freedombone-pass 3.8KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143
  1. #!/bin/bash
  2. #
  3. # .---. . .
  4. # | | |
  5. # |--- .--. .-. .-. .-.| .-. .--.--. |.-. .-. .--. .-.
  6. # | | (.-' (.-' ( | ( )| | | | )( )| | (.-'
  7. # ' ' --' --' -' - -' ' ' -' -' -' ' - --'
  8. #
  9. # Freedom in the Cloud
  10. #
  11. # Simple multi-user password store using symmetric encryption
  12. # and the backup gpg key
  13. #
  14. # License
  15. # =======
  16. #
  17. # Copyright (C) 2016 Bob Mottram <bob@freedombone.net>
  18. #
  19. # This program is free software: you can redistribute it and/or modify
  20. # it under the terms of the GNU Affero General Public License as published by
  21. # the Free Software Foundation, either version 3 of the License, or
  22. # (at your option) any later version.
  23. #
  24. # This program is distributed in the hope that it will be useful,
  25. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  26. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  27. # GNU Affero General Public License for more details.
  28. #
  29. # You should have received a copy of the GNU Affero General Public License
  30. # along with this program. If not, see <http://www.gnu.org/licenses/>.
  31. PROJECT_NAME='freedombone'
  32. export TEXTDOMAIN=${PROJECT_NAME}-pass
  33. export TEXTDOMAINDIR="/usr/share/locale"
  34. MY_BACKUP_KEY_ID=
  35. CURR_USERNAME=
  36. CURR_APP=
  37. CURR_PASSWORD=""
  38. function get_backup_key_id {
  39. MY_BACKUP_KEY_ID=$(gpg --list-keys "(backup key)" | \
  40. grep 'pub ' | awk -F ' ' '{print $2}' | \
  41. awk -F '/' '{print $2}')
  42. if [ ${#MY_BACKUP_KEY_ID} -lt 4 ]; then
  43. echo $"gpg backup key was not found"
  44. return 58213
  45. fi
  46. }
  47. function pass_show_help {
  48. echo ''
  49. echo $"${PROJECT_NAME}-pass"
  50. echo ''
  51. echo $'Password store using gpg'
  52. echo ''
  53. echo $' -h --help Show help'
  54. echo $' -u --user [name] Username'
  55. echo $' -a --app [name] Name of the application'
  56. echo $' -p --pass [password] The password to store'
  57. echo ''
  58. echo $'To encrypt a password:'
  59. echo ''
  60. echo $" ${PROJECT_NAME}-pass -u [username] -a [app] -p [password]"
  61. echo ''
  62. echo $'To retrieve a password:'
  63. echo $''
  64. echo $" ${PROJECT_NAME}-pass -u [username] -a [app]"
  65. echo ''
  66. exit 0
  67. }
  68. function pad_string {
  69. echo -n -e "$1" | sed -e :a -e 's/^.\{1,128\}$/& /;ta'
  70. }
  71. while [[ $# > 1 ]]
  72. do
  73. key="$1"
  74. case $key in
  75. -h|--help)
  76. pass_show_help
  77. ;;
  78. -u|--user|--username)
  79. shift
  80. CURR_USERNAME="${1}"
  81. ;;
  82. -a|--app|--application)
  83. shift
  84. CURR_APP="${1}"
  85. ;;
  86. -p|--pass|--password|--passphrase)
  87. shift
  88. CURR_PASSWORD="${1}"
  89. ;;
  90. *)
  91. # unknown option
  92. ;;
  93. esac
  94. shift
  95. done
  96. get_backup_key_id
  97. MASTER_PASSWORD=$(gpg -q --armor --export-secret-key $MY_BACKUP_KEY_ID)
  98. if [ ! $CURR_USERNAME ]; then
  99. echo $'No username given'
  100. exit 1
  101. fi
  102. if [ ! -d /home/$CURR_USERNAME ]; then
  103. echo $"User $CURR_USERNAME does not exist"
  104. exit 2
  105. fi
  106. if [ ! $CURR_APP ]; then
  107. echo $'No app name given'
  108. exit 3
  109. fi
  110. if [ ${#CURR_PASSWORD} -eq 0 ]; then
  111. # retrieve password
  112. if [ ! -f ~/.passwords/$CURR_USERNAME/$CURR_APP ]; then
  113. echo ""
  114. exit 4
  115. else
  116. pass=$(gpg -dq --passphrase "$MASTER_PASSWORD" ~/.passwords/$CURR_USERNAME/$CURR_APP)
  117. echo ${pass}
  118. fi
  119. else
  120. # store password
  121. if [ ! -d ~/.passwords/$CURR_USERNAME ]; then
  122. mkdir -p ~/.passwords/$CURR_USERNAME
  123. fi
  124. pad_string "${CURR_PASSWORD}" | gpg -ca --cipher-algo AES256 --passphrase "$MASTER_PASSWORD" > ~/.passwords/$CURR_USERNAME/$CURR_APP
  125. if [ ! -f ~/.passwords/$CURR_USERNAME/$CURR_APP ]; then
  126. exit 5
  127. fi
  128. fi
  129. exit 0