xref: /illumos-gate/usr/src/cmd/svc/milestone/net-init (revision db5ca0bda7f0c1698f5046285dec0f0dce9d3704)
17c478bd9Sstevel@tonic-gate#!/sbin/sh
27c478bd9Sstevel@tonic-gate#
37c478bd9Sstevel@tonic-gate# CDDL HEADER START
47c478bd9Sstevel@tonic-gate#
57c478bd9Sstevel@tonic-gate# The contents of this file are subject to the terms of the
66927f468Sdp# Common Development and Distribution License (the "License").
76927f468Sdp# You may not use this file except in compliance with the License.
87c478bd9Sstevel@tonic-gate#
97c478bd9Sstevel@tonic-gate# You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
107c478bd9Sstevel@tonic-gate# or http://www.opensolaris.org/os/licensing.
117c478bd9Sstevel@tonic-gate# See the License for the specific language governing permissions
127c478bd9Sstevel@tonic-gate# and limitations under the License.
137c478bd9Sstevel@tonic-gate#
147c478bd9Sstevel@tonic-gate# When distributing Covered Code, include this CDDL HEADER in each
157c478bd9Sstevel@tonic-gate# file and include the License file at usr/src/OPENSOLARIS.LICENSE.
167c478bd9Sstevel@tonic-gate# If applicable, add the following below this CDDL HEADER, with the
177c478bd9Sstevel@tonic-gate# fields enclosed by brackets "[]" replaced with your own identifying
187c478bd9Sstevel@tonic-gate# information: Portions Copyright [yyyy] [name of copyright owner]
197c478bd9Sstevel@tonic-gate#
207c478bd9Sstevel@tonic-gate# CDDL HEADER END
217c478bd9Sstevel@tonic-gate#
227c478bd9Sstevel@tonic-gate#
23f4b3ec61Sdh155122# Copyright 2007 Sun Microsystems, Inc.  All rights reserved.
247c478bd9Sstevel@tonic-gate# Use is subject to license terms.
257c478bd9Sstevel@tonic-gate#
267c478bd9Sstevel@tonic-gate# ident	"%Z%%M%	%I%	%E% SMI"
277c478bd9Sstevel@tonic-gate#
287c478bd9Sstevel@tonic-gate# This is the second phase of TCP/IP configuration.  The first part is
29a192e900Samaguire# run by the svc:/network/physical service and includes configuring the
30a192e900Samaguire# interfaces and setting the machine's hostname.  The svc:/network/initial
31a192e900Samaguire# service does all configuration that can be done before name services are
32a192e900Samaguire# started, bar configuring IP routing (this is carried out by the
33a192e900Samaguire# svc:/network/routing-setup service).  The final part, run by the
34a192e900Samaguire# svc:/network/service service,  does all configuration that may require
35a192e900Samaguire# name services.  This includes a final re-configuration of the
36a192e900Samaguire# interfaces.
377c478bd9Sstevel@tonic-gate#
387c478bd9Sstevel@tonic-gate
397c478bd9Sstevel@tonic-gate. /lib/svc/share/smf_include.sh
407c478bd9Sstevel@tonic-gate
417c478bd9Sstevel@tonic-gate#
42f4b3ec61Sdh155122# In a shared-IP zone we need this service to be up, but all of the work
437c478bd9Sstevel@tonic-gate# it tries to do is irrelevant (and will actually lead to the service
447c478bd9Sstevel@tonic-gate# failing if we try to do it), so just bail out.
45f4b3ec61Sdh155122# In the global zone and exclusive-IP zones we proceed.
467c478bd9Sstevel@tonic-gate#
47f4b3ec61Sdh155122smf_configure_ip || exit $SMF_EXIT_OK
486927f468Sdp
497c478bd9Sstevel@tonic-gate# Configure IPv6 Default Address Selection.
507c478bd9Sstevel@tonic-gateif [ -f /etc/inet/ipaddrsel.conf ]; then
517c478bd9Sstevel@tonic-gate	/usr/sbin/ipaddrsel -f /etc/inet/ipaddrsel.conf
527c478bd9Sstevel@tonic-gatefi
537c478bd9Sstevel@tonic-gate
547c478bd9Sstevel@tonic-gate#
557c478bd9Sstevel@tonic-gate# Now that /usr is mounted, see if in.mpathd needs to be started by firing it
567c478bd9Sstevel@tonic-gate# up in "adopt" mode; if there are no interfaces it needs to manage, it will
577c478bd9Sstevel@tonic-gate# automatically exit.  Note that it may already be running if we're not
587c478bd9Sstevel@tonic-gate# executing as part of system boot.
