#/!/bin/bash
##################################
# Installation eine SVWS-Servers #
# mit Apache2                    #
# und Samba mit Schild3          #
# Erstellt am 6.8.2024 von TR    #
##################################
### Farbdefinitionen ####
#   TEXT in Weiss       #
#   DATEIEN in Gelb     #
#   ORDNER in HellBlau  #
#########################
# Farbdefinitionen zur Ausgabe #
ROT='\033[0;31m' 
HELLROT='\033[1;31m'
GRUEN='\033[0;32m'
HELLGRUEN='\033[1;32m'
GELB='\033[1;33m'
BLAU='\033[0;34m'
HELLBLAU='\033[1;34m'
LILA='\033[0;35m'
HELLLILA='\033[1;35m'
DUNKELESTUERKIS='\033[0;36m'
TUERKIS='\033[1;36m'
HELLGRAU='\033[0;37m'
WEISS='\033[1;37m'
NC='\033[0m' # No Color
#
## [Variablen]
##
#
VERSIONSNR=""			# Download dieser Version 0.9.0 des SVWS-Servers https://github.com/SVWS-NRW/SVWS-Server
SCHILD_VERSIONSNR=""		# Download dieser Version 3.0.89 der zum Schild3  https://github.com/SVWS-NRW/Schild3-BetaTest
SVWS-Laufbahnplanung=""		# Download dieser Version 0.9.0 des SVWS-Laufbahnplanung https://github.com/SVWS-NRW/SVWS-Server
ROOTPWD=""			# MariaDB ROOT Passwort
USERPWD=""			# MariaDB USER Passwort
SNR=""				# Ausgedachte Schulnummer
FQDN=""				# Zertitifikats name des SVWS-Servers
IP=""				# IP des LXC-Containers
#
##
## [Argumente auslesen]
##
#
clear
if [ -z "${VERSIONSNR}" ]; then
    # 1.Frage: SVWS Versionsnummer
      read -p "Hier BITTE die neuste SVWS-Versionsnummer eingeben: Der Stand am 09.08.2024 war 0.9.0: " VERSIONSNR
fi
if [ -z "${SCHILD_VERSIONSNR}" ]; then
    # 2.Frage: Schild3 Versionsnummer
      read -p "Hier BITTE die neuste Schild3-Versionsnummer eingeben: Der Stand am 09.08.2024 war 3.0.89: " SCHILD_VERSIONSNR
fi
if [ -z "${SNR}" ]; then
    # 5.Frage: MariaDB user Passwort
      read -p "Schulnummer  : " SNR
fi
if [ -z "${FQDN}" ]; then
    # 6.Frage: FQDN
      read -p "Zertivikatsname  : " FQDN
fi
ip a
if [ -z "${IP}" ]; then
    # 7.Frage: FQDN
      read -p "Bitte die Angezeigte IP4 des LXC-Containers eingeben: " IP
fi
if [ -z "${ROOTPWD}" ]; then
    # 3.Frage: MariaDB root Passwort
      read -s -p "Das MariaDB root Passwort wird nicht ANGEZEIGT!!: " ROOTPWD
fi
echo
if [ -z "${USERPWD}" ]; then
    # 4.Frage: MariaDB user Passwort
      read -s -p "Das MariaDB svwsadmin Passwort wird nicht ANGEZEIGT!!: " USERPWD
fi
#
##
## [Softwaredownload]
##
#
echo
