CAUtil.cs 3.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117
  1. using Org.BouncyCastle.Crypto;
  2. using Org.BouncyCastle.X509;
  3. using System;
  4. using System.Collections.Generic;
  5. using System.Linq;
  6. using System.Text;
  7. using System.Threading.Tasks;
  8. namespace CAUtilLib
  9. {
  10. public class CaUtil
  11. {
  12. public string RootPath = "/home/cert";
  13. public const string RcaDirectoryName = "rca";
  14. public const string TrustedDirectoryName = "tcrt";
  15. public const string RcaKeyName = "rca_key.pem";
  16. public const string RcaCertName = "rca.pem";
  17. public string RcaKeyPath => Path.Combine(RootPath, RcaDirectoryName, RcaKeyName);
  18. public string RcaCertPath => Path.Combine(RootPath, RcaDirectoryName, RcaCertName);
  19. public string TrustedCertsPath => Path.Combine(RootPath, TrustedDirectoryName);
  20. public async Task<bool> CreateRootCA()
  21. {
  22. AsymmetricCipherKeyPair kp = BouncyCastleWrapper.GenerateRsaKeyPair(4096);
  23. var saveKeyResult = await BouncyCastleWrapper.TrySaveAsPemAsync(RcaKeyPath, new object[] { kp.Private });
  24. if (!saveKeyResult)
  25. {
  26. return false;
  27. }
  28. X509Certificate cert = BouncyCastleWrapper.GenerateSelfSignedCertificate(kp);
  29. var saveCertResult = await BouncyCastleWrapper.TrySaveAsPemAsync(RcaCertPath, new object[] { cert, kp.Private });
  30. if (!saveCertResult)
  31. {
  32. return false;
  33. }
  34. return true;
  35. }
  36. public async Task<string?> SignCsr(string csr)
  37. {
  38. var parsedCsr = BouncyCastleWrapper.LoadPemCsrFromString(csr);
  39. if (parsedCsr is null)
  40. {
  41. return null;
  42. }
  43. var rca = await BouncyCastleWrapper.LoadPemCertFromFile(RcaCertPath);
  44. if (rca is null)
  45. {
  46. return null;
  47. }
  48. var rcaKey = await BouncyCastleWrapper.LoadPemKeyFromFile(RcaKeyPath);
  49. if (rcaKey is null)
  50. {
  51. return null;
  52. }
  53. var generatedCrt = BouncyCastleWrapper.SignCertificate(parsedCsr, rca, rcaKey);
  54. return await BouncyCastleWrapper.ToStringAsPem(generatedCrt);
  55. }
  56. public async Task<int> VerifyCrt(string crt)
  57. {
  58. var parsedCrt = BouncyCastleWrapper.LoadPemCertFromString(crt);
  59. if (parsedCrt is null)
  60. {
  61. return -1;
  62. }
  63. var isSignedByRca = await VerifyCrtSignedByRCA(parsedCrt!);
  64. if (isSignedByRca)
  65. {
  66. return 0;
  67. }
  68. var isSignedByTrusted = await VerifyCrtSignedByTrused(parsedCrt!);
  69. if (isSignedByTrusted)
  70. {
  71. return 1;
  72. }
  73. return -1;
  74. }
  75. private async Task<bool> VerifyCrtSignedByRCA(X509Certificate crt)
  76. {
  77. var rcaKey = await BouncyCastleWrapper.LoadPemKeyFromFile(RcaKeyPath);
  78. if (rcaKey is null)
  79. {
  80. return false;
  81. }
  82. return BouncyCastleWrapper.ValidateCert(crt, rcaKey.Public);
  83. }
  84. private async Task<bool> VerifyCrtSignedByTrused(X509Certificate crt)
  85. {
  86. var trustedCerts = Directory.GetFiles(TrustedCertsPath);
  87. foreach (var trustedCert in trustedCerts)
  88. {
  89. var cert = await BouncyCastleWrapper.LoadPemCertFromFile(trustedCert);
  90. var checkResult = BouncyCastleWrapper.ValidateCert(crt, cert.GetPublicKey());
  91. if (checkResult)
  92. {
  93. return true;
  94. }
  95. }
  96. return false;
  97. }
  98. }
  99. }