move to openssl3
This commit is contained in:
@@ -0,0 +1 @@
|
|||||||
|
cert
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
cert
|
||||||
+32
-4
@@ -1,7 +1,35 @@
|
|||||||
FROM ubuntu:latest
|
#FROM ubuntu:latest
|
||||||
|
|
||||||
RUN apt-get update && apt-get install -y git unzip sudo wget build-essential pkg-config
|
#RUN apt-get update && apt-get install -y git unzip sudo wget build-essential pkg-config python3 python3-pip
|
||||||
RUN git clone https://github.com/kov-serg/get-cpcert.git && cd get-cpcert && chmod +x *.sh
|
#RUN git clone https://github.com/kov-serg/get-cpcert.git && cd get-cpcert && chmod +x *.sh
|
||||||
RUN cd /get-cpcert/ && ./prepare.sh
|
#RUN cd /get-cpcert/ && ./prepare.sh
|
||||||
|
|
||||||
|
FROM debian
|
||||||
|
RUN apt-get update && apt-get install -y libengine-gost-openssl openssl nano mc git unzip sudo wget build-essential pkg-config python3 python3-pip
|
||||||
|
|
||||||
|
ARG PREFIX="/etc/ssl"
|
||||||
|
ARG ENGINES=/usr/lib/x86_64-linux-gnu/engines-3
|
||||||
|
|
||||||
|
# Enable engine
|
||||||
|
RUN sed -i '6i openssl_conf=openssl_def' ${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "" >>${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "# OpenSSL default section" >>${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "[openssl_def]" >>${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "engines = engine_section" >>${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "" >>${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "# Engine scetion" >>${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "[engine_section]" >>${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "gost = gost_section" >>${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "" >> ${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "# Engine gost section" >>${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "[gost_section]" >>${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "engine_id = gost" >>${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "dynamic_path = ${ENGINES}/gost.so" >>${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "default_algorithms = ALL" >>${PREFIX}/openssl.cnf \
|
||||||
|
&& echo "CRYPT_PARAMS = id-Gost28147-89-CryptoPro-A-ParamSet" >>${PREFIX}/openssl.cnf
|
||||||
|
|
||||||
|
|
||||||
|
ADD ./src /src
|
||||||
|
RUN pip install -r /src/requirements.txt --break-system-packages
|
||||||
|
|
||||||
ENTRYPOINT ["bash"]
|
ENTRYPOINT ["bash"]
|
||||||
+54
@@ -0,0 +1,54 @@
|
|||||||
|
#!flask/bin/python
|
||||||
|
import tempfile
|
||||||
|
import os.path
|
||||||
|
import base64
|
||||||
|
import logging
|
||||||
|
from flask import Flask, jsonify
|
||||||
|
from flask import request
|
||||||
|
|
||||||
|
app = Flask(__name__)
|
||||||
|
certFile = "/app/cert/anna_export.crt"
|
||||||
|
pemFile = "/app/cert/anna_export_pass_1234.pem"
|
||||||
|
passwd = "1234"
|
||||||
|
|
||||||
|
@app.route('/')
|
||||||
|
def index():
|
||||||
|
return "Hello, World!"
|
||||||
|
|
||||||
|
@app.route('/sign', methods=['POST'])
|
||||||
|
def create_task():
|
||||||
|
if not request.json or not 'content' in request.json:
|
||||||
|
abort(400)
|
||||||
|
if not os.path.isfile(certFile):
|
||||||
|
return "No crt file exists", 500
|
||||||
|
if not os.path.isfile(pemFile):
|
||||||
|
return "No pem file exists", 500
|
||||||
|
|
||||||
|
temp_name = next(tempfile._get_candidate_names())
|
||||||
|
source_path = os.path.join(tempfile.mkdtemp(), temp_name)
|
||||||
|
result_path = "{}.sgn".format(source_path)
|
||||||
|
|
||||||
|
#logging.warning("request: {}".format(request.json))
|
||||||
|
|
||||||
|
decoded = base64.b64decode(request.json['content'])
|
||||||
|
with open(source_path, 'wb') as output_file:
|
||||||
|
output_file.write(decoded)
|
||||||
|
|
||||||
|
cmd = "openssl smime -sign -signer {} -inkey {} -engine gost -passin pass:{} -binary -noattr -outform DER -in {} -out {}".format(certFile, pemFile, passwd, source_path, result_path)
|
||||||
|
result = os.popen(cmd).read()
|
||||||
|
|
||||||
|
logging.warning('result file path is: {}'.format(result_path))
|
||||||
|
if not os.path.isfile(result_path):
|
||||||
|
return "No result file exists, somthing goes wrong...", 500
|
||||||
|
|
||||||
|
with open(result_path, "rb") as result_file:
|
||||||
|
result_json = base64.b64encode(result_file.read()).decode()
|
||||||
|
os.remove(result_path)
|
||||||
|
|
||||||
|
response = {
|
||||||
|
'signature': result_json
|
||||||
|
}
|
||||||
|
return jsonify(response), 200
|
||||||
|
|
||||||
|
if __name__ == '__main__':
|
||||||
|
app.run(host='0.0.0.0', port=80, debug=True)
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
flask
|
||||||
Reference in New Issue
Block a user