]> git.madduck.net Git - etc/offlineimap.git/blobdiff - .offlineimap/preauthtunnel.sh

madduck's git repository

Every one of the projects in this repository is available at the canonical URL git://git.madduck.net/madduck/pub/<projectpath> — see each project's metadata for the exact URL.

All patches and comments are welcome. Please squash your changes to logical commits before using git-format-patch and git-send-email to patches@git.madduck.net. If you'd read over the Git project's submission guidelines and adhered to them, I'd be especially grateful.

SSH access, as well as push access can be individually arranged.

If you use my repositories frequently, consider adding the following snippet to ~/.gitconfig and using the third clone URL listed for each project:

[url "git://git.madduck.net/madduck/"]
  insteadOf = madduck:

Add instructions to SSH call
[etc/offlineimap.git] / .offlineimap / preauthtunnel.sh
index 09769746e0f8e6f8ff85e8f67944a857d59c513a..c99f59b2bfa839aa83dfed05e37b8d9c8ae23d3e 100755 (executable)
@@ -1,3 +1,19 @@
 #!/bin/sh
 
-exec ssh -F ~/.offlineimap/ssh_config -i ~/.offlineimap/${1}.ssh-seckey ${1}
+unset SSH_AUTH_SOCK
+
+exec ssh -F ~/.offlineimap/ssh_config -i ~/.offlineimap/${1}.ssh-seckey ${1} \
+  echo -e "Please configure \~/.ssh/authorized_keys on the server and prepend the line with the public key corresponding to the password-less SSH key in ~/.offlineimap/${1}.ssh-seckey :\\\n\\\n  'command=\"MAIL=\$HOME/.maildir /usr/lib/dovecot/imap 2>/dev/null\",no-agent-forwarding,no-X11-forwarding,no-port-forwarding,no-pty'"
+
+# This relies on the IMAP command being specified on the server side, i.e. in
+# ~/.ssh/authorized_keys, put a line like the following
+#
+#   command="MAIL=$HOME/.maildir /usr/lib/dovecot/imap 2>/dev/null",no-agent-forwarding,no-X11-forwarding,no-port-forwarding,no-pty ssh-ed25519 AAA…
+#
+# When a command is specified like this, it overrides the instructions being
+# passed in the command above. So, when you invoke this script directly, you
+# should see the IMAP server greet you:
+#
+# % ~/.offlineimap/preauthtunnel.sh madduck-net.imap.madduck.net
+# * PREAUTH [CAPABILITY IMAP4rev1 […]] Logged in as madduck
+