2026-04-30 14:53:03 +08:00
|
|
|
#include "openVpnConfigurator.h"
|
2023-08-31 16:00:41 +05:00
|
|
|
|
|
|
|
|
#include <QDebug>
|
|
|
|
|
#include <QJsonDocument>
|
|
|
|
|
#include <QJsonObject>
|
2026-04-30 14:53:03 +08:00
|
|
|
#include <QRegularExpression>
|
2020-12-18 14:57:22 +03:00
|
|
|
#include <QProcess>
|
|
|
|
|
#include <QString>
|
|
|
|
|
#include <QTemporaryDir>
|
2021-03-14 21:19:11 +03:00
|
|
|
#include <QTemporaryFile>
|
2023-08-31 21:49:36 +05:00
|
|
|
#if defined(Q_OS_ANDROID) || defined(Q_OS_IOS)
|
|
|
|
|
#include <QGuiApplication>
|
|
|
|
|
#else
|
|
|
|
|
#include <QApplication>
|
|
|
|
|
#endif
|
2020-12-18 14:57:22 +03:00
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
#include "core/utils/errorCodes.h"
|
|
|
|
|
#include "core/utils/routeModes.h"
|
|
|
|
|
#include "core/utils/commonStructs.h"
|
|
|
|
|
#include "core/utils/networkUtilities.h"
|
|
|
|
|
#include "core/utils/containerEnum.h"
|
|
|
|
|
#include "core/utils/containers/containerUtils.h"
|
|
|
|
|
#include "core/utils/protocolEnum.h"
|
|
|
|
|
#include "core/utils/selfhosted/sshSession.h"
|
|
|
|
|
#include "core/utils/selfhosted/scriptsRegistry.h"
|
|
|
|
|
#include "core/utils/utilities.h"
|
|
|
|
|
#include "core/models/protocols/openVpnProtocolConfig.h"
|
|
|
|
|
|
|
|
|
|
using namespace amnezia;
|
2020-12-18 14:57:22 +03:00
|
|
|
|
2023-08-31 16:00:41 +05:00
|
|
|
#include <openssl/pem.h>
|
2021-10-17 13:03:03 +03:00
|
|
|
#include <openssl/rsa.h>
|
|
|
|
|
#include <openssl/x509.h>
|
2020-12-18 14:57:22 +03:00
|
|
|
|
2025-05-02 23:52:59 -07:00
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
OpenVpnConfigurator::OpenVpnConfigurator(SshSession* sshSession, QObject *parent)
|
|
|
|
|
: ConfiguratorBase(sshSession, parent)
|
2022-08-25 17:35:28 +03:00
|
|
|
{
|
|
|
|
|
}
|
|
|
|
|
|
2021-01-15 23:36:35 +03:00
|
|
|
OpenVpnConfigurator::ConnectionData OpenVpnConfigurator::prepareOpenVpnConfig(const ServerCredentials &credentials,
|
2026-04-30 14:53:03 +08:00
|
|
|
DockerContainer container,
|
|
|
|
|
const DnsSettings &dnsSettings,
|
|
|
|
|
ErrorCode &errorCode)
|
2020-12-18 14:57:22 +03:00
|
|
|
{
|
|
|
|
|
OpenVpnConfigurator::ConnectionData connData = OpenVpnConfigurator::createCertRequest();
|
2021-01-06 17:12:24 +03:00
|
|
|
connData.host = credentials.hostName;
|
2020-12-18 14:57:22 +03:00
|
|
|
|
2021-01-07 20:53:42 +03:00
|
|
|
if (connData.privKey.isEmpty() || connData.request.isEmpty()) {
|
2024-04-01 20:20:02 +07:00
|
|
|
errorCode = ErrorCode::OpenSslFailed;
|
2021-01-07 20:53:42 +03:00
|
|
|
return connData;
|
|
|
|
|
}
|
|
|
|
|
|
2023-08-31 16:00:41 +05:00
|
|
|
QString reqFileName = QString("%1/%2.req").arg(amnezia::protocols::openvpn::clientsDirPath).arg(connData.clientId);
|
2021-01-15 23:36:35 +03:00
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
errorCode = m_sshSession->uploadTextFileToContainer(container, credentials, connData.request, reqFileName);
