|
1 | | -namespace k8s |
2 | | -{ |
3 | | - using k8s.Exceptions; |
4 | | - using System; |
5 | | - using System.ComponentModel; |
6 | | - using System.Diagnostics; |
7 | | - using System.IO; |
8 | | - using System.Runtime.InteropServices; |
9 | | - using System.Text; |
10 | | - using System.Threading.Tasks; |
11 | | - |
12 | | - public static class Utils |
13 | | - { |
14 | | - /// <summary> |
15 | | - /// Encode string in base64 format. |
16 | | - /// </summary> |
17 | | - /// <param name="text">string to be encoded.</param> |
18 | | - /// <returns>Encoded string.</returns> |
19 | | - public static string Base64Encode(string text) |
20 | | - { |
21 | | - return Convert.ToBase64String(Encoding.UTF8.GetBytes(text)); |
22 | | - } |
23 | | - |
24 | | - /// <summary> |
25 | | - /// Encode string in base64 format. |
26 | | - /// </summary> |
27 | | - /// <param name="text">string to be encoded.</param> |
28 | | - /// <returns>Encoded string.</returns> |
29 | | - public static string Base64Decode(string text) |
30 | | - { |
31 | | - return Encoding.UTF8.GetString(Convert.FromBase64String(text)); |
32 | | - } |
33 | | - |
34 | | - /// <summary> |
35 | | - /// Generates pfx from client configuration |
36 | | - /// </summary> |
37 | | - /// <param name="config">Kuberentes Client Configuration</param> |
38 | | - /// <returns>Generated Pfx Path</returns> |
39 | | - /// TODO: kabhishek8260 Remplace the method with X509 Certificate with private key(in dotnet 2.0) |
40 | | - public static async Task<string> GeneratePfxAsync(KubernetesClientConfiguration config) |
41 | | - { |
42 | | - var userHomeDir = RuntimeInformation.IsOSPlatform(OSPlatform.Windows) ? |
43 | | - Environment.GetEnvironmentVariable("USERPROFILE") : |
44 | | - Environment.GetEnvironmentVariable("HOME"); |
45 | | - |
46 | | - var certDirPath = Path.Combine(userHomeDir, ".k8scerts"); |
47 | | - Directory.CreateDirectory(certDirPath); |
48 | | - |
49 | | - var keyFilePath = ""; |
50 | | - var certFilePath = ""; |
51 | | - |
52 | | - var filePrefix = config.CurrentContext; |
53 | | - var pfxFilePath = Path.Combine(certDirPath, filePrefix + "pfx"); |
54 | | - if (!string.IsNullOrWhiteSpace(config.ClientCertificateKey)) |
55 | | - { |
56 | | - keyFilePath = Path.Combine(certDirPath, filePrefix + "key"); |
57 | | - using (FileStream fs = File.Create(keyFilePath)) |
58 | | - { |
59 | | - byte[] info = Convert.FromBase64String(config.ClientCertificateKey); |
60 | | - await fs.WriteAsync(info, 0, info.Length).ConfigureAwait(false); |
61 | | - } |
62 | | - } |
63 | | - if (!string.IsNullOrWhiteSpace(config.ClientKey)) |
64 | | - { |
65 | | - keyFilePath = config.ClientKey; |
66 | | - } |
67 | | - |
68 | | - if (!string.IsNullOrWhiteSpace(config.ClientCertificateData)) |
69 | | - { |
70 | | - certFilePath = Path.Combine(certDirPath, filePrefix + "cert"); |
71 | | - |
72 | | - using (FileStream fs = File.Create(certFilePath)) |
73 | | - { |
74 | | - byte[] info = Convert.FromBase64String(config.ClientCertificateData); |
75 | | - await fs.WriteAsync(info, 0, info.Length).ConfigureAwait(false); |
76 | | - } |
77 | | - } |
78 | | - if (!string.IsNullOrWhiteSpace(config.ClientCertificate)) |
79 | | - { |
80 | | - certFilePath = config.ClientCertificate; |
81 | | - } |
82 | | - |
83 | | - var processStartInfo = new ProcessStartInfo |
84 | | - { |
85 | | - FileName = @"openssl", |
86 | | - Arguments = $"pkcs12 -export -out {pfxFilePath} -inkey {keyFilePath} -in {certFilePath} -passout pass:", |
87 | | - CreateNoWindow = true, |
88 | | - RedirectStandardError = true, |
89 | | - RedirectStandardOutput = true |
90 | | - }; |
91 | | - |
92 | | - try |
93 | | - { |
94 | | - using (Process process = Process.Start(processStartInfo)) |
95 | | - { |
96 | | - process.WaitForExit(); |
97 | | - if (process.ExitCode != 0) |
