From 44f5e1cd1bc6c784a0d0507af9546a9401c37000 Mon Sep 17 00:00:00 2001 From: Cyberboss Date: Wed, 8 Nov 2017 19:08:16 -0500 Subject: [PATCH 1/9] Adds signing to released binaries --- TGStationServer3.sln | 4 ++- Tools/DecryptSigningKey.ps1 | 59 ++++++++++++++++++++++++++++++++++ Tools/TGStationServer3.enc.snk | 1 + appveyor.yml | 3 ++ 4 files changed, 66 insertions(+), 1 deletion(-) create mode 100644 Tools/DecryptSigningKey.ps1 create mode 100644 Tools/TGStationServer3.enc.snk diff --git a/TGStationServer3.sln b/TGStationServer3.sln index fd74f4e3f9..f9e733d0a1 100644 --- a/TGStationServer3.sln +++ b/TGStationServer3.sln @@ -1,7 +1,7 @@  Microsoft Visual Studio Solution File, Format Version 12.00 # Visual Studio 15 -VisualStudioVersion = 15.0.26730.16 +VisualStudioVersion = 15.0.26430.6 MinimumVisualStudioVersion = 10.0.40219.1 Project("{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}") = "TGServerService", "TGServerService\TGServerService.csproj", "{F32EDA25-0855-411C-AF5E-F0D042917E2D}" EndProject @@ -76,11 +76,13 @@ Project("{2150E333-8FDC-42A3-9474-1A3956D46DE8}") = "Tools", "Tools", "{081BB0BB Tools\build_byond.sh = Tools\build_byond.sh Tools\Config.dm = Tools\Config.dm Tools\CoverageExclusions.runsettings = Tools\CoverageExclusions.runsettings + Tools\DecryptSigningKey.ps1 = Tools\DecryptSigningKey.ps1 Tools\DMAPITravisTester.dme = Tools\DMAPITravisTester.dme Tools\Doxyfile = Tools\Doxyfile Tools\install_byond.sh = Tools\install_byond.sh Tools\Test.dm = Tools\Test.dm Tools\TGS3Build.ps1 = Tools\TGS3Build.ps1 + Tools\TGStationServer3.enc.snk = Tools\TGStationServer3.enc.snk Tools\UploadCoverage.ps1 = Tools\UploadCoverage.ps1 EndProjectSection EndProject diff --git a/Tools/DecryptSigningKey.ps1 b/Tools/DecryptSigningKey.ps1 new file mode 100644 index 0000000000..5abd09e8a0 --- /dev/null +++ b/Tools/DecryptSigningKey.ps1 @@ -0,0 +1,59 @@ +if (-not (Test-Path env:snk_passphrase)) +{ + exit +} + +[Reflection.Assembly]::LoadWithPartialName("System.Security") + +function Decrypt-String($Encrypted, $Passphrase, $salt="SaltCrypto", $init="IV_Password") +{ + # If the value in the Encrypted is a string, convert it to Base64 + if($Encrypted -is [string]){ + $Encrypted = [Convert]::FromBase64String($Encrypted) + } + + # Create a COM Object for RijndaelManaged Cryptography + $r = new-Object System.Security.Cryptography.RijndaelManaged + # Convert the Passphrase to UTF8 Bytes + $pass = [Text.Encoding]::UTF8.GetBytes($Passphrase) + # Convert the Salt to UTF Bytes + $salt = [Text.Encoding]::UTF8.GetBytes($salt) + + # Create the Encryption Key using the passphrase, salt and SHA1 algorithm at 256 bits + $r.Key = (new-Object Security.Cryptography.PasswordDeriveBytes $pass, $salt, "SHA1", 5).GetBytes(32) #256/8 + # Create the Intersecting Vector Cryptology Hash with the init + $r.IV = (new-Object Security.Cryptography.SHA1Managed).ComputeHash( [Text.Encoding]::UTF8.GetBytes($init) )[0..15] + + + # Create a new Decryptor + $d = $r.CreateDecryptor() + # Create a New memory stream with the encrypted value. + $ms = new-Object IO.MemoryStream @(,$Encrypted) + # Read the new memory stream and read it in the cryptology stream + $cs = new-Object Security.Cryptography.CryptoStream $ms,$d,"Read" + # Read the new decrypted stream + $sr = new-Object IO.StreamReader $cs + # Return from the function the stream + Write-Output $sr.ReadToEnd() + # Stops the stream + $sr.Close() + # Stops the crypology stream + $cs.Close() + # Stops the memory stream + $ms.Close() + # Clears the RijndaelManaged Cryptology IV and Key + $r.Clear() +} + +$encrypted = [IO.File]::ReadAllText("$bf/Tools/TGStationServer3.enc.snk") + +$base64string = Decrypt-String $encrypted $Env:snk_passphrase "SNK-Encrypt" "IV-HashCompute" + +$rawstring = [System.Convert]::FromBase64String($base64string) +[IO.File]::WriteAllBytes("$bf/TGServiceInterface/TGStationServer3.snk", $rawstring) +[IO.File]::WriteAllBytes("$bf/TGServiceTests/TGStationServer3.snk", $rawstring) +[IO.File]::WriteAllBytes("$bf/TGInstallerWrapper/TGStationServer3.snk", $rawstring) +[IO.File]::WriteAllBytes("$bf/TGDreamDaemonBridge/TGStationServer3.snk", $rawstring) +[IO.File]::WriteAllBytes("$bf/TGCommandLine/TGStationServer3.snk", $rawstring) + +Add-Content "$bf/Version.cs" "[assembly: AssemblyKeyFile(`"TGStationServer3.snk`")]" \ No newline at end of file diff --git a/Tools/TGStationServer3.enc.snk b/Tools/TGStationServer3.enc.snk new file mode 100644 index 0000000000..d2883820d1 --- /dev/null +++ b/Tools/TGStationServer3.enc.snk @@ -0,0 +1 @@ +zBxk8Hcf2/FEdhnH7/XfeNzbdMXQ2lRwbP1cM7L4K2c6TrMuczuMWz/ohdIjYHD6CzPNBhfzIawIEB/Aer60Ek0OxRd1rcEXvNbwlmzsdcN/Nj6iGmMq5OhnW4vxm5opjZZqtF5ZsKyXsbrQzRkDfQiXUh40zDw7ysA6LwMEUkR8Ue03UaWghv+MdAu0sUmClC5uQ0E3yW+FwlrpEY4ouvfm4rerhv/qaa4N4tv0IXtZqrzXuTCyGjXRzs83PGyu+3LKu2/g3VOrKV6cK8+m50O21EFac/jvmw96s3V2L2p44Us45bgVhoan4atUXV5XRr2xwO+vK1dEd1tVTyTRVEScIdgHYj2w7MjMqpjPg2toh/++iZjVZ46saJzzDoc9x69RGiGmsyUi6ZioyhwhCX2e17SdLWgs1YtUtEPRggKPRoBbyqpMFMuxnSQEeeSOsOXl6WOSDfO0dfl0Gy+3wPKFEv/QIyrRdMfKvDVqs61lp/brkWP3siUEhZGLGHt/TFHMOeIYYGLpEBkpPgdPwdaOMbUPi/0RHpbrfs3EzgzQg7tVsxFA6qr0nzfvi5dxzkrK0GcVPJX/i1Xj55VWRyizmfo+Fcc4nHnftqOGzTpR610bcpP1Bwbe3lNhj81F4MTNWog4DJKKUbs3+b0WdTiad/iespuu91++W/EmFaxFmLJyZvo+2j9HeAe6nNkMGQIXXWzM5NeSlbD4LzStzE0PR9yz44Tx0zydLARc+Hfleo/tDX2qJ5Fqz+TaOfHKGC87AR7XUY0a67MfuHICBvqnsQpevj74UwyOdya1lR99Ace0da/nagigy0ikDnRAteNb0U1FxQCM3T/FEh0rvIb21tv095gzZIujkF26ThevVN3evW0+1wo23BiqGv6a0M22UftrKIwl2lcOHAIbXj1q8C1WoIb5uGK6jfI9rgyY2O+AkECsy0UhsSI/gL6tyMxuj0odFoQ1xddP18T5oS2oY1YGJFsf42ybQqivYsWQ58fzgwZc8+aLWFKfZq6cPfGASoBrouZLWEkZR5OcyL9Dh517jEQx90eBiskyEYQ= \ No newline at end of file diff --git a/appveyor.yml b/appveyor.yml index 60ea867874..5e9194c090 100644 --- a/appveyor.yml +++ b/appveyor.yml @@ -3,6 +3,8 @@ pull_requests: environment: repo_token: secure: lJNGAXwiB5HlWdthz3K4PetqpTG5IEAyRgKaiKxFMQ8HW8CcOjRtB97B05op7BsK + snk_passphrase: + secure: dsRGlNewYn/JoycPaMoxLCrb3wkL31RsdU7Xwbo7TIAmClwShCVWeRPN+eGA+fMZX12MDNRBs8Fws4IxqLKQ36thQo6p2B+kPksAUJiAOR5QKJoT6nt8JB1wBMFS2kH4 skip_branch_with_pr: true image: Visual Studio 2017 configuration: Release @@ -24,6 +26,7 @@ install: - choco install fciv doxygen.portable graphviz.portable opencover.portable codecov before_build: - nuget restore TGStationServer3.sln + - powershell -Command "Tools/DecryptSigningKey.ps1" build: project: TGStationServer3.sln parallel: true From e85be0bb5078fae3757be26ac948aad992d30973 Mon Sep 17 00:00:00 2001 From: Cyberboss Date: Wed, 8 Nov 2017 19:16:26 -0500 Subject: [PATCH 2/9] Adds missing $bf var to DecryptSigningKey.ps1 --- Tools/DecryptSigningKey.ps1 | 1 + 1 file changed, 1 insertion(+) diff --git a/Tools/DecryptSigningKey.ps1 b/Tools/DecryptSigningKey.ps1 index 5abd09e8a0..1984f8a0d2 100644 --- a/Tools/DecryptSigningKey.ps1 +++ b/Tools/DecryptSigningKey.ps1 @@ -44,6 +44,7 @@ function Decrypt-String($Encrypted, $Passphrase, $salt="SaltCrypto", $init="IV_P # Clears the RijndaelManaged Cryptology IV and Key $r.Clear() } +$bf = $Env:APPVEYOR_BUILD_FOLDER $encrypted = [IO.File]::ReadAllText("$bf/Tools/TGStationServer3.enc.snk") From 7a9451eb7611dbc018cc10880d789c0b4a86cc92 Mon Sep 17 00:00:00 2001 From: Cyberboss Date: Wed, 8 Nov 2017 19:20:58 -0500 Subject: [PATCH 3/9] Move extracted snk to the right location --- Tools/DecryptSigningKey.ps1 | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/Tools/DecryptSigningKey.ps1 b/Tools/DecryptSigningKey.ps1 index 1984f8a0d2..0854dee4cb 100644 --- a/Tools/DecryptSigningKey.ps1 +++ b/Tools/DecryptSigningKey.ps1 @@ -51,10 +51,6 @@ $encrypted = [IO.File]::ReadAllText("$bf/Tools/TGStationServer3.enc.snk") $base64string = Decrypt-String $encrypted $Env:snk_passphrase "SNK-Encrypt" "IV-HashCompute" $rawstring = [System.Convert]::FromBase64String($base64string) -[IO.File]::WriteAllBytes("$bf/TGServiceInterface/TGStationServer3.snk", $rawstring) -[IO.File]::WriteAllBytes("$bf/TGServiceTests/TGStationServer3.snk", $rawstring) -[IO.File]::WriteAllBytes("$bf/TGInstallerWrapper/TGStationServer3.snk", $rawstring) -[IO.File]::WriteAllBytes("$bf/TGDreamDaemonBridge/TGStationServer3.snk", $rawstring) -[IO.File]::WriteAllBytes("$bf/TGCommandLine/TGStationServer3.snk", $rawstring) +[IO.File]::WriteAllBytes("$bf/TGStationServer3.snk", $rawstring) Add-Content "$bf/Version.cs" "[assembly: AssemblyKeyFile(`"TGStationServer3.snk`")]" \ No newline at end of file From e66ac44b7e635112083f1488c7e48c504e3ce188 Mon Sep 17 00:00:00 2001 From: Cyberboss Date: Thu, 9 Nov 2017 12:45:20 -0500 Subject: [PATCH 4/9] Very WIP please force push --- TGCommandLine/Properties/AssemblyInfo.cs | 2 +- TGCommandLine/TGCommandLine.csproj | 7 +++++++ TGControlPanel/TGControlPanel.csproj | 7 +++++++ TGDreamDaemonBridge/TGDreamDaemonBridge.csproj | 7 +++++++ TGInstallerWrapper/TGInstallerWrapper.csproj | 7 +++++++ TGServerService/Properties/AssemblyInfo.cs | 2 +- TGServerService/TGServerService.csproj | 7 +++++++ TGServiceInterface/TGServiceInterface.csproj | 7 +++++++ TGServiceTests/TGServiceTests.csproj | 8 ++++++++ TGStationServer3.pfx | Bin 0 -> 1701 bytes TGStationServer3.sln | 1 - Tools/TGStationServer3.enc.snk | 1 - 12 files changed, 52 insertions(+), 4 deletions(-) create mode 100644 TGStationServer3.pfx delete mode 100644 Tools/TGStationServer3.enc.snk diff --git a/TGCommandLine/Properties/AssemblyInfo.cs b/TGCommandLine/Properties/AssemblyInfo.cs index 27af13774e..322a46bb38 100644 --- a/TGCommandLine/Properties/AssemblyInfo.cs +++ b/TGCommandLine/Properties/AssemblyInfo.cs @@ -17,4 +17,4 @@ using System.Runtime.InteropServices; [assembly: Guid("9ad1f086-a83e-4d14-a844-58a9471106b6")] //allow the unit tester to peek inside us -[assembly: InternalsVisibleTo("TGServiceTests", AllInternalsVisible = true)] +[assembly: InternalsVisibleTo("TGServiceTests, PublicKeyToken=<1521fb3fe76ed910>", AllInternalsVisible = true)] diff --git a/TGCommandLine/TGCommandLine.csproj b/TGCommandLine/TGCommandLine.csproj index 0c299ad037..415cb7db44 100644 --- a/TGCommandLine/TGCommandLine.csproj +++ b/TGCommandLine/TGCommandLine.csproj @@ -40,6 +40,12 @@ MinimumRecommendedRules.ruleset true + + true + + + ..\TGStationServer3.pfx + @@ -58,6 +64,7 @@ + diff --git a/TGControlPanel/TGControlPanel.csproj b/TGControlPanel/TGControlPanel.csproj index d1b390395f..cc3254c1bb 100644 --- a/TGControlPanel/TGControlPanel.csproj +++ b/TGControlPanel/TGControlPanel.csproj @@ -39,6 +39,12 @@ MinimumRecommendedRules.ruleset true + + true + + + ..\TGStationServer3.pfx + @@ -109,6 +115,7 @@ SettingsSingleFileGenerator Settings.Designer.cs + diff --git a/TGDreamDaemonBridge/TGDreamDaemonBridge.csproj b/TGDreamDaemonBridge/TGDreamDaemonBridge.csproj index 99acc47c27..4c25253e64 100644 --- a/TGDreamDaemonBridge/TGDreamDaemonBridge.csproj +++ b/TGDreamDaemonBridge/TGDreamDaemonBridge.csproj @@ -34,6 +34,12 @@ prompt MinimumRecommendedRules.ruleset + + true + + + ..\TGStationServer3.pfx + @@ -51,6 +57,7 @@ + diff --git a/TGInstallerWrapper/TGInstallerWrapper.csproj b/TGInstallerWrapper/TGInstallerWrapper.csproj index ffee3114b1..ca314a4891 100644 --- a/TGInstallerWrapper/TGInstallerWrapper.csproj +++ b/TGInstallerWrapper/TGInstallerWrapper.csproj @@ -42,6 +42,12 @@ MinimumRecommendedRules.ruleset true + + true + + + ..\TGStationServer3.pfx + ..\packages\Costura.Fody.1.6.2\lib\dotnet\Costura.dll @@ -80,6 +86,7 @@ + diff --git a/TGServerService/Properties/AssemblyInfo.cs b/TGServerService/Properties/AssemblyInfo.cs index 6df01aa814..da48afa5bb 100644 --- a/TGServerService/Properties/AssemblyInfo.cs +++ b/TGServerService/Properties/AssemblyInfo.cs @@ -17,4 +17,4 @@ using System.Runtime.InteropServices; [assembly: Guid("f32eda25-0855-411c-af5e-f0d042917e2d")] //allow the unit tester to peek inside us -[assembly: InternalsVisibleTo("TGServiceTests", AllInternalsVisible = true)] +[assembly: InternalsVisibleTo("TGServiceTests, PublicKeyToken=<1521fb3fe76ed910>", AllInternalsVisible = true)] diff --git a/TGServerService/TGServerService.csproj b/TGServerService/TGServerService.csproj index 375c542010..eeabedd68f 100644 --- a/TGServerService/TGServerService.csproj +++ b/TGServerService/TGServerService.csproj @@ -41,6 +41,12 @@ MinimumRecommendedRules.ruleset true + + true + + + ..\TGStationServer3.pfx + ..\packages\Discord.Net.Core.1.0.2\lib\net45\Discord.Net.Core.dll @@ -138,6 +144,7 @@ SettingsSingleFileGenerator Settings.Designer.cs + diff --git a/TGServiceInterface/TGServiceInterface.csproj b/TGServiceInterface/TGServiceInterface.csproj index 5e9befc3be..78858a76d8 100644 --- a/TGServiceInterface/TGServiceInterface.csproj +++ b/TGServiceInterface/TGServiceInterface.csproj @@ -36,6 +36,12 @@ MinimumRecommendedRules.ruleset false + + true + + + ..\TGStationServer3.pfx + @@ -71,6 +77,7 @@ + \ No newline at end of file diff --git a/TGServiceTests/TGServiceTests.csproj b/TGServiceTests/TGServiceTests.csproj index e8ad0a9acc..1a31210837 100644 --- a/TGServiceTests/TGServiceTests.csproj +++ b/TGServiceTests/TGServiceTests.csproj @@ -37,6 +37,12 @@ prompt 4 + + true + + + ..\TGStationServer3.pfx + ..\packages\Castle.Core.4.2.1\lib\net45\Castle.Core.dll @@ -70,9 +76,11 @@ + + diff --git a/TGStationServer3.pfx b/TGStationServer3.pfx new file mode 100644 index 0000000000000000000000000000000000000000..0d12863e897a237f9f87baa7dc34e054fe83d0e7 GIT binary patch literal 1701 zcmcIlX;4#F7`=Hf31Jh02nA&|LS=n{uqiE@tg=g>3K64hA{q!Fi);xRrL0Ai89|7n z2(q^Wi~F6gLO1ck6D^un~%&h%$HcfNPObMANE{oZosVqD@C1czc= zB7-Qd!*k+^q;X<6K9}f@=Mr5Y?SOI7+J7verFbq{1nEK;=ZTVks-z@v2%n48VqByW z+eVc5i-tGfgeN6G6b>C#aqdG9v0w3AyH+bv#`~T=N!rMpdkrg3^vZHsX?R9HZfr8uA+v**yFQQNA)JPc|JhaRBNAH^)soB-ws%a4|vGj*f z+q06zg*hLkf?NVFIoEx<(^@i9;#Vk^`P?EsOE0%jq%nb_5kb-xJTXP`=Z6{fbh5VR zgqpkeyiQV?aH?48V1ULo8RLzcP&1yO>N zVdDWmrAd-?yAZ1vxksaC;%*3VnfLsJ^yxHysGG!)