Files
PiWifiAP/ap-setup.sh

199 lines
6.8 KiB
Bash
Executable File

#!/bin/bash
# ap-setup.sh
# OpenDRS Online Discrepancy Reporting System
# Copyright (C) 2022 Rod Wright
# SPDX-License-Identifier: GPL-2.0
# Wireless Access Point Raspberry Pi Setup
function get_ap_params() {
echo ""
wapssidok="no"
while [[ "$wapssidok" == "no" ]]
do
echo "This access point will need an SSID. This is what will appear"
echo "as the name of this terminal when other devices connect."
echo -n "Please enter the desired SSID for this access point: "
read wapssid
if [[ "$wapssid" = "" ]]
then
echo "SSID cannot be blank. Try again."
else
wapssidok="yes"
fi
done
wappassok="no"
while [[ "$wappassok" == "no" ]]
do
echo "You will need to set a passphrase for this access point. It should"
echo "be at least 8 characters in length and cannot be blank."
echo -n "Please enter the desired passphrase for this access point: "
read wappass
wappasslen=$(echo -n $wappass | wc -m)
if [[ "$wappass" == "" || $wappasslen -lt 8 ]]
then
echo "Passphrase doesn't satisfy requirements above. Try again."
else
wappassok="yes"
fi
done
# Save parameters in config file
sed -i 's|'wapssid=.*'|'wapssid="\'$wapssid\'"'|' /etc/piwifiap/piwifiap.conf
sed -i 's|'wappass=.*'|'wappass="\'$wappass\'"'|' /etc/piwifiap/piwifiap.conf
sed -i 's|'802-11-wireless-security.psk:.*'|'802-11-wireless-security.psk:$wappass'|' /etc/piwifiap/piwifiap.secret
}
function config_systemd-networkd() {
echo "Configuring as wireless access point using systemd-networkd."
get_ap_params
# Save network system type in config file
sed -i 's,'network_system=.*','network_system="\"systemd-networkd\""',' /etc/piwifiap/piwifiap.conf
apt install hostapd
systemctl unmask hostapd
systemctl enable hostapd
echo "[NetDev]" >/etc/systemd/network/bridge-br0.netdev
echo "Name=br0" >>/etc/systemd/network/bridge-br0.netdev
echo "Kind=bridge" >>/etc/systemd/network/bridge-br0.netdev
echo "[Match]" >/etc/systemd/network/br0-member-eth0.network
echo "Name=eth0" >>/etc/systemd/network/br0-member-eth0.network
echo "" >>/etc/systemd/network/br0-member-eth0.network
echo "[Network]" >>/etc/systemd/network/br0-member-eth0.network
echo "Bridge=br0" >>/etc/systemd/network/br0-member-eth0.network
systemctl enable systemd-networkd
mv /etc/dhcpcd.conf /etc/dhcpcd.conf.old
echo "denyinterfaces wlan0 eth0" >/etc/dhcpcd.conf
cat /etc/dhcpcd.conf.old >>/etc/dhcpcd.conf
echo "interface br0" >>/etc/dhcpcd.conf
rfkill unblock wlan
echo "country_code=US" >/etc/hostapd/hostapd.conf
echo "interface=wlan0" >>/etc/hostapd/hostapd.conf
echo "bridge=br0" >>/etc/hostapd/hostapd.conf
echo "ssid=$wapssid" >>/etc/hostapd/hostapd.conf
echo "hw_mode=g" >>/etc/hostapd/hostapd.conf
echo "channel=7" >>/etc/hostapd/hostapd.conf
echo "macaddr_acl=0" >>/etc/hostapd/hostapd.conf
echo "auth_algs=1" >>/etc/hostapd/hostapd.conf
echo "ignore_broadcast_ssid=0" >>/etc/hostapd/hostapd.conf
echo "wpa=2" >>/etc/hostapd/hostapd.conf
echo "wpa_passphrase=$wappass" >>/etc/hostapd/hostapd.conf
echo "wpa_key_mgmt=WPA-PSK" >>/etc/hostapd/hostapd.conf
echo "wpa_pairwise=TKIP" >>/etc/hostapd/hostapd.conf
echo "rsn_pairwise=CCMP" >>/etc/hostapd/hostapd.conf
if dpkg -l|grep webmin >/dev/null 2>&1
then
wget -c http://github.com/pjz/webmin-modules/releases/download/v1.0/hostap.wbm.gz
gzip -d hostap.wbm.gz
/usr/share/webmin/install-module.pl hostap.wbm
fi
echo ""
echo ""
}
function config_NetworkManager() {
echo "Configuring as wireless access point using NetworkManager."
rfkill unblock wlan
get_ap_params
# Clean up a possible failed previous attempt
nmcli con del piwifi-hotspot >/dev/null 2>&1
nmcli con del piwifi-ethernet >/dev/null 2>&1
nmcli con del piwifi-bridge >/dev/null 2>&1
# Save network system type in config file
sed -i 's|'network_system=.*'|'network_system="\"NetworkManager\""'|' /etc/piwifiap/piwifiap.conf
# create bridge interface
nmcli con add type bridge con-name piwifi-bridge ifname bridge0
# add ethernet to bridge
nmcli con add type ethernet slave-type bridge con-name piwifi-ethernet ifname eth0 master bridge0
# create access point
nmcli con add type wifi ifname wlan0 mode ap con-name piwifi-hotspot ssid $wapssid
nmcli con modify piwifi-hotspot wifi-sec.key-mgmt wpa-psk
nmcli con modify piwifi-hotspot 802-11-wireless.band bg
# disable protected management frames for wpa_supplicant bug in trixie
nmcli con modify piwifi-hotspot 802-11-wireless-security.pmf 1
# add wifi to bridge
nmcli con modify piwifi-hotspot master bridge0 slave-type bridge
# activate bridge
nmcli con up piwifi-bridge
# activite wifi
nmcli con up piwifi-hotspot passwd-file /etc/piwifiap/piwifiap.secret
}
current_user=$(whoami)
if [[ "$current_user" != "root" ]]
then
echo "You must have root privileges to run this setup."
echo "Try 'sudo $0'"
exit 1
fi
echo ""
echo ""
echo "If this system connects to a network using ethernet, it can be configured"
echo "as a wireless access point for other systems. Would you like to configure"
echo -n "this system as an access point? [y/N]: "
read wapconf
if [[ "$wapconf" == "Y" || "$wapconf" == "y" ]]
then
# Determine if we are using NetworkManager or systemd-networkd
echo ""
echo "Copying files..."
chmod +x apsetup/usr/local/bin/wap-*
cp -R apsetup/usr/local/bin/* /usr/local/bin/
cp -R apsetup/etc/* /etc/
chown -R root:root /etc/piwifiap
chmod 600 /etc/piwifiap/*
if systemctl status dhcpcd.service|grep -q "Active: active (running)"
then
config_systemd-networkd
elif systemctl status NetworkManager.service|grep -q "Active: active (running)"
then
config_NetworkManager
else
echo "Unable to determine what type of network configuration (systemd-networkd"
echo "or NetworkManager) your system uses. Automatic setup cannot continue."
exit 1
fi
echo "Wireless access point setup is complete. It will be"
echo "automatically enabled after reboot. To change the SSID or"
echo "passphrase in the future, run:"
echo " sudo wap-setssid"
echo "or:"
echo " sudo wap-setpassphrase"
echo "at a command prompt."
echo ""
echo "To disable the access point altogether in the future, run:"
echo " sudo wap-disable"
echo "at a command prompt and reboot. To re-enable it, run:"
echo " sudo wap-enable"
echo "at a command prompt and reboot."
echo ""
echo "The system must be rebooted for the configuration to take effect."
echo ""
read -p "Would you like to reboot now? [Y/n]: " -r rebootok
case "$rebootok" in
"y" | "Y" | "")
reboot
;;
*)
echo "You may continue to use the system, but the access point will not be"
echo "functional until you reboot."
exit 0
;;
esac
else
exit 2
fi