2024-07-26 22:53:52 +00:00
|
|
|
/*
|
2024-09-17 19:00:25 +00:00
|
|
|
* Deskflow -- mouse and keyboard sharing utility
|
2025-11-22 15:06:20 +00:00
|
|
|
* SPDX-FileCopyrightText: (C) 2025 Deskflow Developers
|
2025-01-24 00:11:17 +00:00
|
|
|
* SPDX-FileCopyrightText: (C) 2024 Symless Ltd.
|
|
|
|
|
* SPDX-License-Identifier: GPL-2.0-only WITH LicenseRef-OpenSSL-Exception
|
2024-07-26 22:53:52 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
|
|
#include "TlsUtility.h"
|
|
|
|
|
|
2025-03-06 23:08:08 +00:00
|
|
|
#include "common/Settings.h"
|
2025-11-22 15:29:47 +00:00
|
|
|
#include "net/SecureUtils.h"
|
2025-11-22 15:06:20 +00:00
|
|
|
|
2024-08-10 23:58:24 +00:00
|
|
|
#include <QFile>
|
2025-11-22 15:06:20 +00:00
|
|
|
#include <QSslCertificate>
|
|
|
|
|
#include <QSslKey>
|
2024-08-07 14:05:18 +00:00
|
|
|
#include <QString>
|
|
|
|
|
|
2025-11-22 17:47:33 +00:00
|
|
|
namespace deskflow::gui::TlsUtility {
|
2024-07-26 22:53:52 +00:00
|
|
|
|
2025-11-22 17:47:33 +00:00
|
|
|
bool isEnabled()
|
2024-10-17 18:04:35 +00:00
|
|
|
{
|
2025-03-06 23:08:08 +00:00
|
|
|
return Settings::value(Settings::Security::TlsEnabled).toBool();
|
2024-07-26 22:53:52 +00:00
|
|
|
}
|
|
|
|
|
|
2025-11-22 17:47:33 +00:00
|
|
|
bool isCertValid(const QString &certPath)
|
2025-11-22 15:06:20 +00:00
|
|
|
{
|
|
|
|
|
const auto certs = QSslCertificate::fromPath(certPath);
|
|
|
|
|
if (certs.isEmpty()) {
|
|
|
|
|
//: %1 will be replaced by the certificate path
|
2025-11-22 17:47:33 +00:00
|
|
|
qDebug() << QObject::tr("failed to read key from certificate file: %1").arg(certPath);
|
2025-11-22 15:06:20 +00:00
|
|
|
return false;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
const auto cert = certs.first();
|
|
|
|
|
if (cert.isNull()) {
|
|
|
|
|
//: %1 will be replaced by the certificate path
|
2025-11-22 17:47:33 +00:00
|
|
|
qDebug() << QObject::tr("failed to parse certificate file: %1").arg(certPath);
|
2025-11-22 15:06:20 +00:00
|
|
|
return false;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
const auto key = cert.publicKey();
|
|
|
|
|
if (key.isNull()) {
|
|
|
|
|
//: %1 will be replaced by the certificate path
|
2025-11-22 17:47:33 +00:00
|
|
|
qDebug() << QObject::tr("failed to read key from certificate file: %1").arg(certPath);
|
2025-11-22 15:06:20 +00:00
|
|
|
return false;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if (key.length() != Settings::value(Settings::Security::KeySize).toInt()) {
|
2025-11-22 17:47:33 +00:00
|
|
|
qDebug() << QObject::tr("key detected is the incorrect size");
|
2025-11-22 15:06:20 +00:00
|
|
|
return false;
|
|
|
|
|
}
|
|
|
|
|
|
2025-11-25 03:13:57 +00:00
|
|
|
if (key.algorithm() != QSsl::Rsa) {
|
2025-11-22 15:06:20 +00:00
|
|
|
//: %1 will be replaced by the certificate path
|
2025-11-25 03:13:57 +00:00
|
|
|
qDebug() << QObject::tr("failed to read RSA key from certificate file: %1").arg(certPath);
|
2025-11-22 15:06:20 +00:00
|
|
|
return false;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return true;
|
|
|
|
|
}
|
|
|
|
|
|
2025-11-22 17:47:33 +00:00