echo -e -n "${TUERKIS}Update und Upgrade des Debian ${NC}"
echo
sleep 3
apt-get update && apt upgrade -y
echo
echo -e -n "${TUERKIS}Autoremove der nicht mehr genutzten Dateien ${NC}"
echo
sleep 3
apt-get autoremove -y
echo
echo -e -n "${TUERKIS}Deutsches Tastaurlayout installiern ${NC}"
echo
sleep 3
apt install task-german -y
dpkg-reconfigure locales
echo
echo -e -n "${TUERKIS}XFCE4-Desktop installieren ${NC}"
echo
sleep 3
apt install xfce4 xfce4-goodies xorg dbus-x11 x11-xserver-utils -y
echo
echo -e -n "${TUERKIS}Remotedesktop installieren ${NC}"
echo
sleep 3
apt install xrdp -y
adduser xrdp ssl-cert
systemctl restart xrdp
echo
echo -e -n "${TUERKIS}Firefox installieren ${NC}"
echo
sleep 2
wget -q https://packages.mozilla.org/apt/repo-signing-key.gpg -O- | tee /etc/apt/keyrings/packages.mozilla.org.asc > /dev/null
gpg -n -q --import --import-options import-show /etc/apt/keyrings/packages.mozilla.org.asc | awk '/pub/{getline; gsub(/^ +| +$/,""); if($0 == "35BAA0B33E9EB396F59CA838C0BA5CE6DC6315A3") print "\nThe key fingerprint matches ("$0").\n"; else print "\nVerification failed: the fingerprint ("$0") does not match the expected one.\n"}'
echo "deb [signed-by=/etc/apt/keyrings/packages.mozilla.org.asc] https://packages.mozilla.org/apt mozilla main" | tee -a /etc/apt/sources.list.d/mozilla.list > /dev/null
apt update && apt install firefox -y
apt install firefox-l10n-de -y
echo
echo -e -n "${TUERKIS}Installation der folgenden Pakete ${GELB}net-tools dnsutils nmap samba ufw zip git ssh apache2 php mc ${NC}"
echo
sleep 2
apt-get install net-tools dnsutils nmap samba ufw zip git ssh apache2 mc php -y
# Apache ssl
ln -s /etc/apache2/sites-available/default-ssl.conf /etc/apache2/sites-enabled/default-ssl.conf
a2enmod ssl
systemctl restart apache2
sleep 4
systemctl status apache2 --no-pager
# Download SVWS-Server
wget https://github.com/SVWS-NRW/SVWS-Server/releases/download/v$VERSIONSNR/install-$VERSIONSNR.sh
# Wahrscheinlich verhindert ein Bug den Dowload -- daher neues Workaround:
wget https://github.com/SVWS-NRW/SVWS-Server/releases/download/v$VERSIONSNR/linux-installer-$VERSIONSNR.tar.gz
##
## [SVWS Konfiguration]
##
# Ggf koennen hier noch Anpassungen fuer den Betrieb des SVWS-Severs gemacht werden. Zum Beispiel zur Migration der Datenbank, verwendetem Keystore etc.
