mirror of
https://github.com/kernelkit/infix.git
synced 2026-08-02 05:43:02 +02:00
@@ -7,3 +7,4 @@ include::mdns_allow_deny/Readme.adoc[]
|
||||
|
||||
include::services_basic/Readme.adoc[]
|
||||
|
||||
include::ssh_server_config/Readme.adoc[]
|
||||
|
||||
@@ -9,3 +9,6 @@
|
||||
|
||||
- name: mdns_allow_deny
|
||||
case: mdns_allow_deny/test.py
|
||||
|
||||
- name: ssh_server_config
|
||||
case: ssh_server_config/test.py
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
=== SSH server configuration
|
||||
==== Description
|
||||
Test SSH server functionality with pre-defined key pair:
|
||||
1. Enable/Disable SSH service.
|
||||
2. Configure listen address and port.
|
||||
3. Validate connectivity using static key pair.
|
||||
|
||||
==== Topology
|
||||
ifdef::topdoc[]
|
||||
image::../../test/case/infix_services/ssh_server_config/topology.svg[SSH server configuration topology]
|
||||
endif::topdoc[]
|
||||
ifndef::topdoc[]
|
||||
ifdef::testgroup[]
|
||||
image::ssh_server_config/topology.svg[SSH server configuration topology]
|
||||
endif::testgroup[]
|
||||
ifndef::testgroup[]
|
||||
image::topology.svg[SSH server configuration topology]
|
||||
endif::testgroup[]
|
||||
endif::topdoc[]
|
||||
==== Test sequence
|
||||
. Setup topology and attach to the target
|
||||
. Configure SSH server
|
||||
. Verify SSH public keys
|
||||
. Verify it is not possible to access SSH on other IP address
|
||||
. Disable SSH server
|
||||
|
||||
|
||||
<<<
|
||||
|
||||
+141
@@ -0,0 +1,141 @@
|
||||
#!/usr/bin/env python3
|
||||
"""
|
||||
SSH server configuration
|
||||
|
||||
Test SSH server functionality with pre-defined key pair:
|
||||
1. Enable/Disable SSH service.
|
||||
2. Configure listen address and port.
|
||||
3. Validate connectivity using static key pair.
|
||||
"""
|
||||
|
||||
import subprocess
|
||||
import infamy
|
||||
|
||||
PRIVATE_KEY = "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCtzyoT8/23hSyo7trLaqc6Auj5jvwhhCxUh8WIyfd5G/R9R+/wFEtGo6c6h75/GFCotFCQYvLlqHkrI0QiLYCPo0Rcxzfpy8TZGYjlyD8aYTYeXR2Oow6cjHE3ajQEEPbr5eiV/NBezg00SrCazDN4VHEXcjhl4egaKxDyG1yi98kQISY0+ehNjR/CKOBvOxHqB0N7gUnasbBiiN/iCCkCuDFKnBM6cYrUAvwP/aj+f9dq4lImJ6YpHaSjFKIa2ZFmOi20X0cb0AS1cshjSU2qf9eS2nysbmlC50X8HL9gaIeVInsWTLxEHTrd2gyBCTPO3X6oLJWW7HoB+yA9wp6xAgMBAAECggEACDNXrsaSrFmfFm7jmZikAHmR7LFlfb7W2RupUyeFUrxiDBWscVFBznjK+3jbYPOAnb8ZNIDIqVOKOQHyVWL