1
|
#!/usr/local/bin/php
|
2
|
<?php
|
3
|
/* $Id$ */
|
4
|
/*
|
5
|
system.php
|
6
|
part of m0n0wall (http://m0n0.ch/wall)
|
7
|
|
8
|
Copyright (C) 2003-2004 Manuel Kasper <mk@neon1.net>.
|
9
|
All rights reserved.
|
10
|
|
11
|
Redistribution and use in source and binary forms, with or without
|
12
|
modification, are permitted provided that the following conditions are met:
|
13
|
|
14
|
1. Redistributions of source code must retain the above copyright notice,
|
15
|
this list of conditions and the following disclaimer.
|
16
|
|
17
|
2. Redistributions in binary form must reproduce the above copyright
|
18
|
notice, this list of conditions and the following disclaimer in the
|
19
|
documentation and/or other materials provided with the distribution.
|
20
|
|
21
|
THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES,
|
22
|
INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY
|
23
|
AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
24
|
AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY,
|
25
|
OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
26
|
SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
27
|
INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
28
|
CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
29
|
ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
30
|
POSSIBILITY OF SUCH DAMAGE.
|
31
|
*/
|
32
|
|
33
|
require("guiconfig.inc");
|
34
|
|
35
|
$pconfig['hostname'] = $config['system']['hostname'];
|
36
|
$pconfig['domain'] = $config['system']['domain'];
|
37
|
list($pconfig['dns1'],$pconfig['dns2']) = $config['system']['dnsserver'];
|
38
|
|
39
|
$pconfig['dnsallowoverride'] = isset($config['system']['dnsallowoverride']);
|
40
|
$pconfig['username'] = $config['system']['username'];
|
41
|
if (!$pconfig['username'])
|
42
|
$pconfig['username'] = "admin";
|
43
|
$pconfig['webguiproto'] = $config['system']['webgui']['protocol'];
|
44
|
if (!$pconfig['webguiproto'])
|
45
|
$pconfig['webguiproto'] = "http";
|
46
|
$pconfig['webguiport'] = $config['system']['webgui']['port'];
|
47
|
$pconfig['timezone'] = $config['system']['timezone'];
|
48
|
$pconfig['timeupdateinterval'] = $config['system']['time-update-interval'];
|
49
|
$pconfig['timeservers'] = $config['system']['timeservers'];
|
50
|
|
51
|
if (!isset($pconfig['timeupdateinterval']))
|
52
|
$pconfig['timeupdateinterval'] = 300;
|
53
|
if (!$pconfig['timezone'])
|
54
|
$pconfig['timezone'] = "Etc/UTC";
|
55
|
if (!$pconfig['timeservers'])
|
56
|
$pconfig['timeservers'] = "pool.ntp.org";
|
57
|
|
58
|
$changedesc = "System: ";
|
59
|
$changecount = 0;
|
60
|
|
61
|
function is_timezone($elt) {
|
62
|
return !preg_match("/\/$/", $elt);
|
63
|
}
|
64
|
|
65
|
exec('/usr/bin/tar -tzf /usr/share/zoneinfo.tgz', $timezonelist);
|
66
|
$timezonelist = array_filter($timezonelist, 'is_timezone');
|
67
|
sort($timezonelist);
|
68
|
|
69
|
if ($_POST) {
|
70
|
|
71
|
$changecount++;
|
72
|
|
73
|
unset($input_errors);
|
74
|
$pconfig = $_POST;
|
75
|
|
76
|
/* input validation */
|
77
|
$reqdfields = split(" ", "hostname domain username");
|
78
|
$reqdfieldsn = split(",", "Hostname,Domain,Username");
|
79
|
|
80
|
do_input_validation($_POST, $reqdfields, $reqdfieldsn, &$input_errors);
|
81
|
|
82
|
if ($_POST['hostname'] && !is_hostname($_POST['hostname'])) {
|
83
|
$input_errors[] = "The hostname may only contain the characters a-z, 0-9 and '-'.";
|
84
|
}
|
85
|
