From c16b083b9951896fd1703116c2a8a74cccc53f64 Mon Sep 17 00:00:00 2001 From: asesidaa <1061472754@qq.com> Date: Thu, 23 Feb 2023 17:41:15 +0800 Subject: [PATCH] Add bundled certificates, only manage certificate on windows. Update README.md --- Application/Api/UnlockAllMusicCommand.cs | 5 ++++- Infrastructure/Common/CertificateService.cs | 19 +++++++++++----- MainServer/BundledCertificates/cert.pfx | Bin 0 -> 2701 bytes MainServer/BundledCertificates/root.pfx | Bin 0 -> 2565 bytes MainServer/MainServer.csproj | 18 +++++++++++++++ MainServer/Program.cs | 14 ++++++++---- README.md | 23 ++++++++++++++++++-- 7 files changed, 67 insertions(+), 12 deletions(-) create mode 100644 MainServer/BundledCertificates/cert.pfx create mode 100644 MainServer/BundledCertificates/root.pfx diff --git a/Application/Api/UnlockAllMusicCommand.cs b/Application/Api/UnlockAllMusicCommand.cs index b0c1596..7f5f0e8 100644 --- a/Application/Api/UnlockAllMusicCommand.cs +++ b/Application/Api/UnlockAllMusicCommand.cs @@ -1,4 +1,5 @@ -using Microsoft.Extensions.Logging; +using System.Diagnostics.CodeAnalysis; +using Microsoft.Extensions.Logging; namespace Application.Api; @@ -14,6 +15,8 @@ public class UnlockAllMusicCommandHandler : RequestHandlerBase> Handle(UnlockAllMusicCommand request, CancellationToken cancellationToken) { var unlocks = await CardDbContext.CardDetails.Where( diff --git a/Infrastructure/Common/CertificateService.cs b/Infrastructure/Common/CertificateService.cs index 6494c09..39588f1 100644 --- a/Infrastructure/Common/CertificateService.cs +++ b/Infrastructure/Common/CertificateService.cs @@ -24,6 +24,7 @@ public class CertificateService private const string ROOT_CA_CN = "Taito Arcade Machine CA"; private const string CERT_CN = "GC local server"; + private const string CERT_CN2 = "nesys"; private const string CERT_DIR = "Certificates"; private const string CERT_FILE_NAME = "cert.pfx"; private const string ROOT_CERT_FILE_NAME = "root.pfx"; @@ -116,7 +117,15 @@ public class CertificateService { var existingCert = GetCertificate(StoreName.My, StoreLocation.LocalMachine, CERT_CN); - if (existingCert != null) + if (existingCert is not null) + { + return existingCert; + } + + logger.LogInformation("First try not found, changing CN to nesys"); + + existingCert = GetCertificate(StoreName.My, StoreLocation.LocalMachine, CERT_CN2); + if (existingCert is not null) { return existingCert; } @@ -257,7 +266,7 @@ public class CertificateService store.Open(OpenFlags.ReadOnly); var result = store.Certificates.Find(X509FindType.FindByIssuerName, ROOT_CA_CN, true); - certificateExists = result.Count == 2; + certificateExists = result.Count != 0; store.Close(); } @@ -286,9 +295,9 @@ public class CertificateService try { var store = new X509Store(storeName, storeLocation); - store.Open(OpenFlags.ReadWrite); - var result = store.Certificates.Find(X509FindType.FindBySubjectDistinguishedName, - $"CN={commonName}", true); + store.Open(OpenFlags.ReadOnly); + var result = store.Certificates.Find(X509FindType.FindBySubjectName, + $"{commonName}", true); if (result.Any()) { diff --git a/MainServer/BundledCertificates/cert.pfx b/MainServer/BundledCertificates/cert.pfx new file mode 100644 index 0000000000000000000000000000000000000000..d2aec37a60952e42c0008996a61f4e418d4796fc GIT binary patch literal 2701 zcmY+^cQhM}8U}EYNbFcO5_>eX2&qkoQG2UeZPCVvQG(ctP%3uSNUbWhTWWmfXSHUn zR$JPt+0?A@5n45_@0@$@ckdtXdCz&CbDlqcazw@?S^!Xv$Y=p(xRhX+aL59H0G<#T zF(4wN#(AtFM+9yEQ-PllK?~>6EG>ZM{C)VR0m$)#8UMY&3;@fqg6JzxTZg$C=a^|} z>1kq!pvq~IIe0F-SXh4C4u(UQb`Od^BqJX!|E7tHkLfkDM;lT!8W0BbOIgyRdOY>MD3QsFdARI* z<)E8eoy~|*s>V#_`tKIq!W69HVEG}#w2Kp_`IM0R&)m`(XhK zP=M&j-#nv}$Ar}>DmucBWCMBUu!UjvDb1}_CpiMRXl6whP#*ZW zQMpew;L+>TiN(5~)jjb0Lc!=CzRj?XtCis6Zd=SBAFOURf-@Xr+*=Jc}>`<5T0%@ zpYYG*gd6qw+#gWj4wL`_n7?&-;!<^OmT!M}j7$)wpypm~!AMmY6%{l#p`kP$D59tlAs^l{ z+}(EnabIYH|yfl3TPmh;`c6||xY14HH_GPF2)h(*xXfCNeWqqdp@ub+G zxZP{S&{QK*w0FR1g)mH>V=x~%auuUl6?KLf1e=ql6#REsdyqMJb6Duv1AXt6Vp7wuKGo{*P&Z5aL= z+k#hoZ!dl#KdcR8A;X49hCMbcf3i1uJygf^$}AV6a;EM*M}s=0vTtV9>DkN#nw=a$ z;)r7&Z^hn-58n}rpE%Z$DmTMJW&aWm=RnXGk1sxw;N@A5eBi2PYrSH{YgY1!w4t8o zYQW8klQL>F5THYM_?6e1yrj5ekC$h5>G7%^Xy`AohPYMZ#irTpTP8kuHgOrq>D{N+ zC&OC;f9?q9ukID{PcA%AWy6ypfmut;zQpPS?qQ7h;uQyv1Rf&4o3ZpEyFy@?W{3=x z#&S?J_v4X7fo^-X1%%m0ihz?O?rK6+wb+(@ulIDbLDDAUEVrSXH;w&a*>*01bxB^# zr`?~|E{zWCpr?(h3RNGE$9Upl{wV5a{t#|WT3_i*bR!u9{t5BRr!0ht?S_-K5^-}-@wpdpjn z_}t&fAYiL=bLsMpg%Ou>Hc2OwrkIZ~C1(w9BJE)9rt;c;jK}`C-^|pFQg@Rn-efCx zE(T}6&bfEhn=8>(jz-(}Qu#`bt6al1&w|QXQl`Vkzq1`Ek+@t*^AX#9oqt4>(YG5^ zP-pA!S~5_BgsNjVWWb*!!{^VQlrAJnIZHpdbDumK&&VQL4EJ~>S>swt0}B^gi7vCj z@D1Oa61ofke0`l2P>O8etM({C&EAr+J5)*yUogj-(sx3*Lcf!fd70GHZ{Cx4QB5%SL_$XT!;*MiU*SentXY=c z`vY~HA8-CauhWdN8XJbTCU-#<&-51=7ou1a>nKQB+)aBM(4b|#^kixLO{NnEE-W4k zugwmfkhNt=`tgE0WBM6`l8~ZRZe+fk)3EEc5Z@HAHX_K){aVmB{x{Eb!^N@G5!eC4sYAL-CWZ}#`DK;ao*O{A-+8CJW z>gx;H6-a1_^HA%6Tz@m>Si8w1%D%k8pUhYur8+tl$ngy45OoMutCJ7@N&qVpy^mOZ zie|csqT8tBIoEp}W72i?RE5?)0HvZjL>9@2a>t0|QyYAA_`BzRtEaH0ghub&NhE7N zGImI`SH?S$#RO(tgxF0Vl?E1R64Py4ICAF*szvDz7B#&Hg8qC6DWwjx;gLr0#}*|i zcAuE40KR`-k@0djsW2PSIBqdlMd_7{hxGwb1e0|Ero<{D2`j11*XG@YH4=M5@zB@$ zu7;l?y)O;p_D_3#8+KzkbF@#Ty)2!$jqVN;8OKq0Be-{}lSdP^;@?t%b(~!}$IS<5 zvr1!sY7MFQv|wwU@24QUyRU4|5kp`r=SAqsQ?`gc|L9jV{514J(=S`X9s9-Zs?>i? z(mXpx4|9W2@EFt%>)z`6gHcaS6CJpOm?!_9SbI}$jG^lxf9L@&Uh!C03_SMZngaGq zEuxzN+C__~nHvTKI|fF$aBh~8gE(+|ME?VLy-mT&e$PdFx+wi)+X87Wy570s;kBu%-NnYLz<-WUBF%yTw~kE?!}X?HbF-R5!yn>jOt9S$4Rxl;C6 zWrT(X;cgwWCtI+ZnzcvZ9lOUh36Hv>B zIpg<0`}?SJiXrYX-~3+~VV{jEeP@MFA*US)32!0sQ*2%%vE2|Pf7|d3!