aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorGravatar Michael Gisbers <michael@gisbers.de>2019-03-06 15:25:18 +0100
committerGravatar Christian Hesse <mail@eworm.de>2019-03-06 16:12:03 +0100
commitcf09542635b9f9e0d1af467ec4982d68b94a6b03 (patch)
treee6fc7a5abf58622f490bc6ad46d06d255577ec22
parent6a048d56814c38e82c709d845aa8eb2a65319afd (diff)
daily-psk: prepare for caps-man
Signed-off-by: Christian Hesse <mail@eworm.de>
-rw-r--r--daily-psk-schedule2
-rw-r--r--daily-psk.capsman90
-rw-r--r--daily-psk.local (renamed from daily-psk)9
-rw-r--r--daily-psk.template96
4 files changed, 190 insertions, 7 deletions
diff --git a/daily-psk-schedule b/daily-psk-schedule
index e5eb6f8..2a01bae 100644
--- a/daily-psk-schedule
+++ b/daily-psk-schedule
@@ -17,7 +17,7 @@
:error "Time is not yet synchronized from ntp.";
}
- / system script run daily-psk;
+ / system script run [ find where name~"daily-psk\\.(capsman|local)" ];
/ system scheduler set interval=0s $Scheduler;
}
diff --git a/daily-psk.capsman b/daily-psk.capsman
new file mode 100644
index 0000000..2783afa
--- /dev/null
+++ b/daily-psk.capsman
@@ -0,0 +1,90 @@
+#!rsc
+# RouterOS script: daily-psk.capsman
+# Copyright (c) 2013-2019 Christian Hesse <mail@eworm.de>
+# Michael Gisbers <michael@gisbers.de>
+#
+# update daily PSK (pre shared key)
+
+:global Identity;
+:global DailyPskMatchComment;
+:global UrlEncode;
+
+:global SendNotification;
+
+:local Seen [ :toarray "" ];
+
+# return pseudo-random string for PSK
+:local GeneratePSK do={
+ :local Date [ :tostr $1 ];
+
+ :global DailyPskSecrets;
+
+ :local Months { "jan"; "feb"; "mar"; "apr"; "may"; "jun";
+ "jul"; "aug"; "sep"; "oct"; "nov"; "dec" };
+
+ :local Month [ :pick $Date 0 3 ];
+ :local Day [ :tonum [ :pick $Date 4 6 ] ];
+ :local Year [ :pick $Date 7 11 ];
+
+ :for MIndex from=0 to=[ :len $Months ] do={
+ :if ($Months->$MIndex = $Month) do={
+ :set Month ($MIndex + 1);
+ }
+ }
+
+ :local A ((14 - $Month) / 12);
+ :local B ($Year - $A);
+ :local C ($Month + 12 * $A - 2);
+ :local WeekDay (7000 + $Day + $B + ($B / 4) - ($B / 100) + ($B / 400) + ((31 * $C) / 12));
+ :set WeekDay ($WeekDay - (($WeekDay / 7) * 7));
+
+ :return (($DailyPskSecrets->0->($Day - 1)) . \
+ ($DailyPskSecrets->1->($Month - 1)) . \
+ ($DailyPskSecrets->2->$WeekDay));
+}
+
+:local Date [ / system clock get date ];
+:local NewPsk [ $GeneratePSK $Date ];
+
+:foreach AccList in=[ / caps-man access-list find where comment~$DailyPskMatchComment ] do={
+ :local Ssid [ / caps-man access-list get $AccList ssid-regexp ];
+ :local Configuration [ / caps-man configuration get [ find where ssid=$Ssid ] name ];
+ :local OldPsk [ / caps-man access-list get $AccList private-passphrase ];
+ :local Skip 0;
+
+ :if ($NewPsk != $OldPsk) do={
+ :log info ("Updating daily PSK for " . $Ssid . " to " . $NewPsk . " (was " . $OldPsk . ")");
