fix: Use library config for Windows OpenSSL
This commit is contained in:
parent
31e1c8da84
commit
2d732a4b9d
5 changed files with 18 additions and 124 deletions
4
res/dist/wix/Product.wxs
vendored
4
res/dist/wix/Product.wxs
vendored
|
|
@ -146,8 +146,8 @@
|
||||||
<File Id="OpenSSLDll1" Source="$(var.OpenSslDllDir)/libcrypto-3.dll"/>
|
<File Id="OpenSSLDll1" Source="$(var.OpenSslDllDir)/libcrypto-3.dll"/>
|
||||||
<File Id="OpenSSLDll2" Source="$(var.OpenSslDllDir)/libssl-3.dll"/>
|
<File Id="OpenSSLDll2" Source="$(var.OpenSslDllDir)/libssl-3.dll"/>
|
||||||
<?endif ?>
|
<?endif ?>
|
||||||
<File Source="$(var.OpenSslExeDir)/openssl.exe"/>
|
<File Source="$(var.OpenSslExeDir)/openssl.exe"/>
|
||||||
<File Source="$(var.ResPath)/openssl/deskflow.conf"/>
|
<File Source="$(var.OpenSslExeDir)/openssl.cnf"/>
|
||||||
</Component>
|
</Component>
|
||||||
</ComponentGroup>
|
</ComponentGroup>
|
||||||
</Fragment>
|
</Fragment>
|
||||||
|
|
|
||||||
|
|
@ -1,65 +0,0 @@
|
||||||
#
|
|
||||||
# Deskflow OpenSSL configuration file.
|
|
||||||
# Used for generation of certificate requests.
|
|
||||||
#
|
|
||||||
|
|
||||||
dir = .
|
|
||||||
|
|
||||||
[ca]
|
|
||||||
default_ca = CA_default
|
|
||||||
|
|
||||||
[CA_default]
|
|
||||||
serial = $dir/serial
|
|
||||||
database = $dir/certindex.txt
|
|
||||||
new_certs_dir = $dir/certs
|
|
||||||
certificate = $dir/cacert.pem
|
|
||||||
private_key = $dir/private/cakey.pem
|
|
||||||
default_days = 365
|
|
||||||
default_md = sha256
|
|
||||||
preserve = no
|
|
||||||
email_in_dn = no
|
|
||||||
nameopt = default_ca
|
|
||||||
certopt = default_ca
|
|
||||||
policy = policy_match
|
|
||||||
|
|
||||||
[policy_match]
|
|
||||||
countryName = match
|
|
||||||
stateOrProvinceName = match
|
|
||||||
organizationName = match
|
|
||||||
organizationalUnitName = optional
|
|
||||||
commonName = supplied
|
|
||||||
emailAddress = optional
|
|
||||||
|
|
||||||
[req]
|
|
||||||
default_bits = 1024 # Size of keys
|
|
||||||
default_keyfile = key.pem # name of generated keys
|
|
||||||
default_md = sha256 # message digest algorithm
|
|
||||||
string_mask = nombstr # permitted characters
|
|
||||||
distinguished_name = req_distinguished_name
|
|
||||||
req_extensions = v3_req
|
|
||||||
|
|
||||||
[req_distinguished_name]
|
|
||||||
0.organizationName = Organization Name (company)
|
|
||||||
organizationalUnitName = Organizational Unit Name (department, division)
|
|
||||||
emailAddress = Email Address
|
|
||||||
emailAddress_max = 40
|
|
||||||
localityName = Locality Name (city, district)
|
|
||||||
stateOrProvinceName = State or Province Name (full name)
|
|
||||||
countryName = Country Name (2 letter code)
|
|
||||||
countryName_min = 2
|
|
||||||
countryName_max = 2
|
|
||||||
commonName = Common Name (hostname, IP, or your name)
|
|
||||||
commonName_max = 64
|
|
||||||
0.organizationName_default = My Company
|
|
||||||
localityName_default = My Town
|
|
||||||
stateOrProvinceName_default = State or Providence
|
|
||||||
countryName_default = US
|
|
||||||
|
|
||||||
[v3_ca]
|
|
||||||
basicConstraints = CA:TRUE
|
|
||||||
subjectKeyIdentifier = hash
|
|
||||||
authorityKeyIdentifier = keyid:always,issuer:always
|
|
||||||
|
|
||||||
[v3_req]
|
|
||||||
basicConstraints = CA:FALSE
|
|
||||||
subjectKeyIdentifier = hash
|
|
||||||
|
|
@ -138,11 +138,6 @@ void SettingsDialog::on_m_pPushButtonTlsCertPath_clicked() {
|
||||||
qDebug("no tls certificate file at: %s", qUtf8Printable(fileName));
|
qDebug("no tls certificate file at: %s", qUtf8Printable(fileName));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
updateTlsRegenerateButton();
|
|
||||||
}
|
|
||||||
|
|
||||||
void SettingsDialog::on_m_pComboBoxTlsKeyLength_currentIndexChanged(int) {
