diff --git a/Dockerfile b/Dockerfile index 7f5997e..cb6487b 100644 --- a/Dockerfile +++ b/Dockerfile @@ -9,10 +9,9 @@ RUN curl --fail https://getcaddy.com > /get-caddy.sh RUN bash /get-caddy.sh personal http.forwardproxy COPY gen_caddyfile_and_start.sh /bin/ -COPY stunnel.sh /stunnel.sh VOLUME /root/.caddy -EXPOSE 80 443 2015 +EXPOSE 2018 ENTRYPOINT /bin/gen_caddyfile_and_start.sh diff --git a/build.sh b/build.sh index 2b24dd1..3e957e6 100644 --- a/build.sh +++ b/build.sh @@ -7,6 +7,8 @@ docker build -t caddsies . docker run --rm -it \ -p 2018:2018 \ -v $(pwd)/caddyfile:/etc/caddy/Caddyfile \ - -v $(pwd)/caddsiesserver.crt:/etc/server.crt \ - -v $(pwd)/caddsiesserver.key:/etc/server.key \ + -v $(pwd)/stunfile:/etc/stunfile.conf \ + -v $(pwd)/stunserver.crt:/etc/stunserver.crt \ + -v $(pwd)/stunserver.key:/etc/stunserver.key \ + -v $(pwd)/stunclient.crt:/etc/stunclient.crt \ caddsies:latest diff --git a/caddsiesserver.crt b/caddsiesserver.crt deleted file mode 100644 index ae536ad..0000000 --- a/caddsiesserver.crt +++ /dev/null @@ -1,30 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIFJDCCAwygAwIBAgIJANHKGxC2/tm1MA0GCSqGSIb3DQEBCwUAMD4xCzAJBgNV -BAYTAlVTMQswCQYDVQQIDAJVVDEOMAwGA1UECgwFYnJlZWwxEjAQBgNVBAMMCWxv -Y2FsaG9zdDAeFw0xODEwMDYwMDQyMzZaFw0xOTEwMDYwMDQyMzZaMD4xCzAJBgNV -BAYTAlVTMQswCQYDVQQIDAJVVDEOMAwGA1UECgwFYnJlZWwxEjAQBgNVBAMMCWxv -Y2FsaG9zdDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAJ+VuXBzQ8gQ -HUFQd5N515zCpX31537gDofncJ/RtDCwYyL1e+P6iPyWVM5q6XZshUijB0snCiGg -D4Mu6FhqBLd3UiuFk73UlGR4N3K2iBmr8yUW1/M4vP+PpPhnwFQRUG0Su4Zk3DeC -A0NRHqB1scfzAkpiIsMTGB9FDfW9TUS2vq9uaCJyU4U7qn8HuLBpmA4iZtiT4Uqe -1JaWZK43r51J6rMTJ+nQ1gsus4+t25zMPwUxgy2YB5Lk8lJps/Gbk6bWgiu+OyOc -IML6emgdRjvxt26zjp3JoJX0tEaIxHD0m5X7HYkf7OVzXEOm7EXGIdslkpDWnrsU -b1XcdN0JtH7rzsWUPgl9/6CTRjQb1cqfNcvEeV7TBvogb+JkPg5AUpK+Cg60uBUA -9kjrd+aJqUMp3EcUa4viKKzFd8c7fARC7ZiVzUwXYAkMQj440y4F4ULiOOLB/TS5 -HBMNgu3lgiXOJvd0Yu0qY0x2QX3BekGX3/AtLUdlpsa2LXdSsK0nI/XE9eGlzVys -m8cCU5lfZ3ABO/5qTatMvtMmn9fHOrRBeayuWbKM4eFheAFMuAAXTgD37xeoX0Di -hQaa3FbQUNzXR+FcKUIpeA9h6d7tar8ij4v5E4rgo3HMQjUChKFETbHx0V21Lxdu -tF0ZUAocifoNHO2LnzXZjahbou2ZYat5AgMBAAGjJTAjMCEGA1UdEQQaMBiCCWxv -Y2FsaG9zdIILKi5sb2NhbGhvc3QwDQYJKoZIhvcNAQELBQADggIBAF8LJCBo691x -CM4o7XXWACWj3mlkQTsDRSQ+7ryyedoEAUylJi5musK2Iq+H0ZFmrm3qwT9yOreW -6JvCLhQMZic8xAiLtaqbjSQD0+XJTa9g+q0sY3mpgy/gBqMz8o8Qi36a8TFGFuD0 -PvRGbqbX/rgT/PRkhW1i/AAxJOjOWwqBR2XLUha79XBhOgJErPB92sq9g764ODS8 -LIfxMsXMIseGHRsXVyBDCvvv6ymPc1HLCkF5h+mPxh36Xr12psptp7C5WehOJZzG -UvOMM4A9ZfL5ReWI/fddVsyUVWgeI9cQPNzlt6M0ShqUw+exwlx3B/0kyrQrVgXz -jfEfLkHzqbM9OGGQPLyfeK7m6VmW36Z3VyUVWdgwLzzbtYugBYxYS045Dk7u5FHq -aTfxuwJ9Nk5WlJejr3r+zFjOID5p7Qg3TSOQGZeUDJqU7nYMBvstCdNX1QrtPgVM -QItARCe/ausmR2PcQnYyy7wvNiipeZBeUnbsJIzQuA5EVv/iqexyNzHNPWk7bmX0 -zFdsOfsicqHT9zhGPi24WqsLfCpwSa2X//GhvpvEgg2RdG7JjWG/GN/75hd1kuiY -HA3n98lTdSdnwdo/Yd8qui+3Chz0n5WsQx23ZRBbk8T2VgfqCy5enKtT8PrQdzb0 -2qUEpEesfS6D5mh639hLkgtnZ8Aw2BK3 ------END CERTIFICATE----- diff --git a/caddsiesserver.key b/caddsiesserver.key deleted file mode 100644 index 8a26aec..0000000 --- a/caddsiesserver.key +++ /dev/null @@ -1,51 +0,0 @@ ------BEGIN RSA PRIVATE KEY----- -MIIJKAIBAAKCAgEAn5W5cHNDyBAdQVB3k3nXnMKlffXnfuAOh+dwn9G0MLBjIvV7 -4/qI/JZUzmrpdmyFSKMHSycKIaAPgy7oWGoEt3dSK4WTvdSUZHg3craIGavzJRbX -8zi8/4+k+GfAVBFQbRK7hmTcN4IDQ1EeoHWxx/MCSmIiwxMYH0UN9b1NRLa+r25o -InJThTuqfwe4sGmYDiJm2JPhSp7UlpZkrjevnUnqsxMn6dDWCy6zj63bnMw/BTGD -LZgHkuTyUmmz8ZuTptaCK747I5wgwvp6aB1GO/G3brOOncmglfS0RojEcPSblfsd -iR/s5XNcQ6bsRcYh2yWSkNaeuxRvVdx03Qm0fuvOxZQ+CX3/oJNGNBvVyp81y8R5 -XtMG+iBv4mQ+DkBSkr4KDrS4FQD2SOt35ompQyncRxRri+IorMV3xzt8BELtmJXN -TBdgCQxCPjjTLgXhQuI44sH9NLkcEw2C7eWCJc4m93Ri7SpjTHZBfcF6QZff8C0t -R2WmxrYtd1KwrScj9cT14aXNXKybxwJTmV9ncAE7/mpNq0y+0yaf18c6tEF5rK5Z -sozh4WF4AUy4ABdOAPfvF6hfQOKFBprcVtBQ3NdH4VwpQil4D2Hp3u1qvyKPi/kT -iuCjccxCNQKEoURNsfHRXbUvF260XRlQChyJ+g0c7YufNdmNqFui7Zlhq3kCAwEA -AQKCAgAJe2X3ToH6gyqZ1OQl+RlckRwwLcpBeaKjZJcGh/lC41ggnaFs3FgDWhNT -6HpStQP+WuF2D63EbbQ+QS1BA5ugIxDY0SkEIHtotNPmlv3jOJpL292c8AQa0zgk -IlYFKLo0oOZPh/Klwa3b9BfzxMp5bPD35njWSm4mfX3k2gibSpht6At78HsR8Yeh -4J2SrdOBE3405CSAwIs1H16AE4L1v4yYc0zt0aDGLVIx+UyRNnmQH28B6ISar8vO -JcWxV2MgiKJXYwg0h3RS4XsgcIzZxvT1OOoCahaGknGbt0ikxYPxF2ib2y/COmaD -BooHY0xjrwnUXUw1JXOwEFdJQuhcgjUzYaJC21PDwoMPRUhXXEKPD1phtizVysxj -aEi2PUK1bf5onc7ZQL6ErQ/bEeaPImjTtw0Tm1WWKiWPeXZgLH4jrlyaVjoVq3Xs -7SW0cGm1Tl+K+1lMfQ/I88jh6plFMsGUm/bAhXIUjmo/1mxqbdpvJToLGl1PxFp6 -zO4/0uZPSXc1oAaI2Ye/1jflcibw56TfQEkkWIiGfl27Ywy7+17zs9izFGtby+AG -WhtAAmUFQdudNCzelX3y5edf4iAnqOnbPZaWEE2++F0f1nMlByI56Y7z0jIUdFkf -27hOcZhXz/7+N8tlk7b/nBZA4dzJmtIgVhMw6lcTty6zC78q4QKCAQEAy7JikpJ+ -Lok3hDTmXhYSjyEt1cw2We9J1M8GYa0yATX6l6m1tHmcvqUNL2GhF6prcb34qcMt -VhJ0+WHzAqJmlj4KmI5YMcTy0V6GaEYywqmBSqVKoNl8ayIPoNTv+DXuhdvZokSk -NKLumwFmomoBE+9Pp5xgVRAdBQDBX+pZATOXEWiBaqDW1TKb6u9jv7eNpZmf4jWU -pjhBheBtdEfpYvD4gX9Y44vYP76fVWqAcgPjKJvxLhQD11wigT0ntIGm/tXRJf0U -DCWMz2bwgKie7Nqv64hS4jTUuCKzACOdXHDTg1aRgO44Yhjg3mlpq85/dnLaHHn3 -pXRJtH7EFaTSLQKCAQEAyI+5uzfOQ1M7jA4pj33vPyhAtzoKEEN5nz2TQUarNGYu -IJoHd2dsUhxIhCvTduKBZt0U90s8M+nw0C3qYCx5lzu0nNlmoM/RoAcP1rBgwr93 -bfi/hCD4LqpVPG+Odluc6wUTufeYwgndwhV5CG54YOiKdGUYvTNAhtIKy2RSwgCH -vT/cI8Jbf82IUN4eFbwK8rlzn93uTl+2pdxbrYh8PBbmN98F1RdvWG7ylxUVj6iL -iqH4moCz4bUHFajL3u395PfnfOwrjs5I1+3QmxuRy0DSVlRMj7qRnIAA97fIvoZk -IPuBu3HTJH/rAAFBG0oK++zLPGxxQBCOfwLhsd/p/QKCAQEAsyVR+CKKgxb/EnEL -4dd7vxGpJA0UCAihYF4q+KDAB7yXhecl/XGvXyP98pvkd9HT6RbwqS0UpExbQDDa -7ogxvRUXcJBQFIVoIKcHgpGqdvVo1mOEvO5JtFcic4qS+jNEccmnIEVKPVjGjOCw -iUq9Y/Dmlzy6pFUlkI7Xgymx2ZKr3A2TNFn8V0jJQ9gCXExscSYpLWN+NqnnRnzZ -BplwMypHBG0hmg4VxAo8S3z9Nkkg8Ugk1yeXMULAvfUxBFm6qwkVhlmL1hr4OjgI -cL7b9udmLLmaW4OnScKKtyabcP9xpmLuWPwp7mx+6FzBKO7VvzDHjp/eI0+guvN6 -NKbeiQKCAQBuYAKkEOM30/+KZWTj7jeTd3CeJZfSOYAebcGzg9PGo5ExKfN/9+/6 -BEy4SHI5FBCI7pSSP9pi65U2zH4W7YMBAr+0LkS3rYc83YYO7cRiiQKOB/5GFerf -q6f6+Z3abzKdeI7Ronx0FP/wxuZ0CG/BTVidE+IYhbM2PzPnmU+eKrKJKTLajyTR -4efqMUM3TORtjjgevAFhKnWXM/1UNC/C1gtepiNMkXgan/xrvxO9mtEou1jYlono -Zjr+5YVFK461yuSfsE2MauRVyTArnHGQ/RyEnCICW3e1PBDMQ1171PQX3rIX2V2M -0cUfnJEbFpWS7U8v8rIkwrfZGFnjDUp1AoIBAD7jX9JlSG7C+u7Itjm+BsSGdKeM -u2P6z7b7jvMs762O4XY9QBXetYFveOfAK/Q7G/9aiM2BHZZB8TJ41Fwr4nu9su1M -k6Sc4QLOXHgm1YWonT6sFXOvlscUcMwIEPJHlOgSn6GblkHMc2FlEwl5LbRxD81/ -UbDNf3Fz/PYTALUW8H2uvju5h1Af11IEbKbi2/qChRL3+FW7y70YB8mxhZVgYqvV -9P8wqr8wEnM9oizVPQSipeHBEWg8ept0n4mK3hqVE9WalLJxiSONYqWw4v6TSS/k -1M9rhV5qh0QrEMdG5m0PoGkRrNmtKHJjnOhi8ZC3IcVj155XZIyAdD14a4Q= ------END RSA PRIVATE KEY----- diff --git a/gen_caddyfile_and_start.sh b/gen_caddyfile_and_start.sh index e7bc860..a8a5e67 100755 --- a/gen_caddyfile_and_start.sh +++ b/gen_caddyfile_and_start.sh @@ -29,7 +29,7 @@ else generate_caddyfile fi -bash /stunnel.sh & +stunnel /etc/stunfile.conf > /stun-access.log 2>&1 & $(which caddy) ${CADDY_OPTS} -conf ${CADDYFILE} & pid=$! diff --git a/stunclient.crt b/stunclient.crt new file mode 100644 index 0000000..71607ee --- /dev/null +++ b/stunclient.crt @@ -0,0 +1,29 @@ +-----BEGIN CERTIFICATE----- +MIIE8DCCAtgCAQEwDQYJKoZIhvcNAQELBQAwPjELMAkGA1UEBhMCVVMxCzAJBgNV +BAgMAlVUMQ4wDAYDVQQKDAVicmVlbDESMBAGA1UEAwwJbG9jYWxob3N0MB4XDTE4 +MTAwNjEzMzcxNVoXDTE5MTAwNjEzMzcxNVowPjELMAkGA1UEBhMCVVMxCzAJBgNV +BAgMAlVUMQ4wDAYDVQQKDAVicmVlbDESMBAGA1UEAwwJbG9jYWxob3N0MIICIjAN +BgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAqhUozwLoKbxwG3mu3jbfUrQr3/ko +8L6Bm61gBbeBTuKjbMyJS6MYcWvMlR7h+4VfPRSIdMfKZqaWYjF8QVRJKMO3I1od +3ULN8gx/KImwdMR2s8JXCBhLR1gO35uxPSO/3QUyaXz7QL8tx7uCxTJp8C7eJ+Ry +f8uJICVaIB4WeLfjrTCQ2BJuIhOrlORjnww5uN92ESYjigkaT5yKWTjeJUA6CM8U +P1i4PaZweNEXY92NjiHwpeMTPB/GAU4B0myxNCgl0E9MccKedqPdKbm+WaXpp7mt +m3LmA0PGRiAmmutVKc4I0A/MqOYtxWZvAfw2LmQTEcoa+OWvcFPFV4a1uI05Quzj +pRNCLMtsAYNs10EInI0aiLzr2yguPTwT8sKQtOLL/zKXjlDSkCD/oHUg8bW/Gynl +1QP/GovInEP8502I3QBoROTLrkQxLqxIHTXRxoVtKMDsipphqdFnFKi9YdG7NRyJ +uBz9v3YfumF1FeOFW0MnqDitI5pC3wBavHRVpX8vbrVG24NJS77bgh0gs+P0gEL7 +zM6H2f8wKQ9UKlRk0/Rr1usf1ehz3GCa9vpiLGB+l0kQYgSZJ2KfmuCBxuUlWZzh +d4pGhV7Dn2fkjO/lgNAdLfs9ctZJaoJ2O4amqQ7TktJ/odKkPqGICqcnkVECXl/t +x+a0BqxTJfH2wjMCAwEAATANBgkqhkiG9w0BAQsFAAOCAgEAl/jF5eTVUYxZzzMq +5LxAkblPiqQGYUFfYXh3NCM2GcwFrplnRYlKYgiQvUktHUuZ/Lf6tcGrxNkvRoIf +GoosCQF4ookWg77lCuNSb6vFAnqDE6QKIGDUqZuAuLpDMhxiwmNWNexc2gZrH7Es +z/ToQxfdB/iBgVqjSD9bRT8/vBcPijpdrrLT6ZwzVelA4EzXRjVz54LdapQOOJBi +5G8Vo3LeoZ5YQGRTxdXMN7JJOxpnP4s8dW7EEZRaCcKONpS6Ec6RR8HNKYn0QRAQ +lT17mwFWlMuTCdnfuhTzQMXhQcFiIrxY6JkCBUSpFUUOKllXnhkkDO9V7yOQSpMN +IxwPFQdILnHAuSKWW2WOja/7CFiwbWxVvknfv+4WTEiHTRzpNbjZt+MUpz5vTGwg +/tVK3DOp+IqunYPHbgnLPdbb4rme7IYM89QWNNrn88FtFq9L3kX4rc+uiBvlryhV +gXXL8masfwI7VztXCT3d40amfWP5iTxjqhsX3jnnzg6t9wdfGc/fF9dAR0CUNRys +hisbqTpdFaL/gGAxnxPKRxW1P13O5xFcmUV+SQJ+Db/c7INhmC0QZNrLNoT/L8AN +Zv1jfH6ZKwIqg+zmTSLi0IM+RQz35ASyF3n54dXieKSr3zwU5vSH+owCwgGcpkAU +5qjcCGHD+Wqj7jSA8Hs4cDoKSuQ= +-----END CERTIFICATE----- diff --git a/stunclient.key b/stunclient.key new file mode 100644 index 0000000..79c2a54 --- /dev/null +++ b/stunclient.key @@ -0,0 +1,51 @@ +-----BEGIN RSA PRIVATE KEY----- +MIIJKQIBAAKCAgEAqhUozwLoKbxwG3mu3jbfUrQr3/ko8L6Bm61gBbeBTuKjbMyJ +S6MYcWvMlR7h+4VfPRSIdMfKZqaWYjF8QVRJKMO3I1od3ULN8gx/KImwdMR2s8JX +CBhLR1gO35uxPSO/3QUyaXz7QL8tx7uCxTJp8C7eJ+Ryf8uJICVaIB4WeLfjrTCQ +2BJuIhOrlORjnww5uN92ESYjigkaT5yKWTjeJUA6CM8UP1i4PaZweNEXY92NjiHw +peMTPB/GAU4B0myxNCgl0E9MccKedqPdKbm+WaXpp7mtm3LmA0PGRiAmmutVKc4I +0A/MqOYtxWZvAfw2LmQTEcoa+OWvcFPFV4a1uI05QuzjpRNCLMtsAYNs10EInI0a +iLzr2yguPTwT8sKQtOLL/zKXjlDSkCD/oHUg8bW/Gynl1QP/GovInEP8502I3QBo +ROTLrkQxLqxIHTXRxoVtKMDsipphqdFnFKi9YdG7NRyJuBz9v3YfumF1FeOFW0Mn +qDitI5pC3wBavHRVpX8vbrVG24NJS77bgh0gs+P0gEL7zM6H2f8wKQ9UKlRk0/Rr +1usf1ehz3GCa9vpiLGB+l0kQYgSZJ2KfmuCBxuUlWZzhd4pGhV7Dn2fkjO/lgNAd +Lfs9ctZJaoJ2O4amqQ7TktJ/odKkPqGICqcnkVECXl/tx+a0BqxTJfH2wjMCAwEA +AQKCAgEAhEyFO9GFCcH8akLS1SNVv51Ka6QCRpHJe3D3OjstqFD+0kifm2g4QTGb +J3uoSN/L31Uzd7NZK1P1slfP0Xlglwb2U9drV4r5a4hw+PVxfsK7msRWsoNDOzGy +EBmpWmeOfLvoJMoFHq4XTD/9TqsSYLP0No+qyOFnvsuPOWBuFmTkAvm+EXT0mik2 +1FB7dWIrHDUmP9ys1FiUUMzxiMmFcvBstCFwHH5EgiAPaMssKJBT5fVcnYzuj1wf +xzAIlsfZZzq7fzfPvMWoQZzhEe3btRwrjj4OXtaXOH7lofKsVOEtk6EilcVUayTx +AZXWT3MCKj/J3ZKaPHVdbECdRqIQg0MmzBlb6cX9qPPgyP2mIpsJ0asxbQvXKUvv +8pbUpfzQyvIhGY/c6o/5NtNrT+C9z7BOmCMI7p5o6MD6dlRxrBOHRlH8hOlnpA/F +/Z+eENp4ViRW4wJGtLo0Lvia9GHeH5M/cGPK6IwQ3GOQRhIMzkoFoHmaTBeNyAr6 +LMwH+wNaWNu0iJm7ocFAAcI+CgyA7ZQdsvVM/gsjcPD49SHRtjCBNIEN0eTwSRWG +q39gKaZWNDbAVgJb4/F+uqhNJ9X03MWm1qar4NLBJRrske+hyknTG1+B5FGup4m2 +MtEQkcj/+38OihddZkjGdTeQTRiVuqWurdzP0hI6rDIHAGnNWcECggEBANDdiaD6 +W1myBwCwg+fVLkIX9XqGuITXwKD7IJ/s9VHt45vRLvBDBz8yEnInYwlrTXMcMKek +pFG1Fgay2iYhaHSdgm1nOyi77L1yexvUsPxGu3zRKeEwC8NiFttITaM7Zq3C9GB/ +L2a5OG2TC3pvTFUAUEFzx0zRe7xdGOD1QOiRqeYA75w/zQ11UqaugtJnRyr2iyl6 +pJn2yru3Y2nRl8pz9kRGDFoIBGcAFJuR3iIhaa8h10FrR1iBUmOEgITHXBlmRRNL +hxsTmp5jaVSC19Nq/OjnHLvCN/BO4ZL/KhHsE0/4GXc5Kayn/3TIbk5kJlIp3woy +dHRQbAjqartU7OMCggEBANB3FhFoVUumOoi/YhiouQyylHeCcmVaktBuU2x6up95 +pnJq+KtkshIj6CGht49gMGCTJTw8V0bqekLNL+NX+4/lXl1G4uqrvreTjq+yqiP7 +1D4gUpdVdCOORFOV+rYmsB5M0kT35suIaNchyBHndtLoGZqSVa2mICojFLPLxVlr +o4GSgjMrdPXVkJwzAHbZy22UIhmI7x39x9eBDrWdnA8cgAfbNpI/RPJ5OpZYQ+ON +fY7rk1pIpErB+A2o7/BWzTXEn2wOFSkTMz7V9RzvOLGWj5SqvoBWdFsMLcOHFVhR +GuhgjirRVUvgPECEQAMOv5highG9Dx7NjSLixz3VpnECggEBAKbi7M4oXIdtvTSq +1aqO5rg+xpERRiw27B50qdu/DUFacAwXd4bYN9kh3CVEHVjwWOEJ/EJnRjhXFfNi +QvZGqVzMYeOioV1p0r6I058oMgZRSgtwYSMiLbP/Ez5BJm+vzdo3NOZJmYldo53B +6WD5vycH6hhyNyPFGjYmuPM+Y4+wm+1AgDP7so73WIQAWl1d0jqc5hLNgOnYjKKy +5IcvxjYos/RXeBUT5Nib8ttfEPt6cSRTSNhnrIkmQ7tqqvntBUTyN200Yw6aemfm +DMpPBb5S9SPvTkEj7WhgztKSeX36gG/cUBS4Ivlm/rHEWIbgdNIfzKwsJmqtu7Tg +AUoPkHsCggEAMPqp3rEqyTlnK1X8EFskD02uAF5Pzmx3bi1dwHEdg/arGtrzTiG8 +jPKOycgbPr6U3zvzVbG/t9PDogpfpAS6AFcd0sCi9AwiJTOwJKvPueCjP22Mui3D +uc7lUtY8L6vrWVMnXDj6qvuD1ngDb+F4U5lg2qZjJwePKxdO9+d6mMXnhrwLh0ZA +lrn03h5Fj6cgWsChOmqn8936pDGYaSd80TgbBL2Gltnysx20nDpkyQQnafsDhgTn +RQFJ7LuylD9wu59U7ahpZFs0gSD4FDJImcEMPxvW4oRtli7IWdZVN4jmz45QGNNS +PR+USHxKJe3DKmSKtuw6rzwQWw/5TBf0oQKCAQBnQAhqqYFoGj+jznDIyULJtYmU +KH21n6bsMcDfqRdyE2mNdmgM8NIb1YbGYQ+Qz8jYy8jZTNew056dceh6xC58CRuO +dlz65TeIXFRGlhvaBbj4SQxqke5FRcfCCjgyW6dwFf/aiN0GVkGmyWjvs2bYMh4k +xeVmW4vmXPwZ2HsHp/4zk1tgwjDj4KfjjpeXCgEUdJ/miNSogAKxfHirpoBJUx+n +47vTYVPJjjMRP4hlYStlu0yu0zVK/kebZIGQJWhfvRcy3wsTopw2P1JWOJB7PTh3 +n1Af7nkZpjSIax4/GK3oiTghowKkAjwd5/aVqBHNUdnbzazIpshMKE/HrjEd +-----END RSA PRIVATE KEY----- diff --git a/stunfile b/stunfile new file mode 100644 index 0000000..6d20aff --- /dev/null +++ b/stunfile @@ -0,0 +1,17 @@ +; requireCert = yes +; verifyChain = yes +; CAfile = path +; cert = path +; client = no + +; verify = [0-4] 0=ignore, 1=verify if given, 2=verify, 3=verify with locally installed, 4=verify without CA chain + +foreground=yes +output=/stun-access.log +cert=/etc/stunserver.crt +key=/etc/stunserver.key +CAfile=/etc/stunclient.crt +verify=4 +[default] +accept=2018 +connect=2015 diff --git a/stunnel.sh b/stunnel.sh deleted file mode 100644 index ca6bc56..0000000 --- a/stunnel.sh +++ /dev/null @@ -1,19 +0,0 @@ -#! /bin/bash - -# requireCert = yes -# verifyChain = yes | no -# CAfile = path -# cert = path -#client=no - -config=' -foreground=yes -cert=/etc/server.crt -key=/etc/server.key -[default] -accept=2018 -connect=2015 -' -echo "$config" > /stunnel.conf - -stunnel /stunnel.conf -p $(find / -name "*.pem" | tr '\n' ',') diff --git a/stunserver.crt b/stunserver.crt new file mode 100644 index 0000000..604761b --- /dev/null +++ b/stunserver.crt @@ -0,0 +1,30 @@ +-----BEGIN CERTIFICATE----- +MIIFJDCCAwygAwIBAgIJANz/YWAPwd8IMA0GCSqGSIb3DQEBCwUAMD4xCzAJBgNV +BAYTAlVTMQswCQYDVQQIDAJVVDEOMAwGA1UECgwFYnJlZWwxEjAQBgNVBAMMCWxv +Y2FsaG9zdDAeFw0xODEwMDYxMzM3MTNaFw0xOTEwMDYxMzM3MTNaMD4xCzAJBgNV +BAYTAlVTMQswCQYDVQQIDAJVVDEOMAwGA1UECgwFYnJlZWwxEjAQBgNVBAMMCWxv +Y2FsaG9zdDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAKmCQBsCr4hH +qIMTP0mPO2OhBdbMNDIeszAZMsgpX0YPffXFfd3y2RmdXmU/vtMt89XJGmhegypv +zqV4eg6p2A3zUMADUaL1htDNUuy9U0GkJleNRzjukLNJy2Yd4A9PbqEbmHrnQk0S +MetI/ZDNwDK8YDWuZGzehOTgYTrcas88eiJiGevLibUOOufTCQ+GHiLVk3fx1Rrg +cotuRDTmSb2WT98q/KSlFG7kTR789CzbLTPjuhHDP7X2gcN4h+0DjwOGEkk4JqRr +WZzw6g8TewDCBD18laP0PRf7CPNsgDJCSloispFY5rx+Y5iqxX8HkTpwL6lTJAY8 +zFwYbDV5zugzibL+gvyCqSG/kMXVdj/0Ijq68mNArKSkUvd5m4U9pKu1uXacU4G1 +9cug2PYBPC1LJzORP4wC1C94qZIX2ILq9cE+ZwEmSMCUi6O9bKGNNkFNf98GsU34 +ge+4WUjlAzwuptPECMgLguzDufU6zS2q38/e6s5dhoeoSnj+WeBbmlcxIT5AEYFD +dB+LMTbtzYYafH4F08r5R7w1Yy8ctVQfgTDB2aEzzvKnFXFLSDFN8pc7tXiicriV +AhfQuRh2q5jQQS0B0T/umd4iXpeTixr7Jg7RLZgoRMabgBTa1bIT13GAEivzsRD7 +EferrXD/A6OoMnOMPtI9tLxVHIXSNwhDAgMBAAGjJTAjMCEGA1UdEQQaMBiCCWxv +Y2FsaG9zdIILKi5sb2NhbGhvc3QwDQYJKoZIhvcNAQELBQADggIBADbJ5oncsMOh +hTIjko4UzgLpNk336uTw4N1XmbIqFvKyx+oAj/EYli3Z9vW/tG4AMz6PkmueKTEj +M81Gyld/NfqNC3Ek3fiIGwQdvruA3NP+lENxZr99oeGBxF5nAWexm0xV6HxRa1z8 +GSH++DgQ4riIAf/DMfCKSUkrA151PR/zXzS7C6RuhnXz4L8QhnBBiGhkxjsekrnb +cHVIlGdYB6aajt5j/prkWYDHh5IxicREPyEy/X5tnssoUQG46ne9CFL6ihbcnIrJ +vmo/HVR2wG9ZT0qhCBeIp9FZmrHakhEFVMwJzrw1m8Z7yW+42tkuHgkNJEDXQjW0 +Jj5dPkMKnZVBiH/+YOGCEGJ1IoVBJHTfboFsyUdu1/CFLE5wTm7c7iKvx5Fz6qi6 +3lC1k7RW2QvM566e6CVIXBaJ7SHFyLVZs5BaojXkr41jFKP7A3oK99K6raYz7O5O +ID3S7IDmd8sfGRDCtLSWOIm7rzh5b54sXfiJqmU1e86yV4bXGPm3aTM9ot7AoBgL +ExKLoViIdsbfX7wrRVbkPB7Qb2HNvwUHXbcBWrIn6eDAYz9FFXDVp8AWPG53lSTf +CniQNLE2YcQLx3pyE68Nyf2OWfRQ7g+HNmt0YOEZoOq7sDoKOjTn71Dds1IwjvMo +yPBcQ4qpztUt4R0Ei5Cg1e6WQK+4plST +-----END CERTIFICATE----- diff --git a/stunserver.key b/stunserver.key new file mode 100644 index 0000000..9838d58 --- /dev/null +++ b/stunserver.key @@ -0,0 +1,51 @@ +-----BEGIN RSA PRIVATE KEY----- +MIIJKQIBAAKCAgEAqYJAGwKviEeogxM/SY87Y6EF1sw0Mh6zMBkyyClfRg999cV9 +3fLZGZ1eZT++0y3z1ckaaF6DKm/OpXh6DqnYDfNQwANRovWG0M1S7L1TQaQmV41H +OO6Qs0nLZh3gD09uoRuYeudCTRIx60j9kM3AMrxgNa5kbN6E5OBhOtxqzzx6ImIZ +68uJtQ4659MJD4YeItWTd/HVGuByi25ENOZJvZZP3yr8pKUUbuRNHvz0LNstM+O6 +EcM/tfaBw3iH7QOPA4YSSTgmpGtZnPDqDxN7AMIEPXyVo/Q9F/sI82yAMkJKWiKy +kVjmvH5jmKrFfweROnAvqVMkBjzMXBhsNXnO6DOJsv6C/IKpIb+QxdV2P/QiOrry +Y0CspKRS93mbhT2kq7W5dpxTgbX1y6DY9gE8LUsnM5E/jALUL3ipkhfYgur1wT5n +ASZIwJSLo71soY02QU1/3waxTfiB77hZSOUDPC6m08QIyAuC7MO59TrNLarfz97q +zl2Gh6hKeP5Z4FuaVzEhPkARgUN0H4sxNu3Nhhp8fgXTyvlHvDVjLxy1VB+BMMHZ +oTPO8qcVcUtIMU3ylzu1eKJyuJUCF9C5GHarmNBBLQHRP+6Z3iJel5OLGvsmDtEt +mChExpuAFNrVshPXcYASK/OxEPsR96utcP8Do6gyc4w+0j20vFUchdI3CEMCAwEA +AQKCAgBMx2+sDGJf0z1z6aLv+c3HyebwLVyzGw7FCZTj70F1ZY0DZuolP1uw64QX +TnFsDFN3EXlBrxWwgiZS8yguPiZb40s/PgGbU6U2LNqT2wm8INMxMxAArKakXxef +cIbNyIfut6YwfVGdwVEVJuGb1mZpVMQrbIuWeJAvb6b6114V8mnL6y2cjXwZo5Fw +8jkXbAN4ec8rNEH3w5R+rXp9j5X1JwGUr07ycMe5lvWLxL4BF2H5L/xXEV5pWHfc +h1riM4ty6CaePa3bKbjUipcqLwO3CyqKg0Twl6+Yjh+2yv2iRj6RZ0gE6ATTelg4 +jZmZeV8B3lDoXH1jyeQzDujsq/jYncYPbwZmrJTx14W6fx6Oz5CvEIpYEJf8KOJ0 +69DGmFR7AUHOhYMPDsoVdhjtN+HA8o/vmPjwxMn8zNI1cMmu0iwm6Q1QrurYI4X0 +xANCn7kX2lZ8qZJ0muUfFSaSfyH1AYdc4xTnwF0NApkNWJfczv1yfRCo8CEe2p7z +9OlTY0rj6+dm7PDifx3qMBwz9Fm0fBLPzX7q13HkEBgpUSNPk1WQuILI/yyqJ52B +OCAw4CMLsgq1DWUzrS7WvaWbRzsmh2xDW8nL9yq3G2kmHT+5f3aulJuBOHqqpX5D +Iy9/Gryfg1aVHkBG3COsjTWTa5M3hkxXWkxJ1wKF8Tbnj7eLiQKCAQEA1MTLxcDA +S6YTSb8oUhKrWOlzCcU7GBma3wu8ncvF+gO/f7gwaprvDBvsKT59WFlM2QqfVC00 +YuqsFEK4GhUAFI2/zN/iIYOJVKnLM1uQ9+jDHPx9csHUOi5gUW6ZwRyVvZQzqGas +VmiQccYBRsFIivRKHqAZWFchdvfFgDK+wnz/KfQU8FAsmPSaQPqMaRe1yK7otUhb +4Dj/YDOX1qYefwBBI2aBQ23PkfVw6yaVoPX8yLLSHE05nEpELWGkT9XWEUN2kUDm +Q+X9/QV/n3+rIRvkan1YZdvXKY4Uv3emoYc2NjBKepBfbmfcu8iutyoaltCVzY9+ +az0Me3WrDtpnbQKCAQEAy/NH2gJxT/Jmba57PkShRhUh0YD5zj9UCDG7dKWHmJld +g4kKutO96d+hqrjyBnkN9br4+ZXKLZQswiBFerkE6a5OjEBUeeDPz766FrI0hxfN +5XcZysp8dzC6fkO6kcYjDXjrGO+NWcTlC9Tj49uN/7UlDkSISjxwSyCb0BGWESOy +pBXPMpdCeDejUWtzy4qF9Sveh1xIx2IQ2vquCcOxTh5UfeqCalvLx9CYG3kWuiOK +pkjUsgXJDCJ2Ma84OcleylDmiN+N297CgSfa9ADBDXZeftoTjbOiY6o6HaxQBYru +pgKunGVfipcTMZ+tGV7Bnm+JviLTb5DRPEsHhAbwbwKCAQEAxaZK5Vk5SQztvgQl +oJhXNDEo/FqLmseuZqSwgqVZM/dnXW3tDBsBFW6a43V5WykZikWj3L5he8IkOG4C +N7hqaq2DDv6rQha+7DcO3JajBKjlF3g10PTeAW4za3IiwpGbSJDzq+w1C8/23rnh +VakXin2EnQ58fOPz4mAox/5b1q/nGUH0cYkI5M3UvagB515vMA3LfxvIvXI1SVik +JHIMwk2qNQhz6/+GY0BttQQS24OnX4k+Raw3aEhVLRMXYFJ0mXTiH+z5+vkcCH+j +HreqcQdIGOR3yad/KMsj2vl7gXHpmk0h4tlazWUOWCMEqoIiURdTEbHK7jO39LhK +P3IDwQKCAQEAiPb8TeBOEI6NUyNWCN82H0aZy4R+PpAw8r/TT+bKRSTZtDgYSJdi +dumEPI6vmsE5KslB4vtBJ5LW7BeYEW6nafdxMKcTFDZx2OYROqS6ue62i1+Mpq+N +Hs5Or/T0GmmhqK6H09ssZhjgaS2zTZZoqk0QcaB8lr43+3wOp5Dn4uLCWYd7+lGy +heF3gHpU7WA9zgSEEQtcpOmqwCSRNGWDcR7VRypyItM66xmezPRo2uB7gGhwzo0s +E0YhcgRmEgi169CgwVLAheP3Y51MYYkQHOZdV3tEnmkAqUXseXj61H4U/s/WS5mY +rA4BCdZd/Sexh6EIM/RXYhkzKvaIOZYfaQKCAQBXi8MwbqMWN/MFWUOP8nlHCd3Y +ilgIXFRPafDlUvGNc465zD1nd276xoZNJibgY5oQdKqXb3c44Sl5xdpeeqNtnBMC +Ze5LIkMkw4PYqNfa3BE+Y3CI86e7/n2fo+aglWf3ZLBqtpnhCassUMBmIyG3DtbT +tDRWvcpe4vo3wMKJnOcu7rXIeIlEIAvoP1XX5bKGbQR1rDeoyOqTw+yk30XgzvXB +KfP1XTf1Za0SR1JClgHgDY2CbGHkU8Zyv1WoC/mET5ci64UDT04SZMUhBtNyX/su +HTM5Syg+I7XFZg+GYCH43NkEnm/GsUDHu+Y4J+4+vj9BF4B5spydilGdaTT/ +-----END RSA PRIVATE KEY----- diff --git a/test.sh b/test.sh index 3a2459a..70ea0dc 100644 --- a/test.sh +++ b/test.sh @@ -1 +1,7 @@ -curl -v -U breel:ok -x localhost:2015 http://google.com | head -n 2 +curl \ + --proxy-cacert ./stunserver.crt \ + --proxy-key ./stunclient.key \ + --proxy-cert ./stunclient.crt \ + -U breel:ok \ + -x https://localhost:2018 \ + https://blapointe.me