597c478bd9Sstevel@tonic-gate#
60f4b3ec61Sdh155122/usr/bin/pgrep -x -u 0 -z `smf_zonename` in.mpathd >/dev/null 2>&1 || \
61f4b3ec61Sdh155122    /usr/lib/inet/in.mpathd -a
627c478bd9Sstevel@tonic-gate
637c478bd9Sstevel@tonic-gate#
647c478bd9Sstevel@tonic-gate# Pass to the kernel the list of supported IPsec protocols and algorithms.
657c478bd9Sstevel@tonic-gate# This will not cause IPsec to be loaded.
667c478bd9Sstevel@tonic-gate#
677c478bd9Sstevel@tonic-gate/usr/sbin/ipsecalgs -s
687c478bd9Sstevel@tonic-gate
697c478bd9Sstevel@tonic-gate#
707c478bd9Sstevel@tonic-gate# Initialize IPsec only if ipsecinit.conf exists.  Otherwise, save the
717c478bd9Sstevel@tonic-gate# kernel memory that'll be consumed if IPsec is loaded.  See below for more
727c478bd9Sstevel@tonic-gate# IPsec-related commands.
737c478bd9Sstevel@tonic-gate#
747c478bd9Sstevel@tonic-gateif [ -f /etc/inet/ipsecinit.conf ] ; then
757c478bd9Sstevel@tonic-gate	/usr/sbin/ipsecconf -qa /etc/inet/ipsecinit.conf
767c478bd9Sstevel@tonic-gatefi
777c478bd9Sstevel@tonic-gate
787c478bd9Sstevel@tonic-gate#
797c478bd9Sstevel@tonic-gate# Set the RFC 1948 entropy, regardless of if I'm using it or not.  If present,
807c478bd9Sstevel@tonic-gate# use the encrypted root password as a source of entropy.  Otherwise,
817c478bd9Sstevel@tonic-gate# just use the pre-set (and hopefully difficult to guess) entropy that
827c478bd9Sstevel@tonic-gate# tcp used when it loaded.
837c478bd9Sstevel@tonic-gate#
847c478bd9Sstevel@tonic-gateencr=`/usr/bin/awk -F: '/^root:/ {print $2}' /etc/shadow`
857c478bd9Sstevel@tonic-gate[ -z "$encr" ] || /usr/sbin/ndd -set /dev/tcp tcp_1948_phrase $encr
867c478bd9Sstevel@tonic-gateunset encr
877c478bd9Sstevel@tonic-gate
887c478bd9Sstevel@tonic-gate#
897c478bd9Sstevel@tonic-gate# Get values for TCP_STRONG_ISS, ACCEPT6TO4RELAY and RELAY6TO4ADDR.
907c478bd9Sstevel@tonic-gate#
917c478bd9Sstevel@tonic-gate[ -f /etc/default/inetinit ] && . /etc/default/inetinit
927c478bd9Sstevel@tonic-gate
93*db5ca0bdSsangeeta# Set the SDP system Policy.  This needs to happen after basic
94*db5ca0bdSsangeeta# networking is up but before any networking services that might
95*db5ca0bdSsangeeta# want to use SDP are enabled
96*db5ca0bdSsangeetaif [ -f /usr/sbin/sdpadm -a -f /etc/sdp.conf ]; then
97*db5ca0bdSsangeeta	. /etc/sdp.conf
98*db5ca0bdSsangeeta	if [ "$sysenable" = "1" ]; then
99*db5ca0bdSsangeeta		/usr/sbin/sdpadm enable
100*db5ca0bdSsangeeta	fi
101*db5ca0bdSsangeetafi
102*db5ca0bdSsangeeta
1037c478bd9Sstevel@tonic-gate#
1047c478bd9Sstevel@tonic-gate# Set TCP ISS generation.  By default the ISS generation is
1057c478bd9Sstevel@tonic-gate# time + random()-delta.  This might not be strong enough for some users.
