public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
From: Michael Tremer <michael.tremer@ipfire.org>
To: development@lists.ipfire.org
Subject: [PATCH 2/3] Partially revert "vpnmain.cgi: Use new system methods"
Date: Tue, 13 Jul 2021 15:30:52 +0000	[thread overview]
Message-ID: <20210713153053.11281-2-michael.tremer@ipfire.org> (raw)
In-Reply-To: <20210713153053.11281-1-michael.tremer@ipfire.org>

[-- Attachment #1: Type: text/plain, Size: 2838 bytes --]

This reverts commit a81cbf61273536ee36f3d26504aabdcd65d39cca.

It was no longer possible to generate the root/host certificates.

Signed-off-by: Michael Tremer <michael.tremer(a)ipfire.org>
---
 html/cgi-bin/vpnmain.cgi | 52 +++++++++++++---------------------------
 1 file changed, 16 insertions(+), 36 deletions(-)

diff --git a/html/cgi-bin/vpnmain.cgi b/html/cgi-bin/vpnmain.cgi
index 8f13cf51f..80e93ffd3 100644
--- a/html/cgi-bin/vpnmain.cgi
+++ b/html/cgi-bin/vpnmain.cgi
@@ -226,13 +226,9 @@ sub newcleanssldatabase {
 ###
 sub callssl ($) {
 	my $opt = shift;
-
-	# Split the given argument string into single pieces and assign them to an array.
-	my @opts = split(/ /, $opt);
-
-	my @retssl = &General::system_output("/usr/bin/openssl", @opts); #redirect stderr
+	my $retssl = `/usr/bin/openssl $opt 2>&1`; #redirect stderr
 	my $ret = '';
-	foreach my $line (split (/\n/, @retssl)) {
+	foreach my $line (split (/\n/, $retssl)) {
 		&General::log("ipsec", "$line") if (0); # 1 for verbose logging
 		$ret .= '<br>'.$line if ( $line =~ /error|unknown/ );
 	}
@@ -246,21 +242,13 @@ sub callssl ($) {
 ###
 sub getCNfromcert ($) {
 	#&General::log("ipsec", "Extracting name from $_[0]...");
-	my @temp = &General::system_output("/usr/bin/openssl", "x509", "-text", "-in", "$_[0]");
-	my $temp;
-
-	foreach my $line (@temp) {
-		if ($line =~ /Subject:.*CN = (.*)[\n]/) {
-			$temp = $1;
-			$temp =~ s+/Email+, E+;
-			$temp =~ s/ ST = / S = /;
-			$temp =~ s/,//g;
-			$temp =~ s/\'//g;
-
-			last;
-		}
-	}
-
+	my $temp = `/usr/bin/openssl x509 -text -in $_[0]`;
+	$temp =~ /Subject:.*CN = (.*)[\n]/;
+	$temp = $1;
+	$temp =~ s+/Email+, E+;
+	$temp =~ s/ ST = / S = /;
+	$temp =~ s/,//g;
+	$temp =~ s/\'//g;
 	return $temp;
 }
 ###
@@ -268,19 +256,11 @@ sub getCNfromcert ($) {
 ###
 sub getsubjectfromcert ($) {
 	#&General::log("ipsec", "Extracting subject from $_[0]...");
-	my @temp = &General::system_output("/usr/bin/openssl", "x509", "-text", "-in", "$_[0]");
-	my $temp;
-
-	foreach my $line (@temp) {
-		if($line =~ /Subject: (.*)[\n]/) {
-			$temp = $1;
-			$temp =~ s+/Email+, E+;
-			$temp =~ s/ ST = / S = /;
-
-			last;
-		}
-	}
-
+	my $temp = `/usr/bin/openssl x509 -text -in $_[0]`;
+	$temp =~ /Subject: (.*)[\n]/;
+	$temp = $1;
+	$temp =~ s+/Email+, E+;
+	$temp =~ s/ ST = / S = /;
 	return $temp;
 }
 ###
@@ -689,8 +669,8 @@ END
 		$errormessage = $!;
 		goto UPLOADCA_ERROR;
 	}
-	my @temp = &General::system_output("/usr/bin/openssl", "x509", "-text", "-in", "$filename");
-	if (! grep(/CA:TRUE/, @temp)) {
+	my $temp = `/usr/bin/openssl x509 -text -in $filename`;
+	if ($temp !~ /CA:TRUE/i) {
 		$errormessage = $Lang::tr{'not a valid ca certificate'};
 		unlink ($filename);
 		goto UPLOADCA_ERROR;
-- 
2.31.0


  reply	other threads:[~2021-07-13 15:30 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-07-13 15:30 [PATCH 1/3] ovpnmain.cgi: Join certificate output before &Header::cleanhtml(); Michael Tremer
2021-07-13 15:30 ` Michael Tremer [this message]
2021-07-13 15:30 ` [PATCH 3/3] vpnmain.cgi: " Michael Tremer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20210713153053.11281-2-michael.tremer@ipfire.org \
    --to=michael.tremer@ipfire.org \
    --cc=development@lists.ipfire.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox