fix: Use library config for Windows OpenSSL
This commit is contained in:
parent
31e1c8da84
commit
2d732a4b9d
5 changed files with 18 additions and 124 deletions
4
res/dist/wix/Product.wxs
vendored
4
res/dist/wix/Product.wxs
vendored
|
|
@ -146,8 +146,8 @@
|
|||
<File Id="OpenSSLDll1" Source="$(var.OpenSslDllDir)/libcrypto-3.dll"/>
|
||||
<File Id="OpenSSLDll2" Source="$(var.OpenSslDllDir)/libssl-3.dll"/>
|
||||
<?endif ?>
|
||||
<File Source="$(var.OpenSslExeDir)/openssl.exe"/>
|
||||
<File Source="$(var.ResPath)/openssl/deskflow.conf"/>
|
||||
<File Source="$(var.OpenSslExeDir)/openssl.exe"/>
|
||||
<File Source="$(var.OpenSslExeDir)/openssl.cnf"/>
|
||||
</Component>
|
||||
</ComponentGroup>
|
||||
</Fragment>
|
||||
|
|
|
|||
|
|
@ -1,65 +0,0 @@
|
|||
#
|
||||
# Deskflow OpenSSL configuration file.
|
||||
# Used for generation of certificate requests.
|
||||
#
|
||||
|
||||
dir = .
|
||||
|
||||
[ca]
|
||||
default_ca = CA_default
|
||||
|
||||
[CA_default]
|
||||
serial = $dir/serial
|
||||
database = $dir/certindex.txt
|
||||
new_certs_dir = $dir/certs
|
||||
certificate = $dir/cacert.pem
|
||||
private_key = $dir/private/cakey.pem
|
||||
default_days = 365
|
||||
default_md = sha256
|
||||
preserve = no
|
||||
email_in_dn = no
|
||||
nameopt = default_ca
|
||||
certopt = default_ca
|
||||
policy = policy_match
|
||||
|
||||
[policy_match]
|
||||
countryName = match
|
||||
stateOrProvinceName = match
|
||||
organizationName = match
|
||||
organizationalUnitName = optional
|
||||
commonName = supplied
|
||||
emailAddress = optional
|
||||
|
||||
[req]
|
||||
default_bits = 1024 # Size of keys
|
||||
default_keyfile = key.pem # name of generated keys
|
||||
default_md = sha256 # message digest algorithm
|
||||
string_mask = nombstr # permitted characters
|
||||
distinguished_name = req_distinguished_name
|
||||
req_extensions = v3_req
|
||||
|
||||
[req_distinguished_name]
|
||||
0.organizationName = Organization Name (company)
|
||||
organizationalUnitName = Organizational Unit Name (department, division)
|
||||
emailAddress = Email Address
|
||||
emailAddress_max = 40
|
||||
localityName = Locality Name (city, district)
|
||||
stateOrProvinceName = State or Province Name (full name)
|
||||
countryName = Country Name (2 letter code)
|
||||
countryName_min = 2
|
||||
countryName_max = 2
|
||||
commonName = Common Name (hostname, IP, or your name)
|
||||
commonName_max = 64
|
||||
0.organizationName_default = My Company
|
||||
localityName_default = My Town
|
||||
stateOrProvinceName_default = State or Providence
|
||||
countryName_default = US
|
||||
|
||||
[v3_ca]
|
||||
basicConstraints = CA:TRUE
|
||||
subjectKeyIdentifier = hash
|
||||
authorityKeyIdentifier = keyid:always,issuer:always
|
||||
|
||||
[v3_req]
|
||||
basicConstraints = CA:FALSE
|
||||
subjectKeyIdentifier = hash
|
||||
|
|
@ -138,11 +138,6 @@ void SettingsDialog::on_m_pPushButtonTlsCertPath_clicked() {
|
|||
qDebug("no tls certificate file at: %s", qUtf8Printable(fileName));
|
||||
}
|
||||
}
|
||||
updateTlsRegenerateButton();
|
||||
}
|
||||
|
||||
void SettingsDialog::on_m_pComboBoxTlsKeyLength_currentIndexChanged(int) {
|
||||
updateTlsRegenerateButton();
|
||||
}
|
||||
|
||||
void SettingsDialog::on_m_pPushButtonTlsRegenCert_clicked() {
|
||||
|
|
@ -277,18 +272,6 @@ bool SettingsDialog::isClientMode() const {
|
|||
return m_coreProcess.mode() == deskflow::gui::CoreProcess::Mode::Client;
|
||||
}
|
||||
|
||||
void SettingsDialog::updateTlsRegenerateButton() {
|
||||
const auto writable = m_appConfig.isActiveScopeWritable();
|
||||
const auto keyLength = m_pComboBoxTlsKeyLength->currentText().toInt();
|
||||
const auto path = m_pLineEditTlsCertPath->text();
|
||||
const auto keyChanged = m_appConfig.tlsKeyLength() != keyLength;
|
||||
const auto pathChanged = m_appConfig.tlsCertPath() != path;
|
||||
const auto tlsEnabled = m_pCheckBoxEnableTls->isChecked();
|
||||
|
||||
m_pPushButtonTlsRegenCert->setEnabled(
|
||||
writable && tlsEnabled && (keyChanged || pathChanged));
|
||||
}
|
||||
|
||||
void SettingsDialog::updateKeyLengthOnFile(const QString &path) {
|
||||
TlsCertificate ssl;
|
||||
if (!QFile(path).exists()) {
|
||||
|
|
@ -337,7 +320,5 @@ void SettingsDialog::updateControls() {
|
|||
