#!/bin/sh set -eu # Installs the public key from id_ed25519_zelavis-one.pub for root. # Expected fingerprint: SHA256:awofEu5WUPon/pgV0v101XAqqHvPMtxvJ05Kd1fUoKA # Run as root in the server's normal operating system. if [ "$(id -u)" -ne 0 ]; then printf '%s\n' 'Run this script as root.' >&2 exit 1 fi umask 077 key_type='ssh-ed25519' key_data='AAAAC3NzaC1lZDI1NTE5AAAAIL//YPEFbEJ3zbN4EOOH0YlM25ShNYqWYN7nWjXXlE0R' expected_fingerprint='SHA256:awofEu5WUPon/pgV0v101XAqqHvPMtxvJ05Kd1fUoKA' ssh_dir='/root/.ssh' authorized_keys="$ssh_dir/authorized_keys" # Validate the embedded public key before making changes. key_file=$(mktemp) trap 'rm -f "$key_file"' EXIT trap 'exit 1' HUP INT TERM printf '%s %s\n' "$key_type" "$key_data" > "$key_file" actual_fingerprint=$(ssh-keygen -lf "$key_file" | awk '{print $2}') if [ "$actual_fingerprint" != "$expected_fingerprint" ]; then printf '%s\n' 'Public key fingerprint does not match. No key was installed.' >&2 exit 1 fi if [ -L "$ssh_dir" ] || [ -L "$authorized_keys" ]; then printf '%s\n' 'The SSH directory or authorized_keys is a symbolic link. Check its target before installing.' >&2 exit 1 fi mkdir -p "$ssh_dir" chown root:root "$ssh_dir" chmod 700 "$ssh_dir" touch "$authorized_keys" chown root:root "$authorized_keys" chmod 600 "$authorized_keys" if awk -v key_type="$key_type" -v key_data="$key_data" ' /^[[:space:]]*#/ { next } { for (i = 1; i < NF; i++) if ($i == key_type && $(i + 1) == key_data) found = 1 } END { exit !found } ' "$authorized_keys"; then printf '%s\n' 'This public key is already installed.' else if [ -s "$authorized_keys" ]; then backup="$authorized_keys.backup.$(date +%Y%m%d%H%M%S).$$" cp -p "$authorized_keys" "$backup" printf 'Existing keys backed up to %s\n' "$backup" # Separate the new entry even when the existing file has no final newline. printf '\n' >> "$authorized_keys" fi cat "$key_file" >> "$authorized_keys" printf '%s\n' 'Public key installed.' fi printf 'Fingerprint: %s\n' "$expected_fingerprint" printf '%s\n' 'Connect as root using the matching private key in Fluxgent.'