1
0
mirror of https://git.zx2c4.com/wireguard-windows synced 2024-11-10 16:59:18 +00:00
wireguard-windows/embeddable-dll-service
Simon Rozman b279eab97a build: make code signing method configurable
Existing code signing was hard-coded to use a locally installed
certificate (hardware security dongles included). However, signtool.exe
is extensible to allow any kind of digest signing plugin with /dlib and
/dmdf switches. This is used for cloud-based code signing (e.g.
Microsoft Trusted Signing).

Signed-off-by: Simon Rozman <simon@rozman.si>
2024-10-17 14:27:00 +02:00
..
csharp embeddable-dll-service: csharp: ensure double \0 termination 2022-03-28 12:40:20 +02:00
.gitignore embeddable-dll-service: build: .gitignore outputs 2022-03-28 13:19:14 +02:00
build.bat build: make code signing method configurable 2024-10-17 14:27:00 +02:00
main.go global: bump date 2022-01-06 17:28:13 +01:00
README.md embeddable-dll-service: correctness in README 2022-03-28 12:40:20 +02:00

Embeddable WireGuard Tunnel Library

This allows embedding WireGuard as a service inside of another application. Build tunnel.dll by running ./build.bat in this folder. The first time you run it, it will invoke ..\build.bat simply for downloading dependencies. After, you should have amd64/tunnel.dll, x86/tunnel.dll, and arm64/tunnel.dll. In addition, tunnel.dll requires wireguard.dll, which can be downloaded from the wireguard-nt download server.

The basic setup to use tunnel.dll is:

1. Install a service with these parameters:
Service Name:  "WireGuardTunnel$SomeTunnelName"
Display Name:  "Some Service Name"
Service Type:  SERVICE_WIN32_OWN_PROCESS
Start Type:    StartAutomatic
Error Control: ErrorNormal,
Dependencies:  [ "Nsi", "TcpIp" ]
Sid Type:      SERVICE_SID_TYPE_UNRESTRICTED
Executable:    "C:\path\to\example\vpnclient.exe /service configfile.conf"

Some of these may have to be changed with ChangeServiceConfig2 after the initial call to CreateService The SERVICE_SID_TYPE_UNRESTRICTED parameter is absolutely essential; do not forget it.

2. Have your program's main function handle the /service switch:
if (wargc == 3 && !wcscmp(wargv[1], L"/service")) {
    HMODULE tunnel_lib = LoadLibrary("tunnel.dll");
    if (!tunnel_lib)
        abort();
    BOOL (_cdecl *tunnel_proc)(_In_ LPCWSTR conf_file);
    *(FARPROC*)&tunnel_proc = GetProcAddress(tunnel_lib, "WireGuardTunnelService");
    if (!tunnel_proc)
        abort();
    return tunnel_proc(wargv[2]);
}
3. Scoop up logs by implementing a ringlogger format reader.

There is a sample implementation of bits and pieces of this inside of the csharp\ directory.