#!/bin/bash # ap-setup.sh # OpenDRS Online Discrepancy Reporting System # Copyright (C) 2022 Rod Wright # SPDX-License-Identifier: GPL-2.0 # Wireless Access Point Raspberry Pi Setup function get_ap_params() { echo "" wapssidok="no" while [[ "$wapssidok" == "no" ]] do echo "This access point will need an SSID. This is what will appear" echo "as the name of this terminal when other devices connect." echo -n "Please enter the desired SSID for this access point: " read wapssid if [[ "$wapssid" = "" ]] then echo "SSID cannot be blank. Try again." else wapssidok="yes" fi done wappassok="no" while [[ "$wappassok" == "no" ]] do echo "You will need to set a passphrase for this access point. It should" echo "be at least 8 characters in length and cannot be blank." echo -n "Please enter the desired passphrase for this access point: " read wappass wappasslen=$(echo -n $wappass | wc -m) if [[ "$wappass" == "" || $wappasslen -lt 8 ]] then echo "Passphrase doesn't satisfy requirements above. Try again." else wappassok="yes" fi done # Save parameters in config file sed -i 's|'wapssid=.*'|'wapssid="\'$wapssid\'"'|' /etc/piwifiap/piwifiap.conf sed -i 's|'wappass=.*'|'wappass="\'$wappass\'"'|' /etc/piwifiap/piwifiap.conf sed -i 's|'802-11-wireless-security.psk:.*'|'802-11-wireless-security.psk:$wappass'|' /etc/piwifiap/piwifiap.secret } function config_systemd-networkd() { echo "Configuring as wireless access point using systemd-networkd." get_ap_params # Save network system type in config file sed -i 's,'network_system=.*','network_system="\"systemd-networkd\""',' /etc/piwifiap/piwifiap.conf apt install hostapd systemctl unmask hostapd systemctl enable hostapd echo "[NetDev]" >/etc/systemd/network/bridge-br0.netdev echo "Name=br0" >>/etc/systemd/network/bridge-br0.netdev echo "Kind=bridge" >>/etc/systemd/network/bridge-br0.netdev echo "[Match]" >/etc/systemd/network/br0-member-eth0.network echo "Name=eth0" >>/etc/systemd/network/br0-member-eth0.network echo "" >>/etc/systemd/network/br0-member-eth0.network echo "[Network]" >>/etc/systemd/network/br0-member-eth0.network echo "Bridge=br0" >>/etc/systemd/network/br0-member-eth0.network systemctl enable systemd-networkd mv /etc/dhcpcd.conf /etc/dhcpcd.conf.old echo "denyinterfaces wlan0 eth0" >/etc/dhcpcd.conf cat /etc/dhcpcd.conf.old >>/etc/dhcpcd.conf echo "interface br0" >>/etc/dhcpcd.conf rfkill unblock wlan echo "country_code=US" >/etc/hostapd/hostapd.conf echo "interface=wlan0" >>/etc/hostapd/hostapd.conf echo "bridge=br0" >>/etc/hostapd/hostapd.conf echo "ssid=$wapssid" >>/etc/hostapd/hostapd.conf echo "hw_mode=g" >>/etc/hostapd/hostapd.conf echo "channel=7" >>/etc/hostapd/hostapd.conf echo "macaddr_acl=0" >>/etc/hostapd/hostapd.conf echo "auth_algs=1" >>/etc/hostapd/hostapd.conf echo "ignore_broadcast_ssid=0" >>/etc/hostapd/hostapd.conf echo "wpa=2" >>/etc/hostapd/hostapd.conf echo "wpa_passphrase=$wappass" >>/etc/hostapd/hostapd.conf echo "wpa_key_mgmt=WPA-PSK" >>/etc/hostapd/hostapd.conf echo "wpa_pairwise=TKIP" >>/etc/hostapd/hostapd.conf echo "rsn_pairwise=CCMP" >>/etc/hostapd/hostapd.conf if dpkg -l|grep webmin >/dev/null 2>&1 then wget -c http://github.com/pjz/webmin-modules/releases/download/v1.0/hostap.wbm.gz gzip -d hostap.wbm.gz /usr/share/webmin/install-module.pl hostap.wbm fi echo "" echo "" } function config_NetworkManager() { echo "Configuring as wireless access point using NetworkManager." rfkill unblock wlan get_ap_params # Clean up a possible failed previous attempt nmcli con del piwifi-hotspot >/dev/null 2>&1 nmcli con del piwifi-ethernet >/dev/null 2>&1 nmcli con del piwifi-bridge >/dev/null 2>&1 # Save network system type in config file sed -i 's|'network_system=.*'|'network_system="\"NetworkManager\""'|' /etc/piwifiap/piwifiap.conf # create bridge interface nmcli con add type bridge con-name piwifi-bridge ifname bridge0 # add ethernet to bridge nmcli con add type ethernet slave-type bridge con-name piwifi-ethernet ifname eth0 master bridge0 # create access point nmcli con add type wifi ifname wlan0 mode ap con-name piwifi-hotspot ssid $wapssid nmcli con modify piwifi-hotspot wifi-sec.key-mgmt wpa-psk nmcli con modify piwifi-hotspot 802-11-wireless.band bg nmcli con modify piwifi-hotspot 802-11-wireless-security.pmf 1 # add wifi to bridge nmcli con modify piwifi-hotspot master bridge0 slave-type bridge # activate bridge nmcli con up piwifi-bridge # activite wifi nmcli con up piwifi-hotspot passwd-file /etc/piwifiap/piwifiap.secret } current_user=$(whoami) if [[ "$current_user" != "root" ]] then echo "You must have root privileges to run this setup." echo "Try 'sudo $0'" exit 1 fi echo "" echo "" echo "If this system connects to a network using ethernet, it can be configured" echo "as a wireless access point for other systems. Would you like to configure" echo -n "this system as an access point? [y/N]: " read wapconf if [[ "$wapconf" == "Y" || "$wapconf" == "y" ]] then # Determine if we are using NetworkManager or systemd-networkd echo "" echo "Copying files..." chmod +x apsetup/usr/local/bin/wap-* cp -R apsetup/usr/local/bin/* /usr/local/bin/ cp -R apsetup/etc/* /etc/ chown -R root:root /etc/piwifiap chmod 600 /etc/piwifiap/* if systemctl status dhcpcd.service|grep -q "Active: active (running)" then config_systemd-networkd elif systemctl status NetworkManager.service|grep -q "Active: active (running)" then config_NetworkManager else echo "Unable to determine what type of network configuration (systemd-networkd" echo "or NetworkManager) your system uses. Automatic setup cannot continue." exit 1 fi echo "Wireless access point setup is complete. It will be" echo "automatically enabled after reboot. To change the SSID or" echo "passphrase in the future, run:" echo " sudo wap-setssid" echo "or:" echo " sudo wap-setpassphrase" echo "at a command prompt." echo "" echo "To disable the access point altogether in the future, run:" echo " sudo wap-disable" echo "at a command prompt and reboot. To re-enable it, run:" echo " sudo wap-enable" echo "at a command prompt and reboot." echo "" echo "The system must be rebooted for the configuration to take effect." echo "" read -p "Would you like to reboot now? [Y/n]: " -r rebootok case "$rebootok" in "y" | "Y" | "") reboot ;; *) echo "You may continue to use the system, but the access point will not be" echo "functional until you reboot." exit 0 ;; esac else exit 2 fi