refactor: use FingerprintData for fingerprints

based-on: 7cced74119
This commit is contained in:
sithlord48 2025-02-08 20:21:36 -05:00 committed by Nick Bolton
parent d0d5182425
commit 743c3feef3
7 changed files with 19 additions and 37 deletions

View file

@ -54,10 +54,8 @@ bool TlsCertificate::generateFingerprint(const QString &certificateFilename)
auto localPath = QStringLiteral("%1/%2/%3").arg(profileDir, kSslDir, kFingerprintLocalFilename).toStdString(); auto localPath = QStringLiteral("%1/%2/%3").arg(profileDir, kSslDir, kFingerprintLocalFilename).toStdString();
const deskflow::FingerprintData data{"sha1", fingerprint};
deskflow::FingerprintDatabase db; deskflow::FingerprintDatabase db;
db.addTrusted(data); db.addTrusted(fingerprint);
db.write(localPath); db.write(localPath);
qDebug("tls fingerprint generated"); qDebug("tls fingerprint generated");

View file

@ -4,7 +4,6 @@
# SPDX-License-Identifier: MIT # SPDX-License-Identifier: MIT
add_library(net STATIC add_library(net STATIC
FingerprintTypes.h
FingerprintData.cpp FingerprintData.cpp
FingerprintData.h FingerprintData.h
FingerprintDatabase.cpp FingerprintDatabase.cpp

View file

@ -7,14 +7,19 @@
#pragma once #pragma once
#include "FingerprintTypes.h"
#include <cstdint> #include <cstdint>
#include <string> #include <string>
#include <vector> #include <vector>
namespace deskflow { namespace deskflow {
enum FingerprintType
{
Invalid,
SHA1,
SHA256
};
struct FingerprintData struct FingerprintData
{ {
std::string algorithm; std::string algorithm;

View file

@ -1,18 +0,0 @@
/*
* Deskflow -- mouse and keyboard sharing utility
* SPDX-FileCopyrightText: (C) 2025 Deskflow Developers
* SPDX-License-Identifier: GPL-2.0-only WITH LicenseRef-OpenSSL-Exception
*/
#pragma once
namespace deskflow {
enum FingerprintType
{
Invalid,
SHA1,
SHA256
};
}

View file

@ -613,16 +613,15 @@ void SecureSocket::disconnect()
bool SecureSocket::verifyCertFingerprint() bool SecureSocket::verifyCertFingerprint()
{ {
// calculate received certificate fingerprint // calculate received certificate fingerprint
std::vector<std::uint8_t> fingerprint_raw; deskflow::FingerprintData fingerprint;
try { try {
fingerprint_raw = fingerprint = deskflow::sslCertFingerprint(SSL_get_peer_certificate(m_ssl->m_ssl), deskflow::FingerprintType::SHA1);
deskflow::SSLCertFingerprint(SSL_get_peer_certificate(m_ssl->m_ssl), deskflow::FingerprintType::SHA1);
} catch (const std::exception &e) { } catch (const std::exception &e) {
LOG((CLOG_ERR "%s", e.what())); LOG((CLOG_ERR "%s", e.what()));
return false; return false;
} }
LOG((CLOG_NOTE "server fingerprint: %s", deskflow::formatSSLFingerprint(fingerprint_raw).c_str())); LOG((CLOG_NOTE "server fingerprint: %s", deskflow::formatSSLFingerprint(fingerprint.data).c_str()));
std::string trustedServersFilename = deskflow::string::sprintf( std::string trustedServersFilename = deskflow::string::sprintf(
"%s/%s/%s", ARCH->getProfileDirectory().c_str(), kSslDir, kFingerprintTrustedServersFilename "%s/%s/%s", ARCH->getProfileDirectory().c_str(), kSslDir, kFingerprintTrustedServersFilename
@ -642,8 +641,6 @@ bool SecureSocket::verifyCertFingerprint()
return false; return false;
} }
deskflow::FingerprintData fingerprint{"sha1", fingerprint_raw};
if (!db.isTrusted(fingerprint)) { if (!db.isTrusted(fingerprint)) {
LOG((CLOG_WARN "fingerprint does not match trusted fingerprint")); LOG((CLOG_WARN "fingerprint does not match trusted fingerprint"));
return false; return false;

View file

@ -6,6 +6,7 @@
*/ */
#include "SecureUtils.h" #include "SecureUtils.h"
#include "FingerprintDatabase.h"
#include "base/String.h" #include "base/String.h"
#include "base/finally.h" #include "base/finally.h"
#include "io/filesystem.h" #include "io/filesystem.h"
@ -50,7 +51,7 @@ std::string formatSSLFingerprint(const std::vector<uint8_t> &fingerprint, bool e
return result; return result;
} }
std::vector<uint8_t> SSLCertFingerprint(X509 *cert, FingerprintType type) FingerprintData sslCertFingerprint(X509 *cert, FingerprintType type)
{ {
if (!cert) { if (!cert) {
throw std::runtime_error("certificate is null"); throw std::runtime_error("certificate is null");
@ -66,10 +67,10 @@ std::vector<uint8_t> SSLCertFingerprint(X509 *cert, FingerprintType type)
std::vector<std::uint8_t> digestVec; std::vector<std::uint8_t> digestVec;
digestVec.assign(reinterpret_cast<std::uint8_t *>(digest), reinterpret_cast<std::uint8_t *>(digest) + digestLength); digestVec.assign(reinterpret_cast<std::uint8_t *>(digest), reinterpret_cast<std::uint8_t *>(digest) + digestLength);
return digestVec; return {fingerprintTypeToString(type), digestVec};
} }
std::vector<std::uint8_t> pemFileCertFingerprint(const std::string &path, FingerprintType type) FingerprintData pemFileCertFingerprint(const std::string &path, FingerprintType type)
{ {
auto fp = fopenUtf8Path(path, "r"); auto fp = fopenUtf8Path(path, "r");
if (!fp) { if (!fp) {
@ -83,7 +84,7 @@ std::vector<std::uint8_t> pemFileCertFingerprint(const std::string &path, Finger
} }
auto certFree = finally([cert]() { X509_free(cert); }); auto certFree = finally([cert]() { X509_free(cert); });
return SSLCertFingerprint(cert, type); return sslCertFingerprint(cert, type);
} }
void generatePemSelfSignedCert(const std::string &path, int keyLength) void generatePemSelfSignedCert(const std::string &path, int keyLength)

View file

@ -7,7 +7,7 @@
#pragma once #pragma once
#include "FingerprintTypes.h" #include "FingerprintData.h"
#include <cstdint> #include <cstdint>
#include <openssl/ossl_typ.h> #include <openssl/ossl_typ.h>
@ -24,9 +24,9 @@ namespace deskflow {
*/ */
std::string formatSSLFingerprint(const std::vector<uint8_t> &fingerprint, bool enableSeparators = true); std::string formatSSLFingerprint(const std::vector<uint8_t> &fingerprint, bool enableSeparators = true);
std::vector<std::uint8_t> SSLCertFingerprint(X509 *cert, FingerprintType type); FingerprintData sslCertFingerprint(X509 *cert, FingerprintType type);
std::vector<std::uint8_t> pemFileCertFingerprint(const std::string &path, FingerprintType type); FingerprintData pemFileCertFingerprint(const std::string &path, FingerprintType type);
void generatePemSelfSignedCert(const std::string &path, int keyLength = 2048); void generatePemSelfSignedCert(const std::string &path, int keyLength = 2048);