#!/bin/bash

# AlmaLinux 9 / RHEL 9 - SSH Root Login Fix Script

RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[1;33m'
BLUE='\033[0;34m'
NC='\033[0m'

if [[ $EUID -ne 0 ]]; then
   echo -e "${RED}Run this as root${NC}"
   exit 1
fi

SSH_CONFIG="/etc/ssh/sshd_config"

echo -e "${BLUE}=== AlmaLinux 9 SSH Root Login Fix ===${NC}\n"

# 1. Check RedHat drop-in override
echo -e "${YELLOW}[1] Checking /etc/ssh/sshd_config.d/ for overrides...${NC}"
if [ -d /etc/ssh/sshd_config.d ]; then
    for f in /etc/ssh/sshd_config.d/*.conf; do
        [ -e "$f" ] || continue
        if grep -qEi "^PermitRootLogin|^PasswordAuthentication" "$f" 2>/dev/null; then
            echo -e "${RED}Found in $f:${NC}"
            grep -Ei "^PermitRootLogin|^PasswordAuthentication" "$f"
        fi
    done
fi
echo ""

# 2. Fix main config
echo -e "${YELLOW}[2] Setting values in main sshd_config...${NC}"
sed -i '/^PermitRootLogin/d; /^#PermitRootLogin/d' "$SSH_CONFIG"
sed -i '/^PasswordAuthentication/d; /^#PasswordAuthentication/d' "$SSH_CONFIG"
echo "PermitRootLogin yes" >> "$SSH_CONFIG"
echo "PasswordAuthentication yes" >> "$SSH_CONFIG"
echo -e "${GREEN}Done${NC}"

# 3. Override any RedHat drop-in configs with highest-priority file
echo -e "${YELLOW}[3] Creating override drop-in (loads last, wins)...${NC}"
mkdir -p /etc/ssh/sshd_config.d
cat > /etc/ssh/sshd_config.d/zz-root-login.conf << 'EOF'
PermitRootLogin yes
PasswordAuthentication yes
EOF
echo -e "${GREEN}Created zz-root-login.conf${NC}"

# 4. Fix SELinux context (common AlmaLinux issue after manual edits)
echo -e "${YELLOW}[4] Restoring SELinux context on ssh config files...${NC}"
if command -v restorecon &>/dev/null; then
    restorecon -Rv /etc/ssh/ 2>/dev/null
    echo -e "${GREEN}SELinux context restored${NC}"
else
    echo "restorecon not available, skipping"
fi

# 5. Check/unlock root account
echo -e "${YELLOW}[5] Checking root account status...${NC}"
ROOT_STATUS=$(passwd -S root 2>/dev/null | awk '{print $2}')
echo "Status: $ROOT_STATUS"
if [[ "$ROOT_STATUS" == "L" || "$ROOT_STATUS" == "LK" ]]; then
    echo -e "${RED}Root is locked. Unlocking...${NC}"
    passwd -u root
    echo -e "${GREEN}Unlocked${NC}"
fi
if [[ "$ROOT_STATUS" == "NP" ]]; then
    echo -e "${RED}Root has no password. Set one now:${NC}"
    passwd root
fi

# 6. Open firewalld port 22 (usually open by default, but confirm)
echo -e "${YELLOW}[6] Checking firewalld for SSH access...${NC}"
if systemctl is-active --quiet firewalld; then
    if firewall-cmd --list-services | grep -qw ssh; then
        echo -e "${GREEN}SSH service already allowed in firewalld${NC}"
    else
        echo -e "${YELLOW}Adding ssh service to firewalld...${NC}"
        firewall-cmd --permanent --add-service=ssh
        firewall-cmd --reload
        echo -e "${GREEN}SSH allowed and firewall reloaded${NC}"
    fi
else
    echo "firewalld not active"
fi

# 7. Validate and restart sshd
echo -e "${YELLOW}[7] Validating and restarting sshd...${NC}"
sshd -t
if [ $? -eq 0 ]; then
    echo -e "${GREEN}Config valid${NC}"
    systemctl restart sshd
    systemctl status sshd --no-pager | head -5
    echo -e "${GREEN}sshd restarted${NC}"
else
    echo -e "${RED}Config has syntax errors — fix before restarting!${NC}"
    exit 1
fi

echo -e "\n${BLUE}=== Done ===${NC}"
echo -e "${YELLOW}Test with: ssh -v root@your_server_ip${NC}"
echo -e "${YELLOW}If it still fails, check: tail -f /var/log/secure${NC}"