{$pgtitle}

"; } if ($savemsg) { echo "
"; print_info_box($savemsg); echo "
"; } if ($input_errors) { print_input_errors($input_errors); } if ($hostname <> $myhostname) { print_info_box("Warning! You are currently viewing an alternate host's backup history ($hostname)"); } ?>
Loading, please wait...
 
setTimezone($mytz); $savemsg = "Backup revision " . htmlspecialchars($budate->format(DATE_RFC2822)) . " has been removed."; } print_info_box($savemsg); } if ($_REQUEST['newver'] != "") { // Phone home and obtain backups $curl_session = curl_init(); curl_setopt($curl_session, CURLOPT_URL, $get_url); curl_setopt($curl_session, CURLOPT_HTTPHEADER, array("Authorization: Basic " . base64_encode("{$username}:{$password}"))); curl_setopt($curl_session, CURLOPT_POST, 3); if ($pf_version < 2.2) { // pre-2.2 doesn't have ca-root-nss curl_setopt($curl_session, CURLOPT_SSL_VERIFYPEER, 0); } else { curl_setopt($curl_session, CURLOPT_SSL_VERIFYPEER, 1); } curl_setopt($curl_session, CURLOPT_RETURNTRANSFER, 1); curl_setopt($curl_session, CURLOPT_POSTFIELDS, "action=restore" . "&hostname=" . urlencode($hostname) . "&revision=" . urlencode($_REQUEST['newver'])); curl_setopt($curl_session, CURLOPT_USERAGENT, $g['product_name'] . '/' . rtrim(file_get_contents("/etc/version"))); // Proxy curl_setopt_array($curl_session, configure_proxy()); $data = curl_exec($curl_session); $data_split = split("\+\+\+\+", $data); $sha256 = trim($data_split[0]); $data = $data_split[1]; if (!tagfile_deformat($data, $data, "config.xml")) { $input_errors[] = "The downloaded file does not appear to contain an encrypted pfSense configuration."; } $out = decrypt_data($data, $decrypt_password); $pos = stripos($out, ""); $data = substr($out, 0, $pos); $data = $data . "\n"; $fd = fopen("/tmp/config_restore.xml", "w"); fwrite($fd, $data); fclose($fd); if (strlen($data) < 50) { $input_errors[] = "The decrypted config.xml is under 50 characters, something went wrong. Aborting."; } $ondisksha256 = trim(shell_exec("/sbin/sha256 /tmp/config_restore.xml | /usr/bin/awk '{ print $4 }'")); // We might not have a sha256 on file for older backups if ($sha256 != "0" && $sha256 != "") { if ($ondisksha256 <> $sha256) { $input_errors[] = "SHA256 values do not match, cannot restore. $ondisksha256 <> $sha256"; } } if (curl_errno($curl_session)) { /* If an error occured, log the error in /tmp/ */ $fd = fopen("/tmp/acb_restoredebug.txt", "w"); fwrite($fd, $get_url . "" . "action=restore&hostname={$hostname}&revision=" . urlencode($_REQUEST['newver']) . "\n\n"); fwrite($fd, $data); fwrite($fd, curl_error($curl_session)); fclose($fd); } else { curl_close($curl_session); } if (!$input_errors && $data) { conf_mount_rw(); if (config_restore("/tmp/config_restore.xml") == 0) { $savemsg = "Successfully reverted the pfSense configuration to revision " . urldecode($_REQUEST['newver']) . "."; $savemsg .= <<
Would you like to reboot?
EOF; } else { $savemsg = "Unable to revert to the selected configuration."; } print_info_box($savemsg); } else { log_error("There was an error when restoring the AutoConfigBackup item"); } unlink_if_exists("/tmp/config_restore.xml"); conf_mount_ro(); } if ($_REQUEST['download']) { // Phone home and obtain backups $curl_session = curl_init(); curl_setopt($curl_session, CURLOPT_URL, $get_url); curl_setopt($curl_session, CURLOPT_HTTPHEADER, array("Authorization: Basic " . base64_encode("{$username}:{$password}"))); curl_setopt($curl_session, CURLOPT_POST, 3); if ($pf_version < 2.2) { // pre-2.2 doesn't have ca-root-nss curl_setopt($curl_session, CURLOPT_SSL_VERIFYPEER, 0); } else { curl_setopt($curl_session, CURLOPT_SSL_VERIFYPEER, 1); } curl_setopt($curl_session, CURLOPT_RETURNTRANSFER, 1); curl_setopt($curl_session, CURLOPT_POSTFIELDS, "action=restore" . "&hostname=" . urlencode($hostname) . "&revision=" . urlencode($_REQUEST['download'])); curl_setopt($curl_session, CURLOPT_USERAGENT, $g['product_name'] . '/' . rtrim(file_get_contents("/etc/version"))); // Proxy curl_setopt_array($curl_session, configure_proxy()); $data = curl_exec($curl_session); if (!tagfile_deformat($data, $data1, "config.xml")) { $input_errors[] = "The downloaded file does not appear to contain an encrypted pfSense configuration."; } if ($input_errors) { print_input_errors($input_errors); } else { $ds = split("\+\+\+\+", $data); $revision = $_REQUEST['download']; $sha256sum = $ds[0]; if ($sha256sum == "0") { $sha256sum = "None on file."; } $data = $ds[1]; $configtype = "Encrypted"; if (!tagfile_deformat($data, $data, "config.xml")) { $input_errors[] = "The downloaded file does not appear to contain an encrypted pfSense configuration."; } $data = htmlentities(decrypt_data($data, $decrypt_password)); if (!strstr($data, "pfsense")) { $data = "Could not decrypt. Different encryption key?"; $input_errors[] = "Could not decrypt config.xml"; } echo "

