26 lines
1.3 KiB
C#
26 lines
1.3 KiB
C#
|
|
using System.Net;
|
||
|
|
using System.Security.Cryptography;
|
||
|
|
using System.Security.Cryptography.X509Certificates;
|
||
|
|
|
||
|
|
namespace MusicBridge.Agent.Network;
|
||
|
|
|
||
|
|
internal static class AgentCertificate
|
||
|
|
{
|
||
|
|
public static X509Certificate2 Create()
|
||
|
|
{
|
||
|
|
using var key = RSA.Create(2048);
|
||
|
|
var request = new CertificateRequest("CN=MusicBridge Agent", key, HashAlgorithmName.SHA256, RSASignaturePadding.Pkcs1);
|
||
|
|
request.CertificateExtensions.Add(new X509BasicConstraintsExtension(false, false, 0, true));
|
||
|
|
request.CertificateExtensions.Add(new X509KeyUsageExtension(X509KeyUsageFlags.DigitalSignature | X509KeyUsageFlags.KeyEncipherment, true));
|
||
|
|
request.CertificateExtensions.Add(new X509EnhancedKeyUsageExtension(
|
||
|
|
new OidCollection { new("1.3.6.1.5.5.7.3.1") }, false));
|
||
|
|
var names = new SubjectAlternativeNameBuilder();
|
||
|
|
names.AddDnsName("localhost");
|
||
|
|
names.AddIpAddress(IPAddress.Loopback);
|
||
|
|
request.CertificateExtensions.Add(names.Build());
|
||
|
|
using var certificate = request.CreateSelfSigned(DateTimeOffset.UtcNow.AddMinutes(-5), DateTimeOffset.UtcNow.AddYears(5));
|
||
|
|
// Reload so Schannel can use the private key independently of the RSA object.
|
||
|
|
return X509CertificateLoader.LoadPkcs12(certificate.Export(X509ContentType.Pfx), null, X509KeyStorageFlags.Exportable);
|
||
|
|
}
|
||
|
|
}
|