From bb181cb2a95d5620b2e52884fa400d745f4e7cfa Mon Sep 17 00:00:00 2001 From: Ossi Herrala Date: Fri, 14 Mar 2014 16:17:21 +0000 Subject: [PATCH] sudo: Add fake version. You know why. :) --- sudo/files/fakesudo | 25 +++++++++++++++++++++++++ sudo/manifests/init.pp | 14 ++++++++++++++ 2 files changed, 39 insertions(+) create mode 100644 sudo/files/fakesudo diff --git a/sudo/files/fakesudo b/sudo/files/fakesudo new file mode 100644 index 0000000..390d017 --- /dev/null +++ b/sudo/files/fakesudo @@ -0,0 +1,25 @@ +#!/bin/sh + +trap report SIGINT SIGTERM + +function askpw { + # echo -n "Password:" + read -s -p "Password:" password + password="" + echo "" + echo "Sorry, try again." +} + +function report { + stty echo # Fix echo if ^C during password prompt + ( whoami ; date ) | mailx -s "Someone sudo'ed (`id -un`, ${SSH_CONNECTION})" root + exit 1 +} + +function main { + for try in 1 2 3; do askpw; done + echo "sudo: 3 incorrect password attempts" + report +} + +main diff --git a/sudo/manifests/init.pp b/sudo/manifests/init.pp index 6b21b1f..6a4f273 100644 --- a/sudo/manifests/init.pp +++ b/sudo/manifests/init.pp @@ -37,6 +37,20 @@ class sudo { } +# Install fake sudo +# +class sudo::fake { + + file { "/usr/bin/sudo": + ensure => present, + mode => 0555, + owner => "root", + group => "root", + source => "puppet:///modules/sudo/fakesudo", + } + +} + # Add sudoer. # # === Parameters