+ / caps-man access-list set $AccList private-passphrase=$NewPsk;
+
+ :if ([ / caps-man interface print count-only where configuration=$Configuration ] > 0) do={
+ :foreach SeenSsid in=$Seen do={
+ :if ($SeenSsid = $Ssid) do={
+ :log debug ("Already sent a mail for SSID " . $Ssid . ", skipping.");
+ :set Skip 1;
+ }
+ }
+
+ :if ($Skip = 0) do={
+ :set Seen ($Seen, $Ssid);
+
+ :local Url ("https://www.eworm.de/cgi-bin/cqrlogo-wifi.cgi" . \
+ "?scale=8&level=1&ssid=" . [ $UrlEncode $Ssid ] . "&pass=" . [ $UrlEncode $NewPsk ]);
+ :local Attach "qrcode-daily.png";
+
+ :do {
+ / tool fetch mode=https check-certificate=yes-without-crl \
+ $Url dst-path=$Attach;
+ } on-error={
+ :set Attach "";
+ }
+
+ $SendNotification ("daily PSK " . $Ssid) \
+ ("This is the daily PSK on " . $Identity . ":\n\n" . \
+ "SSID: " . $Ssid . "\n" . \
+ "PSK: " . $NewPsk . "\n" . \
+ "Date: " . $Date . "\n\n" . \
+ $Url) $Attach;
+ }
+ }
+ }
+}
diff --git a/daily-psk b/daily-psk.local
index f05af1c..363765f 100644
--- a/daily-psk
+++ b/daily-psk.local
@@ -1,5 +1,5 @@
#!rsc
-# RouterOS script: daily-psk
+# RouterOS script: daily-psk.local
# Copyright (c) 2013-2019 Christian Hesse <mail@eworm.de>
# Michael Gisbers <michael@gisbers.de>
#
@@ -48,16 +48,15 @@
:foreach AccList in=[ / interface wireless access-list find where comment~$DailyPskMatchComment ] do={
:local IntName [ / interface wireless access-list get $AccList interface ];
- :local Interface [ / interface wireless find where name=$IntName disabled=no ];
:local Ssid [ / interface wireless get $IntName ssid ];
:local OldPsk [ / interface wireless access-list get $AccList private-pre-shared-key ];
:local Skip 0;
:if ($NewPsk != $OldPsk) do={
- :log info ("Updating daily PSK for " . $IntName . " to " . $NewPsk . " (was " . $OldPsk . ")");
+ :log info ("Updating daily PSK for " . $Ssid . " to " . $NewPsk . " (was " . $OldPsk . ")");
/ interface wireless access-list set $AccList private-pre-shared-key=$NewPsk;
- :if ([ :len $Interface ] = 1) do={
+ :if ([ / interface wireless print count-only where name=$IntName disabled=no ] = 1) do={
:foreach SeenSsid in=$Seen do={
:if ($SeenSsid = $Ssid) do={
:log debug ("Already sent a mail for SSID " . $Ssid . ", skipping.");
@@ -86,8 +85,6 @@
"Date: " . $Date . "\n\n" . \
$Url) $Attach;
}
- } else={
- :log debug ("Missing active interface " . $IntName . " for access list entry.");
}
}
}
diff --git a/daily-psk.template b/daily-psk.template
new file mode 100644
index 0000000..a9d65f2
--- /dev/null
+++ b/daily-psk.template
@@ -0,0 +1,96 @@
+#!rsc
+# RouterOS script: daily-psk%TEMPL%
+# Copyright (c) 2013-2019 Christian Hesse <mail@eworm.de>
+# Michael Gisbers <michael@gisbers.de>
+#
+# update daily PSK (pre shared key)
+
+:global Identity;
+:global DailyPskMatchComment;
+:global UrlEncode;
+
+:global SendNotification;
+