if ($_POST['domain'] && !is_domain($_POST['domain'])) {
|
86
|
$input_errors[] = "The domain may only contain the characters a-z, 0-9, '-' and '.'.";
|
87
|
}
|
88
|
if (($_POST['dns1'] && !is_ipaddr($_POST['dns1'])) || ($_POST['dns2'] && !is_ipaddr($_POST['dns2']))) {
|
89
|
$input_errors[] = "A valid IP address must be specified for the primary/secondary DNS server.";
|
90
|
}
|
91
|
if ($_POST['username'] && !preg_match("/^[a-zA-Z0-9]*$/", $_POST['username'])) {
|
92
|
$input_errors[] = "The username may only contain the characters a-z, A-Z and 0-9.";
|
93
|
}
|
94
|
if ($_POST['webguiport'] && (!is_numericint($_POST['webguiport']) ||
|
95
|
($_POST['webguiport'] < 1) || ($_POST['webguiport'] > 65535))) {
|
96
|
$input_errors[] = "A valid TCP/IP port must be specified for the webGUI port.";
|
97
|
}
|
98
|
if (($_POST['password']) && ($_POST['password'] != $_POST['password2'])) {
|
99
|
$input_errors[] = "The passwords do not match.";
|
100
|
}
|
101
|
|
102
|
$t = (int)$_POST['timeupdateinterval'];
|
103
|
if (($t < 0) || (($t > 0) && ($t < 6)) || ($t > 1440)) {
|
104
|
$input_errors[] = "The time update interval must be either 0 (disabled) or between 6 and 1440.";
|
105
|
}
|
106
|
foreach (explode(' ', $_POST['timeservers']) as $ts) {
|
107
|
if (!is_domain($ts)) {
|
108
|
$input_errors[] = "A NTP Time Server name may only contain the characters a-z, 0-9, '-' and '.'.";
|
109
|
}
|
110
|
}
|
111
|
|
112
|
if (!$input_errors) {
|
113
|
update_if_changed("hostname", $config['system']['hostname'], strtolower($_POST['hostname']));
|
114
|
update_if_changed("domain", $config['system']['domain'], strtolower($_POST['domain']));
|
115
|
update_if_changed("username", $config['system']['username'], $_POST['username']);
|
116
|
|
117
|
if (update_if_changed("webgui protocol", $config['system']['webgui']['protocol'], $pconfig['webguiproto']) || update_if_changed("webgui port", $config['system']['webgui']['port'], $pconfig['webguiport']))
|
118
|
$restart_webgui = true;
|
119
|
|
120
|
update_if_changed("timezone", $config['system']['timezone'], $_POST['timezone']);
|
121
|
update_if_changed("NTP servers", $config['system']['timeservers'], strtolower($_POST['timeservers']));
|
122
|
update_if_changed("NTP update interval", $config['system']['time-update-interval'], $_POST['timeupdateinterval']);
|
123
|
|
124
|
/* XXX - billm: these still need updating after figuring out how to check if they actually changed */
|
125
|
unset($config['system']['dnsserver']);
|
126
|
if ($_POST['dns1'])
|
127
|
$config['system']['dnsserver'][] = $_POST['dns1'];
|
128
|
if ($_POST['dns2'])
|
129
|
$config['system']['dnsserver'][] = $_POST['dns2'];
|
130
|
|
131
|
$olddnsallowoverride = $config['system']['dnsallowoverride'];
|
132
|
|
133
|
unset($config['system']['dnsallowoverride']);
|
134
|
$config['system']['dnsallowoverride'] = $_POST['dnsallowoverride'] ? true : false;
|
135
|
|
136
|
if ($_POST['password']) {
|
137
|
$config['system']['password'] = crypt($_POST['password']);
|
138
|
$fd = popen("/usr/sbin/pw usermod -n root -H 0", "w");
|
139
|
$salt = md5(time());
|
140
|
$crypted_pw = crypt($_POST['password'],$salt);
|
141
|
fwrite($fd, $crypted_pw);
|
142
|
pclose($fd);
|
143
|
update_changedesc("password changed");
|
144
|
}
|
145
|
|
146
|
if ($changecount > 0)
|
147
|
write_config($changedesc);
|
148
|
|
149
|
// restart webgui if proto or port changed
|
150
|
if ($restart_webgui) {
|
151
|
global $_SERVER;
|
152
|
