[2/3] Partially revert "vpnmain.cgi: Use new system methods"

Message ID 20210713153053.11281-2-michael.tremer@ipfire.org
State Accepted
Commit b71a7fb97dfa9bc041d6782a2b2cd0dd5e9cd66e
Headers
Series [1/3] ovpnmain.cgi: Join certificate output before &Header::cleanhtml(); |

Commit Message

Michael Tremer July 13, 2021, 3:30 p.m. UTC
  This reverts commit a81cbf61273536ee36f3d26504aabdcd65d39cca.

It was no longer possible to generate the root/host certificates.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
---
 html/cgi-bin/vpnmain.cgi | 52 +++++++++++++---------------------------
 1 file changed, 16 insertions(+), 36 deletions(-)
  

Patch

diff --git a/html/cgi-bin/vpnmain.cgi b/html/cgi-bin/vpnmain.cgi
index 8f13cf51f..80e93ffd3 100644
--- a/html/cgi-bin/vpnmain.cgi
+++ b/html/cgi-bin/vpnmain.cgi
@@ -226,13 +226,9 @@  sub newcleanssldatabase {
 ###
 sub callssl ($) {
 	my $opt = shift;
-
-	# Split the given argument string into single pieces and assign them to an array.
-	my @opts = split(/ /, $opt);
-
-	my @retssl = &General::system_output("/usr/bin/openssl", @opts); #redirect stderr
+	my $retssl = `/usr/bin/openssl $opt 2>&1`; #redirect stderr
 	my $ret = '';
-	foreach my $line (split (/\n/, @retssl)) {
+	foreach my $line (split (/\n/, $retssl)) {
 		&General::log("ipsec", "$line") if (0); # 1 for verbose logging
 		$ret .= '<br>'.$line if ( $line =~ /error|unknown/ );
 	}
@@ -246,21 +242,13 @@  sub callssl ($) {
 ###
 sub getCNfromcert ($) {
 	#&General::log("ipsec", "Extracting name from $_[0]...");
-	my @temp = &General::system_output("/usr/bin/openssl", "x509", "-text", "-in", "$_[0]");
-	my $temp;
-
-	foreach my $line (@temp) {
-		if ($line =~ /Subject:.*CN = (.*)[\n]/) {
-			$temp = $1;
-			$temp =~ s+/Email+, E+;
-			$temp =~ s/ ST = / S = /;
-			$temp =~ s/,//g;
-			$temp =~ s/\'//g;
-
-			last;
-		}
-	}
-
+	my $temp = `/usr/bin/openssl x509 -text -in $_[0]`;
+	$temp =~ /Subject:.*CN = (.*)[\n]/;
+	$temp = $1;
+	$temp =~ s+/Email+, E+;
+	$temp =~ s/ ST = / S = /;
+	$temp =~ s/,//g;
+	$temp =~ s/\'//g;
 	return $temp;
 }
 ###
@@ -268,19 +256,11 @@  sub getCNfromcert ($) {
 ###
 sub getsubjectfromcert ($) {
 	#&General::log("ipsec", "Extracting subject from $_[0]...");
-	my @temp = &General::system_output("/usr/bin/openssl", "x509", "-text", "-in", "$_[0]");
-	my $temp;
-
-	foreach my $line (@temp) {
-		if($line =~ /Subject: (.*)[\n]/) {
-			$temp = $1;
-			$temp =~ s+/Email+, E+;
-			$temp =~ s/ ST = / S = /;
-
-			last;
-		}
-	}
-
+	my $temp = `/usr/bin/openssl x509 -text -in $_[0]`;
+	$temp =~ /Subject: (.*)[\n]/;
+	$temp = $1;
+	$temp =~ s+/Email+, E+;
+	$temp =~ s/ ST = / S = /;
 	return $temp;
 }
 ###
@@ -689,8 +669,8 @@  END
 		$errormessage = $!;
 		goto UPLOADCA_ERROR;
 	}
-	my @temp = &General::system_output("/usr/bin/openssl", "x509", "-text", "-in", "$filename");
-	if (! grep(/CA:TRUE/, @temp)) {
+	my $temp = `/usr/bin/openssl x509 -text -in $filename`;
+	if ($temp !~ /CA:TRUE/i) {
 		$errormessage = $Lang::tr{'not a valid ca certificate'};
 		unlink ($filename);
 		goto UPLOADCA_ERROR;