|
2024-04-01 20:20:02 +07:00
|
|
|
if (errorCode != ErrorCode::NoError) {
|
2021-01-06 17:12:24 +03:00
|
|
|
return connData;
|
|
|
|
|
}
|
2020-12-18 14:57:22 +03:00
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
errorCode = signCert(container, credentials, dnsSettings, connData.clientId);
|
2024-04-01 20:20:02 +07:00
|
|
|
if (errorCode != ErrorCode::NoError) {
|
2021-01-15 23:36:35 +03:00
|
|
|
return connData;
|
|
|
|
|
}
|
2020-12-18 14:57:22 +03:00
|
|
|
|
2024-04-12 20:00:21 +05:00
|
|
|
connData.caCert =
|
2026-04-30 14:53:03 +08:00
|
|
|
m_sshSession->getTextFileFromContainer(container, credentials, amnezia::protocols::openvpn::caCertPath, errorCode);
|
|
|
|
|
connData.clientCert = m_sshSession->getTextFileFromContainer(
|
2024-04-12 20:00:21 +05:00
|
|
|
container, credentials, QString("%1/%2.crt").arg(amnezia::protocols::openvpn::clientCertPath).arg(connData.clientId), errorCode);
|
2021-04-04 23:12:36 +03:00
|
|
|
|
2024-04-01 20:20:02 +07:00
|
|
|
if (errorCode != ErrorCode::NoError) {
|
2021-01-06 17:12:24 +03:00
|
|
|
return connData;
|
|
|
|
|
}
|
2020-12-18 14:57:22 +03:00
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
connData.taKey = m_sshSession->getTextFileFromContainer(container, credentials, amnezia::protocols::openvpn::taKeyPath, errorCode);
|
2021-01-15 23:36:35 +03:00
|
|
|
|
|
|
|
|
if (connData.caCert.isEmpty() || connData.clientCert.isEmpty() || connData.taKey.isEmpty()) {
|
2024-04-01 20:20:02 +07:00
|
|
|
errorCode = ErrorCode::SshScpFailureError;
|
2021-01-15 23:36:35 +03:00
|
|
|
}
|
2020-12-18 14:57:22 +03:00
|
|
|
|
|
|
|
|
return connData;
|
|
|
|
|
}
|
|
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
ProtocolConfig OpenVpnConfigurator::createConfig(const ServerCredentials &credentials, DockerContainer container,
|
|
|
|
|
const ContainerConfig &containerConfig,
|
|
|
|
|
const DnsSettings &dnsSettings,
|
|
|
|
|
ErrorCode &errorCode)
|
2020-12-18 14:57:22 +03:00
|
|
|
{
|
2026-04-30 14:53:03 +08:00
|
|
|
const OpenVpnServerConfig* serverConfig = nullptr;
|
|
|
|
|
if (auto* openVpnProtocolConfig = containerConfig.getOpenVpnProtocolConfig()) {
|
|
|
|
|
serverConfig = &openVpnProtocolConfig->serverConfig;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
amnezia::ScriptVars vars = amnezia::genBaseVars(credentials, container, dnsSettings.primaryDns, dnsSettings.secondaryDns);
|
|
|
|
|
vars.append(amnezia::genProtocolVarsForContainer(container, containerConfig));
|
|
|
|
|
QString config = m_sshSession->replaceVars(amnezia::scriptData(ProtocolScriptType::openvpn_template, container), vars);
|
2020-12-18 14:57:22 +03:00
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
ConnectionData connData = prepareOpenVpnConfig(credentials, container, dnsSettings, errorCode);
|
2024-04-01 20:20:02 +07:00
|
|
|
if (errorCode != ErrorCode::NoError) {
|
2026-04-30 14:53:03 +08:00
|
|
|
return OpenVpnProtocolConfig{};
|
2021-04-04 23:12:36 +03:00
|
|
|
}
|
2021-01-15 23:36:35 +03:00
|
|
|
|
2025-10-06 16:04:49 +03:00
|
|
|
auto sanitizeStaticKey = [](const QString &key) {
|
|
|
|
|
QStringList lines = key.split('\n');
|
|
|
|
|
QStringList filtered;
|
|
|
|
|
filtered.reserve(lines.size());
|
|
|
|
|
for (const QString &line : lines) {
|
|
|
|
|
const QString trimmed = line.trimmed();
|
|
|
|
|
if (trimmed.startsWith('#')) {
|
|
|
|
|
continue;
|
|
|
|
|
}
|
|
|
|
|
filtered.append(line);
|
|
|
|
|
}
|
|
|
|
|
QString result = filtered.join('\n');
|
|
|
|
|
if (!result.endsWith('\n')) {
|
|
|
|
|
result.append('\n');
|
|
|
|
|
}
|
|
|
|
|
return result;
|
|
|
|
|
};
|
|
|
|
|
|
2021-05-07 23:28:37 +03:00
|
|
|
config.replace("$OPENVPN_CA_CERT", connData.caCert);
|
|
|
|
|
config.replace("$OPENVPN_CLIENT_CERT", connData.clientCert);
|
|
|
|
|
config.replace("$OPENVPN_PRIV_KEY", connData.privKey);
|
2021-05-18 15:50:52 +03:00
|
|
|
|
|
|
|
|
if (config.contains("$OPENVPN_TA_KEY")) {
|
2025-10-06 16:04:49 +03:00
|
|
|
config.replace("$OPENVPN_TA_KEY", sanitizeStaticKey(connData.taKey));
|
2023-08-31 16:00:41 +05:00
|
|
|
} else {
|
2021-05-18 15:50:52 +03:00
|
|
|
config.replace("<tls-auth>", "");
|
|
|
|
|
config.replace("</tls-auth>", "");
|
|
|
|
|
}
|
2020-12-18 14:57:22 +03:00
|
|
|
|
2023-07-15 14:19:48 -07:00
|
|
|
#ifndef MZ_WINDOWS
|
2021-02-21 09:44:53 -08:00
|
|
|
config.replace("block-outside-dns", "");
|
|
|
|
|
#endif
|
2021-05-10 02:33:31 +03:00
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
OpenVpnProtocolConfig protocolConfig;
|
|
|
|
|
if (serverConfig) {
|
|
|
|
|
protocolConfig.serverConfig = *serverConfig;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
OpenVpnClientConfig clientConfig;
|
|
|
|
|
clientConfig.nativeConfig = config;
|
|
|
|
|
clientConfig.clientId = connData.clientId;
|
|
|
|
|
clientConfig.blockOutsideDns = false;
|
|
|
|
|
|
|
|
|
|
protocolConfig.setClientConfig(clientConfig);
|
|
|
|
|
|
|
|
|
|
return protocolConfig;
|
2021-05-10 02:33:31 +03:00
|
|
|
}
|
|
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
ProtocolConfig OpenVpnConfigurator::processConfigWithLocalSettings(const ConnectionSettings &settings,
|
|
|
|
|
ProtocolConfig protocolConfig)
|
2021-05-10 02:33:31 +03:00
|
|
|
{
|
2026-04-30 14:53:03 +08:00
|
|
|
applyDnsToNativeConfig(settings.dns, protocolConfig);
|
2024-04-01 20:20:02 +07:00
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
QString config = protocolConfig.nativeConfig();
|
2021-10-14 12:01:14 +03:00
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
if (!settings.isApiConfig) {
|
2024-01-17 00:34:23 +07:00
|
|
|
QRegularExpression regex("redirect-gateway.*");
|
|
|
|
|
config.replace(regex, "");
|
2025-10-06 16:04:49 +03:00
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
if (settings.dns.primaryDns.contains(protocols::dns::amneziaDnsIp)) {
|
|
|
|
|
