expect "the access key is kept for the unit""FELIS_OFFSITE_ACCESS_KEY='AK'""$envf"
expect "an encryption key is generated""FELIS_OFFSITE_KEY='""$envf"
@@ -2485,7 +2489,15 @@ if [ "$(stat -c %a "$odir/offsite.env" 2>/dev/null || stat -f %Lp "$odir/offsite
else
echo"FAIL offsite.env must be 0600";fails=$((fails +1))
fi
expect "a new key is shown once, with the warning to keep it elsewhere""WARN: FELIS_OFFSITE_KEY=${key}""$out"
tty_out="$(cat"$odir/tty" 2>/dev/null)"
expect "a new key is shown on the terminal""WARN: FELIS_OFFSITE_KEY=${key}""$tty_out"
expect "the terminal gets the warning to keep it elsewhere""WARN: The off-site copies are encrypted with this key. Store it NOW somewhere other than
WARN: this machine (a password manager): without it nothing in the bucket can be read.""$tty_out"
case"$out"in
*"$key"*)echo"FAIL the new key reached the install's output, which a log keeps";fails=$((fails +1));;
*)echo"PASS the new key stays out of the install's output";;
esac
expect "the output says where the key shown on the terminal is""WARN: Off-site copy: the new encryption key was shown on the terminal and is in $odir/offsite.env""$out"
# A re-run with new credentials keeps the key; a different key is refused.
*"$key2"*)echo"FAIL with no terminal the new key reached the install's output";fails=$((fails +1));;
*)echo"PASS with no terminal the new key stays out of the install's output";;
esac
case"$out"in
*no-terminal*)echo"FAIL the terminal that could not be opened left an error in the output: $out";fails=$((fails +1));;
*)echo"PASS the terminal that could not be opened leaves no error in the output";;
esac
else
echo"FAIL the install without a terminal generated no key";fails=$((fails +1))
fi
expect "with no terminal the output says the key stays out of it""WARN: With no terminal to show it on, it stays out of this output; read it with""$out"
expect "with no terminal the output names the command that reads the key""WARN: sudo grep '^FELIS_OFFSITE_KEY=' $odir/offsite.env""$out"