1067c478bd9Sstevel@tonic-gate# See /etc/default/inetinit for settings and further info on TCP_STRONG_ISS.
1077c478bd9Sstevel@tonic-gate# If not set, use TCP's internal default setting.
1087c478bd9Sstevel@tonic-gate#
1097c478bd9Sstevel@tonic-gateif [ $TCP_STRONG_ISS ]; then
1107c478bd9Sstevel@tonic-gate	/usr/sbin/ndd -set /dev/tcp tcp_strong_iss $TCP_STRONG_ISS
1117c478bd9Sstevel@tonic-gatefi
1127c478bd9Sstevel@tonic-gate
1137c478bd9Sstevel@tonic-gate#
1147c478bd9Sstevel@tonic-gate# In spite of global policy, there may be a need for IPsec because of
1157c478bd9Sstevel@tonic-gate# per-socket policy or tunnelled policy.  With that in mind, check for manual
1167c478bd9Sstevel@tonic-gate# keys in /etc/inet/secret/ipseckeys, or check for IKE configuration in
1177c478bd9Sstevel@tonic-gate# /etc/inet/ike/config.  Either of these will also load and initialize IPsec,
1187c478bd9Sstevel@tonic-gate# thereby consuming kernel memory.
1197c478bd9Sstevel@tonic-gate#
1207c478bd9Sstevel@tonic-gate
1217c478bd9Sstevel@tonic-gateif [ -f /etc/inet/secret/ipseckeys ] ; then
1227c478bd9Sstevel@tonic-gate	/usr/sbin/ipseckey -f /etc/inet/secret/ipseckeys
1237c478bd9Sstevel@tonic-gatefi
1247c478bd9Sstevel@tonic-gate
1257c478bd9Sstevel@tonic-gateif [ -f /etc/inet/ike/config ] ; then
1267c478bd9Sstevel@tonic-gate	/usr/lib/inet/in.iked
1277c478bd9Sstevel@tonic-gatefi
1287c478bd9Sstevel@tonic-gate
1297c478bd9Sstevel@tonic-gate#
1307c478bd9Sstevel@tonic-gate# Configure tunnels which were deferred by /lib/svc/method/net-physical
1317c478bd9Sstevel@tonic-gate# (the svc:/network/physical service) since it depends on the tunnel endpoints
1327c478bd9Sstevel@tonic-gate# being reachable i.e. routing must be running.
1337c478bd9Sstevel@tonic-gate#
1347c478bd9Sstevel@tonic-gate# WARNING: you may wish to turn OFF forwarding if you haven't already, because
1357c478bd9Sstevel@tonic-gate# of various possible security vulnerabilities when configuring tunnels for
1367c478bd9Sstevel@tonic-gate# Virtual Private Network (VPN) construction.
1377c478bd9Sstevel@tonic-gate#
1387c478bd9Sstevel@tonic-gate# Also, if names are used in the /etc/hostname.ip.tun* file, those names
1397c478bd9Sstevel@tonic-gate# have to be in either DNS (and DNS is used) or in /etc/hosts, because this
1407c478bd9Sstevel@tonic-gate# file is executed before NIS or NIS+ is started.
1417c478bd9Sstevel@tonic-gate#
1427c478bd9Sstevel@tonic-gate
1437c478bd9Sstevel@tonic-gate#
1447c478bd9Sstevel@tonic-gate# IPv4 tunnels
1457c478bd9Sstevel@tonic-gate# The second component of the name must be either "ip" or "ip6".
1467c478bd9Sstevel@tonic-gate#
1477c478bd9Sstevel@tonic-gateinterface_names="`/usr/bin/ls /etc/hostname.ip*.*[0-9] 2>/dev/null | \
1487c478bd9Sstevel@tonic-gate    /usr/bin/grep '/etc/hostname\.ip6\{0,1\}\.'`"
1497c478bd9Sstevel@tonic-gateif [ -n "$interface_names" ]; then
1507c478bd9Sstevel@tonic-gate	(
1517c478bd9Sstevel@tonic-gate		echo "configuring IPv4 tunnels:\c"
1527c478bd9Sstevel@tonic-gate		# Extract the part after the first '.'
