CertService.cs 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153
  1. using Microsoft.Extensions.Caching.Memory;
  2. using Microsoft.Extensions.Logging;
  3. using System;
  4. using System.Collections.Generic;
  5. using System.Diagnostics;
  6. using System.IO;
  7. using System.Linq;
  8. using System.Net;
  9. using System.Security.Cryptography.X509Certificates;
  10. namespace FastGithub.HttpServer
  11. {
  12. /// <summary>
  13. /// 证书服务
  14. /// </summary>
  15. sealed class CertService
  16. {
  17. private const string CACERT_PATH = "cacert";
  18. private const int KEY_SIZE_BITS = 2048;
  19. private readonly IMemoryCache serverCertCache;
  20. private readonly IEnumerable<ICaCertInstaller> certInstallers;
  21. private readonly ILogger<CertService> logger;
  22. /// <summary>
  23. /// 获取证书文件路径
  24. /// </summary>
  25. public string CaCerFilePath { get; } = $"{CACERT_PATH}/fastgithub.cer";
  26. /// <summary>
  27. /// 获取私钥文件路径
  28. /// </summary>
  29. public string CaKeyFilePath { get; } = $"{CACERT_PATH}/fastgithub.key";
  30. /// <summary>
  31. /// 证书服务
  32. /// </summary>
  33. /// <param name="serverCertCache"></param>
  34. /// <param name="certInstallers"></param>
  35. /// <param name="logger"></param>
  36. public CertService(
  37. IMemoryCache serverCertCache,
  38. IEnumerable<ICaCertInstaller> certInstallers,
  39. ILogger<CertService> logger)
  40. {
  41. this.serverCertCache = serverCertCache;
  42. this.certInstallers = certInstallers;
  43. this.logger = logger;
  44. Directory.CreateDirectory(CACERT_PATH);
  45. }
  46. /// <summary>
  47. /// 生成CA证书
  48. /// </summary>
  49. public bool CreateCaCertIfNotExists()
  50. {
  51. if (File.Exists(this.CaCerFilePath) && File.Exists(this.CaKeyFilePath))
  52. {
  53. return false;
  54. }
  55. File.Delete(this.CaCerFilePath);
  56. File.Delete(this.CaKeyFilePath);
  57. var validFrom = DateTime.Today.AddDays(-1);
  58. var validTo = DateTime.Today.AddYears(10);
  59. CertGenerator.GenerateBySelf(new[] { nameof(FastGithub) }, KEY_SIZE_BITS, validFrom, validTo, this.CaCerFilePath, this.CaKeyFilePath);
  60. return true;
  61. }
  62. /// <summary>
  63. /// 安装和信任CA证书
  64. /// </summary>
  65. public void InstallAndTrustCaCert()
  66. {
  67. var installer = this.certInstallers.FirstOrDefault(item => item.IsSupported());
  68. if (installer != null)
  69. {
  70. installer.Install(this.CaCerFilePath, this.logger);
  71. }
  72. else
  73. {
  74. this.logger.LogWarning($"请根据你的系统平台手动安装和信任CA证书{this.CaCerFilePath}");
  75. }
  76. GitConfigSslverify(false);
  77. }
  78. /// <summary>
  79. /// 设置ssl验证
  80. /// </summary>
  81. /// <param name="value">是否验证</param>
  82. /// <returns></returns>
  83. public static bool GitConfigSslverify(bool value)
  84. {
  85. try
  86. {
  87. Process.Start(new ProcessStartInfo
  88. {
  89. FileName = "git",
  90. Arguments = $"config --global http.sslverify {value.ToString().ToLower()}",
  91. UseShellExecute = true,
  92. CreateNoWindow = true,
  93. WindowStyle = ProcessWindowStyle.Hidden
  94. });
  95. return true;
  96. }
  97. catch (Exception)
  98. {
  99. return false;
  100. }
  101. }
  102. /// <summary>
  103. /// 获取颁发给指定域名的证书
  104. /// </summary>
  105. /// <param name="domain"></param>
  106. /// <returns></returns>
  107. public X509Certificate2 GetOrCreateServerCert(string? domain)
  108. {
  109. var key = $"{nameof(CertService)}:{domain}";
  110. return this.serverCertCache.GetOrCreate(key, GetOrCreateCert);
  111. // 生成域名的1年证书
  112. X509Certificate2 GetOrCreateCert(ICacheEntry entry)
  113. {
  114. var domains = GetDomains(domain).Distinct();
  115. var validFrom = DateTime.Today.AddDays(-1);
  116. var validTo = DateTime.Today.AddYears(1);
  117. entry.SetAbsoluteExpiration(validTo);
  118. return CertGenerator.GenerateByCa(domains, KEY_SIZE_BITS, validFrom, validTo, this.CaCerFilePath, this.CaKeyFilePath);
  119. }
  120. }
  121. /// <summary>
  122. /// 获取域名
  123. /// </summary>
  124. /// <param name="domain"></param>
  125. /// <returns></returns>
  126. private static IEnumerable<string> GetDomains(string? domain)
  127. {
  128. if (string.IsNullOrEmpty(domain) == false)
  129. {
  130. yield return domain;
  131. yield break;
  132. }
  133. yield return Environment.MachineName;
  134. yield return IPAddress.Loopback.ToString();
  135. }
  136. }
  137. }