QRegularExpression dnsRegex("dhcp-option DNS " + settings.dns.secondaryDns);
|
2025-07-01 19:16:58 -07:00
|
|
|
config.replace(dnsRegex, "");
|
|
|
|
|
}
|
|
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
if (!settings.splitTunneling.isSitesSplitTunnelingEnabled) {
|
2024-01-17 00:34:23 +07:00
|
|
|
config.append("\nredirect-gateway def1 ipv6 bypass-dhcp\n");
|
|
|
|
|
config.append("block-ipv6\n");
|
2026-04-30 14:53:03 +08:00
|
|
|
} else if (settings.splitTunneling.routeMode == RouteMode::VpnOnlyForwardSites) {
|
|
|
|
|
// no redirect-gateway
|
|
|
|
|
} else if (settings.splitTunneling.routeMode == RouteMode::VpnAllExceptSites) {
|
2025-08-10 06:12:19 +03:00
|
|
|
#if !defined(Q_OS_ANDROID) && !defined(Q_OS_IOS) && !defined(MACOS_NE)
|
2024-01-17 00:34:23 +07:00
|
|
|
config.append("\nredirect-gateway ipv6 !ipv4 bypass-dhcp\n");
|
2024-07-27 10:38:55 -07:00
|
|
|
#endif
|
2024-01-17 00:34:23 +07:00
|
|
|
config.append("block-ipv6\n");
|
|
|
|
|
}
|
2021-05-18 15:50:52 +03:00
|
|
|
}
|
2021-05-10 02:33:31 +03:00
|
|
|
|
2023-07-15 14:19:48 -07:00
|
|
|
#ifndef MZ_WINDOWS
|
2021-05-11 09:36:43 -07:00
|
|
|
config.replace("block-outside-dns", "");
|
2023-07-15 14:19:48 -07:00
|
|
|
#endif
|
|
|
|
|
|
2023-08-31 16:00:41 +05:00
|
|
|
#if (defined(MZ_MACOS) || defined(MZ_LINUX))
|
2026-04-30 14:53:03 +08:00
|
|
|
config.append(QString("\nscript-security 2\n"
|
|
|
|
|
"up %1/update-resolv-conf.sh\n"
|
|
|
|
|
"down %1/update-resolv-conf.sh\n")
|
|
|
|
|
.arg(qApp->applicationDirPath()));
|
2021-05-11 09:36:43 -07:00
|
|
|
#endif
|
|
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
protocolConfig.setNativeConfig(config);
|
|
|
|
|
return protocolConfig;
|
2020-12-18 14:57:22 +03:00
|
|
|
}
|
2021-03-14 21:19:11 +03:00
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
ProtocolConfig OpenVpnConfigurator::processConfigWithExportSettings(const ExportSettings &settings,
|
|
|
|
|
ProtocolConfig protocolConfig)
|
2021-05-20 15:59:58 +03:00
|
|
|
{
|
2026-04-30 14:53:03 +08:00
|
|
|
applyDnsToNativeConfig(settings.dns, protocolConfig);
|
2024-04-01 20:20:02 +07:00
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
QString config = protocolConfig.nativeConfig();
|
2021-10-14 12:01:14 +03:00
|
|
|
|
2023-08-08 16:41:00 -07:00
|
|
|
QRegularExpression regex("redirect-gateway.*");
|
|
|
|
|
config.replace(regex, "");
|
|
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
if (settings.dns.primaryDns.contains(protocols::dns::amneziaDnsIp)) {
|
|
|
|
|
QRegularExpression dnsRegex("dhcp-option DNS " + settings.dns.secondaryDns);
|
2025-07-01 19:16:58 -07:00
|
|
|
config.replace(dnsRegex, "");
|
|
|
|
|
}
|
|
|
|
|
|
2023-08-08 16:41:00 -07:00
|
|
|
config.append("\nredirect-gateway def1 ipv6 bypass-dhcp\n");
|
|
|
|
|
config.append("block-ipv6\n");
|
2021-05-20 15:59:58 +03:00
|
|
|
config.replace("block-outside-dns", "");
|
|
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
