-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathcheck_resolved-dnssec
80 lines (67 loc) · 2.35 KB
/
check_resolved-dnssec
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
#!/usr/bin/env python3
#-------------------------------------------------------------------------------
import argparse
import sys
import os
import subprocess
import platform
#-------------------------------------------------------------------------------
_candebug = False
def candebug():
global _candebug
return _candebug
def setcandebug(value):
global _candebug
_candebug = value
def infomsg(msg):
if candebug() == True:
print(msg, flush=True)
def exitnagios(status,message):
if status=="OK":
exitcode = 0
elif status=="WARNING":
exitcode = 1
elif status=="CRITICAL":
exitcode = 2
elif status=="UNKNOWN":
exitcode = 3
else:
exitcode = 4
print(status+": "+message, flush=True)
sys.exit(exitcode)
#-------------------------------------------------------------------------------
def doresolveddnsseccall():
cmdline = ["/usr/bin/resolvectl","dnssec"]
completedproc = subprocess.run(cmdline,capture_output=True)
output = completedproc.stdout.decode("utf-8").strip()
errors = completedproc.stderr.decode("utf-8").strip()
exitcode = completedproc.returncode
if exitcode == 0:
allenabled = True
failed = []
for line in output.splitlines():
parts = line.split()
if parts[-1].lower() != "yes":
if parts[0].lower() == "global":
failed.append("Global")
else:
failed.append(parts[2].replace("(","").replace(")",""))
if allenabled:
exitnagios("OK","all interfaces have dnssec activated")
else:
exitnagios("CRITICAL","some interfaces do not have dnssec activated: "+", ".join(failed))
else:
exitnagios("CRITICAL","issue retrieving ospf routes")
#-------------------------------------------------------------------------------
def parse_args():
parser = argparse.ArgumentParser()
parser.add_argument("-®", "--debug", action="store_true", dest="debug", default=False, help="be more verbose")
args = parser.parse_args()
return args
def main():
args = parse_args()
setcandebug(args.debug)
doresolveddnsseccall()
if __name__ == "__main__":
main()
#-------------------------------------------------------------------------------