8d3p6b56yKYik1mHtKrtIl+npg+P8kKXqmvII5vaOsvjqb42izE3X9nsmFhcmjz0uegFQ7yxjUxJGMVLiGyw1khZHFLxAcCzwN2qnxni7MjU2d+ZAtNd4ilSjXZ46Q/6+CyrhoTDUhc+5iqCgXU2wtYWrnvEhCBFd3AYh1vWZuh1TxMgnsfYePk5fHM1AG10XUvI5jOjSkSN+AlJxuXeUSeLyUV4hekem/j/UT3KwVPAiEsBil4KWyneiildXxU5MaQKBgQDm1667T06I/ty6/KZSdfm4EpDKylHohdN8Vr0MfgZSzZgc3bNNMQxAXhGdTIi2keIpitoF+/vLiMhxa9q692XY85eKSOC0Lvv5IRUC9/fUtoKrESOoxwX8SJ3bHj/Xel7Ye0WOXVJcO1/PXO0KFgs2YDRdmQKMFNKS/CdK+2TuCQKBgQDAwEzQ7B3cRYp4R2s230wpSSsPkiJXDQLno82S8K2/vLuWnlwIL3A1833l7PDfp5APABU3EVpQ7EYE6usnO1/HDSZ208uiprx6LIbX0gZVoRnPOKFwRVD7zrYo1n11Lydg8OgKtey5GsruPRbLtAw3/ugayUDCUExXmYlFQLRVaQKBgG+NTrzpiDQfpR8fNGio5jITlrDIsGhDM33klJrS089z1swsPpdQ2nDIhI6VC4PeX4JfvRgjOvySbvqQejTblPYQUOzcZunrwowTdonmtnauc9qi/65x7uyJUu8uYP+J/Qd0Gpq/citr7dLRPyMen/B48RVB+b8j2NZ6z6ombhGxAoGAY2OE+IGX0Bnnkae55/xyKCO7WXcPz/U8lzbGbMs/vEtUKxETAYF8icU5GNL5TUn4pVN0nQWMnYeHf0em437hHyFvwPvq177EFvdYvHZmn8bHKSvZSqvjW0Q2d45J+J/M3Va7P7KZEsV2+Ct10qnPVxxQkGdPxiJjixP3TUdU9WkCgYEAtHa4cwsbgy0HWtNT2smc80jLGFfsX8+/MtgTVdx6zaTybl50hJeVG4kW+7Fvstr78iVl31qPWx14MjoXKTEeVMo6ulrEijnbCx6DgkOwq+EOUvZn0W7ly4RhDDA9W8qdBIAzAGumkCx4456Un3z8wbIVgSZB52IELCBKpbyhSWE="
|
||||
|
||||
PUBLIC_KEY = "MIIBCgKCAQEArc8qE/P9t4UsqO7ay2qnOgLo+Y78IYQsVIfFiMn3eRv0fUfv8BRLRqOnOoe+fxhQqLRQkGLy5ah5KyNEIi2Aj6NEXMc36cvE2RmI5cg/GmE2Hl0djqMOnIxxN2o0BBD26+XolfzQXs4NNEqwmswzeFRxF3I4ZeHoGisQ8htcovfJECEmNPnoTY0fwijgbzsR6gdDe4FJ2rGwYojf4ggpArgxSpwTOnGK1AL8D/2o/n/XauJSJiemKR2koxSiGtmRZjottF9HG9AEtXLIY0lNqn/Xktp8rG5pQudF/By/YGiHlSJ7Fky8RB063doMgQkzzt1+qCyVlux6AfsgPcKesQIDAQAB"
|
||||
|
||||
SSH_RSA_PUBLIC_KEY="AAAAB3NzaC1yc2EAAAADAQABAAABAQCtzyoT8/23hSyo7trLaqc6Auj5jvwhhCxUh8WIyfd5G/R9R+/wFEtGo6c6h75/GFCotFCQYvLlqHkrI0QiLYCPo0Rcxzfpy8TZGYjlyD8aYTYeXR2Oow6cjHE3ajQEEPbr5eiV/NBezg00SrCazDN4VHEXcjhl4egaKxDyG1yi98kQISY0+ehNjR/CKOBvOxHqB0N7gUnasbBiiN/iCCkCuDFKnBM6cYrUAvwP/aj+f9dq4lImJ6YpHaSjFKIa2ZFmOi20X0cb0AS1cshjSU2qf9eS2nysbmlC50X8HL9gaIeVInsWTLxEHTrd2gyBCTPO3X6oLJWW7HoB+yA9wp6x"
|
||||
|
||||
with infamy.Test() as test:
|
||||
with test.step("Setup topology and attach to the target"):
|
||||
env = infamy.Env()
|
||||
target = env.attach("target", "mgmt")
|
||||
|
||||
_, data1 = env.ltop.xlate("target", "data1")
|
||||
_, data2 = env.ltop.xlate("target", "data2")
|
||||
|
||||
with test.step("Configure SSH server"):
|
||||
SSH_PORT_1 = 777
|
||||
SSH_ADDRESS_1 = "77.77.77.77"
|
||||
SSH_ADDRESS_2 = "88.88.88.88"