protocolConfig.setNativeConfig(config);
|
|
|
|
|
return protocolConfig;
|
2021-05-20 15:59:58 +03:00
|
|
|
}
|
|
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
ErrorCode OpenVpnConfigurator::signCert(DockerContainer container, const ServerCredentials &credentials,
|
|
|
|
|
const DnsSettings &dnsSettings, QString clientId)
|
2021-04-04 23:12:36 +03:00
|
|
|
{
|
|
|
|
|
QString script_import = QString("sudo docker exec -i %1 bash -c \"cd /opt/amnezia/openvpn && "
|
2023-08-31 16:00:41 +05:00
|
|
|
"easyrsa import-req %2/%3.req %3\"")
|
2026-04-30 14:53:03 +08:00
|
|
|
.arg(ContainerUtils::containerToString(container))
|
2023-08-31 16:00:41 +05:00
|
|
|
.arg(amnezia::protocols::openvpn::clientsDirPath)
|
|
|
|
|
.arg(clientId);
|
2021-04-04 23:12:36 +03:00
|
|
|
|
|
|
|
|
QString script_sign = QString("sudo docker exec -i %1 bash -c \"export EASYRSA_BATCH=1; cd /opt/amnezia/openvpn && "
|
2023-08-31 16:00:41 +05:00
|
|
|
"easyrsa sign-req client %2\"")
|
2026-04-30 14:53:03 +08:00
|
|
|
.arg(ContainerUtils::containerToString(container))
|
2023-08-31 16:00:41 +05:00
|
|
|
.arg(clientId);
|
2021-04-04 23:12:36 +03:00
|
|
|
|
2023-08-31 16:00:41 +05:00
|
|
|
QStringList scriptList { script_import, script_sign };
|
2026-04-30 14:53:03 +08:00
|
|
|
QString script = m_sshSession->replaceVars(scriptList.join("\n"), amnezia::genBaseVars(credentials, container, dnsSettings.primaryDns, dnsSettings.secondaryDns));
|
2021-04-04 23:12:36 +03:00
|
|
|
|
2026-04-30 14:53:03 +08:00
|
|
|
return m_sshSession->runScript(credentials, script);
|
2021-04-04 23:12:36 +03:00
|
|
|
}
|
2021-10-17 13:03:03 +03:00
|
|
|
|
|
|
|
|
OpenVpnConfigurator::ConnectionData OpenVpnConfigurator::createCertRequest()
|
|
|
|
|
{
|
|
|
|
|
ConnectionData connData;
|
|
|
|
|
connData.clientId = Utils::getRandomString(32);
|
|
|
|
|
|
2023-08-31 16:00:41 +05:00
|
|
|
int ret = 0;
|
2026-05-04 16:59:24 +02:00
|
|
|
int nVersion = 0;
|
2021-10-17 13:03:03 +03:00
|
|
|
|
|
|
|
|
QByteArray clientIdUtf8 = connData.clientId.toUtf8();
|
|
|
|
|
|
2023-08-31 16:00:41 +05:00
|
|
|
EVP_PKEY *pKey = EVP_PKEY_new();
|
2021-10-17 13:03:03 +03:00
|
|
|
q_check_ptr(pKey);
|
2023-08-31 16:00:41 +05:00
|
|
|
RSA *rsa = RSA_generate_key(2048, RSA_F4, nullptr, nullptr);
|
2021-10-17 13:03:03 +03:00
|
|
|
q_check_ptr(rsa);
|
|
|
|
|
EVP_PKEY_assign_RSA(pKey, rsa);
|
|
|
|
|
|
|
|
|
|
// 2. set version of x509 req
|
|
|
|
|
X509_REQ *x509_req = X509_REQ_new();
|
|
|
|
|
ret = X509_REQ_set_version(x509_req, nVersion);
|
|
|
|
|
if (ret != 1) {
|
|
|
|
|
qWarning() << "Could not get X509!";
|
2021-10-17 07:00:00 -07:00
|
|
|
X509_REQ_free(x509_req);
|
|
|
|
|
EVP_PKEY_free(pKey);
|
|
|
|
|
return connData;
|
2021-10-17 13:03:03 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// 3. set subject of x509 req
|
|
|
|
|
X509_NAME *x509_name = X509_REQ_get_subject_name(x509_req);
|
|
|
|
|
|
2023-08-31 16:00:41 +05:00
|
|
|