|
|
||||||
updateTlsRegenerateButton();
|
|
||||||
}
|
}
|
||||||
|
|
||||||
void SettingsDialog::on_m_pPushButtonTlsRegenCert_clicked() {
|
void SettingsDialog::on_m_pPushButtonTlsRegenCert_clicked() {
|
||||||
|
|
@ -277,18 +272,6 @@ bool SettingsDialog::isClientMode() const {
|
||||||
return m_coreProcess.mode() == deskflow::gui::CoreProcess::Mode::Client;
|
return m_coreProcess.mode() == deskflow::gui::CoreProcess::Mode::Client;
|
||||||
}
|
}
|
||||||
|
|
||||||
void SettingsDialog::updateTlsRegenerateButton() {
|
|
||||||
const auto writable = m_appConfig.isActiveScopeWritable();
|
|
||||||
const auto keyLength = m_pComboBoxTlsKeyLength->currentText().toInt();
|
|
||||||
const auto path = m_pLineEditTlsCertPath->text();
|
|
||||||
const auto keyChanged = m_appConfig.tlsKeyLength() != keyLength;
|
|
||||||
const auto pathChanged = m_appConfig.tlsCertPath() != path;
|
|
||||||
const auto tlsEnabled = m_pCheckBoxEnableTls->isChecked();
|
|
||||||
|
|
||||||
m_pPushButtonTlsRegenCert->setEnabled(
|
|
||||||
writable && tlsEnabled && (keyChanged || pathChanged));
|
|
||||||
}
|
|
||||||
|
|
||||||
void SettingsDialog::updateKeyLengthOnFile(const QString &path) {
|
void SettingsDialog::updateKeyLengthOnFile(const QString &path) {
|
||||||
TlsCertificate ssl;
|
TlsCertificate ssl;
|
||||||
if (!QFile(path).exists()) {
|
if (!QFile(path).exists()) {
|
||||||
|
|
@ -337,7 +320,5 @@ void SettingsDialog::updateControls() {
|
||||||
m_pLineEditLogFilename->setEnabled(writable && logToFile);
|
m_pLineEditLogFilename->setEnabled(writable && logToFile);
|
||||||
m_pButtonBrowseLog->setEnabled(writable && logToFile);
|
m_pButtonBrowseLog->setEnabled(writable && logToFile);
|
||||||
|
|
||||||
updateTlsControlsEnabled();
|
|
||||||
updateTlsRegenerateButton();
|
|
||||||
updateTlsControls();
|
updateTlsControls();
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -53,7 +53,6 @@ private slots:
|
||||||
void on_m_pButtonBrowseLog_clicked();
|
void on_m_pButtonBrowseLog_clicked();
|
||||||
void on_m_pRadioSystemScope_toggled(bool checked);
|
void on_m_pRadioSystemScope_toggled(bool checked);
|
||||||
void on_m_pPushButtonTlsCertPath_clicked();
|
void on_m_pPushButtonTlsCertPath_clicked();
|
||||||
void on_m_pComboBoxTlsKeyLength_currentIndexChanged(int index);
|
|
||||||
void on_m_pPushButtonTlsRegenCert_clicked();
|
void on_m_pPushButtonTlsRegenCert_clicked();
|
||||||
void on_m_pCheckBoxServiceEnabled_toggled(bool checked);
|
void on_m_pCheckBoxServiceEnabled_toggled(bool checked);
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -18,7 +18,6 @@
|
||||||
#include "TlsCertificate.h"
|
#include "TlsCertificate.h"
|
||||||
|
|
||||||
#include "TlsFingerprint.h"
|
#include "TlsFingerprint.h"
|
||||||
#include "gui/paths.h"
|
|
||||||
|
|
||||||
#include <QCoreApplication>
|
#include <QCoreApplication>
|
||||||
#include <QDir>
|
#include <QDir>
|
||||||
|
|
@ -32,13 +31,11 @@ static const char *const kCertificateSubjectInfo = "/CN=Deskflow";
|
||||||
#if defined(Q_OS_WIN)
|
#if defined(Q_OS_WIN)
|
||||||
static const char *const kWinOpenSslDir = "OpenSSL";
|
static const char *const kWinOpenSslDir = "OpenSSL";
|
||||||
static const char *const kWinOpenSslBinary = "openssl.exe";
|
static const char *const kWinOpenSslBinary = "openssl.exe";
|
||||||
static const char *const kConfigFile = "deskflow.conf";
|
static const char *const kConfigFile = "openssl.cnf";
|
||||||
#elif defined(Q_OS_UNIX)
|
#elif defined(Q_OS_UNIX)
|
||||||
static const char *const kUnixOpenSslCommand = "openssl";
|
static const char *const kUnixOpenSslCommand = "openssl";
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
using namespace deskflow::gui;
|
|
||||||
|
|
||||||
