diff --git a/src/lib/gui/tls/TlsCertificate.cpp b/src/lib/gui/tls/TlsCertificate.cpp index 1f9e3e323..705ea443b 100644 --- a/src/lib/gui/tls/TlsCertificate.cpp +++ b/src/lib/gui/tls/TlsCertificate.cpp @@ -54,10 +54,8 @@ bool TlsCertificate::generateFingerprint(const QString &certificateFilename) auto localPath = QStringLiteral("%1/%2/%3").arg(profileDir, kSslDir, kFingerprintLocalFilename).toStdString(); - const deskflow::FingerprintData data{"sha1", fingerprint}; - deskflow::FingerprintDatabase db; - db.addTrusted(data); + db.addTrusted(fingerprint); db.write(localPath); qDebug("tls fingerprint generated"); diff --git a/src/lib/net/CMakeLists.txt b/src/lib/net/CMakeLists.txt index ab3a685d5..684d62af3 100644 --- a/src/lib/net/CMakeLists.txt +++ b/src/lib/net/CMakeLists.txt @@ -4,7 +4,6 @@ # SPDX-License-Identifier: MIT add_library(net STATIC - FingerprintTypes.h FingerprintData.cpp FingerprintData.h FingerprintDatabase.cpp diff --git a/src/lib/net/FingerprintData.h b/src/lib/net/FingerprintData.h index e5d53a167..d45f34e86 100644 --- a/src/lib/net/FingerprintData.h +++ b/src/lib/net/FingerprintData.h @@ -7,14 +7,19 @@ #pragma once -#include "FingerprintTypes.h" - #include #include #include namespace deskflow { +enum FingerprintType +{ + Invalid, + SHA1, + SHA256 +}; + struct FingerprintData { std::string algorithm; diff --git a/src/lib/net/FingerprintTypes.h b/src/lib/net/FingerprintTypes.h deleted file mode 100644 index ebfdde09b..000000000 --- a/src/lib/net/FingerprintTypes.h +++ /dev/null @@ -1,18 +0,0 @@ -/* - * Deskflow -- mouse and keyboard sharing utility - * SPDX-FileCopyrightText: (C) 2025 Deskflow Developers - * SPDX-License-Identifier: GPL-2.0-only WITH LicenseRef-OpenSSL-Exception - */ - -#pragma once - -namespace deskflow { - -enum FingerprintType -{ - Invalid, - SHA1, - SHA256 -}; - -} diff --git a/src/lib/net/SecureSocket.cpp b/src/lib/net/SecureSocket.cpp index 7ba987869..1496d1796 100644 --- a/src/lib/net/SecureSocket.cpp +++ b/src/lib/net/SecureSocket.cpp @@ -613,16 +613,15 @@ void SecureSocket::disconnect() bool SecureSocket::verifyCertFingerprint() { // calculate received certificate fingerprint - std::vector fingerprint_raw; + deskflow::FingerprintData fingerprint; try { - fingerprint_raw = - deskflow::SSLCertFingerprint(SSL_get_peer_certificate(m_ssl->m_ssl), deskflow::FingerprintType::SHA1); + fingerprint = deskflow::sslCertFingerprint(SSL_get_peer_certificate(m_ssl->m_ssl), deskflow::FingerprintType::SHA1); } catch (const std::exception &e) { LOG((CLOG_ERR "%s", e.what())); return false; } - LOG((CLOG_NOTE "server fingerprint: %s", deskflow::formatSSLFingerprint(fingerprint_raw).c_str())); + LOG((CLOG_NOTE "server fingerprint: %s", deskflow::formatSSLFingerprint(fingerprint.data).c_str())); std::string trustedServersFilename = deskflow::string::sprintf( "%s/%s/%s", ARCH->getProfileDirectory().c_str(), kSslDir, kFingerprintTrustedServersFilename @@ -642,8 +641,6 @@ bool SecureSocket::verifyCertFingerprint() return false; } - deskflow::FingerprintData fingerprint{"sha1", fingerprint_raw}; - if (!db.isTrusted(fingerprint)) { LOG((CLOG_WARN "fingerprint does not match trusted fingerprint")); return false; diff --git a/src/lib/net/SecureUtils.cpp b/src/lib/net/SecureUtils.cpp index d4683a7a2..c5cd0e8fb 100644 --- a/src/lib/net/SecureUtils.cpp +++ b/src/lib/net/SecureUtils.cpp @@ -6,6 +6,7 @@ */ #include "SecureUtils.h" +#include "FingerprintDatabase.h" #include "base/String.h" #include "base/finally.h" #include "io/filesystem.h" @@ -50,7 +51,7 @@ std::string formatSSLFingerprint(const std::vector &fingerprint, bool e return result; } -std::vector SSLCertFingerprint(X509 *cert, FingerprintType type) +FingerprintData sslCertFingerprint(X509 *cert, FingerprintType type) { if (!cert) { throw std::runtime_error("certificate is null"); @@ -66,10 +67,10 @@ std::vector SSLCertFingerprint(X509 *cert, FingerprintType type) std::vector digestVec; digestVec.assign(reinterpret_cast(digest), reinterpret_cast(digest) + digestLength); - return digestVec; + return {fingerprintTypeToString(type), digestVec}; } -std::vector pemFileCertFingerprint(const std::string &path, FingerprintType type) +FingerprintData pemFileCertFingerprint(const std::string &path, FingerprintType type) { auto fp = fopenUtf8Path(path, "r"); if (!fp) { @@ -83,7 +84,7 @@ std::vector pemFileCertFingerprint(const std::string &path, Finger } auto certFree = finally([cert]() { X509_free(cert); }); - return SSLCertFingerprint(cert, type); + return sslCertFingerprint(cert, type); } void generatePemSelfSignedCert(const std::string &path, int keyLength) diff --git a/src/lib/net/SecureUtils.h b/src/lib/net/SecureUtils.h index 3cebb6558..7ff311aef 100644 --- a/src/lib/net/SecureUtils.h +++ b/src/lib/net/SecureUtils.h @@ -7,7 +7,7 @@ #pragma once -#include "FingerprintTypes.h" +#include "FingerprintData.h" #include #include @@ -24,9 +24,9 @@ namespace deskflow { */ std::string formatSSLFingerprint(const std::vector &fingerprint, bool enableSeparators = true); -std::vector SSLCertFingerprint(X509 *cert, FingerprintType type); +FingerprintData sslCertFingerprint(X509 *cert, FingerprintType type); -std::vector pemFileCertFingerprint(const std::string &path, FingerprintType type); +FingerprintData pemFileCertFingerprint(const std::string &path, FingerprintType type); void generatePemSelfSignedCert(const std::string &path, int keyLength = 2048);