#!/bin/sh
# IPsec startup and shutdown script

prog='ipsec setup'		# for messages

# where the private directory and the config files are
IPSEC_EXECDIR="${IPSEC_EXECDIR-/libexec/ipsec}"
IPSEC_LIBDIR="${IPSEC_LIBDIR-/lib/ipsec}"
IPSEC_SBINDIR="${IPSEC_SBINDIR-/sbin}"
IPSEC_CONFS="${IPSEC_CONFS-/etc}"

if test " $IPSEC_DIR" = " "	# if we were not called by the ipsec command
then
    # we must establish a suitable PATH ourselves
    PATH="${IPSEC_SBINDIR}":/sbin:/usr/sbin:/usr/local/bin:/bin:/usr/bin
    export PATH

    IPSEC_DIR="$IPSEC_LIBDIR"
    export IPSEC_DIR IPSEC_CONFS IPSEC_LIBDIR IPSEC_EXECDIR
fi

# misc setup
umask 022

mkdir -p /var/run/pluto
if [ ! -f /var/lock/subsys ]; then
	mkdir -p /var/lock/subsys
fi

RETVAL=0

start() {
    test -x $IPSEC_SBINDIR/ipsec || exit 5
    test -f /etc/ipsec.conf || exit 6
    
    # Pick up IPsec configuration (until we have done this, successfully, we
    # do not know where errors should go, hence the explicit "daemon.error"s.)
    # Note the "--export", which exports the variables created.
    variables=`ipsec addconn /etc/ipsec.conf --varprefix IPSEC --configsetup`
    eval $variables
    if [ $? != 0 ]
    then
         echo "Failed to parse config setup portion of ipsec.conf"
         exit $?
    fi
    
    IPSEC_confreadsection=${IPSEC_confreadsection:-setup}
    export IPSEC_confreadsection

    IPSECsyslog=${IPSECsyslog-daemon.error}
    export IPSECsyslog

    # remove for: @cygwin_END@
    (
    ipsec _realsetup start
    RETVAL=$? 
    ) 2>&1 | logger -s -p $IPSECsyslog -t ipsec_setup 2>&1  
    return $RETVAL
}


stop() {
    IPSECsyslog=${IPSECsyslog-daemon.error}
    export IPSECsyslog
    (
    ipsec _realsetup stop
    RETVAL=$? 
    ) 2>&1 | logger -s -p $IPSECsyslog -t ipsec_setup 2>&1  
    return $RETVAL
}

restart() {
    stop
    start
}

condrestart() {
    test -x $IPSEC_SBINDIR/ipsec || exit 5
    ipsec _realsetup status || exit 0
    restart
}

status() {
    test -x $IPSEC_SBINDIR/ipsec || exit 5
    ipsec _realsetup status
    RETVAL=$?	
    return $RETVAL
}

version() {
    ipsec version
    RETVAL=$?
    return $RETVAL
}


# do it
case "$1" in
    start|--start)
         start
         ;;
    stop|--stop)
         stop
         ;;
    restart|--restart)
         restart
 	 ;;
    reload|force-reload)
         restart
 	 ;;
    condrestart|try-restart)
         condrestart
         ;;
    status|--status)
         status
         ;;
    version)
         version
         ;;
    *)
         echo $"Usage: $prog {start|stop|restart|reload|force-reload|condrestart|try-restart|status|version}"
 	 RETVAL=2
esac
 	
exit $RETVAL
