refactor: secureUtils fingerprint method

Signed-off-by: sithlord48 <sithlord48@gmail.com>
This commit is contained in:
sithlord48 2025-01-28 23:38:54 -05:00 committed by Nick Bolton
parent 39da277ead
commit fb32f141cc
6 changed files with 77 additions and 16 deletions

View file

@ -113,5 +113,6 @@ if(WIN32)
${target} ${target}
base base
arch arch
net
) )
endif() endif()

View file

@ -4,6 +4,7 @@
# SPDX-License-Identifier: MIT # SPDX-License-Identifier: MIT
add_library(net STATIC add_library(net STATIC
FingerprintTypes.h
IDataSocket.cpp IDataSocket.cpp
IDataSocket.h IDataSocket.h
IListenSocket.h IListenSocket.h
@ -53,5 +54,8 @@ target_link_libraries(
PRIVATE mt io) PRIVATE mt io)
if(WIN32) if(WIN32)
target_link_libraries(net PRIVATE Crypt32 ws2_32) target_link_libraries(
net
PUBLIC OpenSSL::applink
PRIVATE Crypt32 ws2_32 OpenSSL::applink)
endif() endif()

View file

@ -0,0 +1,18 @@
/*
* Deskflow -- mouse and keyboard sharing utility
* SPDX-FileCopyrightText: (C) 2025 Deskflow Developers
* SPDX-License-Identifier: GPL-2.0-only WITH LicenseRef-OpenSSL-Exception
*/
#pragma once
namespace deskflow {
enum FingerprintType
{
Invalid,
SHA1,
SHA256
};
}

View file

@ -1,5 +1,6 @@
/* /*
* Deskflow -- mouse and keyboard sharing utility * Deskflow -- mouse and keyboard sharing utility
* SPDX-FileCopyrightText: (C) 2025 Deskflow Developers
* SPDX-FileCopyrightText: (C) 2015 - 2016 Symless Ltd. * SPDX-FileCopyrightText: (C) 2015 - 2016 Symless Ltd.
* SPDX-License-Identifier: GPL-2.0-only WITH LicenseRef-OpenSSL-Exception * SPDX-License-Identifier: GPL-2.0-only WITH LicenseRef-OpenSSL-Exception
*/ */
@ -614,23 +615,15 @@ void SecureSocket::disconnect()
bool SecureSocket::verifyCertFingerprint() bool SecureSocket::verifyCertFingerprint()
{ {
// calculate received certificate fingerprint // calculate received certificate fingerprint
using AutoX509 = std::unique_ptr<X509, decltype(&X509_free)>; std::vector<std::uint8_t> fingerprint_raw;
AutoX509 cert(SSL_get_peer_certificate(m_ssl->m_ssl), &X509_free); try {
fingerprint_raw =
unsigned char tempFingerprint[EVP_MAX_MD_SIZE]; deskflow::SSLCertFingerprint(SSL_get_peer_certificate(m_ssl->m_ssl), deskflow::FingerprintType::SHA1);
unsigned int tempFingerprintLen; } catch (const std::exception &e) {
int digestResult = X509_digest(cert.get(), EVP_sha256(), tempFingerprint, &tempFingerprintLen); LOG((CLOG_ERR "%s", e.what()));
if (digestResult <= 0) {
LOG((CLOG_ERR "failed to calculate fingerprint, digest result: %d", digestResult));
return false; return false;
} }
// format fingerprint into hexdecimal format with colon separator
std::vector<uint8_t> fingerprint_raw;
fingerprint_raw.assign(
reinterpret_cast<uint8_t *>(tempFingerprint), reinterpret_cast<uint8_t *>(tempFingerprint) + tempFingerprintLen
);
auto fingerprint = deskflow::formatSSLFingerprint(fingerprint_raw); auto fingerprint = deskflow::formatSSLFingerprint(fingerprint_raw);
LOG((CLOG_NOTE "server fingerprint: %s", fingerprint.c_str())); LOG((CLOG_NOTE "server fingerprint: %s", fingerprint.c_str()));

View file

@ -8,8 +8,30 @@
#include "SecureUtils.h" #include "SecureUtils.h"
#include "base/String.h" #include "base/String.h"
#include <openssl/pem.h>
#include <openssl/x509.h>
#include <openssl/x509v3.h>
#include <stdexcept>
namespace deskflow { namespace deskflow {
namespace {
const EVP_MD *digestForType(FingerprintType type)
{
switch (type) {
case FingerprintType::SHA1:
return EVP_sha1();
case FingerprintType::SHA256:
return EVP_sha256();
default:
break;
}
throw std::runtime_error("Unknown fingerprint type " + std::to_string(static_cast<int>(type)));
}
} // namespace
std::string formatSSLFingerprint(const std::vector<uint8_t> &fingerprint, bool enableSeparators) std::string formatSSLFingerprint(const std::vector<uint8_t> &fingerprint, bool enableSeparators)
{ {
std::string result = deskflow::string::toHex(fingerprint, 2); std::string result = deskflow::string::toHex(fingerprint, 2);
@ -25,4 +47,23 @@ std::string formatSSLFingerprint(const std::vector<uint8_t> &fingerprint, bool e
return result; return result;
} }
std::vector<uint8_t> SSLCertFingerprint(X509 *cert, FingerprintType type)
{
if (!cert) {
throw std::runtime_error("certificate is null");
}
unsigned char digest[EVP_MAX_MD_SIZE];
unsigned int digestLength = 0;
int result = X509_digest(cert, digestForType(type), digest, &digestLength);
if (result <= 0) {
throw std::runtime_error("failed to calculate fingerprint, digest result: " + std::to_string(result));
}
std::vector<std::uint8_t> digestVec;
digestVec.assign(reinterpret_cast<std::uint8_t *>(digest), reinterpret_cast<std::uint8_t *>(digest) + digestLength);
return digestVec;
}
} // namespace deskflow } // namespace deskflow

View file

@ -7,7 +7,10 @@
#pragma once #pragma once
#include <stdint.h> #include "FingerprintTypes.h"
#include <cstdint>
#include <openssl/ossl_typ.h>
#include <string> #include <string>
#include <vector> #include <vector>
@ -21,4 +24,5 @@ namespace deskflow {
*/ */
std::string formatSSLFingerprint(const std::vector<uint8_t> &fingerprint, bool enableSeparators = true); std::string formatSSLFingerprint(const std::vector<uint8_t> &fingerprint, bool enableSeparators = true);
std::vector<std::uint8_t> SSLCertFingerprint(X509 *cert, FingerprintType type);
} // namespace deskflow } // namespace deskflow