Subversion Repositories ALCASAR

Rev

Rev 2991 | Rev 3043 | Go to most recent revision | Details | Compare with Previous | Last modification | View Log

Rev Author Line No. Line
838 richard 1
<?php
2688 lucas.echa 2
/* written by steweb57 & Rexy */
2990 rexy 3
 
838 richard 4
# Choice of language
5
$Language = 'en';
6
if(isset($_SERVER['HTTP_ACCEPT_LANGUAGE'])){
7
	$Langue		= explode(",",$_SERVER['HTTP_ACCEPT_LANGUAGE']);
8
	$Language	= strtolower(substr(chop($Langue[0]),0,2)); }
2853 rexy 9
if($Language == 'fr') {
838 richard 10
	$l_services_title	= "Configuration des services";
1157 stephane 11
	$l_main_services	= "Services principaux";
1476 richard 12
	$l_filter_services	= "Services de filtrage";
1157 stephane 13
	$l_opt_services		= "Services optionnels";
2926 rexy 14
	$l_service_title 	= "Rôle du service";
2134 richard 15
	$l_service_start 	= "Démarrer";
16
	$l_service_stop 	= "Arréter";
17
	$l_service_restart 	= "Redémarrer";
838 richard 18
	$l_service_status 	= "Status";
1006 richard 19
	$l_service_status_img_ok= "Démarré";
20
	$l_service_status_img_ko= "Arrété";
838 richard 21
	$l_service_action 	= "Actions";
22
	$l_radiusd		= "Serveur d'authentification et d'autorisation";
2531 rexy 23
	$l_chilli		= "Passerelle d'interception et serveur DHCP";
2521 armand.ito 24
	$l_e2guardian		= "Filtre d'URL et de contenu WEB";
1476 richard 25
	$l_mysqld		= "Serveur de la base des usagers";
2488 lucas.echa 26
	$l_lighttpd		= "Serveur WEB (Alcasar Control Center)";
1476 richard 27
	$l_sshd			= "Accès sécurisée distant";
2776 rexy 28
	$l_clamav_freshclam	= "Mise à jour de l'antivirus (toutes les 4 heures)";
2840 rexy 29
	$l_clamav_daemon	= "Antimalware";
838 richard 30
	$l_ntpd			= "Service de mise à l'heure réseau";
2990 rexy 31
	$l_postfix		= "Service de messagerie";
2531 rexy 32
	$l_fail2ban		= "Détecteur d'intrusion";
2775 rexy 33
	$l_nfcapd 		= "Collecteur de flux NetFlow";
2531 rexy 34
	$l_vnstat		= "Grapheur de flux réseau";
2688 lucas.echa 35
	$l_unbound		= "Serveur DNS principal";
36
	$l_unbound_blacklist	= "Serveur DNS pour la Blacklist";
37
	$l_unbound_whitelist	= "Serveur DNS pour la Whitelist";
38
	$l_dnsmasq_whitelist	= "Serveur DNS pour la Whitelist (IPSET)";
39
	$l_unbound_blackhole	= "Serveur DNS 'trou noir'";
1484 richard 40
	$l_ulogd_ssh		= "journalisation des accès par SSH";
1476 richard 41
	$l_ulogd_ext_access	= "journalisation des tentatives d'accès externes";
42
	$l_ulogd_traceability	= "journalisation des connexions WEB filtrés";
2926 rexy 43
	$l_wifi4eu_id	= "Entrez votre identifiant réseau";
1574 richard 44
	$l_execute		= "Exécuter";
2926 rexy 45
	$l_stop_restart		= "Arrêt et redémarrage du système";
1574 richard 46
	$l_halt			= "Arréter le système";
47
	$l_reboot		= "Relancer le système";
2853 rexy 48
} else if($Language == 'es') {
49
	$l_services_title	= "Configuración de Servicios";
50
	$l_main_services	= "Servicios Principales";
51
	$l_filter_services	= "Servicios de Filtrado";
52
	$l_opt_services		= "Servicios Opcionales";
2926 rexy 53
	$l_service_title 	= "función del servicio";
2853 rexy 54
	$l_service_start 	= "Iniciar";
55
	$l_service_stop 	= "Detener";
56
	$l_service_restart 	= "Reiniciar";
57
	$l_service_status 	= "Estado";
58
	$l_service_status_img_ok= "Corriendo";
59
	$l_service_status_img_ko= "Detenido";
60
	$l_service_action 	= "Acciones";
61
	$l_radiusd		= "Servidor de autenticación y autorización.";
