1
0

pureftpd.sh 4.9 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788
  1. #!/bin/bash
  2. # Author: yeho <lj2007331 AT gmail.com>
  3. # BLOG: https://linuxeye.com
  4. #
  5. # Notes: OneinStack for CentOS/RedHat 6+ Debian 7+ and Ubuntu 12+
  6. #
  7. # Project home page:
  8. # https://oneinstack.com
  9. # https://github.com/oneinstack/oneinstack
  10. Install_PureFTPd() {
  11. pushd ${oneinstack_dir}/src > /dev/null
  12. id -u ${run_user} >/dev/null 2>&1
  13. [ $? -ne 0 ] && useradd -M -s /sbin/nologin ${run_user}
  14. tar xzf pure-ftpd-${pureftpd_ver}.tar.gz
  15. pushd pure-ftpd-${pureftpd_ver} > /dev/null
  16. [ ! -d "${pureftpd_install_dir}" ] && mkdir -p ${pureftpd_install_dir}
  17. ./configure --prefix=${pureftpd_install_dir} CFLAGS=-O2 --with-puredb --with-quotas --with-cookie --with-virtualhosts --with-virtualchroot --with-diraliases --with-sysquotas --with-ratios --with-altlog --with-paranoidmsg --with-shadow --with-welcomemsg --with-throttling --with-uploadscript --with-language=english --with-rfc2640 --with-tls
  18. make -j ${THREAD} && make install
  19. popd > /dev/null
  20. if [ -e "${pureftpd_install_dir}/sbin/pure-ftpwho" ]; then
  21. if [ -e /bin/systemctl ]; then
  22. /bin/cp ../init.d/pureftpd.service /lib/systemd/system/
  23. sed -i "s@/usr/local/pureftpd@${pureftpd_install_dir}@g" /lib/systemd/system/pureftpd.service
  24. systemctl enable pureftpd
  25. else
  26. /bin/cp ../init.d/Pureftpd-init /etc/init.d/pureftpd
  27. sed -i "s@/usr/local/pureftpd@${pureftpd_install_dir}@g" /etc/init.d/pureftpd
  28. chmod +x /etc/init.d/pureftpd
  29. [ "${PM}" == 'yum' ] && { chkconfig --add pureftpd; chkconfig pureftpd on; }
  30. [ "${PM}" == 'apt-get' ] && { sed -i 's@^. /etc/rc.d/init.d/functions@. /lib/lsb/init-functions@' /etc/init.d/pureftpd; update-rc.d pureftpd defaults; }
  31. [ "${Debian_ver}" == '7' ] && sed -i 's@/var/lock/subsys/@/var/lock/@g' /etc/init.d/pureftpd
  32. fi
  33. [ ! -e "${pureftpd_install_dir}/etc" ] && mkdir ${pureftpd_install_dir}/etc
  34. /bin/cp ../config/pure-ftpd.conf ${pureftpd_install_dir}/etc
  35. sed -i "s@^PureDB.*@PureDB ${pureftpd_install_dir}/etc/pureftpd.pdb@" ${pureftpd_install_dir}/etc/pure-ftpd.conf
  36. sed -i "s@^LimitRecursion.*@LimitRecursion 65535 8@" ${pureftpd_install_dir}/etc/pure-ftpd.conf
  37. IPADDR=${IPADDR:-127.0.0.1}
  38. [ ! -d /etc/ssl/private ] && mkdir -p /etc/ssl/private
  39. openssl dhparam -out /etc/ssl/private/pure-ftpd-dhparams.pem 2048
  40. openssl req -x509 -days 7300 -sha256 -nodes -subj "/C=CN/ST=Shanghai/L=Shanghai/O=OneinStack/CN=${IPADDR}" -newkey rsa:2048 -keyout /etc/ssl/private/pure-ftpd.pem -out /etc/ssl/private/pure-ftpd.pem
  41. chmod 600 /etc/ssl/private/pure-ftpd*.pem
  42. sed -i "s@^# TLS.*@&\nCertFile /etc/ssl/private/pure-ftpd.pem@" ${pureftpd_install_dir}/etc/pure-ftpd.conf
  43. sed -i "s@^# TLS.*@&\nTLSCipherSuite HIGH:MEDIUM:+TLSv1:\!SSLv2:\!SSLv3@" ${pureftpd_install_dir}/etc/pure-ftpd.conf
  44. sed -i "s@^# TLS.*@TLS 1@" ${pureftpd_install_dir}/etc/pure-ftpd.conf
  45. ulimit -s unlimited
  46. service pureftpd start
  47. # iptables Ftp
  48. if [ "${PM}" == 'yum' ]; then
  49. if [ -n "`grep 'dport 80 ' /etc/sysconfig/iptables`" ] && [ -z "$(grep '20000:30000' /etc/sysconfig/iptables)" ]; then
  50. iptables -I INPUT 5 -p tcp -m state --state NEW -m tcp --dport 21 -j ACCEPT
  51. iptables -I INPUT 6 -p tcp -m state --state NEW -m tcp --dport 20000:30000 -j ACCEPT
  52. service iptables save
  53. ip6tables -I INPUT 5 -p tcp -m state --state NEW -m tcp --dport 21 -j ACCEPT
  54. ip6tables -I INPUT 6 -p tcp -m state --state NEW -m tcp --dport 20000:30000 -j ACCEPT
  55. service ip6tables save
  56. fi
  57. elif [ "${PM}" == 'apt-get' ]; then
  58. if [ -e '/etc/iptables/rules.v4' ]; then
  59. if [ -n "`grep 'dport 80 ' /etc/iptables/rules.v4`" ] && [ -z "$(grep '20000:30000' /etc/iptables/rules.v4)" ]; then
  60. iptables -I INPUT 5 -p tcp -m state --state NEW -m tcp --dport 21 -j ACCEPT
  61. iptables -I INPUT 6 -p tcp -m state --state NEW -m tcp --dport 20000:30000 -j ACCEPT
  62. iptables-save > /etc/iptables/rules.v4
  63. ip6tables -I INPUT 5 -p tcp -m state --state NEW -m tcp --dport 21 -j ACCEPT
  64. ip6tables -I INPUT 6 -p tcp -m state --state NEW -m tcp --dport 20000:30000 -j ACCEPT
  65. ip6tables-save > /etc/iptables/rules.v6
  66. fi
  67. elif [ -e '/etc/iptables.up.rules' ]; then
  68. if [ -n "`grep 'dport 80 ' /etc/iptables.up.rules`" ] && [ -z "$(grep '20000:30000' /etc/iptables.up.rules)" ]; then
  69. iptables -I INPUT 5 -p tcp -m state --state NEW -m tcp --dport 21 -j ACCEPT
  70. iptables -I INPUT 6 -p tcp -m state --state NEW -m tcp --dport 20000:30000 -j ACCEPT
  71. iptables-save > /etc/iptables.up.rules
  72. fi
  73. fi
  74. fi
  75. echo "${CSUCCESS}Pure-Ftp installed successfully! ${CEND}"
  76. rm -rf pure-ftpd-${pureftpd_ver}
  77. else
  78. rm -rf ${pureftpd_install_dir}
  79. echo "${CFAILURE}Pure-Ftpd install failed, Please contact the author! ${CEND}"
  80. kill -9 $$
  81. fi
  82. popd > /dev/null
  83. }