fix: Use library config for Windows OpenSSL

This commit is contained in:
Nick Bolton 2024-10-01 08:52:10 +01:00
parent 31e1c8da84
commit 2d732a4b9d
5 changed files with 18 additions and 124 deletions

View file

@ -146,8 +146,8 @@
<File Id="OpenSSLDll1" Source="$(var.OpenSslDllDir)/libcrypto-3.dll"/>
<File Id="OpenSSLDll2" Source="$(var.OpenSslDllDir)/libssl-3.dll"/>
<?endif ?>
<File Source="$(var.OpenSslExeDir)/openssl.exe"/>
<File Source="$(var.ResPath)/openssl/deskflow.conf"/>
<File Source="$(var.OpenSslExeDir)/openssl.exe"/>
<File Source="$(var.OpenSslExeDir)/openssl.cnf"/>
</Component>
</ComponentGroup>
</Fragment>

View file

@ -1,65 +0,0 @@
#
# Deskflow OpenSSL configuration file.
# Used for generation of certificate requests.
#
dir = .
[ca]
default_ca = CA_default
[CA_default]
serial = $dir/serial
database = $dir/certindex.txt
new_certs_dir = $dir/certs
certificate = $dir/cacert.pem
private_key = $dir/private/cakey.pem
default_days = 365
default_md = sha256
preserve = no
email_in_dn = no
nameopt = default_ca
certopt = default_ca
policy = policy_match
[policy_match]
countryName = match
stateOrProvinceName = match
organizationName = match
organizationalUnitName = optional
commonName = supplied
emailAddress = optional
[req]
default_bits = 1024 # Size of keys
default_keyfile = key.pem # name of generated keys
default_md = sha256 # message digest algorithm
string_mask = nombstr # permitted characters
distinguished_name = req_distinguished_name
req_extensions = v3_req
[req_distinguished_name]
0.organizationName = Organization Name (company)
organizationalUnitName = Organizational Unit Name (department, division)
emailAddress = Email Address
emailAddress_max = 40
localityName = Locality Name (city, district)
stateOrProvinceName = State or Province Name (full name)
countryName = Country Name (2 letter code)
countryName_min = 2
countryName_max = 2
commonName = Common Name (hostname, IP, or your name)
commonName_max = 64
0.organizationName_default = My Company
localityName_default = My Town
stateOrProvinceName_default = State or Providence
countryName_default = US
[v3_ca]
basicConstraints = CA:TRUE
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer:always
[v3_req]
basicConstraints = CA:FALSE
subjectKeyIdentifier = hash

View file

@ -138,11 +138,6 @@ void SettingsDialog::on_m_pPushButtonTlsCertPath_clicked() {
qDebug("no tls certificate file at: %s", qUtf8Printable(fileName));
}
}
updateTlsRegenerateButton();
}
void SettingsDialog::on_m_pComboBoxTlsKeyLength_currentIndexChanged(int) {
updateTlsRegenerateButton();
}
void SettingsDialog::on_m_pPushButtonTlsRegenCert_clicked() {
@ -277,18 +272,6 @@ bool SettingsDialog::isClientMode() const {
return m_coreProcess.mode() == deskflow::gui::CoreProcess::Mode::Client;
}
void SettingsDialog::updateTlsRegenerateButton() {
const auto writable = m_appConfig.isActiveScopeWritable();
const auto keyLength = m_pComboBoxTlsKeyLength->currentText().toInt();
const auto path = m_pLineEditTlsCertPath->text();
const auto keyChanged = m_appConfig.tlsKeyLength() != keyLength;
const auto pathChanged = m_appConfig.tlsCertPath() != path;
const auto tlsEnabled = m_pCheckBoxEnableTls->isChecked();
m_pPushButtonTlsRegenCert->setEnabled(
writable && tlsEnabled && (keyChanged || pathChanged));
}
void SettingsDialog::updateKeyLengthOnFile(const QString &path) {
TlsCertificate ssl;
if (!QFile(path).exists()) {
@ -337,7 +320,5 @@ void SettingsDialog::updateControls() {
m_pLineEditLogFilename->setEnabled(writable && logToFile);
m_pButtonBrowseLog->setEnabled(writable && logToFile);
updateTlsControlsEnabled();
updateTlsRegenerateButton();
updateTlsControls();
}

