parent
d0d5182425
commit
743c3feef3
7 changed files with 19 additions and 37 deletions
|
|
@ -54,10 +54,8 @@ bool TlsCertificate::generateFingerprint(const QString &certificateFilename)
|
|||
|
||||
auto localPath = QStringLiteral("%1/%2/%3").arg(profileDir, kSslDir, kFingerprintLocalFilename).toStdString();
|
||||
|
||||
const deskflow::FingerprintData data{"sha1", fingerprint};
|
||||
|
||||
deskflow::FingerprintDatabase db;
|
||||
db.addTrusted(data);
|
||||
db.addTrusted(fingerprint);
|
||||
db.write(localPath);
|
||||
|
||||
qDebug("tls fingerprint generated");
|
||||
|
|
|
|||
|
|
@ -4,7 +4,6 @@
|
|||
# SPDX-License-Identifier: MIT
|
||||
|
||||
add_library(net STATIC
|
||||
FingerprintTypes.h
|
||||
FingerprintData.cpp
|
||||
FingerprintData.h
|
||||
FingerprintDatabase.cpp
|
||||
|
|
|
|||
|
|
@ -7,14 +7,19 @@
|
|||
|
||||
#pragma once
|
||||
|
||||
#include "FingerprintTypes.h"
|
||||
|
||||
#include <cstdint>
|
||||
#include <string>
|
||||
#include <vector>
|
||||
|
||||
namespace deskflow {
|
||||
|
||||
enum FingerprintType
|
||||
{
|
||||
Invalid,
|
||||
SHA1,
|
||||
SHA256
|
||||
};
|
||||
|
||||
struct FingerprintData
|
||||
{
|
||||
std::string algorithm;
|
||||
|
|
|
|||
|
|
@ -1,18 +0,0 @@
|
|||
/*
|
||||
* Deskflow -- mouse and keyboard sharing utility
|
||||
* SPDX-FileCopyrightText: (C) 2025 Deskflow Developers
|
||||
* SPDX-License-Identifier: GPL-2.0-only WITH LicenseRef-OpenSSL-Exception
|
||||
*/
|
||||
|
||||
#pragma once
|
||||
|
||||
namespace deskflow {
|
||||
|
||||
enum FingerprintType
|
||||
{
|
||||
Invalid,
|
||||
SHA1,
|
||||
SHA256
|
||||
};
|
||||
|
||||
}
|
||||
|
|
@ -613,16 +613,15 @@ void SecureSocket::disconnect()
|
|||
bool SecureSocket::verifyCertFingerprint()
|
||||
{
|
||||
// calculate received certificate fingerprint
|
||||
std::vector<std::uint8_t> fingerprint_raw;
|
||||
deskflow::FingerprintData fingerprint;
|
||||
try {
|
||||
fingerprint_raw =
|
||||
deskflow::SSLCertFingerprint(SSL_get_peer_certificate(m_ssl->m_ssl), deskflow::FingerprintType::SHA1);
|
||||
fingerprint = deskflow::sslCertFingerprint(SSL_get_peer_certificate(m_ssl->m_ssl), deskflow::FingerprintType::SHA1);
|
||||
} catch (const std::exception &e) {
|
||||
LOG((CLOG_ERR "%s", e.what()));
|
||||
return false;
|
||||
}
|
||||
|
||||
LOG((CLOG_NOTE "server fingerprint: %s", deskflow::formatSSLFingerprint(fingerprint_raw).c_str()));
|
||||
LOG((CLOG_NOTE "server fingerprint: %s", deskflow::formatSSLFingerprint(fingerprint.data).c_str()));
|
||||
|
||||
std::string trustedServersFilename = deskflow::string::sprintf(
|
||||
"%s/%s/%s", ARCH->getProfileDirectory().c_str(), kSslDir, kFingerprintTrustedServersFilename
|
||||
|
|
@ -642,8 +641,6 @@ bool SecureSocket::verifyCertFingerprint()
|
|||
return false;
|
||||
}
|
||||
|
||||
deskflow::FingerprintData fingerprint{"sha1", fingerprint_raw};
|
||||
|
||||
if (!db.isTrusted(fingerprint)) {
|
||||
LOG((CLOG_WARN "fingerprint does not match trusted fingerprint"));
|
||||
return false;
|
||||
|
|
|
|||
|
|
@ -6,6 +6,7 @@
|
|||
*/
|
||||
|
||||
#include "SecureUtils.h"
|
||||
#include "FingerprintDatabase.h"
|
||||
#include "base/String.h"
|
||||
#include "base/finally.h"
|
||||
#include "io/filesystem.h"
|
||||
|
|
@ -50,7 +51,7 @@ std::string formatSSLFingerprint(const std::vector<uint8_t> &fingerprint, bool e
|
|||
return result;
|
||||
}
|
||||
|
||||
std::vector<uint8_t> SSLCertFingerprint(X509 *cert, FingerprintType type)
|
||||
FingerprintData sslCertFingerprint(X509 *cert, FingerprintType type)
|
||||
{
|
||||
if (!cert) {
|
||||
throw std::runtime_error("certificate is null");
|
||||
|
|
@ -66,10 +67,10 @@ std::vector<uint8_t> SSLCertFingerprint(X509 *cert, FingerprintType type)
|
|||
|
||||
std::vector<std::uint8_t> digestVec;
|
||||
digestVec.assign(reinterpret_cast<std::uint8_t *>(digest), reinterpret_cast<std::uint8_t *>(digest) + digestLength);
|
||||
return digestVec;
|
||||
return {fingerprintTypeToString(type), digestVec};
|
||||
}
|
||||
|
||||
std::vector<std::uint8_t> pemFileCertFingerprint(const std::string &path, FingerprintType type)
|
||||
FingerprintData pemFileCertFingerprint(const std::string &path, FingerprintType type)
|
||||
{
|
||||
auto fp = fopenUtf8Path(path, "r");
|
||||
if (!fp) {
|
||||
|
|
@ -83,7 +84,7 @@ std::vector<std::uint8_t> pemFileCertFingerprint(const std::string &path, Finger
|
|||
}
|
||||
auto certFree = finally([cert]() { X509_free(cert); });
|
||||
|
||||
return SSLCertFingerprint(cert, type);
|
||||
return sslCertFingerprint(cert, type);
|
||||
}
|
||||
|
||||
void generatePemSelfSignedCert(const std::string &path, int keyLength)
|
||||
|
|
|
|||
|
|
@ -7,7 +7,7 @@
|
|||
|
||||
#pragma once
|
||||
|
||||
#include "FingerprintTypes.h"
|
||||
#include "FingerprintData.h"
|
||||
|
||||
#include <cstdint>
|
||||
#include <openssl/ossl_typ.h>
|
||||
|
|
@ -24,9 +24,9 @@ namespace deskflow {
|
|||
*/
|
||||
std::string formatSSLFingerprint(const std::vector<uint8_t> &fingerprint, bool enableSeparators = true);
|
||||
|
||||
std::vector<std::uint8_t> SSLCertFingerprint(X509 *cert, FingerprintType type);
|
||||
FingerprintData sslCertFingerprint(X509 *cert, FingerprintType type);
|
||||
|
||||
std::vector<std::uint8_t> pemFileCertFingerprint(const std::string &path, FingerprintType type);
|
||||
FingerprintData pemFileCertFingerprint(const std::string &path, FingerprintType type);
|
||||
|
||||
void generatePemSelfSignedCert(const std::string &path, int keyLength = 2048);
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue