%PDF- <> %âãÏÓ endobj 2 0 obj <> endobj 3 0 obj <>/ExtGState<>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI] >>/Annots[ 28 0 R 29 0 R] /MediaBox[ 0 0 595.5 842.25] /Contents 4 0 R/Group<>/Tabs/S>> endobj ºaâÚÎΞ-ÌE1ÍØÄ÷{òò2ÿ ÛÖ^ÔÀá TÎ{¦?§®¥kuµùÕ5sLOšuY>endobj 2 0 obj<>endobj 2 0 obj<>endobj 2 0 obj<>endobj 2 0 obj<> endobj 2 0 obj<>endobj 2 0 obj<>es 3 0 R>> endobj 2 0 obj<> ox[ 0.000000 0.000000 609.600000 935.600000]/Fi endobj 3 0 obj<> endobj 7 1 obj<>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI]>>/Subtype/Form>> stream
# Copyright (C) 2016 Canonical Ltd. # Copyright (C) 2016 VMware INC. # # Author: Maitreyee Saikia <msaikia@vmware.com> # # This file is part of cloud-init. See LICENSE file for license information. import logging import os from cloudinit import subp, util LOG = logging.getLogger(__name__) class PasswordConfigurator: """ Class for changing configurations related to passwords in a VM. Includes setting and expiring passwords. """ def configure(self, passwd, resetPasswd, distro): """ Main method to perform all functionalities based on configuration file inputs. @param passwd: encoded admin password. @param resetPasswd: boolean to determine if password needs to be reset. @return cfg: dict to be used by cloud-init set_passwd code. """ LOG.info("Starting password configuration") if passwd: passwd = util.b64d(passwd) allRootUsers = [] for line in open("/etc/passwd", "r"): if line.split(":")[2] == "0": allRootUsers.append(line.split(":")[0]) # read shadow file and check for each user, if its uid0 or root. uidUsersList = [] for line in open("/etc/shadow", "r"): user = line.split(":")[0] if user in allRootUsers: uidUsersList.append(user) if passwd: LOG.info("Setting admin password") distro.set_passwd("root", passwd) if resetPasswd: self.reset_password(uidUsersList) LOG.info("Configure Password completed!") def reset_password(self, uidUserList): """ Method to reset password. Use passwd --expire command. Use chage if not succeeded using passwd command. Log failure message otherwise. @param: list of users for which to expire password. """ LOG.info("Expiring password.") for user in uidUserList: try: subp.subp(["passwd", "--expire", user]) except subp.ProcessExecutionError as e: if os.path.exists("/usr/bin/chage"): subp.subp(["chage", "-d", "0", user]) else: LOG.warning( "Failed to expire password for %s with error: %s", user, e, ) # vi: ts=4 expandtab