system_webgui_start();
|
153
|
if ($pconfig['webguiport'])
|
154
|
header("Location: {$pconfig['webguiproto']}://{$_SERVER['SERVER_NAME']}:{$pconfig['webguiport']}/system.php");
|
155
|
else
|
156
|
header("Location: {$pconfig['webguiproto']}://{$_SERVER['SERVER_NAME']}/system.php");
|
157
|
}
|
158
|
|
159
|
$retval = 0;
|
160
|
if (!file_exists($d_sysrebootreqd_path)) {
|
161
|
config_lock();
|
162
|
$retval = system_hostname_configure();
|
163
|
$retval |= system_hosts_generate();
|
164
|
$retval |= system_resolvconf_generate();
|
165
|
$retval |= system_password_configure();
|
166
|
$retval |= services_dnsmasq_configure();
|
167
|
$retval |= system_timezone_configure();
|
168
|
$retval |= system_ntp_configure();
|
169
|
|
170
|
if ($olddnsallowoverride != $config['system']['dnsallowoverride'])
|
171
|
$retval |= interfaces_wan_configure();
|
172
|
|
173
|
config_unlock();
|
174
|
}
|
175
|
|
176
|
$savemsg = get_std_save_message($retval);
|
177
|
}
|
178
|
}
|
179
|
?>
|
180
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
|
181
|
<html>
|
182
|
<head>
|
183
|
<title><?=gentitle("System: General setup");?></title>
|
184
|
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
|
185
|
<link href="gui.css" rel="stylesheet" type="text/css">
|
186
|
</head>
|
187
|
|
188
|
<body link="#0000CC" vlink="#0000CC" alink="#0000CC">
|
189
|
<?php include("fbegin.inc"); ?>
|
190
|
<p class="pgtitle">System: General setup</p>
|
191
|
<?php if ($input_errors) print_input_errors($input_errors); ?>
|
192
|
<?php if ($savemsg) print_info_box($savemsg); ?>
|
193
|
<form action="system.php" method="post">
|
194
|
<table width="100%" border="0" cellpadding="6" cellspacing="0">
|
195
|
<tr>
|
196
|
<td width="22%" valign="top" class="vncellreq">Hostname</td>
|
197
|
<td width="78%" class="vtable"> <input name="hostname" type="text" class="formfld" id="hostname" size="40" value="<?=htmlspecialchars($pconfig['hostname']);?>">
|
198
|
<br> <span class="vexpl">name of the firewall host, without
|
199
|
domain part<br>
|
200
|
e.g. <em>firewall</em></span></td>
|
201
|
</tr>
|
202
|
<tr>
|
203
|
<td width="22%" valign="top" class="vncellreq">Domain</td>
|
204
|
<td width="78%" class="vtable"> <input name="domain" type="text" class="formfld" id="domain" size="40" value="<?=htmlspecialchars($pconfig['domain']);?>">
|
205
|
<br> <span class="vexpl">e.g. <em>mycorp.com</em> </span></td>
|
206
|
</tr>
|
207
|
<tr>
|
208
|
<td width="22%" valign="top" class="vncell">DNS servers</td>
|
209
|
<td width="78%" class="vtable"> <p>
|
210
|
<input name="dns1" type="text" class="formfld" id="dns1" size="20" value="<?=htmlspecialchars($pconfig['dns1']);?>">
|
211
|
<br>
|
212
|
<input name="dns2" type="text" class="formfld" id="dns22" size="20" value="<?=htmlspecialchars($pconfig['dns2']);?>">
|
213
|
<br>
|
214
|
<span class="vexpl">IP addresses; these are also used for
|
215
|
the DHCP service, DNS forwarder and for PPTP VPN clients<br>
|
216
|
<br>
|
217
|
<input name="dnsallowoverride" type="checkbox" id="dnsallowoverride" value="yes" <?php if ($pconfig['dnsallowoverride']) echo "checked"; ?>>
|
218
|
<strong>Allow DNS server list to be overridden by DHCP/PPP
|
219
|
on WAN</strong><br>
|
220
|
If this option is set, pfSense will use DNS servers assigned
|
221
|
by a DHCP/PPP server on WAN for its own purposes (including
|
222
|
the DNS forwarder). They will not be assigned to DHCP and
|
223
|
PPTP VPN clients, though.</span></p></td>
