doorstatus/setstatus.py

180 lines
6 KiB
Python
Raw Normal View History

#!/usr/bin/python3
# -*- coding: utf-8 -*-
# file: setstatus.py
# date: 26.07.2019
# email: berhsi@web.de
2020-07-09 20:12:49 +02:00
# Setstatus.py is part of doorstatus - a programm to deal with the
# krautspaces doorstatus.
# client, who connects to the statusserver at port 10001 to update the
# krautspace door status. If no status is given as argument, he reads from
# stdin until input is 0 or 1.
2020-09-04 19:58:23 +02:00
import os
import ssl
2020-07-09 20:12:49 +02:00
import socket
import logging
import configparser
from sys import exit, argv
2020-09-04 19:58:23 +02:00
def check_certs(certs):
'''
Check if certs readable.
'''
logging.debug('Check certificates')
for certfile in certs:
if os.access(certfile, os.R_OK) is False:
logging.error('Failed to read certificate: {}'.format(certfile))
return False
return True
def check_arguments(argv):
'''
Checks length and validity of command line argument vectors. If there is
no argument or argument is not valid, it returns None. Otherwise it
converts the string value into a byte value.
param 1: array of strings
return: None or byte value
'''
if len(argv) == 1:
byte_value = None
else:
if argv[1].strip() == '0' or argv[1].strip() == '1':
i = int(argv[1].strip())
2020-07-09 20:12:49 +02:00
logging.debug('Set value to {}'.format(i))
byte_value = bytes([i])
else:
byte_value = None
return byte_value
2020-09-04 19:58:23 +02:00
def log_config(config):
2020-07-09 20:12:49 +02:00
'''
Logs the config with level debug.
'''
logging.debug('Using config:')
for section in config.sections():
logging.debug('Section {}'.format(section))
for i in config[section]:
logging.debug(' {}: {}'.format(i, config[section][i]))
def main():
STATUS = None
RESPONSE = None
2020-09-04 19:58:23 +02:00
# basic configuration
loglevel = logging.WARNING
2020-07-09 20:12:49 +02:00
formatstring = '%(asctime)s: %(levelname)s: %(message)s'
logging.basicConfig(format=formatstring, level=loglevel)
default_config = {
'general': {
'timeout': 5.0,
'loglevel': 'warning'
},
'server': {
'host': 'localhost',
'port': 10001,
2020-09-04 19:58:23 +02:00
'cert': './certs/server-pub.pem',
'fqdn': 'kraut.space'
2020-07-09 20:12:49 +02:00
},
'client': {
2020-09-04 19:58:23 +02:00
'cert': './certs/client-pub.pem',
'key': './certs/client-key.pem'
2020-07-09 20:12:49 +02:00
}
}
2020-09-04 19:58:23 +02:00
# read config file
2020-07-09 20:12:49 +02:00
configfile = './setstatus.conf'
config = configparser.ConfigParser()
config.read_dict(default_config)
if not config.read(configfile):
logging.warning('Configuration file {} not found or not readable.'.format(
configfile))
logging.warning('Using default values.')
2020-09-04 19:58:23 +02:00
# set loglevel
2020-07-09 20:12:49 +02:00
logger = logging.getLogger()
2020-09-04 19:58:23 +02:00
if not config['general']['loglevel'].lower() in ('critical', 'error',
'warning', 'info',
'debug'):
2020-07-09 20:12:49 +02:00
logging.warning('Invalid loglevel %s given. Using default level %s.',
config['general']['loglevel'],
default_config['general']['loglevel'])
config.set('general', 'loglevel', default_config['general']['loglevel'])
logger.setLevel(config['general']['loglevel'].upper())
2020-09-04 19:58:23 +02:00
# log config if level is debug
if config['general']['loglevel'].lower() == 'debug':
log_config(config)
# check certificates are readable
certs = (config['server']['cert'],
config['client']['cert'],
config['client']['key'])
if check_certs(certs) is False:
sys.exit(1)
# check cli arguments
STATUS = check_arguments(argv)
2020-09-04 19:58:23 +02:00
if STATUS is None:
logging.error('No valid status given')
sys.exit(2)
2020-09-04 19:58:23 +02:00
# create ssl context
context = ssl.create_default_context(ssl.Purpose.SERVER_AUTH,
2020-07-09 20:12:49 +02:00
cafile=config['server']['cert'])
2020-09-04 19:58:23 +02:00
context.set_ciphers('EECDH+AESGCM') # only ciphers for tls 1.2 and 1.3
context.options |= getattr(ssl._ssl, 'OP_NO_COMPRESSION', 0)
2020-07-09 20:12:49 +02:00
context.load_cert_chain(certfile=config['client']['cert'],
keyfile=config['client']['key'])
logging.debug('SSL context created')
2020-09-04 19:58:23 +02:00
# create socket and send status bit
with socket.socket(socket.AF_INET, socket.SOCK_STREAM, 0) as mySocket:
2020-07-09 20:12:49 +02:00
logging.debug('Socket created')
try:
conn = context.wrap_socket(mySocket, server_side=False,
2020-07-09 20:12:49 +02:00
server_hostname=config['server']['fqdn'])
logging.debug('Connection wrapped with ssl.context')
except Exception as e:
logging.error('Context wrapper failed: {}'.format(e))
try:
conn.settimeout(float(config['general']['timeout']))
except Exception as e:
2020-07-09 20:12:49 +02:00
logging.debug('Failed to set timeout: {}'.format(e))
try:
2020-07-09 20:12:49 +02:00
conn.connect((config['server']['host'], int(config['server']['port'])))
except socket.timeout:
2020-09-04 19:58:23 +02:00
logging.error('Connection timeout')
except Exception as e:
2020-07-09 20:12:49 +02:00
logging.error('Connection failed: {}'.format(e))
2020-09-04 19:58:23 +02:00
exit(3)
2020-07-09 20:12:49 +02:00
logging.debug('Peer certificate commonName: {}'.format(
conn.getpeercert()['subject'][5][0][1]))
logging.debug('Peer certificate serialNumber: {}'.format(
conn.getpeercert()['serialNumber']))
try:
2020-07-09 20:12:49 +02:00
logging.debug('Send new status: {}'.format(STATUS))
conn.send(STATUS)
except Exception as e:
2020-07-09 20:12:49 +02:00
logging.error('Error: {}'.format(e))
2020-09-04 19:58:23 +02:00
exit(4)
try:
RESPONSE = conn.recv(1)
2020-07-09 20:12:49 +02:00
logging.debug('Server returns: {}'.format(RESPONSE))
if RESPONSE == STATUS:
2020-07-09 20:12:49 +02:00
logging.info('Status sucessfull updated')
else:
2020-07-09 20:12:49 +02:00
logging.error('Failed to update status')
logging.debug('Disconnect from server')
except Exception as e:
2020-07-09 20:12:49 +02:00
logging.error('Error: {}'.format(e))
2020-09-04 19:58:23 +02:00
exit(5)
if __name__ == '__main__':
main()