daily-psk.template 3.37 KB
Newer Older
1
#!rsc
2
# RouterOS script: daily-psk%TEMPL%
Christian Hesse's avatar
Christian Hesse committed
3
# Copyright (c) 2013-2019 Christian Hesse <mail@eworm.de>
4
#                         Michael Gisbers <michael@gisbers.de>
Christian Hesse's avatar
Christian Hesse committed
5 6
#
# update daily PSK (pre shared key)
7 8 9
#
# !! This is just a template! Replace '%PATH%' with 'caps-man'
# !! or 'interface wireless'!
Christian Hesse's avatar
Christian Hesse committed
10

11 12
:global Identity;
:global DailyPskMatchComment;
Christian Hesse's avatar
Christian Hesse committed
13

14
:global SendNotification;
15 16
:global UrlEncode;
:global WaitForFile;
17

18
:local Seen [ :toarray "" ];
19

20 21
# return pseudo-random string for PSK
:local GeneratePSK do={
22
  :local Date [ :tostr $1 ];
23

24
  :global DailyPskSecrets;
25

26 27
  :local Months { "jan"; "feb"; "mar"; "apr"; "may"; "jun";
                  "jul"; "aug"; "sep"; "oct"; "nov"; "dec" };
28

29 30 31
  :local Month [ :pick $Date 0 3 ];
  :local Day [ :tonum [ :pick $Date 4 6 ] ];
  :local Year [ :pick $Date 7 11 ];
32

33
  :for MIndex from=0 to=[ :len $Months ] do={
34 35
    :if ($Months->$MIndex = $Month) do={
      :set Month ($MIndex + 1);
36 37 38
    }
  }

39 40 41 42 43
  :local A ((14 - $Month) / 12);
  :local B ($Year - $A);
  :local C ($Month + 12 * $A - 2);
  :local WeekDay (7000 + $Day + $B + ($B / 4) - ($B / 100) + ($B / 400) + ((31 * $C) / 12));
  :set WeekDay ($WeekDay - (($WeekDay / 7) * 7));
44

45 46 47
  :return (($DailyPskSecrets->0->($Day - 1)) . \
    ($DailyPskSecrets->1->($Month - 1)) . \
    ($DailyPskSecrets->2->$WeekDay));
48
}
49

50 51 52
:local Date [ / system clock get date ];
:local NewPsk [ $GeneratePSK $Date ];

53
:foreach AccList in=[ / %PATH% access-list find where comment~$DailyPskMatchComment ] do={
54 55
  :local IntName [ / interface wireless access-list get $AccList interface ];
  :local Ssid [ / interface wireless get $IntName ssid ];
56
  :local Ssid [ / caps-man access-list get $AccList ssid-regexp ];
57
  :local Configuration [ / caps-man configuration get ([ find where ssid=$Ssid ]->0) name ];
58
  :local OldPsk [ / interface wireless access-list get $AccList private-pre-shared-key ];
59
  :local OldPsk [ / caps-man access-list get $AccList private-passphrase ];
60 61 62
  :local Skip 0;

  :if ($NewPsk != $OldPsk) do={
63
    :log info ("Updating daily PSK for " . $Ssid . " to " . $NewPsk . " (was " . $OldPsk . ")");
64
    / interface wireless access-list set $AccList private-pre-shared-key=$NewPsk;
65
    / caps-man access-list set $AccList private-passphrase=$NewPsk;
66

67 68
    :if ([ / interface wireless print count-only where name=$IntName disabled=no ] = 1) do={
    :if ([ / caps-man interface print count-only where configuration=$Configuration ] > 0) do={
69 70 71 72
      :foreach SeenSsid in=$Seen do={
        :if ($SeenSsid = $Ssid) do={
          :log debug ("Already sent a mail for SSID " . $Ssid . ", skipping.");
          :set Skip 1;
73 74 75
        }
      }

76 77
      :if ($Skip = 0) do={
        :set Seen ($Seen, $Ssid);
78

79
        :local Url ("https://www.eworm.de/cgi-bin/cqrlogo-wifi.cgi" . \
80
            "?scale=8&level=1&ssid=" . [ $UrlEncode $Ssid ] . "&pass=" . [ $UrlEncode $NewPsk ]);
81
        :local Attach "qrcode-daily.png";
82

83
        :do {
84
          / tool fetch check-certificate=yes-without-crl \
85
              $Url dst-path=$Attach;
86
          $WaitForFile $Attach;
87
        } on-error={
88
          :set Attach "";
89
        }
90

91 92 93 94 95
        $SendNotification ("daily PSK " . $Ssid) \
          ("This is the daily PSK on " . $Identity . ":\n\n" . \
            "SSID: " . $Ssid . "\n" . \
            "PSK:  " . $NewPsk . "\n" . \
            "Date: " . $Date . "\n\n" . \
96
            "A client device specific rule must not exist!\n\n" . \
97
            $Url) $Attach;
98 99
      }
    }
Christian Hesse's avatar
Christian Hesse committed
100 101
  }
}