=zD~neRAN z^5HGO&}x!w+2fmsmro6@qRTq%oa80s#Qv)z!v%S65SP2-o3fC-J5a{^JUaW|?qWq> zwd~8u%ZbP_faxx?0%>7%G$5`6#rl|$y!M1A>LGEA(I!mRtDk>?=;60CD{u4U=l!kZ FzW}%y>r?;$ literal 0 HcmV?d00001 diff --git a/MainServer/BundledCertificates/root.pfx b/MainServer/BundledCertificates/root.pfx new file mode 100644 index 0000000000000000000000000000000000000000..16299d3c14eccf49c21582b8590fd26b43b40104 GIT binary patch literal 2565 zcmY+^c{CJ^8U}D<7Hb(x#-50pp)q4?M49;_%DxPm5EDj7mWl|U@nOVA*|KKMPL>#C zNhn*{8Ic*w$Wr#TMqQnA@BQxm<2~;=&vVZ6=MP2Z2CxHwC^FZ32p1wkKVt6~fCG?C z=Bfvgxn3Q`l_)ZZ^iKuJCWCB_B1?7v+tD-nrvacOAl(06-~~WX$3dL00tZ|4U9HF1 z**V$%B!i@12e#$KVa`#Av=fd^!&RYQqXT8L8sLz%rEdLtzlW|wrQ~-pr5p)mn}?(7 zZLBjRY;QCW7F6i=w(K+7uQ;APIXk(j9Yh~M|AQeI7VrS|~a6a;HE(Np7tP-41c@8@D&8#PqjoD75Dm&xMiy{I$))lNXk zp}gIPEh0u^f!g>GR5>;x`04Z-}t8#t3;Ileucwqj{MzaGsBP0N?cq?0Uq5n22Gt!tJWVauBp z`ZU;7IdZ1iBj9?P9VbT4Kbv`wdN*&1I~vPZd2L>q8ep>r2+5yUJ^myg@U_F2QBMoL zj!Q6?0b|ToBen8o?(5_*iRvy&VvJ!asw`8?mM!}PD;9pf%8losAr*KgtH#NbMK330Rz|b<=1OA$b3uN`*>G&ksy`7%{lb-vYJ^rHB(Xews z^wtNe1)gmhkFpm6Sw`7)Jr9>Rk}+g8wO;*>tnX>-$=Ypi2oXzxn#@yhsa?9F;H#XC zvSBo%P6KFS3j%ySzEL5A>1FO}5sMxdlz$!?escX{2B0ax?GHMlWl5hs#XZmOxz3eM zY!jZ<-?hE&azkxYvmHI+FhHL9jxn74c&3wU_%!z%)zi&$q{}^)|JDqPJLOvOK?#4a zEHn9*Lrdh2FQTEtlK8qzi&NDe{N;-f!q42#(FQST5N*09j4jy=h1iAnY*AqS7`@SV zSYQ9}m{T%TXpIxk+5XBpm>PB{dYbn(nD?pKLRe%@evyu#%@$j#Su^6$t65t$RNk0H zyJ5{0GIHB#pkVxR!S@VzX?WO=bxtg!s`5YyXCc+tz=zPt|Er`p$Y}Nt*$!sMf*A)} z9bTeSD-MXd9aTvl(xh0!b>*US&IpkN4pM>&~~Nm2(6m z7@Z*fW*@PT{bEEt>1V;Z^%8u*np!?s5i)|Zpf_riBv}Vx3XMnR_Lp6y@6{59jWdx| zPbf<<%tRK8UsUleRb~#RpzfEALHm#gcOUQ8NU&NkvVROU)djp`+@~>g@5R*Ygh_2C zp4%ae*9X~4=Uk}Lx(7I}K|+zixc>nqn+#S4k-^BL7;$v+5T5_=a%9$#L#sysE&rc7 zz~Aar)Lv0}5Qx0@TOAM?)Ro256}QqBd$CvjZR1DT9FH!r_uvxqj)Z5sCi{FZMBUh- z<C9*>|K7l8Z{O*R!`G|*z-ju-N&K6QQ4FoL^3D6?AR_9_ungBvG?%` z(ERFK?Vn;CRS}m7m)kV{+fYWLf1=9rl9kDJN35RoZh#P@^lBm8w=|;mOX+iM;k{+F zCgJ`4kNwx8Pb=<}7|#`}`{+$|9W+vvq__@tzYuR(e*89FGna1d0h{6UdeunR61WiW zq?4E2vYiVwrwcMz4L0+K8k;A}&+9FhtNQ+MPD^!aQi7s-z(GiBXM*Rb`HF#RgHbSYfsXH>!#FCtJS*jv-*>E;&z1xb_Qc{%!| zeFwy~Lad$|4G|~I&VJNOQF_xpp#V1_#)Df(!7;G_0f`>54R3tK7y2tXl+@pR&iIG zyDgVYNRuI=*v3VDc^K`9Y1W!j_~FgR*?w^7b!X;A&pF%EA)`9dc}u^a7*J)Xz>n1Y+h z(5>p(8EFaF<@T3vC-q$4e}G#_h+Rz=qA00#yCr|g8l9qR7%4H{eeY*wx>Zf6E!Pa4 zm7&Kmw)z9(6FyUm+&(&5G~~RuirKu4{EtDbwbuPfTwV#bjx+BG$+UVXK|`y7&H zEkMcG!gsV!H*s6R22>|J@qCW~B}dB6%Iz=#}{0)sW4$JC&He#deVsE~J$`8D1edG=)e(mA%L)YNG8g1_>QL z;#DHb;doPXJN4uJV}EKO*04dT3hahV@x-n*{awu2kZS?Ln7~LJBT{8A3j8y?KhDn& z>p{Q@;2${fNz_`^Gc)`6d9=20OYJ34K?JEHPX)$OyW(|_X`cRB9hZ)lL&^SEN3IiS zVUQ5Lta(arMqx7#8_RC$IgnQIL(&U{Mx8=&LBI;ff$U;nHjt1E&0)OJG|=Tk)Jh@o YmRss9rnV8pS@^IiU?swT PreserveNewest + true PreserveNewest + true PreserveNewest + true PreserveNewest + true PreserveNewest + true PreserveNewest + true PreserveNewest + true PreserveNewest + true + + + + PreserveNewest + true + + + + PreserveNewest + true diff --git a/MainServer/Program.cs b/MainServer/Program.cs index 8fa9584..a78c8cc 100644 --- a/MainServer/Program.cs +++ b/MainServer/Program.cs @@ -1,4 +1,5 @@ using System.Reflection; +using System.Security.Authentication; using Application; using Application.Interfaces; using Domain.Config; @@ -45,10 +46,15 @@ try var serverIp = builder.Configuration["ServerIp"] ?? "127.0.0.1"; var certificateManager = new CertificateService(serverIp, new SerilogLoggerFactory(Log.Logger).CreateLogger("")); - builder.WebHost.ConfigureKestrel(options => - options.ConfigureHttpsDefaults(adapterOptions => - adapterOptions.ServerCertificate = certificateManager.InitializeCertificate() - )); + if (Environment.OSVersion.Platform == PlatformID.Win32NT) + { + builder.WebHost.UseKestrel(options => + options.ConfigureHttpsDefaults(adapterOptions => + { + adapterOptions.ServerCertificate = certificateManager.InitializeCertificate(); + })); + } + builder.Host.UseSerilog((context, configuration) => { diff --git a/README.md b/README.md index 09227f1..eb85a48 100644 --- a/README.md +++ b/README.md @@ -73,11 +73,23 @@ To enable these, try use the omnimixed version of stage_param.dat. That can fix ## Local network -If your game and server is not on the same computer, import the certificates in `Certificates` folder. `root.pfx` goes into LocalMachine/My and Trusted root, the other only LocalMachine/My. +If your game and server is not on the same computer, import the certificates in `BundledCertificates` folder. `root.pfx` goes into LocalMachine/My and Trusted root, `cert.pfx` only LocalMachine/My. Then in `server.json`, modify the following section: + +``` + "Https": { + "Url": "https://0.0.0.0:443", + "Certificate": { + "Path": "BundledCertificates/cert.pfx", + "Password": "" + } + }, +``` + + ## Windows XP -If you are using Windows XP (e.g. using real machine), it will not recognize the generated certificate since it uses SHA256. +If you are using Windows XP (e.g. using a real arcade machine), it will not recognize the generated certificate since it uses SHA256. You will have to generate the certificates yourself. @@ -92,3 +104,10 @@ There's a basic web interface for check scores and set options. ## Song unlock To unlock all songs, first play for one time and save, then in web UI, go to `Edit Options` to unlock all songs. + +Notice that unlock all songs without playing them can increase card saving time a lot, so it is better to play them, or manually create an empty failed record, using the following SQL + +```sqlite +INSERT INTO "main"."card_detail" VALUES ({card_id}, {song_id}, 0, 2, 5, 1, 0,0,0,0,0,0,'1337',0,0,0,638127691353989741); +``` +