Hostname

"; echo ""; echo "

Revision date/time

"; echo ""; echo "

Revision reason

"; echo ""; echo "

SHA256 summary

"; echo ""; echo "

Encrypted config.xml

"; echo ""; echo "

Decrypted config.xml

"; echo ""; } if (!$input_errors) { echo "
"; } echo ""; echo "
"; require("fend.inc"); exit; } // Populate available backups $curl_session = curl_init(); curl_setopt($curl_session, CURLOPT_URL, $get_url); curl_setopt($curl_session, CURLOPT_HTTPHEADER, array("Authorization: Basic " . base64_encode("{$username}:{$password}"))); if ($pf_version < 2.2) { // pre-2.2 doesn't have ca-root-nss curl_setopt($curl_session, CURLOPT_SSL_VERIFYPEER, 0); } else { curl_setopt($curl_session, CURLOPT_SSL_VERIFYPEER, 1); } curl_setopt($curl_session, CURLOPT_POST, 1); curl_setopt($curl_session, CURLOPT_RETURNTRANSFER, 1); curl_setopt($curl_session, CURLOPT_POSTFIELDS, "action=showbackups&hostname={$hostname}"); curl_setopt($curl_session, CURLOPT_USERAGENT, $g['product_name'] . '/' . rtrim(file_get_contents("/etc/version"))); // Proxy curl_setopt_array($curl_session, configure_proxy()); $data = curl_exec($curl_session); if (curl_errno($curl_session)) { $fd = fopen("/tmp/acb_backupdebug.txt", "w"); fwrite($fd, $get_url . "" . "action=showbackups" . "\n\n"); fwrite($fd, $data); fwrite($fd, curl_error($curl_session)); fclose($fd); } else { curl_close($curl_session); } // Loop through and create new confvers $data_split = split("\n", $data); $confvers = array(); foreach ($data_split as $ds) { $ds_split = split($oper_sep, $ds); $tmp_array = array(); $tmp_array['username'] = $ds_split[0]; $tmp_array['reason'] = $ds_split[1]; $tmp_array['time'] = $ds_split[2]; /* Convert the time from server time to local. See #5250 */ $budate = new DateTime($tmp_array['time'], $acbtz); $budate->setTimezone($mytz); $tmp_array['localtime'] = $budate->format(DATE_RFC2822); if ($ds_split[2] && $ds_split[0]) { $confvers[] = $tmp_array; } } if ($input_errors) { print_input_errors($input_errors); } ?>
Hostname:
Date Configuration Change "; echo "$('loading').innerHTML = '';"; echo ""; foreach ($confvers as $cv): ?> Sorry, we could not locate any backups at portal.pfsense.org for this hostname ({$hostname})."; } else { echo "
Backups hosted currently for this hostname on portal.pfsense.org: {$counter}."; } ?>
  Hint: Click the + sign next to the revision you would like to restore.