【问题标题】:Changing SSL certificates on the fly in IdHTTPServer在 IdHTTPServer 中动态更改 SSL 证书
【发布时间】:2019-08-25 00:23:13
【问题描述】:

我正在使用 indy 在 delphi 10.3 中开发支持 SSL 的 MITM 代理。我使用 IdHttpServer 组件,它在 CommandOther 事件中起作用。我设法让它即时解密和转储数据,并重新加密并将其发送到浏览器,但我需要更改每个域的 idhttpserver 证书。我可以生成它们并安装我自己的 CA,但我无法找到一种方法来更改它们在我的代理工作时。如果有人能告诉我怎么做,我将不胜感激!

 procedure TForm3.IdHTTPServer1CommandOther(AContext: TIdContext;
  ARequestInfo: TIdHTTPRequestInfo; AResponseInfo: TIdHTTPResponseInfo);
 var
S: string;
LClient: TIdtcpClient;
 newsize:int64;
LBuf: TIdBytes;
Len: Integer;

var response:integer;
s3: TStringDynArray;
var cmd:string;
bytes:tidbytes;

oldstr,newstr:string;
ResponseCode, ResponseText: string;
  Size: Int64;
ssl:tIdServerIOHandlerSSLopenssl;


begin
 if not TextIsSame(ARequestInfo.Command, 'CONNECT') then Exit;


 LClient := TIdtcpClient.Create(nil);
  try

S := ARequestInfo.URI;
LClient.Host := Fetch(S, ':', True);
LClient.Port := StrToIntDef(S, 443);


LClient.IOHandler := TIdSSLIOHandlerSocketOpenSSL.Create(LClient);


LClient.ConnectTimeout := 5000;



// connect and activate SSL between this proxy and the target server

LClient.Connect;
try
  AResponseInfo.ResponseNo := 200;
  AResponseInfo.ResponseText := 'Connection established';
  AResponseInfo.WriteHeader;


  // activate SSL between this proxy and the client
  TIdSSLIOHandlerSocketOpenSSL(AContext.Connection.Socket).PassThrough:=false;

  // pass data between AContext.Connection.IOHandler and LClient.IOHandler
//as needed.


  // received data will be decrypted, and sent data will be encryted...
  while AContext.Connection.Connected and lclient.Connected do
  begin

    //mitm traffic modification routine      


  end;

finally

 LClient.Disconnect;

end;
 finally
 LClient.Free;

end;
 end;

这是证书切换代码:

procedure TForm3.IdHTTPServer1Connect(AContext: TIdContext);
var

SSL: TIdSSLIOHandlerSocketOpenSSL;
begin

if AContext.Connection.Socket.Binding.Port = 443 then
        begin



sslh:=tIdSSLIOHandlerSocketOpenSSL(AContext.Connection.IOHandler);



          sslh.SSLOptions.CertFile:='Certificate.pem';
     sslh.SSLOptions.keyfile:='PrivateKey.pem';
    sslh.SSLOptions.RootCertFile:='certificateAuthorityCertificate.pem';
     sslh.SSLOptions.SSLVersions:=[sslvSSLv23];
     sslh.ssloptions.mode:=sslmBoth;
   sslh.OnGetPassword:= IdServerIOHandlerSSLOpenSSL1GetPassword;

     sslh.PassThrough:=false;

      TIdSSLIOHandlerSocketOpenSSL(AContext.Connection).PassThrough:=false;
       //memo2.Text:=AContext.Connection.IOHandler.ReadLn();

        end;

  end;

在一个表单上,我有一个 tidhttpserver 和 TIdServerIOHandlerSSLOpenSSL 作为它的 iohandler。

【问题讨论】:

    标签: delphi ssl ssl-certificate pascal indy


    【解决方案1】:

    分配OnQuerySSLPort 事件处理程序,该事件处理程序无条件地将VUseSSL 参数设置为False,而不管请求的APort。然后,在OnConnect 事件中,如果AContext.Connection.Socket.Binding.Port 属性为443(或您想在其上使用HTTPS 的任何端口),您可以将AContext.Connection.IOHandler 属性类型转换为TIdSSLIOHandlerSocketBase(或后代,如TIdSSLIOHandlerSocketOpenSSL,如果使用 OpenSSL),根据需要配置其证书,然后将其 PassThrough 属性设置为 False 以完成 SSL/TLS 握手。

    【讨论】:

    • 谢谢雷米!这是我在检查端口后在 OnConnect 事件中使用的例程,但它不起作用,页面只是没有加载并立即获取安全连接失败 inf FF sslh:= TIdSSLIOHandlerSocketOpenSSL.Create; AContext.Connection.IOHandler:= sslh; sslh.SSLOptions.CertFile:='Certificate.pem'; sslh.SSLOptions.keyfile:='PrivateKey.pem'; sslh.SSLOptions.RootCertFile:='AuthorityCertificate.pem'; @ 987654337@TIdSSLIOHandlerSocketOpenSSL(AContext.Connection).PassThrough:=false;
    • @JoshSterling 在设置PassThrough 时,您正在转换Connection 对象,而不是它的IOHandler 对象。您可以改用sslh.PassThrough。但是您不需要手动创建TIdSSLIOHandlerSocketOpenSSL 对象,因为如果您将TIdServerIOHandlerSSLOpenSSL 分配给服务器的IOHandler,服务器会为您执行此操作,只需对现有客户端IOHandler 进行类型转换,例如:sslh := TIdSSLIOHandlerSocketOpenSSL(AContext.Connection.IOHandler);
    • 如果 PassThrough 设置为 true,则上面的代码适用于 TIdServerIOHandlerSSLOpenSSL 中设置的证书,但 PassThrough 设置为 False 时它不允许连接,FF 表示无法验证接收到的数据的真实性。我觉得我只是不明白整个事情应该如何工作,但找不到任何快速证书切换的好例子
    • @JoshSterling 然后请更新您的问题以包含您遇到问题的实际代码
    • 完成。我也包括了你的代码。在 CommandOther 事件中,我的代理解密并修改流量
    猜你喜欢
    • 1970-01-01
    • 2020-10-06
    • 1970-01-01
    • 2015-12-21
    • 2022-01-17
    • 2020-08-16
    • 2022-11-27
    • 2011-09-03
    • 2019-06-22
    相关资源
    最近更新 更多