|
224
|
</tr>
|
225
|
<tr>
|
226
|
<td valign="top" class="vncell">Username</td>
|
227
|
<td class="vtable"> <input name="username" type="text" class="formfld" id="username" size="20" value="<?=$pconfig['username'];?>">
|
228
|
<br>
|
229
|
<span class="vexpl">If you want
|
230
|
to change the username for accessing the webGUI, enter it
|
231
|
here.</span></td>
|
232
|
</tr>
|
233
|
<tr>
|
234
|
<td width="22%" valign="top" class="vncell">Password</td>
|
235
|
<td width="78%" class="vtable"> <input name="password" type="password" class="formfld" id="password" size="20">
|
236
|
<br> <input name="password2" type="password" class="formfld" id="password2" size="20">
|
237
|
(confirmation) <br> <span class="vexpl">If you want
|
238
|
to change the password for accessing the webGUI, enter it
|
239
|
here twice.</span></td>
|
240
|
</tr>
|
241
|
<tr>
|
242
|
<td width="22%" valign="top" class="vncell">webGUI protocol</td>
|
243
|
<td width="78%" class="vtable"> <input name="webguiproto" type="radio" value="http" <?php if ($pconfig['webguiproto'] == "http") echo "checked"; ?>>
|
244
|
HTTP <input type="radio" name="webguiproto" value="https" <?php if ($pconfig['webguiproto'] == "https") echo "checked"; ?>>
|
245
|
HTTPS</td>
|
246
|
</tr>
|
247
|
<tr>
|
248
|
<td valign="top" class="vncell">webGUI port</td>
|
249
|
<td class="vtable"> <input name="webguiport" type="text" class="formfld" id="webguiport" "size="5" value="<?=htmlspecialchars($pconfig['webguiport']);?>">
|
250
|
<br>
|
251
|
<span class="vexpl">Enter a custom port number for the webGUI
|
252
|
above if you want to override the default (80 for HTTP, 443
|
253
|
for HTTPS). Changes will take effect immediately after save.</span></td>
|
254
|
</tr>
|
255
|
<tr>
|
256
|
<td width="22%" valign="top" class="vncell">Time zone</td>
|
257
|
<td width="78%" class="vtable"> <select name="timezone" id="timezone">
|
258
|
<?php foreach ($timezonelist as $value): ?>
|
259
|
<option value="<?=htmlspecialchars($value);?>" <?php if ($value == $pconfig['timezone']) echo "selected"; ?>>
|
260
|
<?=htmlspecialchars($value);?>
|
261
|
</option>
|
262
|
<?php endforeach; ?>
|
263
|
</select> <br> <span class="vexpl">Select the location closest
|
264
|
to you</span></td>
|
265
|
</tr>
|
266
|
<tr>
|
267
|
<td width="22%" valign="top" class="vncell">Time update interval</td>
|
268
|
<td width="78%" class="vtable"> <input name="timeupdateinterval" type="text" class="formfld" id="timeupdateinterval" size="4" value="<?=htmlspecialchars($pconfig['timeupdateinterval']);?>">
|
269
|
<br> <span class="vexpl">Minutes between network time sync.;
|
270
|
300 recommended, or 0 to disable </span></td>
|
271
|
</tr>
|
272
|
<tr>
|
273
|
<td width="22%" valign="top" class="vncell">NTP time server</td>
|
274
|
<td width="78%" class="vtable"> <input name="timeservers" type="text" class="formfld" id="timeservers" size="40" value="<?=htmlspecialchars($pconfig['timeservers']);?>">
|
275
|
<br> <span class="vexpl">Use a space to separate multiple
|
276
|
hosts (only one required). Remember to set up at least one
|
277
|
DNS server if you enter a host name here!</span></td>
|
278
|
</tr>
|
279
|
<tr>
|
280
|
<td width="22%" valign="top"> </td>
|
281
|
<td width="78%"> <input name="Submit" type="submit" class="formbtn" value="Save">
|
282
|
</td>
|
283
|
</tr>
|
284
|
</table>
|
285
|
</form>
|
286
|
<?php include("fend.inc"); ?>
|
287
|
</body>
|
288
|
</html>
|