910 Commits

Author SHA1 Message Date
Richard T Bonhomme
368db7fc5c
Replace non-POSIX mktemp with POSIX mkdir and mv
mktemp was used to create temp-files but it is not POSIX and
the version shipped for Windows has known bugs.

Replace mktemp with atomic directory and file creation using mkdir
and mv, both of which are atomic.

The temporary directory "session" directory is created using mkdir
with a 32bit random number for the name.

eg: /tmp/easyrsa-temp/b01dface

The temporary file is created by moving another file into the place
of the temp-file, with a 32bit random number for the name.

eg: /tmp/easyrsa-temp/b01dface/c01dface

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-16 16:57:27 +01:00
Richard T Bonhomme
d827747600
Use easyrsa_openssl() wrapper for +verify_curve_ec()
Plus some minor formatting tweaks.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-16 16:46:37 +01:00
Richard T Bonhomme
4fc2696a67
Minor improvement to verify_curve_ec()
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-13 15:13:53 +01:00
Richard T Bonhomme
d7b5c98d69
Fix version information and avoid warnings for version and help
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-13 15:09:41 +01:00
Richard T Bonhomme
f4af868cbc
Minor improvement to verify_curve_ed()
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-13 12:47:18 +01:00
Richard T Bonhomme
7e73368a28
Flip short-circuit to avoid having to capture unnecessary error
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-13 12:36:02 +01:00
Richard T Bonhomme
d29aee3e1b
Output only - Standardise message use of notice(), warn() and die
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-13 12:28:56 +01:00
Richard T Bonhomme
8c606c532c
Merge branch 'TinCanTech-build-ca-quote-temp-pass-file-name'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-13 12:10:12 +01:00
Richard T Bonhomme
41c0248de6
Merge branch 'build-ca-quote-temp-pass-file-name' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-build-ca-quote-temp-pass-file-name
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-13 11:06:06 +01:00
Richard T Bonhomme
b68ffc28d7
ChangeLog: Announce new maintenance
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-13 03:22:45 +01:00
Richard T Bonhomme
1d6a5f803e
Set default EASYRSA_PKI to $EASYRSA/pki and some minor improvements
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-13 02:37:50 +01:00
Richard T Bonhomme
29a8a48638
build_ca() - Quote temporary password file "$out_key_pass_tmp"
The problem:

* crypto_opts="$crypto_opts -pass file:$out_key_pass_tmp"

This cannot be reliably expanded and passed as an unquoted option.
This is due to the unquoted file name $out_key_pass_tmp.

The solution:

* Do not polute $crypto_opts with password related options.
* Specifiy the correct '-pass/-passin/-passout file:xx' for each command.

This allows "$out_key_pass_tmp" to be corrrectly quoted.

Also, apply the same quoting technique to $crypto_opts.

Minor alterations to OpenSSL command line layout, readability.

Comment out the replaced code, not removed. For comparison.
(Follow-up patch will remove the comments)

Full unit-tests completed throughout development.
Manually tested multiple password protected PKIs.
OpenSSL 1.1.1 and 3.0.2

Not tested:
* OpenSSL options: -pass/-passin-/passout file:"$out_key_pass_tmp"

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-13 01:00:08 +01:00
Richard T Bonhomme
c18d7f2bf0
Improve informational output: 'init-pki' completed
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-12 20:50:55 +01:00
Richard T Bonhomme
079aedda73
Merge branch 'TinCanTech-easyrsa_openssl-style'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-12 19:21:50 +01:00
Richard T Bonhomme
e1dfacef6b
Merge branch 'easyrsa_openssl-style' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-easyrsa_openssl-style
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-12 19:18:18 +01:00
Richard T Bonhomme
3dfd57b760
Optimize 'vars_in_pki' - Allow further checks on PKI/vars
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-12 19:09:48 +01:00
Richard T Bonhomme
6e2d139177
Add helpful Warnings to promote preferred use of PKI/vars
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-12 18:35:47 +01:00
Richard T Bonhomme
17ebec2a3e
Merge branch 'TinCanTech-vars-single-quote'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-12 15:40:20 +01:00
Richard T Bonhomme
bff4a486e2
Merge branch 'vars-single-quote' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-vars-single-quote
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-12 15:37:41 +01:00
Richard T Bonhomme
7d5185f52c
easyrsa_openssl() - Minor syle changes
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-12 14:01:42 +01:00
Richard T Bonhomme
de7735115c
Only warn if 'vars' is in PKI
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-11 23:32:17 +01:00
Richard T Bonhomme
4c4efbd6ae
Change Error to Warning: Make (') in vars-file non-fatal
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-11 23:08:36 +01:00
Richard T Bonhomme
e30bfd3773
Unit test: Improve output
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-11 21:58:11 +01:00
Richard T Bonhomme
3160cac48f
Merge branch 'TinCanTech-easyrsa_openssl'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-11 21:54:19 +01:00
Richard T Bonhomme
7b4272f34d Merge branch 'easyrsa_openssl' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-easyrsa_openssl 2022-04-11 21:52:28 +01:00
Richard T Bonhomme
6745e0e58a
Merge branch 'TinCanTech-win-git-bash'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-11 21:21:42 +01:00
Richard T Bonhomme
f0a3047cec Merge branch 'win-git-bash' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-win-git-bash 2022-04-11 21:19:50 +01:00
Richard T Bonhomme
540c6ff5af
Unit test: shellcheck easyrsa-unit-tests.sh
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-11 21:16:25 +01:00
Richard T Bonhomme
3e24a76d7e
Allow saving test data and improve log output
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-11 19:38:44 +01:00
Richard T Bonhomme
1aeddd9fcf
Unit tests: Enable shellcheck and OpenSSL v3 (*nix only)
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-11 16:13:04 +01:00
Richard T Bonhomme
50850f5ff3
op-test.sh - Set System SSL for Windows
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-11 16:07:26 +01:00
Richard T Bonhomme
ea666d5b97
op-test.sh - exit with correct status
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-11 16:00:45 +01:00
Richard T Bonhomme
f79b66aba7
op-test.sh - Total rewrite
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-11 15:36:30 +01:00
Richard T Bonhomme
adc03b5a5d
Enable unit test with OpenSSL version 3 on REMOTE-CI
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-09 22:40:22 +01:00
Richard T Bonhomme
a482caa79b
Unit test - Temporarily disable shellcheck
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-09 22:00:03 +01:00
Richard T Bonhomme
538f3eada6
Enable OpenSSL version 3 unit tests
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-09 21:44:51 +01:00
Richard T Bonhomme
4b75783375
Upgrade Linux based unit test to OpenSSL 3.0.2
- 15 Mar 2022 (Library: OpenSSL 3.0.2 15 Mar 2022)

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-09 21:40:44 +01:00
Richard T Bonhomme
484bc56acc
Remove redundant Create $EASYRSA_SSL_CONF
The config file is unambiguously and previously created by
install_data_to_pki().

The config file location is exported in the previous command.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-09 19:28:18 +01:00
Richard T Bonhomme
057be57825
Remove EASYRSA_EXTRA_EXTS code injection inside 'sed' script.
This code injection 'attempted' to insert a temp-file created with
EASYRSA_EXTRA_EXTS data. The insertion would take place at the awk
script marker "^#%EXTRA_EXTS%". However, this marker has already
been replaced by gen_req(), thus the condition to insert the code
was never met and the code injection has never taken place.

Testing this, I created a new marker for this injection to key from
and, due to the file-name variable not having been quoted, the test
fails when the file name has a space in it.

General tidy-up of easyrsa_openssl()

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-09 17:52:42 +01:00
Richard T Bonhomme
ccec36d3ea
Fold vars_source_check() back into verify_pki_init()
vars_source_check() is ONLY used by verify_pki_init(),
remove the extra function.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-08 21:32:12 +01:00
Richard T Bonhomme
324aa4e660
Merge branch 'TinCanTech-cleanup-cleanup'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-08 21:17:11 +01:00
Richard T Bonhomme
1e7fb8243a
Silence cleanup()
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-08 20:33:25 +01:00
Richard T Bonhomme
29eaa061c2
Simplify detecting Windows
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-08 20:14:46 +01:00
Richard T Bonhomme
1844ec10af
Remove old comment for upgrade function
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-08 20:02:30 +01:00
Richard T Bonhomme
0db21c3dd4
Detect Windows and Git-for-Windows bash
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-08 19:47:27 +01:00
Richard T Bonhomme
b4ab1713c1
Remove all use of single quote (') from vars.example
A step toward a solution to #364

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-08 02:11:17 +01:00
Richard T Bonhomme
fe47eba2c0
Style improvements to vars_setup()
Make detecting all vars files more simple and robust.
Improve warning and error messages.

Favour PKI/vars, wiith bias.

* Minor changes to output format for warn() and notice()

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-07 22:09:50 +01:00
Richard T Bonhomme
75bc3d1ed5
Do not require/use Extended Regular Expression
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-07 18:02:31 +01:00
Richard T Bonhomme
48eee21d2a
Disallow use of single quote (') in vars file
Using single quotes in the vars file does not work:
* Either the vars file syntax is corrupted by an unescaped single quote.
* Or the SSL library will drop the single quote from the signed certificate.

Changes:
* Sanitize vars.example - Remove all single quotes.
* Search vars for single quote before sourcing it.

Closes: #34

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-07 17:18:41 +01:00
Richard T Bonhomme
f06871cf03
ChangeLog: ANNOUNCE Easy-RSA version 3.0.1 - Initial debute
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-04-07 03:50:37 +01:00