Files
David Garcia f60a3bdfdc Persistence: fresh Entra device join (DRS)
Native implementation of the DRS wire protocol - joins a fresh fake
device to Entra and persists the returned deviceId + X.509 device
cert. Cert-based persistence survives password reset.

- shared/DeviceCryptoHelper.{h,cpp}: pure-OpenSSL asymmetric
  primitives (Qt exposes none of these).
    generateRsa2048()      RSA-2048 keypair, PKCS#8 PEM out.
    buildCsr()             PKCS#10 CSR signed with SHA-256, PEM out.
    csrPemToDrsBase64()    strip PEM armor for the DRS enroll body.
    signJwtRS256()         compact JWS serialization for cert-bound
                           client_assertion (used by follow-up PRT
                           mint; not needed for the join itself).
    certSha256Thumbprint() hex uppercase, for x5t#S256 + UI display.
- shared/DeviceStore.{h,cpp}: sibling of SessionPersistence. Stores
  {deviceId, tenantId, displayName, thumbprint, joinedAt,
   privateKeyPem, deviceCertPem, transportKeyPem}. Private key +
  cert bytes are AES-256-GCM encrypted at rest via CryptoHelper,
  keyed by the same machine-derived default password. File:
  data/device_certs.dat.
- client/DeviceJoinWindow.{h,cpp} (Persistence menu): inherits
  EnumerationWindowBase. Operator pastes a DRS-audience token
  (client-id 01cb2876-7ebd-4aa4-9cc9-d28bd4d359a9, resource
  urn:ms-drs:enterpriseregistration.windows.net), fills device
  details, submits. On success renders deviceId + thumbprint, adds
  a row to the stored table. Per-row: export cert PEM (public),
  export private key PEM (red confirm dialog), remove local record.
- Wired at Persistence menu between "Auth Methods" and "Windows
  Hello Attack". No CMake changes - both new .cpp files live in
  shared/ which globs *.cpp; OpenSSL is already linked PUBLIC
  through shared and transitively available in client.
2026-07-28 15:04:40 -06:00
..