m_pLineEditLogFilename->setEnabled(writable && logToFile);
|
||||
m_pButtonBrowseLog->setEnabled(writable && logToFile);
|
||||
|
||||
updateTlsControlsEnabled();
|
||||
updateTlsRegenerateButton();
|
||||
updateTlsControls();
|
||||
}
|
||||
|
|
|
|||
|
|
@ -53,7 +53,6 @@ private slots:
|
|||
void on_m_pButtonBrowseLog_clicked();
|
||||
void on_m_pRadioSystemScope_toggled(bool checked);
|
||||
void on_m_pPushButtonTlsCertPath_clicked();
|
||||
void on_m_pComboBoxTlsKeyLength_currentIndexChanged(int index);
|
||||
void on_m_pPushButtonTlsRegenCert_clicked();
|
||||
void on_m_pCheckBoxServiceEnabled_toggled(bool checked);
|
||||
|
||||
|
|
|
|||
|
|
@ -18,7 +18,6 @@
|
|||
#include "TlsCertificate.h"
|
||||
|
||||
#include "TlsFingerprint.h"
|
||||
#include "gui/paths.h"
|
||||
|
||||
#include <QCoreApplication>
|
||||
#include <QDir>
|
||||
|
|
@ -32,13 +31,11 @@ static const char *const kCertificateSubjectInfo = "/CN=Deskflow";
|
|||
#if defined(Q_OS_WIN)
|
||||
static const char *const kWinOpenSslDir = "OpenSSL";
|
||||
static const char *const kWinOpenSslBinary = "openssl.exe";
|
||||
static const char *const kConfigFile = "deskflow.conf";
|
||||
static const char *const kConfigFile = "openssl.cnf";
|
||||
#elif defined(Q_OS_UNIX)
|
||||
static const char *const kUnixOpenSslCommand = "openssl";
|
||||
#endif
|
||||
|
||||
using namespace deskflow::gui;
|
||||
|
||||
#if defined(Q_OS_WIN)
|
||||
|
||||
namespace deskflow::gui {
|
||||
|
|
@ -90,61 +87,43 @@ using namespace deskflow::gui;
|
|||
TlsCertificate::TlsCertificate(QObject *parent) : QObject(parent) {}
|
||||
|
||||
bool TlsCertificate::runTool(const QStringList &args) {
|
||||
QString program;
|
||||
#if defined(Q_OS_WIN)
|
||||
program = openSslWindowsBinary();
|
||||
const auto program = openSslWindowsBinary();
|
||||
#else
|
||||
program = kUnixOpenSslCommand;
|
||||
const auto program = kUnixOpenSslCommand;
|
||||
#endif
|
||||
|
||||
QStringList environment;
|
||||
#if defined(Q_OS_WIN)
|
||||
auto openSslDir = QDir(openSslWindowsDir());
|
||||
auto config = QDir::cleanPath(openSslDir.filePath(kConfigFile));
|
||||
if (!QFile::exists(config)) {
|
||||
qDebug("openssl config file not found: %s", qUtf8Printable(config));
|
||||
|
||||
// if the expected production file location doesn't exist, try the dev path.
|
||||
config = QDir::cleanPath(QString("res/openssl/%1").arg(kConfigFile));
|
||||
|
||||
// if it still isn't there, then there's something seriously wrong.
|
||||
if (!QFile::exists(config)) {
|
||||
qFatal() << "openssl config file not found: " << config;
|
||||
}
|
||||
}
|
||||
|
||||
const auto openSslDir = QDir(openSslWindowsDir());
|
||||
const auto config = QDir::cleanPath(openSslDir.filePath(kConfigFile));
|
||||
environment << QString("OPENSSL_CONF=%1").arg(config);
|
||||
#endif
|
||||
|
||||
QProcess process;
|
||||
process.setEnvironment(environment);
|
||||
for (const auto &envVar : environment) {
|
||||
qDebug("set env var: %s", qUtf8Printable(envVar));
|
||||
}
|
||||
|
||||
qDebug(
|
||||
"running: %s %s", qUtf8Printable(program),
|
||||
qUtf8Printable(args.join(" ")));
|
||||
|
||||
QProcess process;
|
||||
|
||||
for (const auto &envVar : environment) {
|
||||
qDebug("setting env var %s", qUtf8Printable(envVar));
|
||||
}
|
||||
|
||||
process.setEnvironment(environment);
|
||||
|
||||
process.start(program, args);
|
||||
|
||||
bool success = process.waitForStarted();
|
||||
|
||||
QString stderrOutput;
|
||||
QString toolStderr;
|
||||
if (success && process.waitForFinished()) {
|
||||
m_toolStdout = process.readAllStandardOutput().trimmed();
|
||||
stderrOutput = process.readAllStandardError().trimmed();
|
||||
toolStderr = process.readAllStandardError().trimmed();
|
||||
}
|
||||
|
||||
if (int code = process.exitCode(); !success || code != 0) {
|
||||
qDebug(
|
||||
"openssl failed with code %d: %s", code, qUtf8Printable(stderrOutput));
|
||||
qDebug("openssl failed with code %d: %s", code, qUtf8Printable(toolStderr));
|
||||
|
||||
qCritical(
|
||||
"failed to generate TLS certificate:\n\n%s",
|
||||
qUtf8Printable(stderrOutput));
|
||||
"failed to generate tls certificate:\n\n%s",
|
||||
qUtf8Printable(toolStderr));
|
||||
return false;
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue