KestrelServerOptionsExtensions.cs 5.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154
  1. using FastGithub.ReverseProxy;
  2. using Microsoft.AspNetCore.Hosting;
  3. using Microsoft.AspNetCore.Server.Kestrel.Core;
  4. using Microsoft.Extensions.DependencyInjection;
  5. using Microsoft.Extensions.Logging;
  6. using System;
  7. using System.Collections.Concurrent;
  8. using System.Collections.Generic;
  9. using System.IO;
  10. using System.Linq;
  11. using System.Net;
  12. using System.Net.NetworkInformation;
  13. using System.Net.Sockets;
  14. using System.Security.Cryptography.X509Certificates;
  15. using System.Threading;
  16. namespace FastGithub
  17. {
  18. /// <summary>
  19. /// Kestrel扩展
  20. /// </summary>
  21. public static class KestrelServerOptionsExtensions
  22. {
  23. /// <summary>
  24. /// 域名与证书
  25. /// </summary>
  26. private static readonly ConcurrentDictionary<string, Lazy<X509Certificate2>> domainCerts = new();
  27. /// <summary>
  28. /// 监听https的反向代理
  29. /// </summary>
  30. /// <param name="kestrel"></param>
  31. public static void ListenHttpsReverseProxy(this KestrelServerOptions kestrel)
  32. {
  33. var loggerFactory = kestrel.ApplicationServices.GetRequiredService<ILoggerFactory>();
  34. var logger = loggerFactory.CreateLogger($"{nameof(FastGithub)}.{nameof(ReverseProxy)}");
  35. const string CAPATH = "CACert";
  36. Directory.CreateDirectory(CAPATH);
  37. var caPublicCerPath = $"{CAPATH}/{Environment.MachineName}.cer";
  38. var caPrivateKeyPath = $"{CAPATH}/{Environment.MachineName}.key";
  39. GeneratorCaCert(caPublicCerPath, caPrivateKeyPath);
  40. InstallCaCert(caPublicCerPath, logger);
  41. kestrel.Listen(IPAddress.Any, 443, listen =>
  42. listen.UseHttps(https =>
  43. https.ServerCertificateSelector = (ctx, domain) =>
  44. GetDomainCert(domain, caPublicCerPath, caPrivateKeyPath)));
  45. }
  46. /// <summary>
  47. /// 生成根证书
  48. /// </summary>
  49. /// <param name="caPublicCerPath"></param>
  50. /// <param name="caPrivateKeyPath"></param>
  51. private static void GeneratorCaCert(string caPublicCerPath, string caPrivateKeyPath)
  52. {
  53. if (File.Exists(caPublicCerPath) && File.Exists(caPublicCerPath))
  54. {
  55. return;
  56. }
  57. File.Delete(caPublicCerPath);
  58. File.Delete(caPrivateKeyPath);
  59. var validFrom = DateTime.Today.AddYears(-10);
  60. var validTo = DateTime.Today.AddYears(50);
  61. CertGenerator.GenerateBySelf(new[] { nameof(FastGithub) }, 2048, validFrom, validTo, caPublicCerPath, caPrivateKeyPath);
  62. }
  63. /// <summary>
  64. /// 安装根证书
  65. /// </summary>
  66. /// <param name="caPublicCerPath"></param>
  67. /// <param name="logger"></param>
  68. private static void InstallCaCert(string caPublicCerPath, ILogger logger)
  69. {
  70. try
  71. {
  72. var caCert = new X509Certificate2(caPublicCerPath);
  73. using var store = new X509Store(StoreName.Root, StoreLocation.LocalMachine);
  74. store.Open(OpenFlags.ReadWrite);
  75. if (store.Certificates.Find(X509FindType.FindByThumbprint, caCert.Thumbprint, true).Count == 0)
  76. {
  77. store.Add(caCert);
  78. store.Close();
  79. }
  80. }
  81. catch (Exception)
  82. {
  83. if (OperatingSystem.IsWindows())
  84. {
  85. logger.LogWarning($"安装根证书{caPublicCerPath}失败:请手动安装到“将所有的证书都放入下载存储”\\“受信任的根证书颁发机构”");
  86. }
  87. else
  88. {
  89. logger.LogWarning($"安装根证书{caPublicCerPath}失败:请根据你的系统平台要求安装和信任根证书");
  90. }
  91. }
  92. }
  93. /// <summary>
  94. /// 获取颁发给指定域名的证书
  95. /// </summary>
  96. /// <param name="domain"></param>
  97. /// <param name="caPublicCerPath"></param>
  98. /// <param name="caPrivateKeyPath"></param>
  99. /// <returns></returns>
  100. private static X509Certificate2 GetDomainCert(string domain, string caPublicCerPath, string caPrivateKeyPath)
  101. {
  102. return domainCerts.GetOrAdd(domain, GetOrCreateCert).Value;
  103. Lazy<X509Certificate2> GetOrCreateCert(string host)
  104. {
  105. return new Lazy<X509Certificate2>(() =>
  106. {
  107. var domains = GetDomains(host).Distinct();
  108. var validFrom = DateTime.Today.AddYears(-1);
  109. var validTo = DateTime.Today.AddYears(10);
  110. return CertGenerator.GenerateByCa(domains, 2048, validFrom, validTo, caPublicCerPath, caPrivateKeyPath);
  111. }, LazyThreadSafetyMode.ExecutionAndPublication);
  112. }
  113. }
  114. /// <summary>
  115. /// 获取域名
  116. /// </summary>
  117. /// <param name="host"></param>
  118. /// <returns></returns>
  119. private static IEnumerable<string> GetDomains(string host)
  120. {
  121. if (string.IsNullOrEmpty(host) == false)
  122. {
  123. yield return host;
  124. }
  125. yield return Environment.MachineName;
  126. yield return IPAddress.Loopback.ToString();
  127. foreach (var @interface in NetworkInterface.GetAllNetworkInterfaces())
  128. {
  129. foreach (var addressInfo in @interface.GetIPProperties().UnicastAddresses)
  130. {
  131. if (addressInfo.Address.AddressFamily == AddressFamily.InterNetwork)
  132. {
  133. yield return addressInfo.Address.ToString();
  134. }
  135. }
  136. }
  137. }
  138. }
  139. }