upload snippets

This commit is contained in:
Evert Prants 2022-11-26 19:02:05 +00:00
parent 75bf2d468d
commit 3665663802
5 changed files with 785 additions and 0 deletions

ca.sh Normal file
View File

@ -0,0 +1,616 @@
# Source: https://jamielinux.com/docs/openssl-certificate-authority/index.html
if [ -z "$1" ]; then
echo "=x=> Path for your CA root is required!"
exit 1
CA_ROOT=$(realpath "$1")
# Intermediate directory
# Static config blanks
read -r -d '' OPENSSL_CA_CFG << EOM
# OpenSSL root CA configuration file.
# Auto-generated.
[ ca ]
# \`man ca\`
default_ca = CA_default
[ CA_default ]
# Directory and file locations.
dir = $CA_ROOT
certs = \$dir/certs
crl_dir = \$dir/crl
new_certs_dir = \$dir/newcerts
database = \$dir/index.txt
serial = \$dir/serial
RANDFILE = \$dir/private/.rand
# The root key and root certificate.
private_key = \$dir/private/ca.key.pem
certificate = \$dir/certs/ca.cert.pem
# For certificate revocation lists.
crlnumber = \$dir/crlnumber
crl = \$dir/crl/ca.crl.pem
crl_extensions = crl_ext
default_crl_days = 30
# SHA-1 is deprecated, so use SHA-2 instead.
default_md = sha256
name_opt = ca_default
cert_opt = ca_default
default_days = 375
preserve = no
policy = policy_strict
[ policy_strict ]
# The root CA should only sign intermediate certificates that match.
# See the POLICY FORMAT section of \`man ca\`.
countryName = match
stateOrProvinceName = match
organizationName = match
organizationalUnitName = optional
commonName = supplied
emailAddress = optional
[ policy_loose ]
# Allow the intermediate CA to sign a more diverse range of certificates.
# See the POLICY FORMAT section of the \`ca\` man page.
countryName = optional
stateOrProvinceName = optional
localityName = optional
organizationName = optional
organizationalUnitName = optional
commonName = supplied
emailAddress = optional
[ req ]
# Options for the \`req\` tool (\`man req\`).
default_bits = 4096
distinguished_name = req_distinguished_name
string_mask = utf8only
# SHA-1 is deprecated, so use SHA-2 instead.
default_md = sha256
# Extension to add when the -x509 option is used.
x509_extensions = v3_ca
[ req_distinguished_name ]
# See <https://en.wikipedia.org/wiki/Certificate_signing_request>.
countryName = Country Name (2 letter code)
stateOrProvinceName = State or Province Name
localityName = Locality Name
0.organizationName = Organization Name
organizationalUnitName = Organizational Unit Name
commonName = Common Name
emailAddress = Email Address
[ v3_ca ]
# Extensions for a typical CA (\`man x509v3_config\`).
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer
basicConstraints = critical, CA:true
keyUsage = critical, digitalSignature, cRLSign, keyCertSign
[ v3_intermediate_ca ]
# Extensions for a typical intermediate CA (\`man x509v3_config\`).
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer
basicConstraints = critical, CA:true, pathlen:0
keyUsage = critical, digitalSignature, cRLSign, keyCertSign
[ usr_cert ]
# Extensions for client certificates (\`man x509v3_config\`).
basicConstraints = CA:FALSE
nsCertType = client, email
nsComment = "OpenSSL Generated Client Certificate"
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer
keyUsage = critical, nonRepudiation, digitalSignature, keyEncipherment
extendedKeyUsage = clientAuth, emailProtection
[ server_cert ]
# Extensions for server certificates (\`man x509v3_config\`).
basicConstraints = CA:FALSE
nsCertType = server
nsComment = "OpenSSL Generated Server Certificate"
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer:always
keyUsage = critical, digitalSignature, keyEncipherment
extendedKeyUsage = serverAuth
[ crl_ext ]
# Extension for CRLs (\`man x509v3_config\`).
[ ocsp ]
# Extension for OCSP signing certificates (\`man ocsp\`).
basicConstraints = CA:FALSE
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer
keyUsage = critical, digitalSignature
extendedKeyUsage = critical, OCSPSigning
# OpenSSL intermediate CA configuration file.
# Auto-generated.
[ ca ]
# \`man ca\`
default_ca = CA_default
[ CA_default ]
# Directory and file locations.
certs = \$dir/certs
crl_dir = \$dir/crl
new_certs_dir = \$dir/newcerts
database = \$dir/index.txt
serial = \$dir/serial
RANDFILE = \$dir/private/.rand
# The root key and root certificate.
private_key = \$dir/private/intermediate.key.pem
certificate = \$dir/certs/intermediate.cert.pem
# For certificate revocation lists.
crlnumber = \$dir/crlnumber
crl = \$dir/crl/intermediate.crl.pem
crl_extensions = crl_ext
default_crl_days = 30
# SHA-1 is deprecated, so use SHA-2 instead.
default_md = sha256
name_opt = ca_default
cert_opt = ca_default
default_days = 375
preserve = no
policy = policy_loose
# Allow copying extensions from CSRs
copy_extensions = copy
[ policy_strict ]
# The root CA should only sign intermediate certificates that match.
# See the POLICY FORMAT section of \`man ca\`.
countryName = match
stateOrProvinceName = match
organizationName = match
organizationalUnitName = optional
commonName = supplied
emailAddress = optional
[ policy_loose ]
# Allow the intermediate CA to sign a more diverse range of certificates.
# See the POLICY FORMAT section of the \`ca\` man page.
countryName = optional
stateOrProvinceName = optional
localityName = optional
organizationName = optional
organizationalUnitName = optional
commonName = supplied
emailAddress = optional
[ req ]
# Options for the \`req\` tool (\`man req\`).
default_bits = 4096
distinguished_name = req_distinguished_name
string_mask = utf8only
# SHA-1 is deprecated, so use SHA-2 instead.
default_md = sha256
# Extension to add when the -x509 option is used.
x509_extensions = v3_intermediate_ca
[ req_distinguished_name ]
# See <https://en.wikipedia.org/wiki/Certificate_signing_request>.
countryName = Country Name (2 letter code)
stateOrProvinceName = State or Province Name
localityName = Locality Name
0.organizationName = Organization Name
organizationalUnitName = Organizational Unit Name
commonName = Common Name
emailAddress = Email Address
[ v3_ca ]
# Extensions for a typical CA (\`man x509v3_config\`).
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer
basicConstraints = critical, CA:true
keyUsage = critical, digitalSignature, cRLSign, keyCertSign
[ v3_intermediate_ca ]
# Extensions for a typical intermediate CA (\`man x509v3_config\`).
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer
basicConstraints = critical, CA:true, pathlen:0
keyUsage = critical, digitalSignature, cRLSign, keyCertSign
[ usr_cert ]
# Extensions for client certificates (\`man x509v3_config\`).
basicConstraints = CA:FALSE
nsCertType = client, email
nsComment = "OpenSSL Generated Client Certificate"
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer
keyUsage = critical, nonRepudiation, digitalSignature, keyEncipherment
extendedKeyUsage = clientAuth, emailProtection
[ server_cert ]
# Extensions for server certificates (\`man x509v3_config\`).
basicConstraints = CA:FALSE
nsCertType = server
nsComment = "OpenSSL Generated Server Certificate"
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer:always
keyUsage = critical, digitalSignature, keyEncipherment
extendedKeyUsage = serverAuth
[ crl_ext ]
# Extension for CRLs (\`man x509v3_config\`).
[ ocsp ]
# Extension for OCSP signing certificates (\`man ocsp\`).
basicConstraints = CA:FALSE
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer
keyUsage = critical, digitalSignature
extendedKeyUsage = critical, OCSPSigning
deployFiles () {
echo "Deploying a Certificate Authority to $CA_ROOT"
echo ''
if [ ! -d "$CA_ROOT" ]; then
# Create directory
mkdir -p "$CA_ROOT"
# Create sub-directories
mkdir -p "$CA_ROOT/private" "$CA_ROOT/csr" "$CA_ROOT/certs" "$CA_ROOT/newcerts"
touch "$CA_ROOT/index.txt"
echo 1000 > "$CA_ROOT/serial"
chmod 700 "$CA_ROOT/private"
echo "$OPENSSL_CA_CFG" > "$CA_ROOT/openssl.cfg"
if [ ! -d "$INTERMEDIATE_ROOT" ]; then
touch "$INTERMEDIATE_ROOT/index.txt"
echo 1000 > "$INTERMEDIATE_ROOT/serial"
chmod 700 "$INTERMEDIATE_ROOT/private"
generateRootPair () {
echo '==> Starting the generation of the root key pair.'
echo '==> Please fill in the appropriate information asked.'
echo ''
# Set CWD
cd "$CA_ROOT"
# CA Root Private Key
if [ ! -e "$CA_ROOT/private/ca.key.pem" ]; then
echo '=> Generating CA key.. Please enter a strong passphrase.'
echo ''
openssl genrsa -aes256 -out private/ca.key.pem 4096
echo '=> Root CA key exists, skipping..'
if [ ! -e "$CA_ROOT/private/ca.key.pem" ]; then
echo '=x=> Root CA key was not generated!'
return 1
chmod 400 private/ca.key.pem
# CA Root Certificate
if [ ! -e "$CA_ROOT/certs/ca.cert.pem" ]; then
echo '=> Generating CA certificate..'
echo ''
openssl req -config "$CA_ROOT/openssl.cfg" \
-key private/ca.key.pem \
-new -x509 -days 7300 -sha256 -extensions v3_ca \
-out certs/ca.cert.pem
echo '=> Root certificate exists, skipping..'
if [ ! -e "$CA_ROOT/certs/ca.cert.pem" ]; then
echo '=x=> Root certificate was not generated!'
return 1
chmod 444 certs/ca.cert.pem
# Print info
openssl x509 -noout -text -in certs/ca.cert.pem
echo '==> Root key pair generated.'
echo ''
generateIntermediate () {
if [ ! -e "$CA_ROOT/certs/ca.cert.pem" ]; then
echo '=x=> Could not generate intermediate certificate.'
echo '=x=> CA certificate is missing!'
return 1
cd "$CA_ROOT"
echo '==> Starting the generation of the intermediate key pair.'
echo '==> This is used to sign server and user certificates.'
echo '==> Please fill in the appropriate information asked.'
echo ''
if [ ! -e "$CA_ROOT/intermediate/private/intermediate.key.pem" ]; then
# Key
echo '=> Generating intermediate key.. Please enter a strong passphrase.'
echo ''
openssl genrsa -aes256 \
-out intermediate/private/intermediate.key.pem 4096
echo '=> Intermediate certificate key exists, skipping..'
if [ ! -e "$CA_ROOT/intermediate/private/intermediate.key.pem" ]; then
echo '=x=> Intermediate certificate key was not generated!'
return 1
chmod 400 intermediate/private/intermediate.key.pem
if [ -e "$CA_ROOT/intermediate/csr/intermediate.csr.pem" ]; then
rm -f intermediate/csr/intermediate.csr.pem
rm -f intermediate/certs/intermediate.cert.pem
# Certificate Signing Request (CSR)
echo '=> Generating intermediate CSR..'
echo ''
openssl req -config "$INTERMEDIATE_ROOT/openssl.cfg" -new -sha256 \
-key intermediate/private/intermediate.key.pem \
-out intermediate/csr/intermediate.csr.pem
if [ ! -e "$CA_ROOT/intermediate/csr/intermediate.csr.pem" ]; then
echo '=x=> Intermediate signing request was not generated!'
return 1
echo '=> Singing the intermediate certificate. Please answer yes in order to continue.'
echo ''
openssl ca -config "$CA_ROOT/openssl.cfg" -extensions v3_intermediate_ca \
-days 3650 -notext -md sha256 \
-in intermediate/csr/intermediate.csr.pem \
-out intermediate/certs/intermediate.cert.pem
if [ ! -e "$CA_ROOT/intermediate/certs/intermediate.cert.pem" ]; then
echo '=x=> Intermediate certificate was not signed!'
return 1
chmod 444 intermediate/certs/intermediate.cert.pem
# Print info
openssl x509 -noout -text \
-in intermediate/certs/intermediate.cert.pem
openssl verify -CAfile certs/ca.cert.pem \
# Generate Certificate Chain
cat intermediate/certs/intermediate.cert.pem \
certs/ca.cert.pem > intermediate/certs/ca-chain.cert.pem
chmod 444 intermediate/certs/ca-chain.cert.pem
echo '==> Intermediate key pair generated.'
echo "==> Your CA (Certificate Authority) is \"$INTERMEDIATE_ROOT/certs/ca-chain.cert.pem\""
createCertificate() {
if [ ! -e "$CA_ROOT" ]; then
echo "=x=> Certificate root was not found."
return 1
elif [ ! -e "$INTERMEDIATE_ROOT/openssl.cfg" ]; then
echo "=x=> Intermediate certificate configuration was not found."
return 1
if [ -z "$1" ]; then
echo "=x=> Please provide a name for this certificate."
return 1
if [ -z "$2" ] || [ "$2" != "server_cert" ] && [ "$2" != "usr_cert" ]; then
echo "=x=> Type must be one of server_cert or usr_cert. If you're unsure about this, use 'usr_cert'."
return 1
cd "$CA_ROOT"
# Custom configuration file
local CSRCFG="$INTERMEDIATE_ROOT/openssl.cfg"
if [ -n $3 ]; then
# Generate the key if it does not exist
if [ ! -e "$INTERMEDIATE_ROOT/private/$1.key.pem" ]; then
echo "==> Generating key for \"$1\""
echo ''
openssl genrsa -out "$INTERMEDIATE_ROOT/private/$1.key.pem" 4096
chmod 400 "$INTERMEDIATE_ROOT/private/$1.key.pem"
if [ ! -e "$INTERMEDIATE_ROOT/private/$1.key.pem" ]; then
echo "=x=> Key was not created!"
return 1
echo "==> Generating CSR for \"$1\""
echo ''
openssl req -config "$CSRCFG" \
-key "$INTERMEDIATE_ROOT/private/$1.key.pem" \
-new -sha256 -out "$INTERMEDIATE_ROOT/csr/$1.csr.pem"
if [ ! -e "$INTERMEDIATE_ROOT/csr/$1.csr.pem" ]; then
echo "=x=> CSR was not created!"
return 1
echo "==> Generating certificate for \"$1\""
echo ''
openssl ca -config "$INTERMEDIATE_ROOT/openssl.cfg" \
-extensions "$2" -days 375 -notext -md sha256 \
-in "$INTERMEDIATE_ROOT/csr/$1.csr.pem" \
-out "$INTERMEDIATE_ROOT/certs/$1.cert.pem"
if [ ! -e "$INTERMEDIATE_ROOT/certs/$1.cert.pem" ]; then
echo "=x=> Certificate was not created!"
return 1
chmod 444 "$INTERMEDIATE_ROOT/certs/$1.cert.pem"
echo "==> Done."
echo "==> Key: $INTERMEDIATE_ROOT/private/$1.key.pem"
echo "==> Cert: $INTERMEDIATE_ROOT/certs/$1.cert.pem"
revokeCertificate() {
if [ ! -e "$CA_ROOT" ]; then
echo "=x=> Certificate root was not found."
return 1
elif [ ! -e "$INTERMEDIATE_ROOT/openssl.cfg" ]; then
echo "=x=> Intermediate certificate configuration was not found."
return 1
if [ -z "$1" ]; then
echo "=x=> Please provide a name for a certificate to revoke."
return 1
cd "$CA_ROOT"
echo "==> Revoking certificate"
openssl ca -config "$INTERMEDIATE_ROOT/openssl.cfg" \
-revoke "$INTERMEDIATE_ROOT/certs/$1.cert.pem"
echo "==> Done."
printInfo () {
if [ ! -e "$CA_ROOT" ]; then
echo "=x=> Certificate root was not found."
return 1
elif [ ! -e "$INTERMEDIATE_ROOT/openssl.cfg" ]; then
echo "=x=> Intermediate certificate configuration was not found."
return 1
if [ -n "$1" ]; then
openssl x509 -noout -text -in "$CA_ROOT/intermediate/certs/$1.cert.pem"
return 0
echo "=> Root certificate"
openssl x509 -noout -text -in "$CA_ROOT/certs/ca.cert.pem"
echo "=> Intermediate certificate"
openssl x509 -noout -text \
-in "$CA_ROOT/intermediate/certs/intermediate.cert.pem"
openssl verify -CAfile "$CA_ROOT/certs/ca.cert.pem" \
echo ""
echo "==> Paths"
echo "Root: $CA_ROOT"
echo "Intermediate: $CA_ROOT/intermediate"
echo ""
echo "Root Key: $CA_ROOT/private/ca.key.pem"
echo "Root Cert: $CA_ROOT/certs/ca.cert.pem"
echo "CA Key: $CA_ROOT/intermediate/private/intermediate.key.pem"
echo "Chain: $CA_ROOT/intermediate/certs/ca-chain.cert.pem"
echo ""
printHelp () {
echo "Usage: ./ca <CA Path> info | wizard | root | intm | revoke [<name>] | new [<name>] [ server_cert | usr_cert ] [ openssl.cfg ]"
echo -e " info\t- Print information about your CA"
echo -e " wizard\t- Create a new CA"
echo -e " root\t- Generate root certificate. For use when wizard fails."
echo -e " intm\t- Generate intermediate certificate. For use when wizard fails."
echo -e " new \t- Create a new certificate signed with your CA. Can also be used for renewal."
echo -e " revoke\t- Revoke a certificate by name"
set -e
case "$2" in
printInfo $3
"wizard" | "generate" | "newca")
echo "==> Proceeding with full generation for path $1"
"rootpair" | "root")
"intermediate" | "intm")
"certificate" | "cert" | "new" | "renew")
createCertificate $3 $4 $5
revokeCertificate $3
echo "Usage: ./ca <CA Path> info | wizard | root | intm | revoke [<name>] | new [<name>] [ server_cert | usr_cert ] [ openssl.cfg ]"

mesher.js Normal file
View File

@ -0,0 +1,114 @@
function mesh (params) {
const dims = params.dims
const vertices = []
const indices = []
const normals = []
for (let backFace = true, b = false; b !== backFace; backFace = backFace && b, b = !b) {
// Sweep over 3-axes
for (let d = 0; d < 3; ++d) {
let i, j, k, l, w, h, side
const u = (d + 1) % 3
const v = (d + 2) % 3
const x = [0, 0, 0]
const q = [0, 0, 0]
// Here we're keeping track of the side that we're meshing.
if (d === 0) side = backFace ? LEFT : RIGHT
else if (d === 1) side = backFace ? BOTTOM : TOP
else if (d === 2) side = backFace ? BACK : FRONT
const mask = new Int32Array(dims[u] * dims[v])
q[d] = 1
// Move through the dimension from front to back
for (x[d] = -1; x[d] < dims[d];) {
// Compute mask
let n = 0
for (x[v] = 0; x[v] < dims[v]; ++x[v]) {
for (x[u] = 0; x[u] < dims[u]; ++x[u]) {
const current = this.getBlockAt(params, dims, x[0], x[1], x[2])
const ajacent = this.getBlockAt(params, dims, x[0] + q[0], x[1] + q[1], x[2] + q[2])
mask[n++] = ((current && ajacent && current === ajacent)) ? null : (backFace ? ajacent : current)
// Increment x[d]
// Generate mesh for mask using lexicographic ordering
n = 0
for (j = 0; j < dims[v]; ++j) {
for (i = 0; i < dims[u];) {
if (mask[n]) {
// Compute width
for (w = 1; mask[n + w] && mask[n + w] === mask[n] && i + w < dims[u]; ++w) {}
// Compute height
let done = false
for (h = 1; j + h < dims[v]; ++h) {
for (k = 0; k < w; ++k) {
if (!mask[n + k + h * dims[u]] || mask[n + k + h * dims[u]] !== mask[n]) {
done = true
if (done) break
// Create quad
x[u] = i
x[v] = j
const du = [0, 0, 0]
du[u] = w
const dv = [0, 0, 0]
dv[v] = h
const quad = [
[x[0], x[1], x[2]],
[x[0] + du[0], x[1] + du[1], x[2] + du[2]],
[x[0] + du[0] + dv[0], x[1] + du[1] + dv[1], x[2] + du[2] + dv[2]],
[x[0] + dv[0], x[1] + dv[1], x[2] + dv[2]]
// Add vertices and normals
const mul = backFace ? -1 : 1
for (var qindex = 0; qindex < 4; ++qindex) {
vertices.push(quad[qindex][0], quad[qindex][1], quad[qindex][2])
normals.push(q[0] * mul, q[1] * mul, q[2] * mul)
// Add indices
const indexi = vertices.length / 3 - 4
if (backFace) {
indices.push(indexi + 2, indexi + 1, indexi)
indices.push(indexi + 3, indexi + 2, indexi)
} else {
indices.push(indexi, indexi + 1, indexi + 2)
indices.push(indexi, indexi + 2, indexi + 3)
// Zero-out mask
for (l = 0; l < h; ++l) {
for (k = 0; k < w; ++k) {
mask[n + k + l * dims[u]] = false
// Increment counters and continue
i += w
n += w
} else {
return { vertices, indices, normals }

point-on-sphere.js Normal file
View File

@ -0,0 +1,17 @@
// Get angle on circle from mouse position
function getAngleOnCircleFromOffsetMouse(evt) {
const x = (evt.pageX - element.offset().left);
const y = (evt.pageY - element.offset().top);
// https://math.stackexchange.com/a/127615
const center = { x: width / 2, y: width / 2 };
const xCenter = (x - center.x);
const yCenter = (y - center.y);
const circlePoint = {
x: center.x + radius * (xCenter / Math.sqrt(xCenter * xCenter + yCenter * yCenter)),
y: center.y + radius * (yCenter / Math.sqrt(xCenter * xCenter + yCenter * yCenter)),
const angle = Math.atan2(circlePoint.y - center.y, circlePoint.x - center.x) + Math.PI / 2;
return angle < 0 ? Math.PI * 2 - Math.abs(angle) : angle;

restream.sh Normal file
View File

@ -0,0 +1,10 @@
STREAM_KEY="<twitch stream key>"
SOURCE="https://tv.icynet.eu/live/<channel name>.m3u8"
# Choose the server closest to you
# https://stream.twitch.tv/ingests/
ffmpeg -re -i "$SOURCE" -c:v copy -c:a aac -ar 44100 -ab 128k -ac 2 -strict -2 -flags +global_header -bsf:a aac_adtstoasc -bufsize 3000k -f flv "$DESTINATION/$STREAM_KEY"

sector.js Normal file
View File

@ -0,0 +1,28 @@
function getSectorPath(centre, rIn, rOut, startDeg, delta) {
const startOut = {
x: centre.x + rOut * Math.cos(startDeg),
y: centre.y + rOut * Math.sin(startDeg)
const endOut = {
x: centre.x + rOut * Math.cos(startDeg + delta),
y: centre.y + rOut * Math.sin(startDeg + delta)
const startIn = {
x: centre.x + rIn * Math.cos(startDeg + delta),
y: centre.y + rIn * Math.sin(startDeg + delta)
const endIn = {
x: centre.x + rIn * Math.cos(startDeg),
y: centre.y + rIn * Math.sin(startDeg)
const largeArc = delta > 180 ? 1 : 0;
return [
`M${startOut.x},${startOut.y}`, `A${rOut},${rOut}`, '0',
`${largeArc},1`, `${endOut.x},${endOut.y}`,
`A${rIn},${rIn}`, '0', `${largeArc},0`,
`L${startOut.x},${startOut.y}`, 'Z',
].join(' ');