|
|
|
int getCertKeyLength(const QString &certPath)
|
2025-11-22 15:29:47 +00:00
|
|
|
{
|
2025-11-25 02:45:16 +00:00
|
|
|
QFile file(certPath);
|
|
|
|
|
if (!file.open(QFile::ReadOnly)) {
|
|
|
|
|
//: %1 will be replaced by the certificate path
|
|
|
|
|
qDebug() << QObject::tr("failed to read key from certificate file: %1").arg(certPath);
|
|
|
|
|
return -1;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
const auto key = QSslKey(&file, QSsl::Rsa);
|
|
|
|
|
if (key.isNull()) {
|
|
|
|
|
//: %1 will be replaced by the certificate path
|
|
|
|
|
qDebug() << QObject::tr("failed to parse certificate file: %1").arg(certPath);
|
|
|
|
|
return -1;
|
|
|
|
|
}
|
|
|
|
|
return key.length();
|
2025-11-22 15:29:47 +00:00
|
|
|
}
|
|
|
|
|
|
2025-11-22 17:47:33 +00:00
|
|
|
QByteArray certFingerprint(const QString &certPath)
|
2025-11-22 15:51:39 +00:00
|
|
|
{
|
|
|
|
|
QByteArray fingerprint;
|
|
|
|
|
|
|
|
|
|
const auto certs = QSslCertificate::fromPath(certPath);
|
|
|
|
|
if (certs.isEmpty()) {
|
|
|
|
|
//: %1 will be replaced by the certificate path
|
2025-11-22 17:47:33 +00:00
|
|
|
qDebug() << QObject::tr("failed to read key from certificate file: %1").arg(certPath);
|
2025-11-22 15:51:39 +00:00
|
|
|
return fingerprint;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
const auto cert = certs.first();
|
|
|
|
|
if (cert.isNull()) {
|
|
|
|
|
//: %1 will be replaced by the certificate path
|
2025-11-22 17:47:33 +00:00
|
|
|
qWarning() << QObject::tr("failed to parse certificate file: %1").arg(certPath);
|
2025-11-22 15:51:39 +00:00
|
|
|
return fingerprint;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return cert.digest(QCryptographicHash::Sha256);
|
|
|
|
|
}
|
|
|
|
|
|
2025-11-22 17:47:33 +00:00
|
|
|
bool generateCertificate()
|
2024-10-17 18:04:35 +00:00
|
|
|
{
|
2025-03-11 00:21:57 +00:00
|
|
|
qDebug(
|
|
|
|
|
"generating tls certificate, "
|
|
|
|
|
"all clients must trust the new fingerprint"
|
|
|
|
|
);
|
2024-08-03 00:17:29 +00:00
|
|
|
|
2025-11-22 17:35:41 +00:00
|
|
|
const auto keyLength = std::max(2048, Settings::value(Settings::Security::KeySize).toInt());
|
|
|
|
|
const auto certPath = Settings::value(Settings::Security::Certificate).toString();
|
2025-06-16 01:21:16 +00:00
|
|
|
|
2025-11-22 17:35:41 +00:00
|
|
|
QFileInfo info(certPath);
|
|
|
|
|
if (QDir dir(info.absolutePath()); !dir.exists() && !dir.mkpath(".")) {
|
|
|
|
|
qCritical("failed to create directory for tls certificate");
|
|
|
|
|
return false;
|
2025-06-16 01:21:16 +00:00
|
|
|
}
|
|
|
|
|
|
2025-11-22 17:35:41 +00:00
|
|
|
try {
|
2025-12-05 20:52:40 +00:00
|
|
|
deskflow::generatePemSelfSignedCert(certPath, keyLength);
|
2025-11-22 17:35:41 +00:00
|
|
|
} catch (const std::exception &e) {
|
|
|
|
|
qCritical() << "failed to generate self-signed pem cert: " << e.what();
|
|
|
|
|
return false;
|
|
|
|
|
}
|
|
|
|
|
qDebug("tls certificate generated");
|
|
|
|
|
return true;
|
2024-08-10 23:58:24 +00:00
|
|
|
}
|
|
|
|
|
|
2025-11-22 17:47:33 +00:00
|
|
|
} // namespace deskflow::gui::TlsUtility
|