You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

ssh_key_fingerprint.go 3.0KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899
  1. // Copyright 2021 The Gitea Authors. All rights reserved.
  2. // SPDX-License-Identifier: MIT
  3. package asymkey
  4. import (
  5. "context"
  6. "fmt"
  7. "strings"
  8. "code.gitea.io/gitea/models/db"
  9. "code.gitea.io/gitea/modules/log"
  10. "code.gitea.io/gitea/modules/process"
  11. "code.gitea.io/gitea/modules/setting"
  12. "code.gitea.io/gitea/modules/util"
  13. "golang.org/x/crypto/ssh"
  14. )
  15. // ___________.__ .__ __
  16. // \_ _____/|__| ____ ____ ________________________|__| _____/ |_
  17. // | __) | |/ \ / ___\_/ __ \_ __ \____ \_ __ \ |/ \ __\
  18. // | \ | | | \/ /_/ > ___/| | \/ |_> > | \/ | | \ |
  19. // \___ / |__|___| /\___ / \___ >__| | __/|__| |__|___| /__|
  20. // \/ \//_____/ \/ |__| \/
  21. //
  22. // This file contains functions for fingerprinting SSH keys
  23. //
  24. // The database is used in checkKeyFingerprint however most of these functions probably belong in a module
  25. // checkKeyFingerprint only checks if key fingerprint has been used as public key,
  26. // it is OK to use same key as deploy key for multiple repositories/users.
  27. func checkKeyFingerprint(ctx context.Context, fingerprint string) error {
  28. has, err := db.GetByBean(ctx, &PublicKey{
  29. Fingerprint: fingerprint,
  30. })
  31. if err != nil {
  32. return err
  33. } else if has {
  34. return ErrKeyAlreadyExist{0, fingerprint, ""}
  35. }
  36. return nil
  37. }
  38. func calcFingerprintSSHKeygen(publicKeyContent string) (string, error) {
  39. // Calculate fingerprint.
  40. tmpPath, err := writeTmpKeyFile(publicKeyContent)
  41. if err != nil {
  42. return "", err
  43. }
  44. defer func() {
  45. if err := util.Remove(tmpPath); err != nil {
  46. log.Warn("Unable to remove temporary key file: %s: Error: %v", tmpPath, err)
  47. }
  48. }()
  49. stdout, stderr, err := process.GetManager().Exec("AddPublicKey", "ssh-keygen", "-lf", tmpPath)
  50. if err != nil {
  51. if strings.Contains(stderr, "is not a public key file") {
  52. return "", ErrKeyUnableVerify{stderr}
  53. }
  54. return "", util.NewInvalidArgumentErrorf("'ssh-keygen -lf %s' failed with error '%s': %s", tmpPath, err, stderr)
  55. } else if len(stdout) < 2 {
  56. return "", util.NewInvalidArgumentErrorf("not enough output for calculating fingerprint: %s", stdout)
  57. }
  58. return strings.Split(stdout, " ")[1], nil
  59. }
  60. func calcFingerprintNative(publicKeyContent string) (string, error) {
  61. // Calculate fingerprint.
  62. pk, _, _, _, err := ssh.ParseAuthorizedKey([]byte(publicKeyContent))
  63. if err != nil {
  64. return "", err
  65. }
  66. return ssh.FingerprintSHA256(pk), nil
  67. }
  68. // CalcFingerprint calculate public key's fingerprint
  69. func CalcFingerprint(publicKeyContent string) (string, error) {
  70. // Call the method based on configuration
  71. var (
  72. fnName, fp string
  73. err error
  74. )
  75. if setting.SSH.StartBuiltinServer {
  76. fnName = "calcFingerprintNative"
  77. fp, err = calcFingerprintNative(publicKeyContent)
  78. } else {
  79. fnName = "calcFingerprintSSHKeygen"
  80. fp, err = calcFingerprintSSHKeygen(publicKeyContent)
  81. }
  82. if err != nil {
  83. if IsErrKeyUnableVerify(err) {
  84. log.Info("%s", publicKeyContent)
  85. return "", err
  86. }
  87. return "", fmt.Errorf("%s: %w", fnName, err)
  88. }
  89. return fp, nil
  90. }