the user cert store As part of this work, rewrite the windows_client.ps1.j2 deployment script template - Add comment-based help - Require admin privileges - Use a Param() block - Use parameter sets with -Add and -Remove switches - Add the -GetInstalledCerts switch, to list any Algo certificates installed the machine's cert store - Add the -SaveCerts switch, to save the embedded certificates to files - Put Jinja2 variables inside Powershell variables, - Use native Powershell cmdlets rather than shell out to certutil.exe - Add a playbook to regenerate the windows_USER.ps1 scripts
87 lines
2.3 KiB
YAML
87 lines
2.3 KiB
YAML
---
|
|
|
|
- name: Register p12 PayloadContent
|
|
shell: cat private/{{ item }}.p12 | base64
|
|
register: PayloadContent
|
|
args:
|
|
chdir: "configs/{{ IP_subject_alt_name }}/pki/"
|
|
with_items: "{{ users }}"
|
|
|
|
- name: Set facts for mobileconfigs
|
|
set_fact:
|
|
PayloadContentCA: "{{ lookup('file' , 'configs/{{ IP_subject_alt_name }}/pki/cacert.pem')|b64encode }}"
|
|
|
|
- name: Build the mobileconfigs
|
|
template:
|
|
src: mobileconfig.j2
|
|
dest: configs/{{ IP_subject_alt_name }}/{{ item.0 }}.mobileconfig
|
|
mode: 0600
|
|
with_together:
|
|
- "{{ users }}"
|
|
- "{{ PayloadContent.results }}"
|
|
no_log: True
|
|
|
|
- name: Build the strongswan app android config
|
|
template:
|
|
src: sswan.j2
|
|
dest: configs/{{ IP_subject_alt_name }}/android_{{ item.0 }}.sswan
|
|
mode: 0600
|
|
with_together:
|
|
- "{{ users }}"
|
|
- "{{ PayloadContent.results }}"
|
|
no_log: True
|
|
|
|
- name: Build the android helper html
|
|
template:
|
|
src: android_html_helper.j2
|
|
dest: configs/{{ IP_subject_alt_name }}/android_{{ item.0 }}_helper.html
|
|
mode: 0600
|
|
with_together:
|
|
- "{{ users }}"
|
|
no_log: True
|
|
|
|
- name: Build the client ipsec config file
|
|
template:
|
|
src: client_ipsec.conf.j2
|
|
dest: configs/{{ IP_subject_alt_name }}/ipsec_{{ item }}.conf
|
|
mode: 0600
|
|
with_items:
|
|
- "{{ users }}"
|
|
|
|
- name: Build the client ipsec secret file
|
|
template:
|
|
src: client_ipsec.secrets.j2
|
|
dest: configs/{{ IP_subject_alt_name }}/ipsec_{{ item }}.secrets
|
|
mode: 0600
|
|
with_items:
|
|
- "{{ users }}"
|
|
|
|
- name: Create the windows check file
|
|
file:
|
|
state: touch
|
|
path: configs/{{ IP_subject_alt_name }}/.supports_windows
|
|
when: Win10_Enabled is defined and Win10_Enabled == "Y"
|
|
|
|
- name: Check if the windows check file exists
|
|
stat:
|
|
path: configs/{{ IP_subject_alt_name }}/.supports_windows
|
|
register: supports_windows
|
|
|
|
- name: Build the windows client powershell script
|
|
template:
|
|
src: client_windows.ps1.j2
|
|
dest: configs/{{ IP_subject_alt_name }}/windows_{{ item.0 }}.ps1
|
|
mode: 0600
|
|
when: Win10_Enabled is defined and Win10_Enabled == "Y" or supports_windows.stat.exists == true
|
|
with_together:
|
|
- "{{ users }}"
|
|
- "{{ PayloadContent.results }}"
|
|
|
|
- name: Restrict permissions for the local private directories
|
|
file:
|
|
path: "{{ item }}"
|
|
state: directory
|
|
mode: 0700
|
|
with_items:
|
|
- configs/{{ IP_subject_alt_name }}
|