|
||||
PREFIX_LENGTH = 24
|
||||
|
||||
# Disable SSH before remove hostkey to pass YANG-validation.
|
||||
target.put_config_dicts({"infix-services": {
|
||||
"ssh": {
|
||||
"enabled": False
|
||||
}
|
||||
}})
|
||||
target.delete_xpath("/infix-services:ssh/hostkey[name()='genkey']")
|
||||
target.put_config_dicts({
|
||||
"ietf-keystore": {
|
||||
"keystore": {
|
||||
"asymmetric-keys": {
|
||||
"asymmetric-key": [
|
||||
{
|
||||
"name": "test-host-key",
|
||||
"public-key-format": "ietf-crypto-types:ssh-public-key-format",
|
||||
"public-key": PUBLIC_KEY,
|
||||
"private-key-format": "ietf-crypto-types:rsa-private-key-format",
|
||||
"cleartext-private-key": PRIVATE_KEY
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
},
|
||||
"ietf-interfaces": {
|
||||
"interfaces": {
|
||||
"interface": [
|
||||
{
|
||||
"name": data1,
|
||||
"ipv4": {
|
||||
"address": [
|
||||
{
|
||||
"ip": SSH_ADDRESS_1,
|
||||
"prefix-length": PREFIX_LENGTH
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": data2,
|
||||
"ipv4": {
|
||||
"address": [
|
||||
{
|
||||
"ip": SSH_ADDRESS_2,
|
||||
"prefix-length": PREFIX_LENGTH
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
"infix-services": {
|
||||
"ssh": {
|
||||
"enabled": True,
|
||||
"hostkey": [
|
||||
"test-host-key"
|
||||
],
|
||||
"listen": [
|
||||
{
|
||||
"name": "test-listener-1",
|
||||
"address": SSH_ADDRESS_1,
|
||||
"port": SSH_PORT_1
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
})
|
||||
|
||||
with test.step("Verify SSH public keys"):
|
||||
_, hport1 = env.ltop.xlate("host", "data1")
|
||||
_, hport2 = env.ltop.xlate("host", "data2")
|
||||
|
||||
with infamy.IsolatedMacVlan(hport1) as ns77:
|
||||
ns77.addip("77.77.77.70", prefix_length=24)
|
||||
ns77.must_reach(SSH_ADDRESS_1)
|
||||
ssh_scan_result = ns77.runsh(f"ssh-keyscan -p {SSH_PORT_1} {SSH_ADDRESS_1}")
|
||||
lines = [
|
||||
line for line in ssh_scan_result.stdout.splitlines()
|
||||
if line.strip().startswith(f"[{SSH_ADDRESS_1}]:{SSH_PORT_1}")
|
||||
]
|
||||
assert len(lines) == 1, f"Unexpected ssh-keyscan output: {ssh_scan_result.stdout}"
|
||||
target_public_key = lines[0].split()[2]
|
||||
|
||||
assert target_public_key.strip() == SSH_RSA_PUBLIC_KEY.strip(), "Public key mismatch"
|
||||
|
||||
print("Public key verified successfully.")
|
||||
|
||||
with test.step("Verify it is not possible to access SSH on other IP address"):
|
||||
with infamy.IsolatedMacVlan(hport2) as ns88:
|
||||
ns88.addip("88.88.88.80", prefix_length=24)
|
||||
ns88.must_reach(SSH_ADDRESS_2)
|
||||
|
||||
assert ns88.runsh(f"ssh-keyscan -p {SSH_PORT_1} {SSH_ADDRESS_2}").returncode == 1, "SSH is accessable on wrong interface"
|
||||
|
||||
with test.step("Disable SSH server"):
|
||||
target.put_config_dict("infix-services", {
|
||||
"ssh": {
|
||||
"enabled": False
|
||||
}
|
||||
})
|
||||
assert(ns77.run(
|
||||
f"ssh-keyscan -p {SSH_PORT_1} {SSH_ADDRESS_1}",
|
||||
shell=True,
|
||||
text=True,
|
||||
stdout=subprocess.PIPE,
|
||||
).returncode == 1)
|
||||
|
||||
test.succeed()
|
||||
@@ -0,0 +1,24 @@
|
||||
graph "1x3" {
|
||||
layout="neato";
|
||||
overlap="false";
|
||||
esep="+80";
|
||||
|
||||
node [shape=record, fontname="DejaVu Sans Mono, Book"];
|
||||
edge [color="cornflowerblue", penwidth="2", fontname="DejaVu Serif, Book"];
|
||||
|
||||
host [
|
||||
label="host | { <mgmt> mgmt | <data1> data1 | <data2> data2 }",
|
||||
pos="0,12!",
|
||||
kind="controller",
|
||||
];
|
||||
|
||||
target [
|
||||