+:local Seen [ :toarray "" ];
+
+# return pseudo-random string for PSK
+:local GeneratePSK do={
+ :local Date [ :tostr $1 ];
+
+ :global DailyPskSecrets;
+
+ :local Months { "jan"; "feb"; "mar"; "apr"; "may"; "jun";
+ "jul"; "aug"; "sep"; "oct"; "nov"; "dec" };
+
+ :local Month [ :pick $Date 0 3 ];
+ :local Day [ :tonum [ :pick $Date 4 6 ] ];
+ :local Year [ :pick $Date 7 11 ];
+
+ :for MIndex from=0 to=[ :len $Months ] do={
+ :if ($Months->$MIndex = $Month) do={
+ :set Month ($MIndex + 1);
+ }
+ }
+
+ :local A ((14 - $Month) / 12);
+ :local B ($Year - $A);
+ :local C ($Month + 12 * $A - 2);
+ :local WeekDay (7000 + $Day + $B + ($B / 4) - ($B / 100) + ($B / 400) + ((31 * $C) / 12));
+ :set WeekDay ($WeekDay - (($WeekDay / 7) * 7));
+
+ :return (($DailyPskSecrets->0->($Day - 1)) . \
+ ($DailyPskSecrets->1->($Month - 1)) . \
+ ($DailyPskSecrets->2->$WeekDay));
+}
+
+:local Date [ / system clock get date ];
+:local NewPsk [ $GeneratePSK $Date ];
+
+:foreach AccList in=[ / interface wireless access-list find where comment~$DailyPskMatchComment ] do={
+:foreach AccList in=[ / caps-man access-list find where comment~$DailyPskMatchComment ] do={
+ :local IntName [ / interface wireless access-list get $AccList interface ];
+ :local Ssid [ / interface wireless get $IntName ssid ];
+ :local Ssid [ / caps-man access-list get $AccList ssid-regexp ];
+ :local Configuration [ / caps-man configuration get [ find where ssid=$Ssid ] name ];
+ :local OldPsk [ / interface wireless access-list get $AccList private-pre-shared-key ];
+ :local OldPsk [ / caps-man access-list get $AccList private-passphrase ];
+ :local Skip 0;
+
+ :if ($NewPsk != $OldPsk) do={
+ :log info ("Updating daily PSK for " . $Ssid . " to " . $NewPsk . " (was " . $OldPsk . ")");
+ / interface wireless access-list set $AccList private-pre-shared-key=$NewPsk;
+ / caps-man access-list set $AccList private-passphrase=$NewPsk;
+
+ :if ([ / interface wireless print count-only where name=$IntName disabled=no ] = 1) do={
+ :if ([ / caps-man interface print count-only where configuration=$Configuration ] > 0) do={
+ :foreach SeenSsid in=$Seen do={
+ :if ($SeenSsid = $Ssid) do={
+ :log debug ("Already sent a mail for SSID " . $Ssid . ", skipping.");
+ :set Skip 1;
+ }
+ }
+
+ :if ($Skip = 0) do={
+ :set Seen ($Seen, $Ssid);
+
+ :local Url ("https://www.eworm.de/cgi-bin/cqrlogo-wifi.cgi" . \
+ "?scale=8&level=1&ssid=" . [ $UrlEncode $Ssid ] . "&pass=" . [ $UrlEncode $NewPsk ]);
+ :local Attach "qrcode-daily.png";
+
+ :do {
+ / tool fetch mode=https check-certificate=yes-without-crl \
+ $Url dst-path=$Attach;
+ } on-error={
+ :set Attach "";
+ }
+
+ $SendNotification ("daily PSK " . $Ssid) \
+ ("This is the daily PSK on " . $Identity . ":\n\n" . \
+ "SSID: " . $Ssid . "\n" . \
+ "PSK: " . $NewPsk . "\n" . \
+ "Date: " . $Date . "\n\n" . \
+ $Url) $Attach;
+ }
+ }
+ }
+}