tee -a /root/.env  <<EOF
CREATE_MariaDB=j
CREATE_KEYSTORE=j
CREATE_TESTDATA=j
MariaDB_ROOT_PASSWORD=$ROOTPWD
MariaDB_DATABASE=svwsdb
MariaDB_HOST=localhost
MariaDB_USER=svwsadmin
MariaDB_PASSWORD=$USERPWD
APP_PATH=/opt/app/svws
CONF_PATH=/etc/app/svws/conf
APP_PORT=8443
SVWS_TLS_KEYSTORE_PATH=/etc/app/svws/conf/keystore
SVWS_TLS_KEYSTORE_PASSWORD=$ROOTPWD
SVWS_TLS_KEY_ALIAS=
INPUT_common_name=svws-server
INPUT_organizational_unit=$SNR
INPUT_organization=$FQDN
INPUT_locality=NRW
INPUT_state=DE
INPUT_country=DE
validity_days=9999
TMP_DIR=/tmp/svws
#
# Hier kann ggf. Ihre Schuldatenbank hinterlegt werden und ggf auch automatisch migriert werden.
# Des Weiteren gibt es noch die Moeglichkein per CURL ein Backup einzuspielen oder eine Migration zu starten.
# Dazu bitte die naechsten beiden Zeilen benutzen und die dritte natuerlich loeschen.
#MDBFILE=/tmp/svws/SVWS-TestMDBs-main/GOST_Abitur/Abi-Test-Daten-01/GymAbi.mdb
#INIT_EMPTY_DB=N
INIT_EMPTY_DB=J
#
EOF
##
# [Installation SVWS-Server]
echo
echo -e -n "${TUERKIS}Installation des SVWS-SERVERS ${NC}"
echo
sleep 2
bash install-$VERSIONSNR.sh
##
## [Installation Schild3]
##
# Samba einrichten
echo
echo -e -n "${TUERKIS}Installation des SAMBA-SERVERS und erstellen von SchILD3 ${NC}"
echo
sleep 2
mkdir /netzlaufwerk/
mkdir /netzlaufwerk/Schild_3
mkdir /netzlaufwerk/Schild_3_Arbeitsverzeichnis
mkdir /netzlaufwerk/Schild_3/Connection-Files
mkdir /netzlaufwerk/installationfiles
mkdir /netzlaufwerk/Programme
wget https://github.com/SVWS-NRW/Schild3-BetaTest/releases/download/v$SCHILD_VERSIONSNR/Setup_SchILD3_v$SCHILD_VERSIONSNR.zip
mv /root/Setup_SchILD3_v$SCHILD_VERSIONSNR.zip /netzlaufwerk/installationfiles/
#mv Schild-Reports.zip /netzlaufwerk/installationfiles
unzip /netzlaufwerk/installationfiles/Setup_SchILD3_v$SCHILD_VERSIONSNR.zip -d /netzlaufwerk/Schild_3/
# Download SVWS-Laufbahnplanung
wget https://github.com/SVWS-NRW/SVWS-Server/releases/download/v$VERSIONSNR/SVWS-Laufbahnplanung-$VERSIONSNR.zip
mkdir /var/www/html/Laufbahnplanung
mv /root/SVWS-Laufbahnplanung-$VERSIONSNR.zip /var/www/html/Laufbahnplanung
unzip /var/www/html/Laufbahnplanung/SVWS-Laufbahnplanung-$VERSIONSNR.zip -d /var/www/html/Laufbahnplanung/
git clone https://github.com/SVWS-NRW/SVWS-TestMDBs /netzlaufwerk/installationfiles/SVWS-TestMDBs/
tee -a /etc/samba/smb.conf <<EOF

[netzlaufwerk]
path = /netzlaufwerk
public = yes
writable = yes
comment = SVWS Freigabe
printable = no
guest ok = yes
EOF
#
#
#
# Schild 3 Connection Files
tee -a /netzlaufwerk/Schild_3/Connection-Files/server.con.example <<EOF
[SchILDconnection]
ProviderName=MYSQL
ProviderType=MARIADB
server=$IP
Port=3306
Database=svwsdb
Username=svwsadmin
Password=AAjcM0WrUSlfbBR5EtcPSyTzso2858zMPOY0Ih3nUlm31S3aD3Fs/LwxUHYCFjs8iLU=
Direct=0
SVWSServerURL=$IP:8443
EOF
#
cp /netzlaufwerk/Schild_3/Connection-Files/server.con.example /netzlaufwerk/Schild_3/Connection-Files/svwsdb.con
systemctl restart smbd.service
echo
echo -e "${TUERKIS} Ausgabe des Status des Samba-Servers !?!${NC}"
echo
systemctl status smbd.service --no-pager
wget http://web.webolch.de/bauanleitung/downloads/linux/zip/dateien.zip
unzip dateien.zip
mv 50-server.cnf /etc/mysql/mariadb.conf.d
mv sshd_config /etc/ssh
systemctl restart ssh
systemctl status ssh --no-pager
wget http://web.webolch.de/bauanleitung/downloads/linux/zip/Admin.zip
unzip Admin.zip
mv Admin /netzlaufwerk/Programme
wget http://web.webolch.de/bauanleitung/downloads/windows/exe/ChromeStandaloneSetup64.exe
mv ChromeStandaloneSetup64.exe /netzlaufwerk/installationfiles
wget http://web.webolch.de/bauanleitung/downloads/windows/exe/italc-2.0.2-win64-setup.exe
mv italc-2.0.2-win64-setup.exe /netzlaufwerk/installationfiles
wget http://web.webolch.de/bauanleitung/downloads/windows/exe/AcroRdrDC1500920069_de_DE.exe
mv AcroRdrDC1500920069_de_DE.exe /netzlaufwerk/installationfiles
chmod -R 777 /netzlaufwerk/
apt install phpmyadmin -y
systemctl restart mysql
systemctl status mysql --no-pager
