refactor: move SecureUtils::getCertLength -> TlsUtility, and use Qt to get the length of the key file
This commit is contained in:
parent
1a6f81a34b
commit
ff02285a6a
4 changed files with 15 additions and 32 deletions
|
|
@ -61,7 +61,20 @@ bool isCertValid(const QString &certPath)
|
||||||
|
|
||||||
int getCertKeyLength(const QString &certPath)
|
int getCertKeyLength(const QString &certPath)
|
||||||
{
|
{
|
||||||
return deskflow::getCertLength(certPath.toStdString());
|
QFile file(certPath);
|
||||||
|
if (!file.open(QFile::ReadOnly)) {
|
||||||
|
//: %1 will be replaced by the certificate path
|
||||||
|
qDebug() << QObject::tr("failed to read key from certificate file: %1").arg(certPath);
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
|
|
||||||
|
const auto key = QSslKey(&file, QSsl::Rsa);
|
||||||
|
if (key.isNull()) {
|
||||||
|
//: %1 will be replaced by the certificate path
|
||||||
|
qDebug() << QObject::tr("failed to parse certificate file: %1").arg(certPath);
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
|
return key.length();
|
||||||
}
|
}
|
||||||
|
|
||||||
QByteArray certFingerprint(const QString &certPath)
|
QByteArray certFingerprint(const QString &certPath)
|
||||||
|
|
|
||||||
|
|
@ -29,7 +29,7 @@ bool isCertValid(const QString &certPath = Settings::value(Settings::Security::C
|
||||||
/**
|
/**
|
||||||
* @brief Get the lenght of a key
|
* @brief Get the lenght of a key
|
||||||
* @param certPath path of the file to check, when unset will use the value of Settings::Security::Certificate
|
* @param certPath path of the file to check, when unset will use the value of Settings::Security::Certificate
|
||||||
* @return the bitsize of the key
|
* @return the bitsize of the key or -1 if there was an error reading the file
|
||||||
*/
|
*/
|
||||||
int getCertKeyLength(const QString &certPath = Settings::value(Settings::Security::Certificate).toString());
|
int getCertKeyLength(const QString &certPath = Settings::value(Settings::Security::Certificate).toString());
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -118,34 +118,6 @@ void generatePemSelfSignedCert(const std::string &path, int keyLength)
|
||||||
PEM_write_X509(fp, cert);
|
PEM_write_X509(fp, cert);
|
||||||
}
|
}
|
||||||
|
|
||||||
int getCertLength(const std::string &path)
|
|
||||||
{
|
|
||||||
auto fp = fopenUtf8Path(path.c_str(), "r");
|
|
||||||
if (!fp) {
|
|
||||||
throw std::runtime_error("could not open certificate output path");
|
|
||||||
return -1;
|
|
||||||
}
|
|
||||||
|
|
||||||
EVP_PKEY *privateKey = PEM_read_PrivateKey(fp, nullptr, nullptr, nullptr);
|
|
||||||
|
|
||||||
fclose(fp);
|
|
||||||
|
|
||||||
if (!privateKey) {
|
|
||||||
throw std::runtime_error("could not open certificate");
|
|
||||||
return -1;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (EVP_PKEY_base_id(privateKey) != EVP_PKEY_RSA) {
|
|
||||||
throw std::runtime_error("not an RSA key");
|
|
||||||
return -1;
|
|
||||||
}
|
|
||||||
int size = EVP_PKEY_get_bits(privateKey);
|
|
||||||
|
|
||||||
EVP_PKEY_free(privateKey);
|
|
||||||
|
|
||||||
return size;
|
|
||||||
}
|
|
||||||
|
|
||||||
QString formatSSLFingerprintColumns(const QByteArray &fingerprint)
|
QString formatSSLFingerprintColumns(const QByteArray &fingerprint)
|
||||||
{
|
{
|
||||||
auto kMaxColumns = 24;
|
auto kMaxColumns = 24;
|
||||||
|
|
|
||||||
|
|
@ -30,7 +30,5 @@ Fingerprint pemFileCertFingerprint(const std::string &path, QCryptographicHash::
|
||||||
|
|
||||||
void generatePemSelfSignedCert(const std::string &path, int keyLength = 2048);
|
void generatePemSelfSignedCert(const std::string &path, int keyLength = 2048);
|
||||||
|
|
||||||
int getCertLength(const std::string &path);
|
|
||||||
|
|
||||||
QString generateFingerprintArt(const QByteArray &rawDigest);
|
QString generateFingerprintArt(const QByteArray &rawDigest);
|
||||||
} // namespace deskflow
|
} // namespace deskflow
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue