Skip to content
Toggle navigation
P
Projects
G
Groups
S
Snippets
Help
haoqu.ma
/
gotty
This project
Loading...
Sign in
Toggle navigation
Go to a project
Project
Repository
Issues
0
Merge Requests
0
Pipelines
Wiki
Snippets
Settings
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Commit 57923e98
authored
Oct 04, 2015
by
Iwasaki Yudai
Browse files
Options
Browse Files
Download
Plain Diff
Merge pull request #67 from freakhill/master
support for client certificate
2 parents
36dfe5de
7e11f664
Show whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
42 additions
and
1 deletions
app/app.go
app/app.go
View file @
57923e9
...
...
@@ -2,6 +2,8 @@ package app
import
(
"crypto/rand"
"crypto/tls"
"crypto/x509"
"encoding/base64"
"errors"
"io/ioutil"
...
...
@@ -46,6 +48,8 @@ type Options struct {
EnableTLS
bool
`hcl:"enable_tls"`
TLSCrtFile
string
`hcl:"tls_crt_file"`
TLSKeyFile
string
`hcl:"tls_key_file"`
VerifyClientCert
bool
`hcl:"verify_client_cert"`
ClientCAs
[]
string
`hcl:"client_cas"`
TitleFormat
string
`hcl:"title_format"`
EnableReconnect
bool
`hcl:"enable_reconnect"`
ReconnectTime
int
`hcl:"reconnect_time"`
...
...
@@ -67,6 +71,8 @@ var DefaultOptions = Options{
EnableTLS
:
false
,
TLSCrtFile
:
"~/.gotty.crt"
,
TLSKeyFile
:
"~/.gotty.key"
,
VerifyClientCert
:
false
,
ClientCAs
:
[]
string
{},
TitleFormat
:
"GoTTY - {{ .Command }} ({{ .Hostname }})"
,
EnableReconnect
:
false
,
ReconnectTime
:
10
,
...
...
@@ -191,9 +197,44 @@ func (app *App) Run() error {
}
}
serverMaker
:=
func
()
*
http
.
Server
{
return
&
http
.
Server
{
Addr
:
endpoint
,
Handler
:
siteHandler
}
}
if
app
.
options
.
VerifyClientCert
&&
app
.
options
.
EnableTLS
{
serverMaker
=
func
()
*
http
.
Server
{
clientCaPool
:=
x509
.
NewCertPool
()
for
_
,
path
:=
range
app
.
options
.
ClientCAs
{
pem
,
err
:=
ioutil
.
ReadFile
(
path
)
if
err
!=
nil
{
log
.
Printf
(
"Could not read pem file at: "
+
path
)
return
nil
}
if
clientCaPool
.
AppendCertsFromPEM
(
pem
)
{
log
.
Printf
(
"Could not parse pem file at: "
+
path
)
return
nil
}
}
return
&
http
.
Server
{
Addr
:
endpoint
,
Handler
:
siteHandler
,
TLSConfig
:
&
tls
.
Config
{
ClientAuth
:
tls
.
RequireAndVerifyClientCert
,
ClientCAs
:
clientCaPool
,
PreferServerCipherSuites
:
true
}}
}
}
server
:=
serverMaker
()
if
server
==
nil
{
log
.
Printf
(
"Failed to build server."
)
return
errors
.
New
(
"Failed to build server."
)
}
var
err
error
app
.
server
=
manners
.
NewWithServer
(
&
http
.
Server
{
Addr
:
endpoint
,
Handler
:
siteHandler
}
,
server
,
)
if
app
.
options
.
EnableTLS
{
crtFile
:=
ExpandHomeDir
(
app
.
options
.
TLSCrtFile
)
...
...
Write
Preview
Markdown
is supported
Attach a file
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to post a comment