move to openssl3

This commit is contained in:
Your Name
2024-01-23 19:42:30 +00:00
parent 21c9536d7a
commit 2d1a456442
5 changed files with 90 additions and 5 deletions
+1
View File
@@ -0,0 +1 @@
cert
+1
View File
@@ -0,0 +1 @@
cert
+33 -5
View File
@@ -1,7 +1,35 @@
FROM ubuntu:latest
#FROM ubuntu:latest
RUN apt-get update && apt-get install -y git unzip sudo wget build-essential pkg-config
RUN git clone https://github.com/kov-serg/get-cpcert.git && cd get-cpcert && chmod +x *.sh
RUN cd /get-cpcert/ && ./prepare.sh
#RUN apt-get update && apt-get install -y git unzip sudo wget build-essential pkg-config python3 python3-pip
#RUN git clone https://github.com/kov-serg/get-cpcert.git && cd get-cpcert && chmod +x *.sh
#RUN cd /get-cpcert/ && ./prepare.sh
ENTRYPOINT ["bash"]
FROM debian
RUN apt-get update && apt-get install -y libengine-gost-openssl openssl nano mc git unzip sudo wget build-essential pkg-config python3 python3-pip
ARG PREFIX="/etc/ssl"
ARG ENGINES=/usr/lib/x86_64-linux-gnu/engines-3
# Enable engine
RUN sed -i '6i openssl_conf=openssl_def' ${PREFIX}/openssl.cnf \
&& echo "" >>${PREFIX}/openssl.cnf \
&& echo "# OpenSSL default section" >>${PREFIX}/openssl.cnf \
&& echo "[openssl_def]" >>${PREFIX}/openssl.cnf \
&& echo "engines = engine_section" >>${PREFIX}/openssl.cnf \
&& echo "" >>${PREFIX}/openssl.cnf \
&& echo "# Engine scetion" >>${PREFIX}/openssl.cnf \
&& echo "[engine_section]" >>${PREFIX}/openssl.cnf \
&& echo "gost = gost_section" >>${PREFIX}/openssl.cnf \
&& echo "" >> ${PREFIX}/openssl.cnf \
&& echo "# Engine gost section" >>${PREFIX}/openssl.cnf \
&& echo "[gost_section]" >>${PREFIX}/openssl.cnf \
&& echo "engine_id = gost" >>${PREFIX}/openssl.cnf \
&& echo "dynamic_path = ${ENGINES}/gost.so" >>${PREFIX}/openssl.cnf \
&& echo "default_algorithms = ALL" >>${PREFIX}/openssl.cnf \
&& echo "CRYPT_PARAMS = id-Gost28147-89-CryptoPro-A-ParamSet" >>${PREFIX}/openssl.cnf
ADD ./src /src
RUN pip install -r /src/requirements.txt --break-system-packages
ENTRYPOINT ["bash"]
+54
View File
@@ -0,0 +1,54 @@
#!flask/bin/python
import tempfile
import os.path
import base64
import logging
from flask import Flask, jsonify
from flask import request
app = Flask(__name__)
certFile = "/app/cert/anna_export.crt"
pemFile = "/app/cert/anna_export_pass_1234.pem"
passwd = "1234"
@app.route('/')
def index():
return "Hello, World!"
@app.route('/sign', methods=['POST'])
def create_task():
if not request.json or not 'content' in request.json:
abort(400)
if not os.path.isfile(certFile):
return "No crt file exists", 500
if not os.path.isfile(pemFile):
return "No pem file exists", 500
temp_name = next(tempfile._get_candidate_names())
source_path = os.path.join(tempfile.mkdtemp(), temp_name)
result_path = "{}.sgn".format(source_path)
#logging.warning("request: {}".format(request.json))
decoded = base64.b64decode(request.json['content'])
with open(source_path, 'wb') as output_file:
output_file.write(decoded)
cmd = "openssl smime -sign -signer {} -inkey {} -engine gost -passin pass:{} -binary -noattr -outform DER -in {} -out {}".format(certFile, pemFile, passwd, source_path, result_path)
result = os.popen(cmd).read()
logging.warning('result file path is: {}'.format(result_path))
if not os.path.isfile(result_path):
return "No result file exists, somthing goes wrong...", 500
with open(result_path, "rb") as result_file:
result_json = base64.b64encode(result_file.read()).decode()
os.remove(result_path)
response = {
'signature': result_json
}
return jsonify(response), 200
if __name__ == '__main__':
app.run(host='0.0.0.0', port=80, debug=True)
+1
View File
@@ -0,0 +1 @@
flask