KestrelServerOptionsExtensions.cs 5.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156
  1. using FastGithub.ReverseProxy;
  2. using Microsoft.AspNetCore.Hosting;
  3. using Microsoft.AspNetCore.Server.Kestrel.Core;
  4. using Microsoft.Extensions.DependencyInjection;
  5. using Microsoft.Extensions.Logging;
  6. using System;
  7. using System.Collections.Concurrent;
  8. using System.Collections.Generic;
  9. using System.IO;
  10. using System.Linq;
  11. using System.Net;
  12. using System.Net.NetworkInformation;
  13. using System.Net.Sockets;
  14. using System.Security.Cryptography.X509Certificates;
  15. using System.Threading;
  16. namespace FastGithub
  17. {
  18. /// <summary>
  19. /// Kestrel扩展
  20. /// </summary>
  21. public static class KestrelServerOptionsExtensions
  22. {
  23. /// <summary>
  24. /// 域名与证书
  25. /// </summary>
  26. private static readonly ConcurrentDictionary<string, Lazy<X509Certificate2>> domainCerts = new();
  27. /// <summary>
  28. /// 监听https的反向代理
  29. /// </summary>
  30. /// <param name="kestrel"></param>
  31. public static void ListenHttpsReverseProxy(this KestrelServerOptions kestrel)
  32. {
  33. var loggerFactory = kestrel.ApplicationServices.GetRequiredService<ILoggerFactory>();
  34. var logger = loggerFactory.CreateLogger($"{nameof(FastGithub)}.{nameof(ReverseProxy)}");
  35. const string CAPATH = "CACert";
  36. Directory.CreateDirectory(CAPATH);
  37. var caPublicCerPath = $"{CAPATH}/{Environment.MachineName}.cer";
  38. var caPrivateKeyPath = $"{CAPATH}/{Environment.MachineName}.key";
  39. GeneratorCaCert(caPublicCerPath, caPrivateKeyPath);
  40. InstallCaCert(caPublicCerPath, logger);
  41. kestrel.ListenAnyIP(443, listen =>
  42. listen.UseHttps(https =>
  43. https.ServerCertificateSelector = (ctx, domain) =>
  44. GetDomainCert(domain, caPublicCerPath, caPrivateKeyPath)));
  45. logger.LogInformation("https反向代理服务启动成功");
  46. }
  47. /// <summary>
  48. /// 生成根证书
  49. /// </summary>
  50. /// <param name="caPublicCerPath"></param>
  51. /// <param name="caPrivateKeyPath"></param>
  52. private static void GeneratorCaCert(string caPublicCerPath, string caPrivateKeyPath)
  53. {
  54. if (File.Exists(caPublicCerPath) && File.Exists(caPublicCerPath))
  55. {
  56. return;
  57. }
  58. File.Delete(caPublicCerPath);
  59. File.Delete(caPrivateKeyPath);
  60. var validFrom = DateTime.Today.AddYears(-10);
  61. var validTo = DateTime.Today.AddYears(50);
  62. CertGenerator.GenerateBySelf(new[] { nameof(FastGithub) }, 2048, validFrom, validTo, caPublicCerPath, caPrivateKeyPath);
  63. }
  64. /// <summary>
  65. /// 安装根证书
  66. /// </summary>
  67. /// <param name="caPublicCerPath"></param>
  68. /// <param name="logger"></param>
  69. private static void InstallCaCert(string caPublicCerPath, ILogger logger)
  70. {
  71. try
  72. {
  73. var caCert = new X509Certificate2(caPublicCerPath);
  74. using var store = new X509Store(StoreName.Root, StoreLocation.LocalMachine);
  75. store.Open(OpenFlags.ReadWrite);
  76. if (store.Certificates.Find(X509FindType.FindByThumbprint, caCert.Thumbprint, true).Count == 0)
  77. {
  78. store.Add(caCert);
  79. store.Close();
  80. }
  81. }
  82. catch (Exception)
  83. {
  84. if (OperatingSystem.IsWindows())
  85. {
  86. logger.LogWarning($"安装根证书{caPublicCerPath}失败:请手动安装到“将所有的证书都放入下载存储”\\“受信任的根证书颁发机构”");
  87. }
  88. else
  89. {
  90. logger.LogWarning($"安装根证书{caPublicCerPath}失败:请根据你的系统平台要求安装和信任根证书");
  91. }
  92. }
  93. }
  94. /// <summary>
  95. /// 获取颁发给指定域名的证书
  96. /// </summary>
  97. /// <param name="domain"></param>
  98. /// <param name="caPublicCerPath"></param>
  99. /// <param name="caPrivateKeyPath"></param>
  100. /// <returns></returns>
  101. private static X509Certificate2 GetDomainCert(string domain, string caPublicCerPath, string caPrivateKeyPath)
  102. {
  103. return domainCerts.GetOrAdd(domain, GetOrCreateCert).Value;
  104. Lazy<X509Certificate2> GetOrCreateCert(string host)
  105. {
  106. return new Lazy<X509Certificate2>(() =>
  107. {
  108. var domains = GetDomains(host).Distinct();
  109. var validFrom = DateTime.Today.AddYears(-1);
  110. var validTo = DateTime.Today.AddYears(10);
  111. return CertGenerator.GenerateByCa(domains, 2048, validFrom, validTo, caPublicCerPath, caPrivateKeyPath);
  112. }, LazyThreadSafetyMode.ExecutionAndPublication);
  113. }
  114. }
  115. /// <summary>
  116. /// 获取域名
  117. /// </summary>
  118. /// <param name="host"></param>
  119. /// <returns></returns>
  120. private static IEnumerable<string> GetDomains(string host)
  121. {
  122. if (string.IsNullOrEmpty(host) == false)
  123. {
  124. yield return host;
  125. }
  126. yield return Environment.MachineName;
  127. yield return IPAddress.Loopback.ToString();
  128. foreach (var @interface in NetworkInterface.GetAllNetworkInterfaces())
  129. {
  130. foreach (var addressInfo in @interface.GetIPProperties().UnicastAddresses)
  131. {
  132. if (addressInfo.Address.AddressFamily == AddressFamily.InterNetwork)
  133. {
  134. yield return addressInfo.Address.ToString();
  135. }
  136. }
  137. }
  138. }
  139. }
  140. }