62
	$l_chilli		= "Pasarela de interceptación y servidor DHCP";
63
	$l_e2guardian		= "Filtro de contenidos URL y WEB";
64
	$l_mysqld		= "Motor de base de datos para usuarios";
65
	$l_lighttpd		= "Servidor WEB (ALCASAR Control Center)";
66
	$l_sshd			= "Servidor Seguro Acceso Remoto";
67
	$l_clamav_freshclam		= "Proceso de actualización Antivirus (cada 4 horas)";
68
	$l_clamav_daemon	= "Antimalware";
69
	$l_ntpd			= "Servidor de hora";
70
	$l_fail2ban		= "Sistema de Detección de Intrusos";
71
	$l_nfcapd		= "Colector de flujo NetFlow";
72
	$l_vnstat		= "Graficador de tráfico de red";
73
	$l_unbound		= "Servidor DNS principal ";
74
	$l_unbound_blacklist	= "Servidor DNS de Lista Negra";
75
	$l_unbound_whitelist	= "Servidor DNS de Lista Blanca";
76
	$l_dnsmasq_whitelist	= "Servidor DNS de Lista Blanca (IPSET)";
77
	$l_unbound_blackhole	= "Agujero negro DNS";
78
	$l_ulogd_ssh		= "Proceso de registro para accesos SSH";
79
	$l_ulogd_ext_access	= "Proceso de registro de intentos de accesos externos";
80
	$l_ulogd_traceability	= "Proceso de registro de acceso WEB";
2926 rexy 81
	$l_wifi4eu_id	= "Introduzca su identificador de red";
2853 rexy 82
	$l_execute		= "Ejecutar";
83
	$l_stop_restart		= "Apagado y Reinicio del sistema";
84
	$l_halt			= "Apagar el sistema";
85
	$l_reboot		= "Reiniciar el sistema";
838 richard 86
} else {
87
	$l_services_title	= "Services configuration";
1157 stephane 88
	$l_main_services	= "Main services";
1476 richard 89
	$l_filter_services	= "Filtering services";
1157 stephane 90
	$l_opt_services		= "Optional services";
2926 rexy 91
	$l_service_title 	= "Role of the service";
838 richard 92
	$l_service_start 	= "Start";
93
	$l_service_stop 	= "Stop";
94
	$l_service_restart 	= "Restart";
95
	$l_service_status 	= "Status";
1006 richard 96
	$l_service_status_img_ok= "Running";
97
	$l_service_status_img_ko= "Stopped";
838 richard 98
	$l_service_action 	= "Actions";
1572 richard 99
	$l_radiusd		= "Authentication and authorisation server";
2531 rexy 100
	$l_chilli		= "Interception gateway and DHCP server";
2521 armand.ito 101
	$l_e2guardian		= "URL and WEB content filter";
838 richard 102
	$l_mysqld		= "User database server";
2488 lucas.echa 103
	$l_lighttpd		= "WEB server (ALCASAR Control Center)";
838 richard 104
	$l_sshd			= "Secure remote access";
2776 rexy 105
	$l_clamav_freshclam	= "Antivirus update process (every 4 hours)";
2840 rexy 106
	$l_clamav_daemon= "Antimalware";
1572 richard 107
	$l_ntpd			= "Network time server";
2531 rexy 108
	$l_fail2ban		= "Intrusion Dectection System";
2775 rexy 109
	$l_nfcapd		= "Netflow collector";
2531 rexy 110
	$l_vnstat		= "Network grapher";
2688 lucas.echa 111
	$l_unbound		= "Main DNS server";
112
	$l_unbound_blacklist	= "Blacklist DNS server";
113
	$l_unbound_whitelist	= "Whitelist DNS server";
114
	$l_dnsmasq_whitelist	= "Whitelist DNS server (IPSET)";
115
	$l_unbound_blackhole	= "Blackhole DNS server";
1476 richard 116
	$l_ulogd_ssh		= "SSH access logging process";
1572 richard 117
	$l_ulogd_ext_access	= "Extern access attempts logging process";
1476 richard 118
	$l_ulogd_traceability	= "Filtering WEB access logging process";
2926 rexy 119
	$l_wifi4eu_id	= "Enter your network identifier";
1574 richard 120
	$l_execute		= "Execute";
121
	$l_stop_restart		= "Halt and restart the system";
122
	$l_halt			= "Halt le system";
123
	$l_reboot		= "Restart the system";
838 richard 124
}
125
 