1537c478bd9Sstevel@tonic-gate		set -- `for intr in $interface_names; do \
1547c478bd9Sstevel@tonic-gate		    /usr/bin/expr //$intr : '[^.]*\.\(.*\)$'; done`
1557c478bd9Sstevel@tonic-gate		while [ $# -ge 1 ]; do
1567c478bd9Sstevel@tonic-gate			# Skip empty files
1577c478bd9Sstevel@tonic-gate			if [ ! -s /etc/hostname\.$1 ]; then
1587c478bd9Sstevel@tonic-gate				shift
1597c478bd9Sstevel@tonic-gate				continue
1607c478bd9Sstevel@tonic-gate			fi
1617c478bd9Sstevel@tonic-gate			/usr/sbin/ifconfig $1 plumb
1627c478bd9Sstevel@tonic-gate			while read ifcmds; do
1637c478bd9Sstevel@tonic-gate				if [ -n "$ifcmds" ]; then
1647c478bd9Sstevel@tonic-gate					/usr/sbin/ifconfig $1 inet $ifcmds
1657c478bd9Sstevel@tonic-gate				fi
1667c478bd9Sstevel@tonic-gate			done </etc/hostname\.$1 >/dev/null
1677c478bd9Sstevel@tonic-gate			echo " $1\c"
1687c478bd9Sstevel@tonic-gate			shift
1697c478bd9Sstevel@tonic-gate		done
1707c478bd9Sstevel@tonic-gate		echo "."
1717c478bd9Sstevel@tonic-gate	)
1727c478bd9Sstevel@tonic-gatefi
1737c478bd9Sstevel@tonic-gate
1747c478bd9Sstevel@tonic-gate#
1757c478bd9Sstevel@tonic-gate# IPv6 Tunnels
1767c478bd9Sstevel@tonic-gate# The second component of the name must be either "ip" or "ip6".
1777c478bd9Sstevel@tonic-gate#
1787c478bd9Sstevel@tonic-gateinterface_names="`/usr/bin/ls /etc/hostname6.ip*.*[0-9] 2>/dev/null | \
1797c478bd9Sstevel@tonic-gate    /usr/bin/grep '/etc/hostname6\.ip6\{0,1\}\.'`"
1807c478bd9Sstevel@tonic-gateif [ -n "$interface_names" ]; then
1817c478bd9Sstevel@tonic-gate	(
1827c478bd9Sstevel@tonic-gate		echo "configuring IPv6 tunnels:\c"
1837c478bd9Sstevel@tonic-gate		# Extract the part after the first '.'
1847c478bd9Sstevel@tonic-gate		set -- `for intr in $interface_names; do \
1857c478bd9Sstevel@tonic-gate		    /usr/bin/expr //$intr : '[^.]*\.\(.*\)$'; done`
1867c478bd9Sstevel@tonic-gate		while [ $# -ge 1 ]; do
1877c478bd9Sstevel@tonic-gate			# Skip empty files
1887c478bd9Sstevel@tonic-gate			if [ ! -s /etc/hostname6\.$1 ]; then
1897c478bd9Sstevel@tonic-gate				shift
1907c478bd9Sstevel@tonic-gate				continue
1917c478bd9Sstevel@tonic-gate			fi
1927c478bd9Sstevel@tonic-gate			/usr/sbin/ifconfig $1 inet6 plumb
1937c478bd9Sstevel@tonic-gate			while read ifcmds; do
1947c478bd9Sstevel@tonic-gate				if [ -n "$ifcmds" ]; then
1957c478bd9Sstevel@tonic-gate					/usr/sbin/ifconfig $1 inet6 $ifcmds
1967c478bd9Sstevel@tonic-gate				fi
1977c478bd9Sstevel@tonic-gate			done </etc/hostname6\.$1 > /dev/null
1987c478bd9Sstevel@tonic-gate			echo " $1\c"
1997c478bd9Sstevel@tonic-gate			shift
2007c478bd9Sstevel@tonic-gate		done
2017c478bd9Sstevel@tonic-gate		echo "."
2027c478bd9Sstevel@tonic-gate	)
2037c478bd9Sstevel@tonic-gatefi
2047c478bd9Sstevel@tonic-gate
2057c478bd9Sstevel@tonic-gate# Clear exit status.
2066927f468Sdpexit $SMF_EXIT_OK
207