#!/usr/bin/python3 """ This Script encrypt Wireguardfiles for Wirepy users for more Security """ import argparse from pathlib import Path import pwd import shutil from subprocess import CompletedProcess, run from wp_app_config import AppConfig parser = argparse.ArgumentParser() parser.add_argument("--user", required=True, help="Username of the target file system") args = parser.parse_args() try: # Retrieve UID and GID user_info = pwd.getpwnam(args.user) uid = user_info.pw_uid # User ID (e.g., 1000) gid = user_info.pw_gid # Group ID (e.g., 1000) except KeyError: print(f"User '{args.user}' not found.") exit(1) keyfile: Path = Path(f"/home/{args.user}/.config/wire_py/pbwgk.pem") target: Path = Path(f"/home/{args.user}/.config/wire_py/") if not keyfile.is_file(): process: CompletedProcess[str] = run( [ "openssl", "rsa", "-in", AppConfig.SYSTEM_PATHS["pkey_path"], "-out", keyfile, "-outform", "PEM", "-pubout", ], capture_output=True, text=True, check=False, ) if process.stdout: print(process.stdout) # Output from Openssl Error if process.stderr: print("(Error):", process.stderr) if process.returncode == 0: print("Public key generated successfully.") else: print(f"Error generate Publickey: Code: {process.returncode}") shutil.chown(keyfile, uid, gid) # any() get True when directory is not empty if AppConfig.TEMP_DIR.exists() and any(AppConfig.TEMP_DIR.iterdir()): clear_files = [str(file) for file in AppConfig.TEMP_DIR.glob("*.conf")] for config_file in clear_files: base_name = Path(config_file).stem process: CompletedProcess[str] = run( [ "openssl", "pkeyutl", "-encrypt", "-inkey", keyfile, "-pubin", "-in", config_file, "-out", f"{target}/{base_name}.dat", ], capture_output=True, text=True, check=False, ) print(f"Processing of the file: {config_file}") # Output from Openssl Error if process.stderr: print("(Error):", process.stderr) if process.returncode == 0: print(f"File {base_name}.dat successfully encrypted.") else: print(f"Error by {config_file}: Code: {process.returncode}")