126
/****************************************************************
2531 rexy 127
*	                   CONST				*
838 richard 128
*****************************************************************/
129
define ("CONF_FILE", "/usr/local/etc/alcasar.conf");
130
 
131
/********************************************************
2531 rexy 132
*			CONF FILE test 			*
838 richard 133
*********************************************************/
134
if (!file_exists(CONF_FILE)){
135
	exit("Fichier de configuration ".CONF_FILE." non présent");
136
}
137
if (!is_readable(CONF_FILE)){
138
	exit("Vous n'avez pas les droits de lecture sur le fichier ".CONF_FILE);
139
}
2926 rexy 140
$file_conf = fopen(CONF_FILE, 'r');
141
if (!$file_conf) {
142
	exit('Error opening the file '.CONF_FILE);
143
}
144
while (!feof($file_conf)) {
145
	$buffer = fgets($file_conf, 4096);
146
	if ((strpos($buffer, '=') !== false) && (substr($buffer, 0, 1) !== '#')) {
147
		$tmp = explode('=', $buffer, 2);
148
		$conf[trim($tmp[0])] = trim($tmp[1]);
149
	}
150
}
151
fclose($file_conf);
152
$wifi4eu = $conf['WIFI4EU'];
153
$wifi4eu_code = $conf['WIFI4EU_CODE'];
2531 rexy 154
// Doing an action on a service (start,stop or restart)
838 richard 155
function serviceExec($service, $action){
156
	if (($action == "start")||($action == "stop")||($action == "restart")){
2934 rexy 157
		exec("sudo /usr/bin/systemctl $action ".escapeshellarg($service), $retval, $retstatus);
2926 rexy 158
		if ($service == "sshd"){ 
2688 lucas.echa 159
			if ($action == "start"){
2931 rexy 160
				//exec("sudo /usr/bin/systemctl enable ".escapeshellarg($service));
161
				file_put_contents(CONF_FILE, str_replace('SSH=off', 'SSH=on', file_get_contents(CONF_FILE))); // in order to keep that conf for SSH at next reboot
2299 tom.houday 162
				exec("sudo /usr/local/bin/alcasar-iptables.sh");
838 richard 163
				}
164
			if ($action == "stop"){
2931 rexy 165
				//exec("sudo /usr/bin/systemctl disable ".escapeshellarg($service));
838 richard 166
				file_put_contents(CONF_FILE, str_replace('SSH=on', 'SSH=off', file_get_contents(CONF_FILE)));
2299 tom.houday 167
				exec("sudo /usr/local/bin/alcasar-iptables.sh");
838 richard 168
				}
169
			}
170
		return $retstatus;
171
	} else {
172
		return false;
173
	}
174
}
2531 rexy 175
 
176
// Testing if a service is active
1006 richard 177
function checkServiceStatus($service){
838 richard 178
	$response = false;
2299 tom.houday 179
	exec("sudo /usr/bin/systemctl is-active ".escapeshellarg("$service.service"), $retval);
838 richard 180
	foreach( $retval as $val ) {
1006 richard 181
		if ($val == "active"){
838 richard 182
			$response = true;
183
			break;
184
		}
185
	}
186
	return $response;
187
}
188
 
189
//-------------------------------
2926 rexy 190
// WIFI4EU
191
//-------------------------------
192
if (isset($_POST['wifi4eu'])){
2934 rexy 193
	switch ($_POST['wifi4eu']){
194
		case 'on' :
2935 rexy 195
			$network_code = trim($_POST['wifi4eu_id']);
196
		        if ($network_code == '') {
197
				$network_code = '123e4567-e89b-12d3-a456-426655440000'; // WIFI4EU test code
198
			}
199
			file_put_contents(CONF_FILE, preg_replace('/WIFI4EU_CODE=.*/', 'WIFI4EU_CODE='.$network_code, file_get_contents(CONF_FILE)));
2934 rexy 200
			exec("sudo /usr/local/bin/alcasar-wifi4eu.sh -on");
201
		break;
202
		case 'off' :
203
			exec("sudo /usr/local/bin/alcasar-wifi4eu.sh -off");
204
		break;
205
	}
206
	header('Location: '.$_SERVER['PHP_SELF']);
2926 rexy 207
}
2934 rexy 208
 