X509_NAME_add_entry_by_txt(x509_name, "C", MBSTRING_ASC, (unsigned char *)"ORG", -1, -1, 0);
|
|
|
|
|
X509_NAME_add_entry_by_txt(x509_name, "O", MBSTRING_ASC, (unsigned char *)"", -1, -1, 0);
|
2024-04-12 20:00:21 +05:00
|
|
|
X509_NAME_add_entry_by_txt(x509_name, "CN", MBSTRING_ASC, reinterpret_cast<unsigned char const *>(clientIdUtf8.data()),
|
|
|
|
|
clientIdUtf8.size(), -1, 0);
|
2021-10-17 13:03:03 +03:00
|
|
|
|
|
|
|
|
// 4. set public key of x509 req
|
|
|
|
|
ret = X509_REQ_set_pubkey(x509_req, pKey);
|
2023-08-31 16:00:41 +05:00
|
|
|
if (ret != 1) {
|
2021-10-17 13:03:03 +03:00
|
|
|
qWarning() << "Could not set pubkey!";
|
2021-10-17 07:00:00 -07:00
|
|
|
X509_REQ_free(x509_req);
|
|
|
|
|
EVP_PKEY_free(pKey);
|
|
|
|
|
return connData;
|
2021-10-17 13:03:03 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// 5. set sign key of x509 req
|
2023-08-31 16:00:41 +05:00
|
|
|
ret = X509_REQ_sign(x509_req, pKey, EVP_sha256()); // return x509_req->signature->length
|
|
|
|
|
if (ret <= 0) {
|
2021-10-17 13:03:03 +03:00
|
|
|
qWarning() << "Could not sign request!";
|
2021-10-17 07:00:00 -07:00
|
|
|
X509_REQ_free(x509_req);
|
|
|
|
|
EVP_PKEY_free(pKey);
|
|
|
|
|
return connData;
|
2021-10-17 13:03:03 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// save private key
|
2023-08-31 16:00:41 +05:00
|
|
|
BIO *bp_private = BIO_new(BIO_s_mem());
|
2021-10-17 13:03:03 +03:00
|
|
|
q_check_ptr(bp_private);
|
2023-08-31 16:00:41 +05:00
|
|
|
if (PEM_write_bio_PrivateKey(bp_private, pKey, nullptr, nullptr, 0, nullptr, nullptr) != 1) {
|
2021-10-17 07:00:00 -07:00
|
|
|
qFatal("PEM_write_bio_PrivateKey");
|
2021-10-17 13:03:03 +03:00
|
|
|
EVP_PKEY_free(pKey);
|
|
|
|
|
BIO_free_all(bp_private);
|
2021-10-17 07:00:00 -07:00
|
|
|
X509_REQ_free(x509_req);
|
|
|
|
|
return connData;
|
2021-10-17 13:03:03 +03:00
|
|
|
}
|
|
|
|
|
|
2023-08-31 16:00:41 +05:00
|
|
|
const char *buffer = nullptr;
|
2021-10-17 13:03:03 +03:00
|
|
|
size_t size = BIO_get_mem_data(bp_private, &buffer);
|
|
|
|
|
q_check_ptr(buffer);
|
|
|
|
|
connData.privKey = QByteArray(buffer, size);
|
|
|
|
|
if (connData.privKey.isEmpty()) {
|
|
|
|
|
qFatal("Failed to generate a random private key");
|
2021-10-17 07:00:00 -07:00
|
|
|
EVP_PKEY_free(pKey);
|
|
|
|
|
BIO_free_all(bp_private);
|
|
|
|
|
X509_REQ_free(x509_req);
|
|
|
|
|
return connData;
|
2021-10-17 13:03:03 +03:00
|
|
|
}
|
|
|
|
|
BIO_free_all(bp_private);
|
|
|
|
|
|
|
|
|
|
// save req
|
2023-08-31 16:00:41 +05:00
|
|
|
BIO *bio_req = BIO_new(BIO_s_mem());
|
2021-10-17 13:03:03 +03:00
|
|
|
PEM_write_bio_X509_REQ(bio_req, x509_req);
|
|
|
|
|
|
|
|
|
|
BUF_MEM *bio_buf;
|
|
|
|
|
BIO_get_mem_ptr(bio_req, &bio_buf);
|
|
|
|
|
connData.request = QByteArray(bio_buf->data, bio_buf->length);
|
|
|
|
|
BIO_free(bio_req);
|
|
|
|
|
|
|
|
|
|
EVP_PKEY_free(pKey); // this will also free the rsa key
|
|
|
|
|
|
|
|
|
|
return connData;
|
|
|
|
|
}
|