parent
d0d5182425
commit
743c3feef3
7 changed files with 19 additions and 37 deletions
|
|
@ -54,10 +54,8 @@ bool TlsCertificate::generateFingerprint(const QString &certificateFilename)
|
||||||
|
|
||||||
auto localPath = QStringLiteral("%1/%2/%3").arg(profileDir, kSslDir, kFingerprintLocalFilename).toStdString();
|
auto localPath = QStringLiteral("%1/%2/%3").arg(profileDir, kSslDir, kFingerprintLocalFilename).toStdString();
|
||||||
|
|
||||||
const deskflow::FingerprintData data{"sha1", fingerprint};
|
|
||||||
|
|
||||||
deskflow::FingerprintDatabase db;
|
deskflow::FingerprintDatabase db;
|
||||||
db.addTrusted(data);
|
db.addTrusted(fingerprint);
|
||||||
db.write(localPath);
|
db.write(localPath);
|
||||||
|
|
||||||
qDebug("tls fingerprint generated");
|
qDebug("tls fingerprint generated");
|
||||||
|
|
|
||||||
|
|
@ -4,7 +4,6 @@
|
||||||
# SPDX-License-Identifier: MIT
|
# SPDX-License-Identifier: MIT
|
||||||
|
|
||||||
add_library(net STATIC
|
add_library(net STATIC
|
||||||
FingerprintTypes.h
|
|
||||||
FingerprintData.cpp
|
FingerprintData.cpp
|
||||||
FingerprintData.h
|
FingerprintData.h
|
||||||
FingerprintDatabase.cpp
|
FingerprintDatabase.cpp
|
||||||
|
|
|
||||||
|
|
@ -7,14 +7,19 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "FingerprintTypes.h"
|
|
||||||
|
|
||||||
#include <cstdint>
|
#include <cstdint>
|
||||||
#include <string>
|
#include <string>
|
||||||
#include <vector>
|
#include <vector>
|
||||||
|
|
||||||
namespace deskflow {
|
namespace deskflow {
|
||||||
|
|
||||||
|
enum FingerprintType
|
||||||
|
{
|
||||||
|
Invalid,
|
||||||
|
SHA1,
|
||||||
|
SHA256
|
||||||
|
};
|
||||||
|
|
||||||
struct FingerprintData
|
struct FingerprintData
|
||||||
{
|
{
|
||||||
std::string algorithm;
|
std::string algorithm;
|
||||||
|
|
|
||||||
|
|
@ -1,18 +0,0 @@
|
||||||
/*
|
|
||||||
* Deskflow -- mouse and keyboard sharing utility
|
|
||||||
* SPDX-FileCopyrightText: (C) 2025 Deskflow Developers
|
|
||||||
* SPDX-License-Identifier: GPL-2.0-only WITH LicenseRef-OpenSSL-Exception
|
|
||||||
*/
|
|
||||||
|
|
||||||
#pragma once
|
|
||||||
|
|
||||||
namespace deskflow {
|
|
||||||
|
|
||||||
enum FingerprintType
|
|
||||||
{
|
|
||||||
Invalid,
|
|
||||||
SHA1,
|
|
||||||
SHA256
|
|
||||||
};
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
@ -613,16 +613,15 @@ void SecureSocket::disconnect()
|
||||||
bool SecureSocket::verifyCertFingerprint()
|
bool SecureSocket::verifyCertFingerprint()
|
||||||
{
|
{
|
||||||
// calculate received certificate fingerprint
|
// calculate received certificate fingerprint
|
||||||
std::vector<std::uint8_t> fingerprint_raw;
|
deskflow::FingerprintData fingerprint;
|
||||||
try {
|
try {
|
||||||
fingerprint_raw =
|
fingerprint = deskflow::sslCertFingerprint(SSL_get_peer_certificate(m_ssl->m_ssl), deskflow::FingerprintType::SHA1);
|
||||||
deskflow::SSLCertFingerprint(SSL_get_peer_certificate(m_ssl->m_ssl), deskflow::FingerprintType::SHA1);
|
|
||||||
} catch (const std::exception &e) {
|
} catch (const std::exception &e) {
|
||||||
LOG((CLOG_ERR "%s", e.what()));
|
LOG((CLOG_ERR "%s", e.what()));
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
LOG((CLOG_NOTE "server fingerprint: %s", deskflow::formatSSLFingerprint(fingerprint_raw).c_str()));
|
LOG((CLOG_NOTE "server fingerprint: %s", deskflow::formatSSLFingerprint(fingerprint.data).c_str()));
|
||||||
|
|
||||||
std::string trustedServersFilename = deskflow::string::sprintf(
|
std::string trustedServersFilename = deskflow::string::sprintf(
|
||||||
"%s/%s/%s", ARCH->getProfileDirectory().c_str(), kSslDir, kFingerprintTrustedServersFilename
|
"%s/%s/%s", ARCH->getProfileDirectory().c_str(), kSslDir, kFingerprintTrustedServersFilename
|
||||||
|
|
@ -642,8 +641,6 @@ bool SecureSocket::verifyCertFingerprint()