2926 rexy 209
//-------------------------------
2934 rexy 210
// Stop/restart system
1574 richard 211
//-------------------------------
2934 rexy 212
if (isset($_POST['system'])){
213
	switch ($_POST['system']){
1574 richard 214
		case 'reboot' :
1827 raphael.pi 215
			exec ("sudo /usr/local/bin/alcasar-logout.sh all");
1599 richard 216
			exec ("sudo /usr/sbin/shutdown -r now");
1574 richard 217
		break;
218
		case 'halt' :
1827 raphael.pi 219
			exec ("sudo /usr/local/bin/alcasar-logout.sh all");
1599 richard 220
			exec ("sudo /usr/sbin/shutdown -h now");
1574 richard 221
		break;
222
	}
223
}
224
 
225
//-------------------------------
2934 rexy 226
// Actions on services
227
//-------------------------------
2990 rexy 228
$autorizeService = array("radiusd","chilli","mysqld","lighttpd","unbound-forward","ulogd-ssh","ulogd-ext-access","ulogd-traceability","unbound-blacklist","unbound-whitelist","dnsmasq-whitelist","unbound-blackhole","e2guardian","clamav-daemon","clamav-freshclam","sshd","ntpd","fail2ban","nfcapd","vnstat","postfix");
2934 rexy 229
$autorizeAction = array("start","stop","restart");
230
 
231
if (isset($_GET['service'])&&(in_array($_GET['service'], $autorizeService))) {
232
    if (isset($_GET['action'])&&(in_array($_GET['action'], $autorizeAction))) {
233
    	$execStatus = serviceExec($_GET['service'], $_GET['action']);
234
		// execStatus non exploité
235
	}
236
}
237
 
238
//-------------------------------
2531 rexy 239
// Check services status
838 richard 240
//-------------------------------
241
$MainServiceStatus = array();
2531 rexy 242
$MainServiceStatus['chilli'] = checkServiceStatus("chilli");
1006 richard 243
$MainServiceStatus['radiusd'] = checkServiceStatus("radiusd");
244
$MainServiceStatus['mysqld'] = checkServiceStatus("mysqld");
2488 lucas.echa 245
$MainServiceStatus['lighttpd'] = checkServiceStatus("lighttpd");
2724 rexy 246
$MainServiceStatus['unbound'] = checkServiceStatus("unbound");
2775 rexy 247
$MainServiceStatus['nfcapd'] = checkServiceStatus("nfcapd");
2531 rexy 248
$MainServiceStatus['ulogd_ssh'] = checkServiceStatus("ulogd-ssh");
249
$MainServiceStatus['ulogd_ext_access'] = checkServiceStatus("ulogd-ext-access");
250
$MainServiceStatus['ulogd_traceability'] = checkServiceStatus("ulogd-traceability");
2926 rexy 251
$MainServiceStatus['sshd'] = checkServiceStatus("sshd");
252
$MainServiceStatus['ntpd'] = checkServiceStatus("ntpd");
253
$MainServiceStatus['fail2ban'] = checkServiceStatus("fail2ban");
254
$MainServiceStatus['vnstat'] = checkServiceStatus("vnstat");
2990 rexy 255
$MainServiceStatus['postfix'] = checkServiceStatus("postfix");
838 richard 256
 
1476 richard 257
$FilterServiceStatus = array();
2688 lucas.echa 258
$FilterServiceStatus['unbound_blacklist'] = checkServiceStatus("unbound-blacklist");
259
$FilterServiceStatus['unbound_whitelist'] = checkServiceStatus("unbound-whitelist");
2531 rexy 260
$FilterServiceStatus['dnsmasq_whitelist'] = checkServiceStatus("dnsmasq-whitelist");
2688 lucas.echa 261
$FilterServiceStatus['unbound_blackhole'] = checkServiceStatus("unbound-blackhole");
2531 rexy 262
$FilterServiceStatus['e2guardian'] = checkServiceStatus("e2guardian");
2840 rexy 263
$FilterServiceStatus['clamav_daemon'] = checkServiceStatus("clamav-daemon");
2776 rexy 264
$FilterServiceStatus['clamav_freshclam'] = checkServiceStatus("clamav-freshclam");
1476 richard 265
 
