Files
amnezia-client/client/configurators/wireguard_configurator.cpp
T

209 lines
6.9 KiB
C++
Raw Normal View History

2021-06-12 11:59:36 +03:00
#include "wireguard_configurator.h"
#include <QApplication>
#include <QProcess>
#include <QString>
#include <QTemporaryDir>
#include <QDebug>
#include <QTemporaryFile>
2022-08-25 17:35:28 +03:00
#include <QJsonDocument>
2021-06-12 11:59:36 +03:00
2021-10-27 00:42:25 +03:00
#include <openssl/rand.h>
#include <openssl/rsa.h>
#include <openssl/x509.h>
#include <openssl/pem.h>
2021-06-12 11:59:36 +03:00
2021-09-09 20:15:44 +03:00
#include "containers/containers_defs.h"
2022-08-25 17:35:28 +03:00
#include "core/server_defs.h"
2021-06-12 11:59:36 +03:00
#include "core/scripts_registry.h"
#include "utilities.h"
2022-08-25 17:35:28 +03:00
#include "core/servercontroller.h"
#include "settings.h"
2021-06-12 11:59:36 +03:00
2022-08-25 17:35:28 +03:00
WireguardConfigurator::WireguardConfigurator(std::shared_ptr<Settings> settings, std::shared_ptr<ServerController> serverController, QObject *parent):
ConfiguratorBase(settings, serverController, parent)
{
}
2021-06-12 11:59:36 +03:00
WireguardConfigurator::ConnectionData WireguardConfigurator::genClientKeys()
{
2021-10-27 00:42:25 +03:00
// TODO review
constexpr size_t EDDSA_KEY_LENGTH = 32;
2021-06-12 11:59:36 +03:00
2021-10-27 00:42:25 +03:00
ConnectionData connData;
2021-09-15 08:03:28 -07:00
2021-10-27 00:42:25 +03:00
unsigned char buff[EDDSA_KEY_LENGTH];
int ret = RAND_priv_bytes(buff, EDDSA_KEY_LENGTH);
if (ret <=0) return connData;
2021-06-12 11:59:36 +03:00
2021-10-27 00:42:25 +03:00
EVP_PKEY * pKey = EVP_PKEY_new();
q_check_ptr(pKey);
2021-11-02 21:50:28 +03:00
pKey = EVP_PKEY_new_raw_private_key(EVP_PKEY_X25519, NULL, &buff[0], EDDSA_KEY_LENGTH);
2021-06-12 11:59:36 +03:00
2021-10-27 00:42:25 +03:00
size_t keySize = EDDSA_KEY_LENGTH;
2021-06-12 11:59:36 +03:00
2021-10-27 00:42:25 +03:00
// save private key
unsigned char priv[EDDSA_KEY_LENGTH];
EVP_PKEY_get_raw_private_key(pKey, priv, &keySize);
connData.clientPrivKey = QByteArray::fromRawData((char*)priv, keySize).toBase64();
2021-06-12 11:59:36 +03:00
2021-10-27 00:42:25 +03:00
// save public key
unsigned char pub[EDDSA_KEY_LENGTH];
EVP_PKEY_get_raw_public_key(pKey, pub, &keySize);
connData.clientPubKey = QByteArray::fromRawData((char*)pub, keySize).toBase64();
2021-06-12 11:59:36 +03:00
return connData;
}
WireguardConfigurator::ConnectionData WireguardConfigurator::prepareWireguardConfig(const ServerCredentials &credentials,
2021-12-25 21:14:55 +03:00
DockerContainer container, const QJsonObject &containerConfig, ErrorCode *errorCode)
2021-06-12 11:59:36 +03:00
{
WireguardConfigurator::ConnectionData connData = WireguardConfigurator::genClientKeys();
connData.host = credentials.hostName;
if (connData.clientPrivKey.isEmpty() || connData.clientPubKey.isEmpty()) {
2021-10-17 07:00:00 -07:00
if (errorCode) *errorCode = ErrorCode::InternalError;
2021-06-12 11:59:36 +03:00
return connData;
}
ErrorCode e = ErrorCode::NoError;
2021-12-25 21:14:55 +03:00
// Get list of already created clients (only IP addreses)
QString nextIpNumber;
{
QString script = QString("cat %1 | grep AllowedIPs").arg(amnezia::protocols::wireguard::serverConfigPath);
QString stdOut;
auto cbReadStdOut = [&](const QString &data) {
2021-12-25 21:14:55 +03:00
stdOut += data + "\n";
};
2022-09-19 00:44:00 +03:00
e = m_serverController->runContainerScript(credentials, container, script, cbReadStdOut);
if (errorCode && e) {
*errorCode = e;
return connData;
}
2021-12-25 21:14:55 +03:00
stdOut.replace("AllowedIPs = ", "");
stdOut.replace("/32", "");
QStringList ips = stdOut.split("\n", Qt::SkipEmptyParts);
// Calc next IP address
if (ips.isEmpty()) {
nextIpNumber = "2";
}
else {
int next = ips.last().split(".").last().toInt() + 1;
if (next > 254) {
if (errorCode) *errorCode = ErrorCode::AddressPoolError;
return connData;
}
nextIpNumber = QString::number(next);
}
}
QString subnetIp = containerConfig.value(config_key::subnet_address).toString(protocols::wireguard::defaultSubnetAddress);
{
QStringList l = subnetIp.split(".", Qt::SkipEmptyParts);
if (l.isEmpty()) {
if (errorCode) *errorCode = ErrorCode::AddressPoolError;
return connData;
}
l.removeLast();
l.append(nextIpNumber);
connData.clientIP = l.join(".");
}
// Get keys
2022-08-25 17:35:28 +03:00
connData.serverPubKey = m_serverController->getTextFileFromContainer(container, credentials, amnezia::protocols::wireguard::serverPublicKeyPath, &e);
2021-06-12 11:59:36 +03:00
connData.serverPubKey.replace("\n", "");
if (e) {
if (errorCode) *errorCode = e;
return connData;
}
2022-08-25 17:35:28 +03:00
connData.pskKey = m_serverController->getTextFileFromContainer(container, credentials, amnezia::protocols::wireguard::serverPskKeyPath, &e);
2021-06-12 11:59:36 +03:00
connData.pskKey.replace("\n", "");
if (e) {
if (errorCode) *errorCode = e;
return connData;
}
2021-12-25 21:14:55 +03:00
// Add client to config
2021-06-12 11:59:36 +03:00
QString configPart = QString(
"[Peer]\n"
"PublicKey = %1\n"
"PresharedKey = %2\n"
2021-12-25 21:14:55 +03:00
"AllowedIPs = %3/32\n\n").
