CertService.cs 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187
  1. using Microsoft.Extensions.Caching.Memory;
  2. using Microsoft.Extensions.Logging;
  3. using System;
  4. using System.Collections.Generic;
  5. using System.Diagnostics;
  6. using System.IO;
  7. using System.Linq;
  8. using System.Net;
  9. using System.Security.Cryptography.X509Certificates;
  10. namespace FastGithub.HttpServer
  11. {
  12. /// <summary>
  13. /// 证书服务
  14. /// </summary>
  15. sealed class CertService
  16. {
  17. private const string CACERT_PATH = "cacert";
  18. private const int KEY_SIZE_BITS = 2048;
  19. private readonly IMemoryCache serverCertCache;
  20. private readonly ILogger<CertService> logger;
  21. /// <summary>
  22. /// 获取证书文件路径
  23. /// </summary>
  24. public string CaCerFilePath { get; } = $"{CACERT_PATH}/fastgithub.cer";
  25. /// <summary>
  26. /// 获取私钥文件路径
  27. /// </summary>
  28. public string CaKeyFilePath { get; } = $"{CACERT_PATH}/fastgithub.key";
  29. /// <summary>
  30. /// 证书服务
  31. /// </summary>
  32. /// <param name="logger"></param>
  33. public CertService(
  34. IMemoryCache serverCertCache,
  35. ILogger<CertService> logger)
  36. {
  37. this.serverCertCache = serverCertCache;
  38. this.logger = logger;
  39. Directory.CreateDirectory(CACERT_PATH);
  40. }
  41. /// <summary>
  42. /// 生成CA证书
  43. /// </summary>
  44. public bool CreateCaCertIfNotExists()
  45. {
  46. if (File.Exists(this.CaCerFilePath) && File.Exists(this.CaKeyFilePath))
  47. {
  48. return false;
  49. }
  50. File.Delete(this.CaCerFilePath);
  51. File.Delete(this.CaKeyFilePath);
  52. var validFrom = DateTime.Today.AddDays(-1);
  53. var validTo = DateTime.Today.AddYears(10);
  54. CertGenerator.GenerateBySelf(new[] { nameof(FastGithub) }, KEY_SIZE_BITS, validFrom, validTo, this.CaCerFilePath, this.CaKeyFilePath);
  55. return true;
  56. }
  57. /// <summary>
  58. /// 安装和信任CA证书
  59. /// </summary>
  60. public void InstallAndTrustCaCert()
  61. {
  62. if (OperatingSystem.IsWindows())
  63. {
  64. this.InstallAndTrustCaCertAtWindows();
  65. }
  66. else if (OperatingSystem.IsLinux())
  67. {
  68. this.logger.LogWarning($"请根据具体linux发行版手动安装CA证书{this.CaCerFilePath}");
  69. }
  70. else if (OperatingSystem.IsMacOS())
  71. {
  72. this.logger.LogWarning($"请手动安装CA证书然后设置信任CA证书{this.CaCerFilePath}");
  73. }
  74. else
  75. {
  76. this.logger.LogWarning($"请根据你的系统平台手动安装和信任CA证书{this.CaCerFilePath}");
  77. }
  78. GitConfigSslverify(false);
  79. }
  80. /// <summary>
  81. /// 设置ssl验证
  82. /// </summary>
  83. /// <param name="value">是否验证</param>
  84. /// <returns></returns>
  85. public static bool GitConfigSslverify(bool value)
  86. {
  87. try
  88. {
  89. Process.Start(new ProcessStartInfo
  90. {
  91. FileName = "git",
  92. Arguments = $"config --global http.sslverify {value.ToString().ToLower()}",
  93. UseShellExecute = true,
  94. CreateNoWindow = true,
  95. WindowStyle = ProcessWindowStyle.Hidden
  96. });
  97. return true;
  98. }
  99. catch (Exception)
  100. {
  101. return false;
  102. }
  103. }
  104. /// <summary>
  105. /// 安装CA证书
  106. /// </summary>
  107. private void InstallAndTrustCaCertAtWindows()
  108. {
  109. try
  110. {
  111. using var store = new X509Store(StoreName.Root, StoreLocation.LocalMachine);
  112. store.Open(OpenFlags.ReadWrite);
  113. var caCert = new X509Certificate2(this.CaCerFilePath);
  114. var subjectName = caCert.Subject[3..];
  115. foreach (var item in store.Certificates.Find(X509FindType.FindBySubjectName, subjectName, false))
  116. {
  117. if (item.Thumbprint != caCert.Thumbprint)
  118. {
  119. store.Remove(item);
  120. }
  121. }
  122. if (store.Certificates.Find(X509FindType.FindByThumbprint, caCert.Thumbprint, true).Count == 0)
  123. {
  124. store.Add(caCert);
  125. }
  126. store.Close();
  127. }
  128. catch (Exception)
  129. {
  130. this.logger.LogWarning($"请手动安装CA证书{this.CaCerFilePath}到“将所有的证书都放入下列存储”\\“受信任的根证书颁发机构”");
  131. }
  132. }
  133. /// <summary>
  134. /// 获取颁发给指定域名的证书
  135. /// </summary>
  136. /// <param name="domain"></param>
  137. /// <returns></returns>
  138. public X509Certificate2 GetOrCreateServerCert(string? domain)
  139. {
  140. var key = $"{nameof(CertService)}:{domain}";
  141. return this.serverCertCache.GetOrCreate(key, GetOrCreateCert);
  142. // 生成域名的1年证书
  143. X509Certificate2 GetOrCreateCert(ICacheEntry entry)
  144. {
  145. var domains = GetDomains(domain).Distinct();
  146. var validFrom = DateTime.Today.AddDays(-1);
  147. var validTo = DateTime.Today.AddYears(1);
  148. entry.SetAbsoluteExpiration(validTo);
  149. return CertGenerator.GenerateByCa(domains, KEY_SIZE_BITS, validFrom, validTo, this.CaCerFilePath, this.CaKeyFilePath);
  150. }
  151. }
  152. /// <summary>
  153. /// 获取域名
  154. /// </summary>
  155. /// <param name="domain"></param>
  156. /// <returns></returns>
  157. private static IEnumerable<string> GetDomains(string? domain)
  158. {
  159. if (string.IsNullOrEmpty(domain) == false)
  160. {
  161. yield return domain;
  162. yield break;
  163. }
  164. yield return Environment.MachineName;
  165. yield return IPAddress.Loopback.ToString();
  166. }
  167. }
  168. }