838 richard 266
/****************
267
*	MAIN	*
268
*****************/
269
 
2926 rexy 270
?><!DOCTYPE HTML>
271
<html>
838 richard 272
<head>
2926 rexy 273
	<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
274
	<title><?php echo $l_services_title; ?></title>
275
	<link rel="stylesheet" href="/css/acc.css" type="text/css">
2990 rexy 276
	<script type="text/javascript" src="/js/jquery.min.js"></script>
838 richard 277
</head>
278
<body>
3028 rexy 279
<div id="ldoverlay" class="overlay">
280
	<div class="lds-spinner" id="spinner"><div></div><div></div><div></div><div></div><div></div><div></div><div></div><div></div><div></div><div></div><div></div><div></div></div>
281
</div>
2926 rexy 282
<div class="panel">
283
	<div class="panel-header"><?= $l_main_services ?></div>
284
	<div class="panel-row">
285
	<table width="100%" border=0 cellspacing=0 cellpadding=0>
286
		<tr align="center"><td><?php echo $l_service_status;?></td><td colspan="2"><?php echo $l_service_title;?></td><td colspan="3"><?php echo $l_service_action;?></td></tr>
287
		<?php foreach( $MainServiceStatus as $serviceName => $statusOK ) { ?>
288
		<tr>
2991 rexy 289
		<?php if ($statusOK) { ?>
2926 rexy 290
			<td align="center"><img src="/images/state_ok.gif" width="15" height="15" alt="<?php echo $l_service_status_img_ok; ?>"></td>
291
			<td align="center"><?php $comment="l_$serviceName"; echo "<b>$serviceName</b></td><td>${$comment}" ;?> </td>
292
			<td width="80" align="center">---</td>
293
			<td width="80" align="center"><?php if (($serviceName != "chilli") && ($serviceName != "lighttpd")) { echo "<a href=\"".$_SERVER['PHP_SELF']."?action=stop&service=".str_replace('_','-',$serviceName)."\"> $l_service_stop</a>"; } else echo "---";?></td>
294
			<td width="80" align="center"><a href="<?php echo $_SERVER['PHP_SELF']."?action=restart&service=".str_replace('_','-',$serviceName)."\"> $l_service_restart";?></a></td>
295
		<?php } else { ?>
296
			<td align="center"><img src="/images/state_error.gif" width="15" height="15" alt="<?php echo $l_service_status_img_ko ?>"></td>
297
			<td align="center"><?php $comment="l_$serviceName"; echo "$serviceName</td><td>${$comment}" ;?> </td>
298
			<td width="80" align="center"><a href="<?php echo $_SERVER['PHP_SELF']."?action=start&service=".str_replace('_','-',$serviceName)."\"> $l_service_start";?></a></td>
299
			<td width="80" align="center">---</td>
300
			<td width="80" align="center">---</td>
301
		<?php } ?>
302
		</tr>
2991 rexy 303
		<?php } ?>
2926 rexy 304
	</table>
305
	</div>
306
</div>
307
<div class="panel">
308
	<div class="panel-header"><?= $l_filter_services ?></div>
309
	<div class="panel-row">
310
	<table width="100%" border=0 cellspacing=0 cellpadding=0>
311
		<tr align="center"><td><?php echo $l_service_status;?></td><td colspan="2"><?php echo $l_service_title;?></td><td colspan="3"><?php echo $l_service_action;?></td></tr>
312
		<!--	<TR align="center"> -->
313
		<?php foreach( $FilterServiceStatus as $serviceName => $statusOK ) { ?>
314
		<tr>
315
		<?php if ($statusOK) { ?>
316
			<td align="center"><img src="/images/state_ok.gif" width="15" height="15" alt="<?php echo $l_service_status_img_ok; ?>"></td>
317
			<td align="center"><?php $comment="l_$serviceName"; echo "<b>$serviceName</b></td><td>${$comment}" ;?> </td>
318
			<td width="80" align="center">---</td>
319