2021-06-12 11:59:36 +03:00
arg(connData.clientPubKey).
2021-12-25 21:14:55 +03:00
arg(connData.pskKey).
arg(connData.clientIP);
2021-06-12 11:59:36 +03:00
2022-08-25 17:35:28 +03:00
e = m_serverController->uploadTextFileToContainer(container, credentials, configPart,
2021-06-12 11:59:36 +03:00
protocols::wireguard::serverConfigPath, QSsh::SftpOverwriteMode::SftpAppendToExisting);
if (e) {
if (errorCode) *errorCode = e;
return connData;
}
2022-08-25 17:35:28 +03:00
e = m_serverController->runScript(credentials,
m_serverController->replaceVars("sudo docker exec -i $CONTAINER_NAME bash -c 'wg syncconf wg0 <(wg-quick strip /opt/amnezia/wireguard/wg0.conf)'",
m_serverController->genVarsForScript(credentials, container)));
2021-06-12 11:59:36 +03:00
return connData;
}
QString WireguardConfigurator::genWireguardConfig(const ServerCredentials &credentials,
DockerContainer container, const QJsonObject &containerConfig, ErrorCode *errorCode)
{
2022-08-25 17:35:28 +03:00
QString config = m_serverController->replaceVars(amnezia::scriptData(ProtocolScriptType::wireguard_template, container),
m_serverController->genVarsForScript(credentials, container, containerConfig));
2021-06-12 11:59:36 +03:00
2021-12-25 21:14:55 +03:00
ConnectionData connData = prepareWireguardConfig(credentials, container, containerConfig, errorCode);
2021-06-12 11:59:36 +03:00
if (errorCode && *errorCode) {
return "";
}
config.replace("$WIREGUARD_CLIENT_PRIVATE_KEY", connData.clientPrivKey);
2021-12-25 21:14:55 +03:00
config.replace("$WIREGUARD_CLIENT_IP", connData.clientIP);
2021-06-12 11:59:36 +03:00
config.replace("$WIREGUARD_SERVER_PUBLIC_KEY", connData.serverPubKey);
config.replace("$WIREGUARD_PSK", connData.pskKey);
2021-10-05 12:22:13 +03:00
QJsonObject jConfig;
jConfig[config_key::config] = config;
2021-10-20 18:43:51 +03:00
jConfig[config_key::hostName] = connData.host;
jConfig[config_key::client_priv_key] = connData.clientPrivKey;
2021-12-25 21:14:55 +03:00
jConfig[config_key::client_ip] = connData.clientIP;
2021-10-20 18:43:51 +03:00
jConfig[config_key::client_pub_key] = connData.clientPubKey;
jConfig[config_key::psk_key] = connData.pskKey;
jConfig[config_key::server_pub_key] = connData.serverPubKey;
2021-10-05 12:22:13 +03:00
return QJsonDocument(jConfig).toJson();
2021-06-12 11:59:36 +03:00
}
QString WireguardConfigurator::processConfigWithLocalSettings(QString config)
{
// TODO replace DNS if it already set
2022-08-25 17:35:28 +03:00
config.replace("$PRIMARY_DNS", m_settings->primaryDns());
config.replace("$SECONDARY_DNS", m_settings->secondaryDns());
2021-06-12 11:59:36 +03:00
2021-10-05 12:22:13 +03:00
QJsonObject jConfig;
jConfig[config_key::config] = config;
return QJsonDocument(jConfig).toJson();
2021-06-12 11:59:36 +03:00
}
QString WireguardConfigurator::processConfigWithExportSettings(QString config)
{
2022-08-25 17:35:28 +03:00
config.replace("$PRIMARY_DNS", m_settings->primaryDns());
config.replace("$SECONDARY_DNS", m_settings->secondaryDns());
2021-06-12 11:59:36 +03:00
return config;
}