98 | | - { |
99 | | - throw new KubernetesClientException($"Failed to generate pfx file with openssl. ExitCode = {process.ExitCode}."); |
100 | | - } |
101 | | - } |
102 | | - } |
103 | | - catch (Win32Exception e) |
104 | | - { |
105 | | - throw new KubernetesClientException("Failed to generate pfx file with openssl.", e); |
106 | | - } |
107 | | - |
108 | | - return pfxFilePath; |
109 | | - } |
110 | | - } |
111 | | -} |
| 1 | +namespace k8s |
| 2 | +{ |
| 3 | + using System; |
| 4 | + using System.Diagnostics; |
| 5 | + using System.Globalization; |
| 6 | + using System.IO; |
| 7 | + using System.Runtime.InteropServices; |
| 8 | + using System.Security.Cryptography; |
| 9 | + using System.Security.Cryptography.X509Certificates; |
| 10 | + using System.Text; |
| 11 | + using System.Threading.Tasks; |
| 12 | + |
| 13 | + using Org.BouncyCastle.Crypto; |
| 14 | + using Org.BouncyCastle.Crypto.Parameters; |
| 15 | + using Org.BouncyCastle.Security; |
| 16 | + using Org.BouncyCastle.OpenSsl; |
| 17 | + |
| 18 | + public static class Utils |
| 19 | + { |
| 20 | + /// <summary> |
| 21 | + /// Encode string in base64 format. |
| 22 | + /// </summary> |
| 23 | + /// <param name="text">string to be encoded.</param> |
| 24 | + /// <returns>Encoded string.</returns> |
| 25 | + public static string Base64Encode(string text) |
| 26 | + { |
| 27 | + return Convert.ToBase64String(Encoding.UTF8.GetBytes(text)); |
| 28 | + } |
| 29 | + |
| 30 | + /// <summary> |
| 31 | + /// Encode string in base64 format. |
| 32 | + /// </summary> |
| 33 | + /// <param name="text">string to be encoded.</param> |
| 34 | + /// <returns>Encoded string.</returns> |
| 35 | + public static string Base64Decode(string text) |
| 36 | + { |
| 37 | + return Encoding.UTF8.GetString(Convert.FromBase64String(text)); |
| 38 | + } |
| 39 | + |
| 40 | + /// <summary> |
| 41 | + /// Generates pfx from client configuration |
| 42 | + /// </summary> |
| 43 | + /// <param name="config">Kuberentes Client Configuration</param> |
| 44 | + /// <returns>Generated Pfx Path</returns> |
| 45 | + public static X509Certificate2 GeneratePfx(KubernetesClientConfiguration config) |
| 46 | + { |
| 47 | + var keyData = new byte[]{}; |
| 48 | + var certData = new byte[]{}; |
| 49 | + |
| 50 | + var filePrefix = config.CurrentContext; |
| 51 | + if (!string.IsNullOrWhiteSpace(config.ClientCertificateKey)) |
| 52 | + { |
| 53 | + keyData = Convert.FromBase64String(config.ClientCertificateKey); |
| 54 | + } |
| 55 | + if (!string.IsNullOrWhiteSpace(config.ClientKey)) |
| 56 | + { |
| 57 | + keyData = File.ReadAllBytes(config.ClientKey); |
| 58 | + } |
| 59 | + |
| 60 | + if (!string.IsNullOrWhiteSpace(config.ClientCertificateData)) |
| 61 | + { |
| 62 | + certData = Convert.FromBase64String(config.ClientCertificateData); |
| 63 | + } |
| 64 | + if (!string.IsNullOrWhiteSpace(config.ClientCertificate)) |
| 65 | + { |
| 66 | + certData = File.ReadAllBytes(config.ClientCertificate); |
| 67 | + } |
| 68 | + |
| 69 | + var cert = new X509Certificate2(certData); |
| 70 | + return addPrivateKey(cert, keyData); |
| 71 | + } |
| 72 | + |
| 73 | + public static X509Certificate2 addPrivateKey(X509Certificate2 cert, byte[] keyData) |
| 74 | + { |
| 75 | + using (var reader = new StreamReader(new MemoryStream(keyData))) |
| 76 | + { |
| 77 | + var obj = new PemReader(reader).ReadObject(); |
| 78 | + if (obj is AsymmetricCipherKeyPair) { |
| 79 | + var cipherKey = (AsymmetricCipherKeyPair)obj; |
| 80 | + obj = cipherKey.Private; |
| 81 | + } |
| 82 | + var rsaKeyParams = (RsaPrivateCrtKeyParameters)obj; |
| 83 | + var rsaKey = RSA.Create(DotNetUtilities.ToRSAParameters(rsaKeyParams)); |
| 84 | + return cert.CopyWithPrivateKey(rsaKey); |
| 85 | + } |
| 86 | + } |
| 87 | + } |
| 88 | +} |
0 commit comments