mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
Update so-functions
This commit is contained in:
@@ -1240,11 +1240,6 @@ firewall_generate_templates() {
|
||||
|
||||
logCmd "cp -r ../files/firewall/* /opt/so/saltstack/local/salt/firewall/"
|
||||
|
||||
# i think this can be commented out for 2.4
|
||||
#for i in analyst beats_endpoint endgame sensors manager managersearch elastic_agent_endpoint searchnodes; do
|
||||
# $default_salt_dir/salt/common/tools/sbin/so-firewall --role="$i" --ip=127.0.0.1
|
||||
#done
|
||||
|
||||
}
|
||||
|
||||
generate_ca() {
|
||||
@@ -2277,12 +2272,9 @@ set_hostname() {
|
||||
}
|
||||
|
||||
set_initial_firewall_policy() {
|
||||
title "Setting Initial Firewall Policy"
|
||||
if [ -f $default_salt_dir/salt/common/tools/sbin/so-firewall ]; then chmod +x $default_salt_dir/salt/common/tools/sbin/so-firewall; fi
|
||||
|
||||
case "$install_type" in
|
||||
'EVAL' | 'MANAGER' | 'MANAGERSEARCH' | 'STANDALONE' | 'IMPORT')
|
||||
$default_salt_dir/salt/common/tools/sbin/so-firewall includehost $minion_type $MAINIP --apply
|
||||
so-firewall includehost $minion_type $MAINIP --apply
|
||||
;;
|
||||
esac
|
||||
}
|
||||
@@ -2369,19 +2361,6 @@ update_sudoers_for_testing() {
|
||||
fi
|
||||
}
|
||||
|
||||
update_sudoers() {
|
||||
|
||||
if ! grep -qE '^soremote\ ALL=\(ALL\)\ NOPASSWD:(\/usr\/bin\/salt\-key|\/opt\/so\/saltstack)' /etc/sudoers; then
|
||||
# Update Sudoers so that soremote can accept keys without a password
|
||||
echo "soremote ALL=(ALL) NOPASSWD:/usr/bin/salt-key" | tee -a /etc/sudoers
|
||||
echo "soremote ALL=(ALL) NOPASSWD:$default_salt_dir/salt/common/tools/sbin/so-firewall" | tee -a /etc/sudoers
|
||||
echo "soremote ALL=(ALL) NOPASSWD:$default_salt_dir/pillar/data/addtotab.sh" | tee -a /etc/sudoers
|
||||
echo "soremote ALL=(ALL) NOPASSWD:$default_salt_dir/salt/manager/files/add_minion.sh" | tee -a /etc/sudoers
|
||||
else
|
||||
info "User soremote already granted sudo privileges"
|
||||
fi
|
||||
}
|
||||
|
||||
update_packages() {
|
||||
if [[ $is_rocky ]]; then
|
||||
logCmd "dnf repolist"
|
||||
|
||||
Reference in New Issue
Block a user