View file

@ -53,7 +53,6 @@ private slots:
void on_m_pButtonBrowseLog_clicked();
void on_m_pRadioSystemScope_toggled(bool checked);
void on_m_pPushButtonTlsCertPath_clicked();
void on_m_pComboBoxTlsKeyLength_currentIndexChanged(int index);
void on_m_pPushButtonTlsRegenCert_clicked();
void on_m_pCheckBoxServiceEnabled_toggled(bool checked);

View file

@ -18,7 +18,6 @@
#include "TlsCertificate.h"
#include "TlsFingerprint.h"
#include "gui/paths.h"
#include <QCoreApplication>
#include <QDir>
@ -32,13 +31,11 @@ static const char *const kCertificateSubjectInfo = "/CN=Deskflow";
#if defined(Q_OS_WIN)
static const char *const kWinOpenSslDir = "OpenSSL";
static const char *const kWinOpenSslBinary = "openssl.exe";
static const char *const kConfigFile = "deskflow.conf";
static const char *const kConfigFile = "openssl.cnf";
#elif defined(Q_OS_UNIX)
static const char *const kUnixOpenSslCommand = "openssl";
#endif
using namespace deskflow::gui;
#if defined(Q_OS_WIN)
namespace deskflow::gui {
@ -90,61 +87,43 @@ using namespace deskflow::gui;
TlsCertificate::TlsCertificate(QObject *parent) : QObject(parent) {}
bool TlsCertificate::runTool(const QStringList &args) {
QString program;
#if defined(Q_OS_WIN)
program = openSslWindowsBinary();
const auto program = openSslWindowsBinary();
#else
program = kUnixOpenSslCommand;
const auto program = kUnixOpenSslCommand;
#endif
QStringList environment;
#if defined(Q_OS_WIN)
auto openSslDir = QDir(openSslWindowsDir());
auto config = QDir::cleanPath(openSslDir.filePath(kConfigFile));
if (!QFile::exists(config)) {
qDebug("openssl config file not found: %s", qUtf8Printable(config));
// if the expected production file location doesn't exist, try the dev path.
config = QDir::cleanPath(QString("res/openssl/%1").arg(kConfigFile));
// if it still isn't there, then there's something seriously wrong.
if (!QFile::exists(config)) {
qFatal() << "openssl config file not found: " << config;
}
}
const auto openSslDir = QDir(openSslWindowsDir());
const auto config = QDir::cleanPath(openSslDir.filePath(kConfigFile));
environment << QString("OPENSSL_CONF=%1").arg(config);
#endif
QProcess process;
process.setEnvironment(environment);
for (const auto &envVar : environment) {
qDebug("set env var: %s", qUtf8Printable(envVar));
}
qDebug(
"running: %s %s", qUtf8Printable(program),
qUtf8Printable(args.join(" ")));
QProcess process;
for (const auto &envVar : environment) {
qDebug("setting env var %s", qUtf8Printable(envVar));
}
process.setEnvironment(environment);
process.start(program, args);
bool success = process.waitForStarted();
QString stderrOutput;
QString toolStderr;
if (success && process.waitForFinished()) {
m_toolStdout = process.readAllStandardOutput().trimmed();
stderrOutput = process.readAllStandardError().trimmed();
toolStderr = process.readAllStandardError().trimmed();
}
if (int code = process.exitCode(); !success || code != 0) {
qDebug(
"openssl failed with code %d: %s", code, qUtf8Printable(stderrOutput));
qDebug("openssl failed with code %d: %s", code, qUtf8Printable(toolStderr));
qCritical(
"failed to generate TLS certificate:\n\n%s",
qUtf8Printable(stderrOutput));
"failed to generate tls certificate:\n\n%s",
qUtf8Printable(toolStderr));
return false;
}