label="{ <mgmt> mgmt | <data1> data1 | <data2> data2 } | target",
|
||||
pos="10,12!",
|
||||
kind="infix",
|
||||
];
|
||||
|
||||
host:mgmt -- target:mgmt [kind=mgmt, color="lightgray"]
|
||||
host:data1 -- target:data1 [color="black"]
|
||||
host:data2 -- target:data2 [color="black"]
|
||||
}
|
||||
@@ -0,0 +1,51 @@
|
||||
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
|
||||
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN"
|
||||
"http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
|
||||
|
||||
<!-- Title: 1x3 Pages: 1 -->
|
||||
<svg width="440pt" height="78pt"
|
||||
viewBox="0.00 0.00 440.03 78.00" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink">
|
||||
<g id="graph0" class="graph" transform="scale(1 1) rotate(0) translate(4 74)">
|
||||
<title>1x3</title>
|
||||
<polygon fill="white" stroke="transparent" points="-4,4 -4,-74 436.03,-74 436.03,4 -4,4"/>
|
||||
<!-- host -->
|
||||
<g id="node1" class="node">
|
||||
<title>host</title>
|
||||
<polygon fill="none" stroke="black" points="0,-0.5 0,-69.5 108,-69.5 108,-0.5 0,-0.5"/>
|
||||
<text text-anchor="middle" x="25" y="-31.3" font-family="DejaVu Sans Mono, Book" font-size="14.00">host</text>
|
||||
<polyline fill="none" stroke="black" points="50,-0.5 50,-69.5 "/>
|
||||
<text text-anchor="middle" x="79" y="-54.3" font-family="DejaVu Sans Mono, Book" font-size="14.00">mgmt</text>
|
||||
<polyline fill="none" stroke="black" points="50,-46.5 108,-46.5 "/>
|
||||
<text text-anchor="middle" x="79" y="-31.3" font-family="DejaVu Sans Mono, Book" font-size="14.00">data1</text>
|
||||
<polyline fill="none" stroke="black" points="50,-23.5 108,-23.5 "/>
|
||||
<text text-anchor="middle" x="79" y="-8.3" font-family="DejaVu Sans Mono, Book" font-size="14.00">data2</text>
|
||||
</g>
|
||||
<!-- target -->
|
||||
<g id="node2" class="node">
|
||||
<title>target</title>
|
||||
<polygon fill="none" stroke="black" points="308.03,-0.5 308.03,-69.5 432.03,-69.5 432.03,-0.5 308.03,-0.5"/>
|
||||
<text text-anchor="middle" x="337.03" y="-54.3" font-family="DejaVu Sans Mono, Book" font-size="14.00">mgmt</text>
|
||||
<polyline fill="none" stroke="black" points="308.03,-46.5 366.03,-46.5 "/>
|
||||
<text text-anchor="middle" x="337.03" y="-31.3" font-family="DejaVu Sans Mono, Book" font-size="14.00">data1</text>
|
||||
<polyline fill="none" stroke="black" points="308.03,-23.5 366.03,-23.5 "/>
|
||||
<text text-anchor="middle" x="337.03" y="-8.3" font-family="DejaVu Sans Mono, Book" font-size="14.00">data2</text>
|
||||
<polyline fill="none" stroke="black" points="366.03,-0.5 366.03,-69.5 "/>
|
||||
<text text-anchor="middle" x="399.03" y="-31.3" font-family="DejaVu Sans Mono, Book" font-size="14.00">target</text>
|
||||
</g>
|
||||
<!-- host--target -->
|
||||
<g id="edge1" class="edge">
|
||||
<title>host:mgmt--target:mgmt</title>
|
||||
<path fill="none" stroke="lightgray" stroke-width="2" d="M108,-58C108,-58 308.03,-58 308.03,-58"/>
|
||||
</g>
|
||||
<!-- host--target -->
|
||||
<g id="edge2" class="edge">
|
||||
<title>host:data1--target:data1</title>
|
||||
<path fill="none" stroke="black" stroke-width="2" d="M108,-35C108,-35 308.03,-35 308.03,-35"/>
|
||||
</g>
|
||||
<!-- host--target -->
|
||||
<g id="edge3" class="edge">
|
||||
<title>host:data2--target:data2</title>
|
||||
<path fill="none" stroke="black" stroke-width="2" d="M108,-12C108,-12 308.03,-12 308.03,-12"/>
|
||||
</g>
|
||||
</g>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 2.8 KiB |
Reference in New Issue
Block a user