-
Notifications
You must be signed in to change notification settings - Fork 28
/
cert.go
94 lines (83 loc) · 2 KB
/
cert.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
package dao
import (
"bytes"
"crypto/ecdsa"
"crypto/elliptic"
"crypto/rand"
"crypto/x509"
"encoding/pem"
"github.com/VaalaCat/frp-panel/models"
"github.com/VaalaCat/frp-panel/utils"
"github.com/sirupsen/logrus"
"google.golang.org/grpc/credentials"
)
func InitCert(template *x509.Certificate) credentials.TransportCredentials {
var (
certPem []byte
keyPem []byte
)
cnt, err := CountCerts()
if err != nil {
logrus.Fatal(err)
}
if cnt == 0 {
certPem, keyPem, err = GenX509Info(template)
if err != nil {
logrus.Fatal(err)
}
if err = models.GetDBManager().GetDefaultDB().Create(&models.Cert{
Name: "default",
CertFile: certPem,
CaFile: certPem,
KeyFile: keyPem,
}).Error; err != nil {
logrus.Fatal(err)
}
} else {
keyPem, certPem, err = GetDefaultKeyPair()
if err != nil {
logrus.Fatal(err)
}
}
resp, err := utils.TLSServerCert(certPem, keyPem)
if err != nil {
logrus.Fatal(err)
}
return resp
}
func GenX509Info(template *x509.Certificate) (certPem []byte, keyPem []byte, err error) {
priv, err := ecdsa.GenerateKey(elliptic.P521(), rand.Reader)
if err != nil {
return nil, nil, err
}
cert, err := x509.CreateCertificate(rand.Reader, template, template,
priv.Public(), priv)
if err != nil {
return nil, nil, err
}
var certBuf bytes.Buffer
pem.Encode(&certBuf, &pem.Block{
Type: "CERTIFICATE", Bytes: cert,
})
var keyBuf bytes.Buffer
pem.Encode(&keyBuf, utils.PemBlockForPrivKey(priv))
return certBuf.Bytes(), keyBuf.Bytes(), nil
}
func CountCerts() (int64, error) {
db := models.GetDBManager().GetDefaultDB()
var count int64
err := db.Model(&models.Cert{}).Count(&count).Error
if err != nil {
return 0, err
}
return count, nil
}
func GetDefaultKeyPair() (keyPem []byte, certPem []byte, err error) {
resp := &models.Cert{}
err = models.GetDBManager().GetDefaultDB().Model(&models.Cert{}).
Where(&models.Cert{Name: "default"}).First(resp).Error
if err != nil {
return nil, nil, err
}
return resp.KeyFile, resp.CertFile, nil
}