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
deskflow::FingerprintData fingerprint{"sha1", fingerprint_raw};
|
|
||||||
|
|
||||||
if (!db.isTrusted(fingerprint)) {
|
if (!db.isTrusted(fingerprint)) {
|
||||||
LOG((CLOG_WARN "fingerprint does not match trusted fingerprint"));
|
LOG((CLOG_WARN "fingerprint does not match trusted fingerprint"));
|
||||||
return false;
|
return false;
|
||||||
|
|
|
||||||
|
|
@ -6,6 +6,7 @@
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include "SecureUtils.h"
|
#include "SecureUtils.h"
|
||||||
|
#include "FingerprintDatabase.h"
|
||||||
#include "base/String.h"
|
#include "base/String.h"
|
||||||
#include "base/finally.h"
|
#include "base/finally.h"
|
||||||
#include "io/filesystem.h"
|
#include "io/filesystem.h"
|
||||||
|
|
@ -50,7 +51,7 @@ std::string formatSSLFingerprint(const std::vector<uint8_t> &fingerprint, bool e
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
std::vector<uint8_t> SSLCertFingerprint(X509 *cert, FingerprintType type)
|
FingerprintData sslCertFingerprint(X509 *cert, FingerprintType type)
|
||||||
{
|
{
|
||||||
if (!cert) {
|
if (!cert) {
|
||||||
throw std::runtime_error("certificate is null");
|
throw std::runtime_error("certificate is null");
|
||||||
|
|
@ -66,10 +67,10 @@ std::vector<uint8_t> SSLCertFingerprint(X509 *cert, FingerprintType type)
|
||||||
|
|
||||||
std::vector<std::uint8_t> digestVec;
|
std::vector<std::uint8_t> digestVec;
|
||||||
digestVec.assign(reinterpret_cast<std::uint8_t *>(digest), reinterpret_cast<std::uint8_t *>(digest) + digestLength);
|
digestVec.assign(reinterpret_cast<std::uint8_t *>(digest), reinterpret_cast<std::uint8_t *>(digest) + digestLength);
|
||||||
return digestVec;
|
return {fingerprintTypeToString(type), digestVec};
|
||||||
}
|
}
|
||||||
|
|
||||||
std::vector<std::uint8_t> pemFileCertFingerprint(const std::string &path, FingerprintType type)
|
FingerprintData pemFileCertFingerprint(const std::string &path, FingerprintType type)
|
||||||
{
|
{
|
||||||
auto fp = fopenUtf8Path(path, "r");
|
auto fp = fopenUtf8Path(path, "r");
|
||||||
if (!fp) {
|
if (!fp) {
|
||||||
|
|
@ -83,7 +84,7 @@ std::vector<std::uint8_t> pemFileCertFingerprint(const std::string &path, Finger
|
||||||
}
|
}
|
||||||
auto certFree = finally([cert]() { X509_free(cert); });
|
auto certFree = finally([cert]() { X509_free(cert); });
|
||||||
|
|
||||||
return SSLCertFingerprint(cert, type);
|
return sslCertFingerprint(cert, type);
|
||||||
}
|
}
|
||||||
|
|
||||||
void generatePemSelfSignedCert(const std::string &path, int keyLength)
|
void generatePemSelfSignedCert(const std::string &path, int keyLength)
|
||||||
|
|
|
||||||
|
|
@ -7,7 +7,7 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "FingerprintTypes.h"
|
#include "FingerprintData.h"
|
||||||
|
|
||||||
#include <cstdint>
|
#include <cstdint>
|
||||||
#include <openssl/ossl_typ.h>
|
#include <openssl/ossl_typ.h>
|
||||||
|
|
@ -24,9 +24,9 @@ namespace deskflow {
|
||||||
*/
|
*/
|
||||||
std::string formatSSLFingerprint(const std::vector<uint8_t> &fingerprint, bool enableSeparators = true);
|
std::string formatSSLFingerprint(const std::vector<uint8_t> &fingerprint, bool enableSeparators = true);
|
||||||
|
|
||||||
std::vector<std::uint8_t> SSLCertFingerprint(X509 *cert, FingerprintType type);
|
FingerprintData sslCertFingerprint(X509 *cert, FingerprintType type);
|
||||||
|
|
||||||
std::vector<std::uint8_t> pemFileCertFingerprint(const std::string &path, FingerprintType type);
|
FingerprintData pemFileCertFingerprint(const std::string &path, FingerprintType type);
|
||||||
|
|
||||||
void generatePemSelfSignedCert(const std::string &path, int keyLength = 2048);
|
void generatePemSelfSignedCert(const std::string &path, int keyLength = 2048);
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue