1614 Commits

Author SHA1 Message Date
Richard T Bonhomme
55ee5fcfde
X509-types insert markers: Move and improve
X509-types insert markers are used by 'awk' to insert data at specific
points in the easyrsa-openssl.cnf file in use.

The checks are moved to below more important imput checks

For build-ca, the check is ONLY done if EASYRSA_EXTRA_EXTS is defined.
This is exceedingly unlikely, because EASYRSA_EXTRA_EXTS is not documented.

For sign-req, the check is only done if --copy-ext isused.

Also, remove an over-indent in "Confirm use of NS extestions"

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-05-01 21:38:35 +01:00
Richard T Bonhomme
a724ca91d1
sign-req: Require confirm use of deprecated Netscape extensions
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-05-01 21:17:48 +01:00
Richard T Bonhomme
4f1c16aa9f
sign_req(): Move generte-random-serial-number below input checks
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-05-01 20:59:19 +01:00
Richard T Bonhomme
f92fa738a9
gen-req, sign-req, build-full: Verify requirements correctly
* gen-req: Use verify_pki_init().
* sign-req: Use verify_ca_init().
* build-full: Defer requirements to functions above.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-05-01 20:32:49 +01:00
Richard T Bonhomme
8451adee6b
Merge branch 'TinCanTech-remove_secure_session-ROS'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-05-01 20:17:54 +01:00
Richard T Bonhomme
ddc87e9c0d
Merge branch 'remove_secure_session-ROS' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-remove_secure_session-ROS
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-05-01 20:17:14 +01:00
Richard T Bonhomme
aca34a051b
Merge branch 'TinCanTech-import-req-check-in-file'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-05-01 20:12:31 +01:00
Richard T Bonhomme
4c077a5b10
Merge branch 'import-req-check-in-file' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-import-req-check-in-file
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-05-01 20:11:37 +01:00
Richard T Bonhomme
b8455ad392
import-req: Check input file exists
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-05-01 19:58:40 +01:00
Richard T Bonhomme
a9192c1866
remove_secure_session(): Add missing 'fi' statement
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-05-01 14:04:30 +01:00
Richard T Bonhomme
a9bc2ee576
remove_secure_session(): Return-On-Success Only
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-05-01 13:59:31 +01:00
Richard T Bonhomme
15299444a4
Status reports: Use verbose(), remove easyrsa_debug()
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-20 14:22:23 +01:00
Richard T Bonhomme
8eae7213c8
Merge branch 'TinCanTech-expire_status-use-ssl-checkend'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-18 23:48:41 +01:00
Richard T Bonhomme
25ba31ce0a
Merge branch 'expire_status-use-ssl-checkend' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-expire_status-use-ssl-checkend
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-18 23:46:53 +01:00
Richard T Bonhomme
86fb03c538
Correct typo in hash value
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-15 21:45:45 +01:00
Richard T Bonhomme
9c03bb9e94
Unit test: Update openssl hash
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-15 21:38:47 +01:00
Richard T Bonhomme
68fa3342a1
Status reports: Additional check, Use SSL to determine expiration
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-15 15:08:56 +01:00
Richard T Bonhomme
8c1971eaaa
easyrsa_mktemp(): Rename 'target' -> 'want_tmp_file' - Avoid conflicts
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-15 14:35:57 +01:00
Richard T Bonhomme
6e80d08abb
Merge branch 'TinCanTech-prohibit-export-in-vars'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-13 23:34:46 +01:00
Richard T Bonhomme
cee79481b3
Merge branch 'prohibit-export-in-vars' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-prohibit-export-in-vars
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-13 23:34:04 +01:00
Richard T Bonhomme
7be58ded91
vars: WARN use of 'export' and 'unset' in vars file
Use 'set_var' (Supported) or 'force_set_var' (User discretion)

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-13 23:22:13 +01:00
Richard T Bonhomme
91e5535455
Merge branch 'TinCanTech-force-safe-ssl'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-13 22:58:49 +01:00
Richard T Bonhomme
dd30507b5b
Merge branch 'force-safe-ssl' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-force-safe-ssl
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-13 22:58:11 +01:00
Richard T Bonhomme
add08b8be1
Merge branch 'TinCanTech-move-calling-secure_session'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-13 22:53:21 +01:00
Richard T Bonhomme
00de6431e4
Merge branch 'move-calling-secure_session' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-move-calling-secure_session
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-13 22:52:38 +01:00
Richard T Bonhomme
78d1efa64b
secure_session(): Move in verify_working_env() Remove from 'init-pki'
In verify_working_env(), move to AFTER the check for temporary folder.
The move is aesthetic because secure_session() does its own check
for temporary folder.

In 'init-pki', remove secure_session() completely, as not required.

Add more verbose output.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-13 22:42:19 +01:00
Richard T Bonhomme
adc3cd3f5d
Merge branch 'TinCanTech-win-prohibit-pki-in-program-files'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-13 21:58:02 +01:00
Richard T Bonhomme
c85a096f55
Merge branch 'win-prohibit-pki-in-program-files' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-win-prohibit-pki-in-program-files
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-13 21:56:26 +01:00
Richard T Bonhomme
289444ca7d
Windows: Warn when using Windows default location in 'Program Files'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-13 14:40:40 +01:00
Richard T Bonhomme
e093ac1c6d
Introduce global option --force-safe-ssl
easyrsa_openssl() default behaviour is to re-use the generated
safe SSL config file, after bieng called for the first time.
NOTE: easyrsa_openssl() is a heavily nested function.

This option forces recreation of a safe SSL config file for each
call to easyrsa_openssl().

Only effective when an SSL config fie is required.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-12 00:57:23 +01:00
Richard T Bonhomme
2ed6c9d5b2
Merge branch 'TinCanTech-single-use-safe-ssl-conf'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-10 18:53:45 +01:00
Richard T Bonhomme
0538f1574c
Merge branch 'single-use-safe-ssl-conf' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-single-use-safe-ssl-conf
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-10 18:52:13 +01:00
Richard T Bonhomme
d1c34d4a77
remove_secure_session(): New function to remove secure session
Status reports function read_db() MUST recreate the secure session
for each record of the database being read.

Introduce remove_secure_session(), to remove the session and reset
related flags:
- secure_session: The directory name of the session. Deleted.
- working_safe_ssl_conf - Safe SSL config file.  Deleted.
- mktemp_counter - Count of temp files. Deleted.

Also use remove_secure_session() in cleanup().

Improve some verbose output.
Wrap some long lines.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-10 18:32:08 +01:00
Richard T Bonhomme
9b95eaa8dc
easyrsa_openssl(): Add verbose output when functions are skipped
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-08 23:58:45 +01:00
Richard T Bonhomme
a9b7c6a8a4
status report: Only provide comparison date when certificate exists
If the certificate does not exist then the database date is used.
The database date is a shortened ISO-8601 date, the certifcate date
is presented in a completely different format.

Omit the calculated "seconds since epoch" double check via 'date',
when the certificate does not exist.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-08 23:41:01 +01:00
Richard T Bonhomme
867333d67e
easyrsa_openssl(): Create a safe SSL config once per instance ONLY
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-08 23:01:33 +01:00
Richard T Bonhomme
1f18f19555
easyrsa_mktemp(): Increase the number of test-temp-files (Squashed)
commit df0a19e7ebaba5cb6fd2787ce4747d6338447a0a
Merge: e3e9f9e a7e58dd
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Sat Apr 8 14:30:46 2023 +0100

    Merge branch 'easyrsa_mktemp-increase-depth' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-easyrsa_mktemp-increase-depth

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit a7e58dd70cb2aeb06ebee39c6b2c438e9ac76cdc
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Sat Apr 8 02:43:20 2023 +0100

    verify_algo_params(): Edwards Curve, call OpenSSL directly

    This allows the output to be discarded via /dev/null, because
    there is no use of temp-files and verbose messages.

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit d64dfcc16676b1e1b3fda7090667aea76bd718fc
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Sat Apr 8 02:13:29 2023 +0100

    easyrsa_mktemp(): Windows, 'set -o noclobber' to control 'mv.exe'

    Currently, mv.exe will always prompt before over-writing a file.
    When creating temp-files, mv.exe must NEVER prompt but silently
    fail and try again with a new, sequentially numbered, file-name.

    Using 'set -o noclobber' causes mv.exe to behave correctly here.

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit 948e1a1fbb338a32cf9b42d6fe9801b0fe7bfde9
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Sat Apr 8 01:22:47 2023 +0100

    easyrsa_mktemp(): Allow nine (9) test files

    Use of easyrsa_openssl() creates temp-files by default
    and is used in subshells.  This requires maximum of (7)
    seven test files to move the shot-file to. (Currently)

    Raise the the number of test-files to maximum nine (9).

    Status reports, read_db(): Recreate temporary session
    directory for each record. 'easyrsa' is designed to run
    one command and then exit, removing the temp session.
    Status reports run 'easyrsa' for the number of records
    in the database, before exiting. Therefore, the temp
    session MUST be reset for eash record read.

    Add verbose output to help debug easyrsa_mktemp problems.

    Improve comments.

    Complete renaming of
    - EASYRSA_CERT_RENEW -to- EASYRSA_PRE_EXPIRY_WINDOW

    Split vars_setup(), add verify_working_env()
    - vars_setup() now only processes vars file.
    - verify_working_env() does the rest.
    The split does not change any of the enclosed code.

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-08 14:32:41 +01:00
Richard T Bonhomme
e3e9f9e08c
Merge branch 'TinCanTech-iso-8601-date-leap-years'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-07 23:53:47 +01:00
Richard T Bonhomme
26c6d4cfc3
Merge branch 'iso-8601-date-leap-years' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-iso-8601-date-leap-years
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-07 23:53:16 +01:00
Richard T Bonhomme
08bc2bd454
Status reports: iso_8601_timestamp_to_seconds(), fix Leap Years
Insert the day "February 29th" only after "Feb-28" during leap years.

Prepend century (eg. 20 or 19) to a two digit Year value. ISO-8601

Require four digit 'yyyy'

Improve verbose output.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-06 00:10:03 +01:00
Richard T Bonhomme
a39de53f94
Merge branch 'TinCanTech-externally-set-vars'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-04 20:51:58 +01:00
Richard T Bonhomme
a7cecaff13
Merge branch 'externally-set-vars' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-externally-set-vars
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-04 20:51:08 +01:00
Richard T Bonhomme
1e0de4c805
vars file: Allow 'EASYRSA_VARS_FILE' to be set externally
The preferred way to set a user defined 'vars' file is to use global
option '--vars=<vars-file>'. Therefore, the current code erronously
does not check for externally set 'EASYRSA_VARS_FILE'.

This change now looks for a user defined 'vars' file by checking if
'EASYRSA_VARS_FILE' is defined, instead of 'user_vars_true'.

Also, move other automated 'vars' file locating to after the check
for user defined 'vars'.

Wrap long lines in set_var().

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-04 16:59:52 +01:00
Richard T Bonhomme
e8ad9fb4f4
Status reports: (Squashed) Use iso_8601 date format
Squashed commit of the following:

commit 423a478dcaf941476f1d8ea339657e2efeb86dec
Merge: 2cadb05 52ebec8
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Sun Apr 2 19:29:40 2023 +0100

    Merge branch 'iso_8601-date-code' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-iso_8601-date-code

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit 52ebec824febbcd8eb7f338a997dcbc513e9efa6
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Sat Apr 1 14:32:56 2023 +0100

    Status reports: Rename EASYRSA_CERT_EXPIRE: EASYRSA_PRE_EXPIRY_WINDOW

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit ec8267afad8bf2c074b7c47e40f300a64d0be4a0
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Sat Apr 1 12:19:54 2023 +0100

    Status reports: Re-order functions (NFC)

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit 72e682d6e9934726ceaf2d4553a456113a57f382
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Sat Apr 1 12:16:59 2023 +0100

    Status reports: Improve comments

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit dccb8c6773aa778404040865640feeccb6d843f7
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Thu Mar 30 20:41:20 2023 +0100

    Status reports: Move force_set_var() to a suitable place (NFC)

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit 9c48513f4adcb30f0f73db72b4fcf156aeeddffd
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Thu Mar 30 20:39:55 2023 +0100

    Status reports: Remove ff_date_to_cert_date() (Unused)

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit 93f51fd0aa2321dd1c511351eec69b4301dd7a80
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Thu Mar 30 20:34:50 2023 +0100

    Status reports: Introduce cert_date_to_iso_8601_date()

    Terminate use of ff_date_to_cert_date() (To be removed).

    Other minor formatting.

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit aa79739235e5ae93ff71fd8860f809fef3ae2451
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Thu Mar 30 15:16:56 2023 +0100

    Status reports: Remove unsed function offset_days_to_cert_date()

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit 6017ae1cefecb6519c15f3a8d5ffd2ba168f744c
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Thu Mar 30 14:43:40 2023 +0100

    Status reports: Use iso_8601 date format

    These changes ONLY effect status reports.

    With OpenSSL v3 there is option '-dateopt iso_8601' which outputs
    dates as specified: 'yyyy-mm-dd HH:MM:SSTZ'

    Using this format, date related calculations become more managable
    because the need to use various 'date' programs is reduced to a
    single use.  The single use is 'date +%s', to print the current
    date/time as a timestamp "seconds since epoch".  All supported
    versions of date use the same exact command.

    Introduce new functions:
    - days_to_timestamp_s()
      Return current date/time +/- number-of-days (Can be zero)
      as a timestamp seconds since epoch.
      Use date program in an OS agnostic manner. 'date +%s'

    - db_date_to_iso_8601_date()
      Renamed db_date_to_ff_date() - No functional changes.

    - iso_8601_cert_startdate()
    - iso_8601_cert_enddate()
      Return certificate -startdate or -enddate in iso_8601 format.
      If the SSL lib does not support iso_8601 format then return error
      to the calling function, which will fallback to old method.

    - iso_8601_timestamp_to_seconds()
      Calculate the "seconds since epoch" from iso_8601 date.
      If input date is not iso_8601 format then return error
      to the calling function, which will fallback to old method.

    Notice:
      EasyRSA will calculate "seconds since epoch" itself. It will also
      use the old method (use various date programs) to get a timestamp
      and verify if the two timestamps are an EXACT match.
      If they do not match then a configurable margin-of-error can be
      used to allow the mismatch to pass. (Not enabled by default)
      Testing so far, all timestamps are exact matches.

    Introduce new global options:
    --verbose: Be very verbose about easyrsa internal activity.
      Only currently used by status reports.

    --days-margin: Allow a margin of error for a timestamp mismatch.
      Only currently used by status reports. (Disabled by default)

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-02 19:31:38 +01:00
Richard T Bonhomme
2cadb05b67
Status reports: Respect silent/batch, remove fix-offset support
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-03-28 00:14:39 +01:00
Richard T Bonhomme
5af6e10b7a
busybox date: Remove unnecessary usage check
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-03-27 21:52:39 +01:00
Richard T Bonhomme
09c5684fc5
+ff_date_to_cert_date(): Prioritise standard date over busybox date
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-03-27 21:48:48 +01:00
Richard T Bonhomme
61914eaab4
Merge branch 'TinCanTech-remove-date-code'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-03-22 23:50:22 +00:00
Richard T Bonhomme
bb16726682
Merge branch 'remove-date-code' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-remove-date-code
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-03-22 23:48:32 +00:00
Richard T Bonhomme
d561a89eaf
Prioritise GNU and Windows date programs over Mac and busybox
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-03-21 18:47:02 +00:00