!SN$mPJu@n`G$EP@<~e4##+oy zxyq7d#UPa-r#1wJJQ?9uNQJjwzBM+Nl){Mf z@gI0a2@15xV~xz=o7q?WTN2|;Lfh1;b&Gc7M5J=Fl6Noaj7whfFtl1+wD0eDl(VAO zZtk6FkJMB0ZR1TQjeX8sv}!I%u4W!%y-Z}HwT@jek*i^pZYxz8A4@*NK)dXj`D#!% z!I`nYFS7mtEg{GHw34Z^%W7^hGV1XtC8Z~|QeCDsH)>(xN6SV%4)_)6PcwAAe$#jvs4#w;?pOEt z*j7;(N$gd>u%K1BofN!mm{p)2#!d*Zd-F6`F14^^aOHM*2sYGkSC96sxbV16g;_OM ztwwXAh+!C-@}Zm2v2uC8)3;T2ea$fzOiH+YMQHOq_Me zVw*R9Z}BZuA|8(e0AT)qlk!w|RabBdP=PV91Gc~d4im5k=mQ%#*04UH0dp8sn3)4J zIMZNe1{`1=6;{|mr7gr5FoL>d40=tMh{NN!W@H@IQ`H@~furCEU;`G2h7kf{fI8R* zuWQT+5DJkU%o9K)ne5Nxn6e?q970q*wBG_8{My&8R0<7B||y^M(mf4 zMd6|wB%L?>Dz305uz&&+$Wt*c?h+qGa0nv1dBJ^>W-WWo?HP{uJ~Uqglit__CrJR9 zAC->nBcgOX`X9e7RYhs48I_7zU>MEZ#N+^k=IhXO9sYkCb4tH_MjQd4oNRz`G7t_2 z+~V(^oOcdqdS&-Z*_g_$8j9XV@$Gva1Tb8#HlE|upzMy{9lx?2`=#9e(5)_0>-h#m zJ87Fr8)36+3_)jjDY4Ua>H9k&mKrCdJmQ7R`0*P}VUiatgAbnRjJk-jO{2HxpQdYx zx9fe=_PKd5&nZ!&<->w?P0ADBG&QfY_!$Jn0o<4E!B2p~zD^oW^5!m2MF=Vucwf z?l{7YFrq8%r*8RoKkdfUFfk%QcN2;zf7m{L2ZX38JzYJ2~kN;f*PmrlaV>os*o Xl3cW$h>^C1Nvw48J649u+JW&02E$(` literal 0 HcmV?d00001 diff --git a/TGStationServer3.sln b/TGStationServer3.sln index f9e733d0a1..b39a6dd329 100644 --- a/TGStationServer3.sln +++ b/TGStationServer3.sln @@ -82,7 +82,6 @@ Project("{2150E333-8FDC-42A3-9474-1A3956D46DE8}") = "Tools", "Tools", "{081BB0BB Tools\install_byond.sh = Tools\install_byond.sh Tools\Test.dm = Tools\Test.dm Tools\TGS3Build.ps1 = Tools\TGS3Build.ps1 - Tools\TGStationServer3.enc.snk = Tools\TGStationServer3.enc.snk Tools\UploadCoverage.ps1 = Tools\UploadCoverage.ps1 EndProjectSection EndProject diff --git a/Tools/TGStationServer3.enc.snk b/Tools/TGStationServer3.enc.snk deleted file mode 100644 index d2883820d1..0000000000 --- a/Tools/TGStationServer3.enc.snk +++ /dev/null @@ -1 +0,0 @@ -zBxk8Hcf2/FEdhnH7/XfeNzbdMXQ2lRwbP1cM7L4K2c6TrMuczuMWz/ohdIjYHD6CzPNBhfzIawIEB/Aer60Ek0OxRd1rcEXvNbwlmzsdcN/Nj6iGmMq5OhnW4vxm5opjZZqtF5ZsKyXsbrQzRkDfQiXUh40zDw7ysA6LwMEUkR8Ue03UaWghv+MdAu0sUmClC5uQ0E3yW+FwlrpEY4ouvfm4rerhv/qaa4N4tv0IXtZqrzXuTCyGjXRzs83PGyu+3LKu2/g3VOrKV6cK8+m50O21EFac/jvmw96s3V2L2p44Us45bgVhoan4atUXV5XRr2xwO+vK1dEd1tVTyTRVEScIdgHYj2w7MjMqpjPg2toh/++iZjVZ46saJzzDoc9x69RGiGmsyUi6ZioyhwhCX2e17SdLWgs1YtUtEPRggKPRoBbyqpMFMuxnSQEeeSOsOXl6WOSDfO0dfl0Gy+3wPKFEv/QIyrRdMfKvDVqs61lp/brkWP3siUEhZGLGHt/TFHMOeIYYGLpEBkpPgdPwdaOMbUPi/0RHpbrfs3EzgzQg7tVsxFA6qr0nzfvi5dxzkrK0GcVPJX/i1Xj55VWRyizmfo+Fcc4nHnftqOGzTpR610bcpP1Bwbe3lNhj81F4MTNWog4DJKKUbs3+b0WdTiad/iespuu91++W/EmFaxFmLJyZvo+2j9HeAe6nNkMGQIXXWzM5NeSlbD4LzStzE0PR9yz44Tx0zydLARc+Hfleo/tDX2qJ5Fqz+TaOfHKGC87AR7XUY0a67MfuHICBvqnsQpevj74UwyOdya1lR99Ace0da/nagigy0ikDnRAteNb0U1FxQCM3T/FEh0rvIb21tv095gzZIujkF26ThevVN3evW0+1wo23BiqGv6a0M22UftrKIwl2lcOHAIbXj1q8C1WoIb5uGK6jfI9rgyY2O+AkECsy0UhsSI/gL6tyMxuj0odFoQ1xddP18T5oS2oY1YGJFsf42ybQqivYsWQ58fzgwZc8+aLWFKfZq6cPfGASoBrouZLWEkZR5OcyL9Dh517jEQx90eBiskyEYQ= \ No newline at end of file From aec5dec77b13be1923319a1bf4aae138a9113ec5 Mon Sep 17 00:00:00 2001 From: Cyberboss Date: Thu, 9 Nov 2017 14:09:42 -0500 Subject: [PATCH 5/9] Add missing .pfx to .sln --- TGStationServer3.sln | 1 + 1 file changed, 1 insertion(+) diff --git a/TGStationServer3.sln b/TGStationServer3.sln index 60dab517a9..2fbfc66cc7 100644 --- a/TGStationServer3.sln +++ b/TGStationServer3.sln @@ -82,6 +82,7 @@ Project("{2150E333-8FDC-42A3-9474-1A3956D46DE8}") = "Tools", "Tools", "{081BB0BB Tools\install_byond.sh = Tools\install_byond.sh Tools\Test.dm = Tools\Test.dm Tools\TGS3Build.ps1 = Tools\TGS3Build.ps1 + Tools\TGStationServer3.pfx = Tools\TGStationServer3.pfx Tools\UploadCoverage.ps1 = Tools\UploadCoverage.ps1 EndProjectSection EndProject From 22c541fccec49398b16c4a174c1f733263e058bf Mon Sep 17 00:00:00 2001 From: Cyberboss Date: Thu, 9 Nov 2017 15:16:13 -0500 Subject: [PATCH 6/9] Fix decrypt script --- Tools/DecryptSigningKey.ps1 | 58 ++++++++----------------------------- 1 file changed, 12 insertions(+), 46 deletions(-) diff --git a/Tools/DecryptSigningKey.ps1 b/Tools/DecryptSigningKey.ps1 index c702383cf5..512b5973c1 100644 --- a/Tools/DecryptSigningKey.ps1 +++ b/Tools/DecryptSigningKey.ps1 @@ -3,54 +3,20 @@ if (-not (Test-Path env:snk_passphrase)) exit } -[Reflection.Assembly]::LoadWithPartialName("System.Security") - -function Decrypt-String($Encrypted, $Passphrase, $salt="SaltCrypto", $init="IV_Password") -{ - # If the value in the Encrypted is a string, convert it to Base64 - if($Encrypted -is [string]){ - $Encrypted = [Convert]::FromBase64String($Encrypted) - } - - # Create a COM Object for RijndaelManaged Cryptography - $r = new-Object System.Security.Cryptography.RijndaelManaged - # Convert the Passphrase to UTF8 Bytes - $pass = [Text.Encoding]::UTF8.GetBytes($Passphrase) - # Convert the Salt to UTF Bytes - $salt = [Text.Encoding]::UTF8.GetBytes($salt) - - # Create the Encryption Key using the passphrase, salt and SHA1 algorithm at 256 bits - $r.Key = (new-Object Security.Cryptography.PasswordDeriveBytes $pass, $salt, "SHA1", 5).GetBytes(32) #256/8 - # Create the Intersecting Vector Cryptology Hash with the init - $r.IV = (new-Object Security.Cryptography.SHA1Managed).ComputeHash( [Text.Encoding]::UTF8.GetBytes($init) )[0..15] - - - # Create a new Decryptor - $d = $r.CreateDecryptor() - # Create a New memory stream with the encrypted value. - $ms = new-Object IO.MemoryStream @(,$Encrypted) - # Read the new memory stream and read it in the cryptology stream - $cs = new-Object Security.Cryptography.CryptoStream $ms,$d,"Read" - # Read the new decrypted stream - $sr = new-Object IO.StreamReader $cs - # Return from the function the stream - Write-Output $sr.ReadToEnd() - # Stops the stream - $sr.Close() - # Stops the crypology stream - $cs.Close() - # Stops the memory stream - $ms.Close() - # Clears the RijndaelManaged Cryptology IV and Key - $r.Clear() -} $bf = $Env:APPVEYOR_BUILD_FOLDER -$encrypted = [IO.File]::ReadAllText("$bf/Tools/TGStationServer3.enc.snk") +$flags = [System.Security.Cryptography.X509Certificates.X509KeyStorageFlags]::Exportable -bor [System.Security.Cryptography.X509Certificates.X509KeyStorageFlags]::PersistKeySet -$base64string = Decrypt-String $encrypted $Env:snk_passphrase "SNK-Encrypt" "IV-HashCompute" +$cert = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2 -ArgumentList "$bf/Tools/TGStationServer3.pfx", $env:snk_passphrase, $flags -$rawstring = [System.Convert]::FromBase64String($base64string) -[IO.File]::WriteAllBytes("$bf/TGStationServer3.snk", $rawstring) +$provider = [System.Security.Cryptography.RSACryptoServiceProvider]$cert.PrivateKey; -Add-Content "$bf/AssemblyInfo.global.cs" "[assembly: AssemblyKeyFile(`"TGStationServer3.snk`")]" \ No newline at end of file +$rawstring = $provider.ExportCspBlob($true) + +[System.IO.File]::WriteAllBytes("$bf/Tools/TGStationServer3.snk", $rawstring); + +&'C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.6.1 Tools\sn.exe' -i "$bf/Tools/TGStationServer3.snk" TGStationServer3 + +Remove-Item "$bf/Tools/TGStationServer3.snk" + +$env:snk_passphrase = "" From 2c4087f2c45e1eebfa7cd07497c25cc7a964170a Mon Sep 17 00:00:00 2001 From: Cyberboss Date: Thu, 9 Nov 2017 15:30:53 -0500 Subject: [PATCH 7/9] Strong name the discord DLLs ourselves --- TGServerService/TGServerService.csproj | 8 +++---- Tools/DecryptSigningKey.ps1 | 32 +++++++++++++++++++++++++- 2 files changed, 35 insertions(+), 5 deletions(-) diff --git a/TGServerService/TGServerService.csproj b/TGServerService/TGServerService.csproj index 70fba689ec..8f4b5939f6 100644 --- a/TGServerService/TGServerService.csproj +++ b/TGServerService/TGServerService.csproj @@ -31,7 +31,7 @@ bin\Release\ - TRACE;NO_STRONG_NAME + TRACE bin\x86\Release\TGServerService.xml true true @@ -45,13 +45,13 @@ false - + ..\packages\Discord.Net.Core.1.0.2\lib\net45\Discord.Net.Core.dll - + ..\packages\Discord.Net.Rest.1.0.2\lib\net45\Discord.Net.Rest.dll - + ..\packages\Discord.Net.WebSocket.1.0.2\lib\net45\Discord.Net.WebSocket.dll diff --git a/Tools/DecryptSigningKey.ps1 b/Tools/DecryptSigningKey.ps1 index 512b5973c1..4abf107b1e 100644 --- a/Tools/DecryptSigningKey.ps1 +++ b/Tools/DecryptSigningKey.ps1 @@ -9,6 +9,8 @@ $flags = [System.Security.Cryptography.X509Certificates.X509KeyStorageFlags]::Ex $cert = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2 -ArgumentList "$bf/Tools/TGStationServer3.pfx", $env:snk_passphrase, $flags +$env:snk_passphrase = "" + $provider = [System.Security.Cryptography.RSACryptoServiceProvider]$cert.PrivateKey; $rawstring = $provider.ExportCspBlob($true) @@ -17,6 +19,34 @@ $rawstring = $provider.ExportCspBlob($true) &'C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.6.1 Tools\sn.exe' -i "$bf/Tools/TGStationServer3.snk" TGStationServer3 +#sign the discord binaries while we're here + +function ReplaceTextInFile +{ + param($text, $replacement, $file) + (Get-Content -Raw "$file").replace($text, $replacement) | Set-Content "$file" +} + +function SignDLL +{ + param($path, $depends) + + &'C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.6.1 Tools\ildasm.exe' "$path" /OUTPUT="$path.il" > $null + + foreach ($dep in $depends) { + $ILPKTokStr = "`r`n .publickeytoken = (15 21 FB 3F E7 6E D9 10 )" + ReplaceTextInFile ".assembly extern $dep`r`n{" ".assembly extern $dep`r`n{$ILPKTokStr" "$path.il" + } + + &'C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe' "$path.il" /DLL /OUTPUT="$path" /KEY="$bf/Tools/TGStationServer3.snk" > $null + Write-Host "Signed $path" +} + +SignDLL "$bf/packages/Discord.Net.Core.1.0.2/lib/net45/Discord.Net.Core.dll" @() +SignDLL "$bf/packages/Discord.Net.Rest.1.0.2/lib/net45/Discord.Net.Rest.dll" @("Discord.Net.Core") +SignDLL "$bf/packages/Discord.Net.WebSocket.1.0.2/lib/net45/Discord.Net.WebSocket.dll" @("Discord.Net.Core", "Discord.Net.Rest") + Remove-Item "$bf/Tools/TGStationServer3.snk" -$env:snk_passphrase = "" +#Replace bad references with our PKTok 1521fb3fe76ed910 +ReplaceTextInFile 'PublicKeyToken=null' 'PublicKeyToken=1521fb3fe76ed910' "$bf/TGServerService/TGServerService.csproj" From 24cbb686da3bcc400d3c683cacf669bb2c441ece Mon Sep 17 00:00:00 2001 From: Cyberboss Date: Thu, 9 Nov 2017 16:46:05 -0500 Subject: [PATCH 8/9] Modify AssemblyInfo.global.cs to enable signing --- AssemblyInfo.global.cs | 9 ++------- Tools/DecryptSigningKey.ps1 | 4 ++++ 2 files changed, 6 insertions(+), 7 deletions(-) diff --git a/AssemblyInfo.global.cs b/AssemblyInfo.global.cs index 1285d90759..6b2553d945 100644 --- a/AssemblyInfo.global.cs +++ b/AssemblyInfo.global.cs @@ -1,15 +1,10 @@ using System.Reflection; using System.Runtime.CompilerServices; -#if !DEBUG && !NO_STRONG_NAME -[assembly: InternalsVisibleTo("TGServiceTests, PublicKey=0024000004800000940000000602000000240000525341310004000001000100f10487511f8056df7ead40f8f3bb0a7a4890d1bafdbf3d2cc0092655849223733672039671c3855e653c950b68b6a9dd04fbe0784f0c6e213c66be8afa4cc37afad52a05744c1305bf1d1c7c2702b4f64036c5b96045a7ccdc421847eec17203ad8188b5a34a5d5cd3c845a071ebf72fff1236410cce8d51616a49f6e53ba0b9")] -[assembly: AssemblyKeyName("TGStationServer3")] -#else -[assembly: InternalsVisibleTo("TGServiceTests")] -#endif - //You cannot one definition the version number //Believe me, I've tried, the compiler hates it so much [assembly: AssemblyVersion("3.2.0.0")] [assembly: AssemblyFileVersion("3.2.0.0")] [assembly: AssemblyInformationalVersion("3.2.0.0")] + +[assembly: InternalsVisibleTo("TGServiceTests")] diff --git a/Tools/DecryptSigningKey.ps1 b/Tools/DecryptSigningKey.ps1 index 4abf107b1e..e92dedb2af 100644 --- a/Tools/DecryptSigningKey.ps1 +++ b/Tools/DecryptSigningKey.ps1 @@ -50,3 +50,7 @@ Remove-Item "$bf/Tools/TGStationServer3.snk" #Replace bad references with our PKTok 1521fb3fe76ed910 ReplaceTextInFile 'PublicKeyToken=null' 'PublicKeyToken=1521fb3fe76ed910' "$bf/TGServerService/TGServerService.csproj" + +#OK all good, modify AssemblyInfo.global.cs to enable strong naming +ReplaceTextInFile 'TGServiceTests' 'TGServiceTests, PublicKey=0024000004800000940000000602000000240000525341310004000001000100f10487511f8056df7ead40f8f3bb0a7a4890d1bafdbf3d2cc0092655849223733672039671c3855e653c950b68b6a9dd04fbe0784f0c6e213c66be8afa4cc37afad52a05744c1305bf1d1c7c2702b4f64036c5b96045a7ccdc421847eec17203ad8188b5a34a5d5cd3c845a071ebf72fff1236410cce8d51616a49f6e53ba0b9' "$bf/AssemblyInfo.global.cs" +Add-Content "$bf/AssemblyInfo.global.cs" "#if !NO_STRONG_NAME`n[assembly: AssemblyKeyName(`"TGStationServer3`")]`n#endif" From 114f13dd98fdc7678ffa05cc983b6ee72d174410 Mon Sep 17 00:00:00 2001 From: Cyberboss Date: Fri, 10 Nov 2017 12:48:24 -0500 Subject: [PATCH 9/9] Switch to digital signatures --- .../TGDreamDaemonBridge.csproj | 2 +- TGServiceInstaller/TGServiceInstaller.wixproj | 6 ++ TGStationServer3.sln | 5 +- Tools/DecryptSigningKey.ps1 | 56 ------------------ Tools/SignBasics.ps1 | 17 ++++++ Tools/SignMSI.ps1 | 13 ++++ Tools/TGS3Build.ps1 | 17 ++++++ Tools/TGStationServer3.pfx | Bin 1701 -> 0 bytes Tools/tgstation13.org.pfx | Bin 0 -> 2669 bytes appveyor.yml | 1 - 10 files changed, 57 insertions(+), 60 deletions(-) delete mode 100644 Tools/DecryptSigningKey.ps1 create mode 100644 Tools/SignBasics.ps1 create mode 100644 Tools/SignMSI.ps1 delete mode 100644 Tools/TGStationServer3.pfx create mode 100644 Tools/tgstation13.org.pfx diff --git a/TGDreamDaemonBridge/TGDreamDaemonBridge.csproj b/TGDreamDaemonBridge/TGDreamDaemonBridge.csproj index 799714d21a..0cb0c67596 100644 --- a/TGDreamDaemonBridge/TGDreamDaemonBridge.csproj +++ b/TGDreamDaemonBridge/TGDreamDaemonBridge.csproj @@ -27,7 +27,7 @@ bin\x86\Release\ - TRACE;NO_STRONG_NAME + TRACE true pdbonly x86 diff --git a/TGServiceInstaller/TGServiceInstaller.wixproj b/TGServiceInstaller/TGServiceInstaller.wixproj index dbe628e0fd..47751a1102 100644 --- a/TGServiceInstaller/TGServiceInstaller.wixproj +++ b/TGServiceInstaller/TGServiceInstaller.wixproj @@ -70,6 +70,12 @@ + + + + + powershell -Command $(SolutionDir)/Tools/SignMSI.ps1 +