#if defined(Q_OS_WIN)
|
#if defined(Q_OS_WIN)
|
||||||
|
|
||||||
namespace deskflow::gui {
|
namespace deskflow::gui {
|
||||||
|
|
@ -90,61 +87,43 @@ using namespace deskflow::gui;
|
||||||
TlsCertificate::TlsCertificate(QObject *parent) : QObject(parent) {}
|
TlsCertificate::TlsCertificate(QObject *parent) : QObject(parent) {}
|
||||||
|
|
||||||
bool TlsCertificate::runTool(const QStringList &args) {
|
bool TlsCertificate::runTool(const QStringList &args) {
|
||||||
QString program;
|
|
||||||
#if defined(Q_OS_WIN)
|
#if defined(Q_OS_WIN)
|
||||||
program = openSslWindowsBinary();
|
const auto program = openSslWindowsBinary();
|
||||||
#else
|
#else
|
||||||
program = kUnixOpenSslCommand;
|
const auto program = kUnixOpenSslCommand;
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
QStringList environment;
|
QStringList environment;
|
||||||
#if defined(Q_OS_WIN)
|
#if defined(Q_OS_WIN)
|
||||||
auto openSslDir = QDir(openSslWindowsDir());
|
const auto openSslDir = QDir(openSslWindowsDir());
|
||||||
auto config = QDir::cleanPath(openSslDir.filePath(kConfigFile));
|
const auto config = QDir::cleanPath(openSslDir.filePath(kConfigFile));
|
||||||
if (!QFile::exists(config)) {
|
|
||||||
qDebug("openssl config file not found: %s", qUtf8Printable(config));
|
|
||||||
|
|
||||||
// if the expected production file location doesn't exist, try the dev path.
|
|
||||||
config = QDir::cleanPath(QString("res/openssl/%1").arg(kConfigFile));
|
|
||||||
|
|
||||||
// if it still isn't there, then there's something seriously wrong.
|
|
||||||
if (!QFile::exists(config)) {
|
|
||||||
qFatal() << "openssl config file not found: " << config;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
environment << QString("OPENSSL_CONF=%1").arg(config);
|
environment << QString("OPENSSL_CONF=%1").arg(config);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
|
QProcess process;
|
||||||
|
process.setEnvironment(environment);
|
||||||
|
for (const auto &envVar : environment) {
|
||||||
|
qDebug("set env var: %s", qUtf8Printable(envVar));
|
||||||
|
}
|
||||||
|
|
||||||
qDebug(
|
qDebug(
|
||||||
"running: %s %s", qUtf8Printable(program),
|
"running: %s %s", qUtf8Printable(program),
|
||||||
qUtf8Printable(args.join(" ")));
|
qUtf8Printable(args.join(" ")));
|
||||||
|
|
||||||
QProcess process;
|
|
||||||
|
|
||||||
for (const auto &envVar : environment) {
|
|
||||||
qDebug("setting env var %s", qUtf8Printable(envVar));
|
|
||||||
}
|
|
||||||
|
|
||||||
process.setEnvironment(environment);
|
|
||||||
|
|
||||||
process.start(program, args);
|
process.start(program, args);
|
||||||
|
|
||||||
bool success = process.waitForStarted();
|
bool success = process.waitForStarted();
|
||||||
|
|
||||||
QString stderrOutput;
|
QString toolStderr;
|
||||||
if (success && process.waitForFinished()) {
|
if (success && process.waitForFinished()) {
|
||||||
m_toolStdout = process.readAllStandardOutput().trimmed();
|
m_toolStdout = process.readAllStandardOutput().trimmed();
|
||||||
stderrOutput = process.readAllStandardError().trimmed();
|
toolStderr = process.readAllStandardError().trimmed();
|
||||||
}
|
}
|
||||||
|
|
||||||
if (int code = process.exitCode(); !success || code != 0) {
|
if (int code = process.exitCode(); !success || code != 0) {
|
||||||
qDebug(
|
qDebug("openssl failed with code %d: %s", code, qUtf8Printable(toolStderr));
|
||||||
"openssl failed with code %d: %s", code, qUtf8Printable(stderrOutput));
|
|
||||||
|
|
||||||
qCritical(
|
qCritical(
|
||||||
"failed to generate TLS certificate:\n\n%s",
|
"failed to generate tls certificate:\n\n%s",
|
||||||
qUtf8Printable(stderrOutput));
|
qUtf8Printable(toolStderr));
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue