898 Commits

Author SHA1 Message Date
Richard T Bonhomme
7510f6163c
Temporarily disable shellcheck test
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-29 02:06:28 +01:00
Richard T Bonhomme
7c97dcd864
Do full shellcheck test. Wrap nasty long lines.
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-29 01:59:15 +01:00
Richard T Bonhomme
9e109cdd7d
Hard wrap excessively long lines
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-29 00:38:20 +01:00
Richard T Bonhomme
0cb51cf1a1
Update ChangeLog - OpenSSL version 3 and Packaging notices
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-29 00:10:45 +01:00
Richard T Bonhomme
875dd27808
Improvements to shellcheck compliance
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-28 23:47:12 +01:00
Richard T Bonhomme
ec6d072707
Merge branch 'TinCanTech-master'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-28 23:30:37 +01:00
Richard T Bonhomme
3f7c7df911
Merge branch 'master' of 'TinCanTech/easy-rsa' into TinCanTech-master
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-28 23:29:15 +01:00
Richard T Bonhomme
388aa0396e
Declare 'vars_file' without use
This is a deliberate misuse of shellcheck: Reminder to fix PKI/vars.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-28 22:57:51 +01:00
Richard T Bonhomme
a8a2171716
Optimize install_data_to_pki()
Thanks to excellent community feedback, this patch forces a single,
reliable list of sources for EasyRSA data-files.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-28 22:44:50 +01:00
Richard T Bonhomme
bc07187073
Change install_data_to_pki() failures to non-fatal warnings
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-28 13:40:28 +01:00
Richard T Bonhomme
80a3ad2943
vars.example: Merge branch 'Prouflon-safessl-patch'
Change $EASYRSA_SSL_CONF to correct default value

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-27 17:41:22 +01:00
Richard T Bonhomme
5255d90b9a
Merge branch: 'safessl-patch' of github.com/Prouflon/easy-rsa-1
Change '$EASYRSA_SSL_CONF' to correct default value in example file.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-27 17:39:34 +01:00
Richard T Bonhomme
3222d17b5e
Introduce install_data_to_pki() - Copy data-files to PKI
The purpose here is to force EasyRSA find the required data-files:

* 'openssl-easyrsa.cnf' MUST be found.
* 'x509-types' MUST be found.
* 'vars.example' should be found.
* 'vars'
  The 'vars' file is more complicated due to user expectations.
  This patch does not copy 'vars', the code is included but DISABED.

The reasons are:

* Allow running 'easyrsa' from PATH.
* Make standard packaging work correctly.

Bug fixes:

* #499 and associated issues with missing files.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-27 14:16:32 +01:00
Richard T Bonhomme
6deae0823e
Merge branch 'TinCanTech-master' #507
Add SSL Library version 2 to easyrsa_openssl()

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-25 19:04:43 +00:00
Richard T Bonhomme
ed7380bab8
Add SSL Library version 2 to easyrsa_openssl()
Closes: #504

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-25 18:52:23 +00:00
Richard T Bonhomme
f08d9a3cf9
Merge: branch 'TinCanTech-master' #505
Expand new verify_ssl_lib() to support LibreSSL version 2.x (again)

Closes: #504

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-25 16:10:18 +00:00
Richard T Bonhomme
8c2a09f374
Expand new verify_ssl_lib() to support LibreSSL version 2.x (again)
Changes made by a0dbc346bd92088ee481f5488ac53a7537b32073 result in
'ossl_major=2' and LibreSSL 2.x not being recognised.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-25 15:49:04 +00:00
Richard T Bonhomme
73e674a5ea
Merge branch 'markus-t314-bugfix/spaces_in_path'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-23 20:48:38 +00:00
Richard T Bonhomme
14d6e24377
Merge branch 'bugfix/spaces_in_path'
markus-t314-bugfix/spaces_in_path

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-23 20:45:33 +00:00
Richard T Bonhomme
af0c70cbc9
Merge: Add CI status badge #501
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-23 19:30:57 +00:00
Richard T Bonhomme
258ec449ff
Windows unit test: Merge branch 'TinCanTech-master'
On error then exit with error

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-23 00:09:29 +00:00
Richard T Bonhomme
ba11ec08a8
Windows unit test: On error then exit with error
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-22 23:05:34 +00:00
Richard T Bonhomme
39b06f1073
Unit test improvements
* Allow local copy of unit tests to persist.
* Quote file-name exapansion for Windows setup.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-22 15:52:04 +00:00
Richard T Bonhomme
8284dec85b
Merge: Update EasyRSA-Readme.md #426
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-22 13:49:23 +00:00
Richard T Bonhomme
111fb7c330
Merge branch 'patch-3' of github.com/noah-de/easy-rsa
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-22 13:47:40 +00:00
Richard T Bonhomme
7f6d5e65a8
Merge branch 'ccin2p3-feature/custom-umask'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-22 13:00:39 +00:00
Richard T Bonhomme
5ece7ccb3d
Merge branch 'feature/custom-umask'
github.com/ccin2p3/easy-rsa into ccin2p3-feature/custom-umask

Fix typo: 'defúlts' -> 'default'

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-22 12:58:07 +00:00
Richard T Bonhomme
764c256fd7
Merge: Simple maintenance improvements #455
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-22 12:26:15 +00:00
Richard T Bonhomme
d0c8f30b66 Merge branch 'master' of github.com/a1346054/easy-rsa into a1346054-master 2022-03-22 12:00:10 +00:00
Richard T Bonhomme
381fda9a93
Merge branch 'lucasluitjes-patch-1'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-22 02:52:28 +00:00
Richard T Bonhomme
6b7eedb5e4
Merge PR #423 with a minor white space correction
Errant space after OpenVPN on line 2

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-22 02:49:43 +00:00
Richard T Bonhomme
a30c3b6871
EasyRSA-Readme.md: Add serverClient certificate type
Closes: #497

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-22 02:08:26 +00:00
Richard T Bonhomme
4dfc380308
Merge branch 'TinCanTech-master' #496
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-22 01:52:32 +00:00
Richard T Bonhomme
753ea21e5f
OpenSSL Configuration: Add required white space separator
Closes: #431

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-21 23:39:50 +00:00
Richard T Bonhomme
0f80268337
Help: Add algorithm 'ed' to --use-algo text
Closes: #488

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-21 23:23:32 +00:00
Richard T Bonhomme
c2a302eeac
Update EasyRSA-Advanced.md: Correct command line option --keysize
Closes: #198

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-21 22:40:54 +00:00
Richard T Bonhomme
ff9e0d139e
Merge branch 'TinCanTech-master'
* Update EasyRSA-Readme.md
* Introduce unit test infrastucture

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-21 21:37:11 +00:00
Richard T Bonhomme
7bc8d30513
Add action.yml - Initial unit-test framework
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-21 20:46:49 +00:00
Richard T Bonhomme
b02f4231a5
Re-arrange "# Signing a request" to fix markdown problem
Supercedes: #430
Closes: #47

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-21 19:28:59 +00:00
Richard T Bonhomme
df63c6385b
Merge branch 'thesteve0-patch-1' - Minor typo
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-21 18:13:02 +00:00
Richard T Bonhomme
91ca33fdf0 Merge branch 'patch-1' of https://github.com/thesteve0/easy-rsa 2022-03-21 18:08:53 +00:00
Richard T Bonhomme
c56eee40bf
Remove spurious echo in upgrade process
Closes: #453

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-21 17:51:11 +00:00
Richard T Bonhomme
32071fc32f
Merge branch 'TinCanTech-master'
Introduce support for OpenSSL version 3

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-21 16:43:08 +00:00
Richard T Bonhomme
8e7bac695d
Quote $algo_opts
When EasyRSA is installed to a path with a space in it, gen_req() fails
for EC and ED crypto.  This is caused by the space in the file-name for
the parameters file $EASYRSA_CURVE.

To resolve this, '-newkey' must be removed from $algo_opts and inserted
into the OpenSSL command.  And $algo_opts must be quoted. (#494)

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-21 15:57:03 +00:00
Richard T Bonhomme
f64fef9af2
Replace needlessly complicated 'if/elif/else' with simple 'case'
Where 'if' is replaced with 'case', functionality is generaly maintained.

With the following exceptions:

* verify_curve_ed() does not need to identify the specific curve.
  Error status will provide the correct result for a curve name error.

* For Edwards curve crypto, the 'case' statement is further reduced to
  use the verified $EASYRSA_CURVE inside the OpenSSL command.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-20 21:55:12 +00:00
Richard T Bonhomme
a7e0b3fe69
Make easyrsa_openssl() aware of the SSL Library version
Commit a0dbc346bd92088ee481f5488ac53a7537b32073 leads to bug caused
by OpenSSL 'genpkey' inconsistency. OpenSSL version 1 'genpkey' does
not support option '-config' but OpenSSL version 3 does.
(Details can be found at: https://www.openssl.org/docs/manpages.html)

To use 'genpkey' option '-config', easyrsa_openssl() needs to be aware
of the SSL Library version and only set '-config' for version 3.

This patch sets OpenSSL version 3 ONLY option '-config' for 'genpkey'.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-20 21:20:20 +00:00
Richard T Bonhomme
7b3fdee224
Quote $out_key_tmp
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-19 17:59:01 +00:00
Richard T Bonhomme
4315356de0
Minor refactoring of build_ca() for OpenSSL version 1
* (1) Move definition of $crypto_opts inside 'case' for OSSLv1 (NFC)
  This defines $crypto_opts for the CA private key.

* Wrap long lines (NFC)

* (2) Expand definition of $crypto_opts to use $no_password.
  This defines $crypto_opts for the CA pair.

Note: Before this change (2), the command which EasyRSA uses
does not include '-nodes' when building an unencrypted CA.

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-19 16:52:22 +00:00
Richard T Bonhomme
73cc4a62cc
Set 'build_ca()' specific $crypto_opts '-pass' for OpenSSL version 3
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-18 20:39:40 +00:00
Richard T Bonhomme
16f2d11f37
Use $crypto_opts to correctly set SSL '-noenc' ($no_password)
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2022-03-18 17:23:55 +00:00