			<td width="80" align="center"><a href="<?php echo $_SERVER['PHP_SELF']."?action=stop&service=".str_replace('_','-',$serviceName)."\"> $l_service_stop";?></a></td>
320
			<td width="80" align="center"><a href="<?php echo $_SERVER['PHP_SELF']."?action=restart&service=".str_replace('_','-',$serviceName)."\"> $l_service_restart";?></a></td>
321
			<?php } else { ?>
322
			<td align="center"><img src="/images/state_error.gif" width="15" height="15" alt="<?php echo $l_service_status_img_ko ?>"></td>
323
			<td align="center"><?php $comment="l_$serviceName"; echo "$serviceName</td><td>${$comment}" ;?> </td>
324
			<td width="80" align="center"><a href="<?php echo $_SERVER['PHP_SELF']."?action=start&service=".str_replace('_','-',$serviceName)."\"> $l_service_start";?></a></td>
325
			<td width="80" align="center">---</td>
326
			<td width="80" align="center">---</td>
327
			<?php } ?>
328
		</tr>
329
		<?php } ?>
330
	</table>
331
	</div>
332
</div>
333
<div class="panel">
334
	<div class="panel-header"><?= $l_opt_services ?></div>
335
	<div class="panel-row">
2991 rexy 336
	<form action="<?php echo $_SERVER['PHP_SELF']?>" method=POST>
2926 rexy 337
	<table width="100%" border=0 cellspacing=0 cellpadding=0>
338
		<tr align="center"><td><?php echo $l_service_status;?></td><td colspan="2"> </td><td colspan="3"><?php echo $l_service_action;?></td></tr>
339
		<tr>
340
			<?php if ($wifi4eu == "on") { ?>
341
			<td align="center"><img src="/images/state_ok.gif" width="15" height="15" alt="<?php echo $l_service_status_img_ok; ?>"></td>
342
			<td align="center"><b>WIFI4EU</b></td><td><?php echo "network ID : $wifi4eu_code"; ?></td>
343
			<td width="80" align="center">---</td>
3028 rexy 344
			<td width="80" align="center"><input type="submit" onClick="document.getElementById('ldoverlay').style.display='block';" value="<?echo $l_service_stop;?>"><input type=hidden name="wifi4eu" value="off"></td>
2926 rexy 345
			<td width="80" align="center">---</td>
346
			<?php } else { ?>
347
			<td align="center"><img src="/images/state_error.gif" width="15" height="15" alt="<?php echo $l_service_status_img_ko; ?>"></td>
2935 rexy 348
			<td align="center">WIFI4EU</td><td><?php echo $l_wifi4eu_id; ?> : <input type ="text" name="wifi4eu_id" value="<?php echo $wifi4eu_code; ?>" size="40"></td>
3028 rexy 349
			<td width="80" align="center"><input type="submit" onClick="document.getElementById('ldoverlay').style.display='block';" value="<?echo $l_service_start;?>"><input type=hidden name="wifi4eu" value="on"></td>
2926 rexy 350
			<td width="80" align="center">---</td>
351
			<td width="80" align="center">---</td>
352
			<?php } ?>
353
		</tr>
354
	</table>
2991 rexy 355
	</form>
2926 rexy 356
	</div>
357
</div>
358
<div class="panel">
359
	<div class="panel-header"><?= $l_stop_restart ?></div>
360
	<div class="panel-row">
361
	<table width="100%" border=0 cellspacing=0 cellpadding=1>
362
		<tr><td valign="middle" align="left">
363
			<form action="<?php echo $_SERVER['PHP_SELF']?>" method=POST>
2934 rexy 364
			<select name='system'>
2926 rexy 365
				<option selected value="reboot"><?echo "$l_reboot";?>
366
				<option value="halt"><?echo "$l_halt";?>
367
			</select>
3028 rexy 368
			<input type="submit" onClick="document.getElementById('ldoverlay').style.display='block';" value="<?echo "$l_execute";?>">
2926 rexy 369
			</form>
370
		</td></tr>
371
	</table>
372
	</div>
373
</div>
838 richard 374
</body>
2991 rexy 375
</html>