From 0c151515fe694991c11e8f8a22f84ba6503fec81 Mon Sep 17 00:00:00 2001 From: hwdsl2 Date: Thu, 28 Jun 2018 00:03:42 -0500 Subject: [PATCH] Improve upgrade scripts - Add note for users downgrading to 3.22 - Add check for Libreswan 3.25 (not yet supported) - Print Libreswan versions and improve message - Cleanup --- extras/vpnupgrade.sh | 72 +++++++++++++++++++++++++------------ extras/vpnupgrade_centos.sh | 72 +++++++++++++++++++++++++------------ 2 files changed, 98 insertions(+), 46 deletions(-) diff --git a/extras/vpnupgrade.sh b/extras/vpnupgrade.sh index 4adcb3d..6a3ffff 100644 --- a/extras/vpnupgrade.sh +++ b/extras/vpnupgrade.sh @@ -47,11 +47,16 @@ if [ -z "$SWAN_VER" ]; then exiterr "Libreswan version 'SWAN_VER' not specified." fi -if ! /usr/local/sbin/ipsec --version 2>/dev/null | grep -q "Libreswan"; then +if [ "$SWAN_VER" = "3.25" ]; then + exiterr "Libreswan 3.25 is not yet supported." +fi + +ipsec_ver="$(/usr/local/sbin/ipsec --version 2>/dev/null)" +if ! printf '%s' "$ipsec_ver" | grep -q "Libreswan"; then exiterr "This script requires Libreswan already installed." fi -if /usr/local/sbin/ipsec --version 2>/dev/null | grep -qF "$SWAN_VER"; then +if printf '%s' "$ipsec_ver" | grep -qF "$SWAN_VER"; then echo "You already have Libreswan version $SWAN_VER installed! " echo "If you continue, the same version will be re-installed." echo @@ -68,13 +73,23 @@ if /usr/local/sbin/ipsec --version 2>/dev/null | grep -qF "$SWAN_VER"; then esac fi +is_downgrade_to_322=0 +if [ "$SWAN_VER" = "3.22" ]; then + if printf '%s' "$ipsec_ver" | grep -qF -e "3.23" -e "3.25"; then + is_downgrade_to_322=1 + fi +fi + clear cat </dev/null | grep -q "Libreswan"; then +if [ "$SWAN_VER" = "3.25" ]; then + exiterr "Libreswan 3.25 is not yet supported." +fi + +ipsec_ver="$(/usr/local/sbin/ipsec --version 2>/dev/null)" +if ! printf '%s' "$ipsec_ver" | grep -q "Libreswan"; then exiterr "This script requires Libreswan already installed." fi -if /usr/local/sbin/ipsec --version 2>/dev/null | grep -qF "$SWAN_VER"; then +if printf '%s' "$ipsec_ver" | grep -qF "$SWAN_VER"; then echo "You already have Libreswan version $SWAN_VER installed! " echo "If you continue, the same version will be re-installed." echo @@ -59,13 +64,23 @@ if /usr/local/sbin/ipsec --version 2>/dev/null | grep -qF "$SWAN_VER"; then esac fi +is_downgrade_to_322=0 +if [ "$SWAN_VER" = "3.22" ]; then + if printf '%s' "$ipsec_ver" | grep -qF -e "3.23" -e "3.25"; then + is_downgrade_to_322=1 + fi +fi + clear cat <