2026-02-08 04:28:13 -05:00
|
|
|
const path = require("path");
|
|
|
|
|
const fs = require("fs");
|
2026-02-27 22:04:57 -05:00
|
|
|
const { MITM_DIR } = require("../paths");
|
2026-02-08 04:28:13 -05:00
|
|
|
|
2026-03-04 23:25:03 -05:00
|
|
|
// Wildcard domains — covers all subdomains without needing cert update per tool
|
|
|
|
|
const WILDCARD_DOMAINS = [
|
|
|
|
|
"*.googleapis.com",
|
|
|
|
|
"*.githubcopilot.com",
|
|
|
|
|
"*.individual.githubcopilot.com",
|
|
|
|
|
"*.business.githubcopilot.com"
|
|
|
|
|
];
|
2026-02-08 04:28:13 -05:00
|
|
|
|
|
|
|
|
/**
|
2026-03-04 23:25:03 -05:00
|
|
|
* Generate self-signed SSL certificate with wildcard SAN.
|
|
|
|
|
* Covers all current and future MITM tool domains automatically.
|
|
|
|
|
* Uses selfsigned (pure JS, no openssl needed).
|
2026-02-08 04:28:13 -05:00
|
|
|
*/
|
|
|
|
|
async function generateCert() {
|
2026-02-27 22:04:57 -05:00
|
|
|
const certDir = MITM_DIR;
|
2026-02-08 04:28:13 -05:00
|
|
|
const keyPath = path.join(certDir, "server.key");
|
|
|
|
|
const certPath = path.join(certDir, "server.crt");
|
|
|
|
|
|
|
|
|
|
if (fs.existsSync(keyPath) && fs.existsSync(certPath)) {
|
|
|
|
|
console.log("✅ SSL certificate already exists");
|
|
|
|
|
return { key: keyPath, cert: certPath };
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if (!fs.existsSync(certDir)) {
|
|
|
|
|
fs.mkdirSync(certDir, { recursive: true });
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
const selfsigned = require("selfsigned");
|
2026-03-04 23:25:03 -05:00
|
|
|
const attrs = [{ name: "commonName", value: "9router-mitm" }];
|
2026-02-08 04:28:13 -05:00
|
|
|
const notAfter = new Date();
|
|
|
|
|
notAfter.setFullYear(notAfter.getFullYear() + 1);
|
|
|
|
|
const pems = await selfsigned.generate(attrs, {
|
|
|
|
|
keySize: 2048,
|
|
|
|
|
algorithm: "sha256",
|
|
|
|
|
notAfterDate: notAfter,
|
|
|
|
|
extensions: [
|
2026-03-04 23:25:03 -05:00
|
|
|
{
|
|
|
|
|
name: "subjectAltName",
|
|
|
|
|
altNames: WILDCARD_DOMAINS.map(domain => ({ type: 2, value: domain }))
|
|
|
|
|
}
|
2026-02-08 04:28:13 -05:00
|
|
|
]
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
fs.writeFileSync(keyPath, pems.private);
|
|
|
|
|
fs.writeFileSync(certPath, pems.cert);
|
|
|
|
|
|
2026-03-04 23:25:03 -05:00
|
|
|
console.log(`✅ Generated wildcard SSL certificate: ${WILDCARD_DOMAINS.join(", ")}`);
|
2026-02-08 04:28:13 -05:00
|
|
|
return { key: keyPath, cert: certPath };
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
module.exports = { generateCert };
|