forked from wazuh/wazuh-docker
Updated test of Docker images
This commit is contained in:
@@ -1,40 +0,0 @@
|
||||
##############################################################################
|
||||
# Downloading Cert Gen Tool
|
||||
##############################################################################
|
||||
# Variables for certificate generation
|
||||
CERT_TOOL="wazuh-certs-tool.sh"
|
||||
CERT_CONFIG_FILE="config.yml"
|
||||
CERT_DIR=/etc/wazuh/certs
|
||||
download_package() {
|
||||
local url=$1
|
||||
local package=$2
|
||||
if curl -fsL "$url" -o "$package"; then
|
||||
echo "Downloaded $package"
|
||||
return 0
|
||||
else
|
||||
echo "Error downloading $package from $url"
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
mkdir -p $CERT_DIR
|
||||
# Download the tool to create the certificates
|
||||
echo "Downloading the tool to create the certificates..."
|
||||
download_package "$wazuh_certs_tool" $CERT_TOOL
|
||||
# Download the config file for the certificate tool
|
||||
echo "Downloading the config file for the certificate tool..."
|
||||
download_package "$wazuh_config_yml" $CERT_CONFIG_FILE
|
||||
|
||||
# Modify the config file to set the IP to localhost
|
||||
sed -i 's/ ip:.*/ ip: "127.0.0.1"/' $CERT_CONFIG_FILE
|
||||
|
||||
chmod 700 "$CERT_CONFIG_FILE"
|
||||
# Create the certificates
|
||||
chmod 755 "$CERT_TOOL" && bash "$CERT_TOOL" -A
|
||||
|
||||
# Copy Wazuh manager certs
|
||||
cp -pr /wazuh-certificates/wazuh-1.pem ${CERT_DIR}/wazuh-1.pem
|
||||
cp -pr /wazuh-certificates/wazuh-1-key.pem ${CERT_DIR}/wazuh-1-key.pem
|
||||
cp -pr /wazuh-certificates/root-ca.key ${CERT_DIR}/root-ca.key
|
||||
cp -pr /wazuh-certificates/root-ca.pem ${CERT_DIR}/root-ca.pem
|
||||
cp -pr /wazuh-certificates/admin.pem ${CERT_DIR}/admin.pem
|
||||
cp -pr /wazuh-certificates/admin-key.pem ${CERT_DIR}/admin-key.pem
|
||||
@@ -6,6 +6,10 @@ source /permanent_data.env
|
||||
|
||||
WAZUH_INSTALL_PATH=/var/ossec
|
||||
WAZUH_CONFIG_MOUNT=/wazuh-config-mount
|
||||
CERT_DIR=/etc/wazuh/certs
|
||||
WAZUH_INDEXER_SSL_CA=$CERT_DIR/root-ca.pem
|
||||
WAZUH_INDEXER_SSL_CERTIFICATE=$CERT_DIR/wazuh.pem
|
||||
WAZUH_INDEXER_SSL_KEY=$CERT_DIR/wazuh-key.pem
|
||||
|
||||
##############################################################################
|
||||
# Aux functions
|
||||
@@ -194,6 +198,14 @@ if [[ -n "$WAZUH_INDEXER_HOSTS" ]]; then
|
||||
sed -i -e '/<indexer>/,/<\/indexer>/{ /<hosts>/,/<\/hosts>/{ /<hosts>/r '"$TMP_HOSTS" \
|
||||
-e 'd }}' "$OSSEC_CONF";
|
||||
rm -f "$TMP_HOSTS";
|
||||
|
||||
# --------------------------
|
||||
# Indexer SSL Configuration
|
||||
# --------------------------
|
||||
sed -i "/<indexer>/,/<\/indexer>/ s|<ca>.*</ca>|<ca>$WAZUH_INDEXER_SSL_CA</ca>|" "$OSSEC_CONF"
|
||||
sed -i "/<indexer>/,/<\/indexer>/ s|<certificate>.*</certificate>|<certificate>$WAZUH_INDEXER_SSL_CERTIFICATE</certificate>|" "$OSSEC_CONF"
|
||||
sed -i "/<indexer>/,/<\/indexer>/ s|<key>.*</key>|<key>$WAZUH_INDEXER_SSL_KEY</key>|" "$OSSEC_CONF"
|
||||
|
||||
fi
|
||||
|
||||
# --------------------------
|
||||
|
||||
Reference in New Issue
Block a user