Module: Proxy::OpenSCAP

Extended by:
Log
Defined in:
lib/smart_proxy_openscap/openscap_version.rb,
lib/smart_proxy_openscap/openscap_exception.rb,
lib/smart_proxy_openscap/openscap_plugin.rb,
lib/smart_proxy_openscap/openscap_lib.rb,
lib/smart_proxy_openscap/openscap_api.rb,
lib/smart_proxy_openscap.rb

Defined Under Namespace

Classes: Api, FileNotFound, ForemanForwarder, OpenSCAPException, Plugin

Constant Summary collapse

VERSION =
'0.3.1'

Class Method Summary collapse

Class Method Details

.common_name(request) ⇒ Object

Raises:

  • (Proxy::Error::Unauthorized)


39
40
41
42
43
44
45
46
47
48
49
50
51
52
# File 'lib/smart_proxy_openscap/openscap_lib.rb', line 39

def self.common_name(request)
  client_cert = request.env['SSL_CLIENT_CERT']
  raise Proxy::Error::Unauthorized, "Client certificate required!" if client_cert.to_s.empty?

  begin
    client_cert = OpenSSL::X509::Certificate.new(client_cert)
  rescue OpenSSL::OpenSSLError => e
    raise Proxy::Error::Unauthorized, e.message
  end
  cn = client_cert.subject.to_a.detect { |name, value| name == 'CN' }
  cn = cn[1] unless cn.nil?
  raise Proxy::Error::Unauthorized, "Common Name not found in the certificate" unless cn
  return cn
end

.fetch_scap_content_xml(policy_id, policy_scap_file) ⇒ Object



87
88
89
90
91
92
93
94
95
96
# File 'lib/smart_proxy_openscap/openscap_lib.rb', line 87

def self.fetch_scap_content_xml(policy_id, policy_scap_file)
  foreman_request = Proxy::HttpRequest::ForemanRequest.new
  policy_content_path = "/api/v2/compliance/policies/#{policy_id}/content"
  req = foreman_request.request_factory.create_get(policy_content_path)
  response = foreman_request.send_request(req)
  unless response.is_a? Net::HTTPSuccess
    raise OpenSCAPException.new(response)
  end
  response.body
end

.get_policy_content(policy_id) ⇒ Object



21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
# File 'lib/smart_proxy_openscap/openscap_lib.rb', line 21

def self.get_policy_content(policy_id)
  policy_store_dir = File.join(Proxy::OpenSCAP::Plugin.settings.contentdir, policy_id.to_s)
  policy_scap_file = File.join(policy_store_dir, "#{policy_id}_scap_content.xml")
  begin
    FileUtils.mkdir_p(policy_store_dir) # will fail silently if exists
  rescue Errno::EACCES => e
    logger.error "No permission to create directory #{policy_store_dir}"
    raise e
  rescue StandardError => e
    logger.error "Could not create '#{policy_store_dir}' directory: #{e.message}"
    raise e
  end

  scap_file = policy_content_file(policy_scap_file)
  scap_file ||= save_or_serve_scap_file(policy_id, policy_scap_file)
  scap_file
end

.policy_content_file(policy_scap_file) ⇒ Object



99
100
101
102
# File 'lib/smart_proxy_openscap/openscap_lib.rb', line 99

def self.policy_content_file(policy_scap_file)
  return nil if !File.file?(policy_scap_file) || File.zero?(policy_scap_file)
  File.open(policy_scap_file, 'rb').read
end

.save_or_serve_scap_file(policy_id, policy_scap_file) ⇒ Object



104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
# File 'lib/smart_proxy_openscap/openscap_lib.rb', line 104

def self.save_or_serve_scap_file(policy_id, policy_scap_file)
  lock = Proxy::HttpDownloads.try_locking(policy_scap_file)
  response = fetch_scap_content_xml(policy_id, policy_scap_file)
  if lock.nil?
    return response
  else
    begin
      File.open(policy_scap_file, 'wb') do |file|
        file << response
      end
    ensure
      Proxy::HttpDownloads.unlock(lock)
    end
    scap_file = policy_content_file(policy_scap_file)
    raise FileNotFound if scap_file.nil?
    return scap_file
  end
end

.send_spool_to_foreman ⇒ Object



74
75
76
77
78
# File 'lib/smart_proxy_openscap/openscap_lib.rb', line 74

def self.send_spool_to_foreman
  arf_dir = File.join(Proxy::OpenSCAP::Plugin.settings.spooldir, "/arf")
  return unless File.exists? arf_dir
  ForemanForwarder.new.do(arf_dir)
end

.spool_arf_dir(common_name, policy_id) ⇒ Object



54
55
56
57
58
59
60
61
62
63
64
65
# File 'lib/smart_proxy_openscap/openscap_lib.rb', line 54

def self.spool_arf_dir(common_name, policy_id)
  validate_policy_id(policy_id)
  date = Time.now.strftime("%Y-%m-%d")
  dir = Proxy::OpenSCAP::Plugin.settings.spooldir + "/arf/#{common_name}/#{policy_id}/#{date}/"
  begin
    FileUtils.mkdir_p dir
  rescue StandardError => e
    logger.error "Could not create '#{dir}' directory: #{e.message}"
    raise e
  end
  dir
end

.store_arf(spool_arf_dir, data) ⇒ Object



67
68
69
70
71
72
# File 'lib/smart_proxy_openscap/openscap_lib.rb', line 67

def self.store_arf(spool_arf_dir, data)
  filename = Digest::SHA256.hexdigest data
  target_path = spool_arf_dir + filename
  File.open(target_path,'w') { |f| f.write(data) }
  return target_path
end

.validate_policy_id(id) ⇒ Object



81
82
83
84
85
# File 'lib/smart_proxy_openscap/openscap_lib.rb', line 81

def self.validate_policy_id(id)
  unless /[\d]+/ =~ id
    raise Proxy::Error::BadRequest, "Malformed policy ID"
  end
end