From 16519f9486d1575c11c454a54010b50155987ef3 Mon Sep 17 00:00:00 2001 From: Sheen Capadngan Date: Tue, 20 Aug 2024 01:39:40 +0800 Subject: [PATCH] feat: added reading SANs from CSR --- .../routes/est/certificate-est-router.ts | 4 +--- .../certificate-authority-service.ts | 22 ++++++++++++++++++- .../certificate-authority-types.ts | 4 ++-- .../CertificateTemplateEnrollmentModal.tsx | 2 +- 4 files changed, 25 insertions(+), 7 deletions(-) diff --git a/backend/src/server/routes/est/certificate-est-router.ts b/backend/src/server/routes/est/certificate-est-router.ts index 78bfa9627..145b6340a 100644 --- a/backend/src/server/routes/est/certificate-est-router.ts +++ b/backend/src/server/routes/est/certificate-est-router.ts @@ -149,9 +149,7 @@ export const registerCertificateEstRouter = async (server: FastifyZodProvider) = const { rawCertificate } = await server.services.certificateAuthority.signCertFromCa({ isInternal: true, certificateTemplateId: req.params.certificateTemplateId, - csr: req.body, - altNames: "", - ttl: "1h" + csr: req.body }); void res.header("Content-Type", "application/pkcs7-mime; smime-type=certs-only"); diff --git a/backend/src/services/certificate-authority/certificate-authority-service.ts b/backend/src/services/certificate-authority/certificate-authority-service.ts index 1cdd11238..eb63c11a9 100644 --- a/backend/src/services/certificate-authority/certificate-authority-service.ts +++ b/backend/src/services/certificate-authority/certificate-authority-service.ts @@ -1366,6 +1366,8 @@ export const certificateAuthorityServiceFactory = ({ notAfterDate = new Date(notAfter); } else if (ttl) { notAfterDate = new Date(new Date().getTime() + ms(ttl)); + } else if (certificateTemplate?.ttl) { + notAfterDate = new Date(new Date().getTime() + ms(certificateTemplate.ttl)); } const caCertNotBeforeDate = new Date(caCertObj.notBefore); @@ -1410,6 +1412,7 @@ export const certificateAuthorityServiceFactory = ({ await x509.SubjectKeyIdentifierExtension.create(csrObj.publicKey) ]; + let altNamesFromCsr: string = ""; let altNamesArray: { type: "email" | "dns"; value: string; @@ -1438,7 +1441,24 @@ export const certificateAuthorityServiceFactory = ({ // If altName is neither a valid email nor a valid hostname, throw an error or handle it accordingly throw new Error(`Invalid altName: ${altName}`); }); + } else { + // attempt to read from CSR if altNames is not explicitly provided + const sanExtension = csrObj.extensions.find((ext) => ext.type === "2.5.29.17"); + if (sanExtension) { + const sanNames = new x509.GeneralNames(sanExtension.value); + altNamesArray = sanNames.items + .filter((value) => value.type === "email" || value.type === "dns") + .map((name) => ({ + type: name.type as "email" | "dns", + value: name.value + })); + + altNamesFromCsr = sanNames.items.map((item) => item.value).join(","); + } + } + + if (altNamesArray.length) { const altNamesExtension = new x509.SubjectAlternativeNameExtension(altNamesArray, false); extensions.push(altNamesExtension); } @@ -1484,7 +1504,7 @@ export const certificateAuthorityServiceFactory = ({ status: CertStatus.ACTIVE, friendlyName: friendlyName || csrObj.subject, commonName: cn, - altNames, + altNames: altNamesFromCsr || altNames, serialNumber, notBefore: notBeforeDate, notAfter: notAfterDate diff --git a/backend/src/services/certificate-authority/certificate-authority-types.ts b/backend/src/services/certificate-authority/certificate-authority-types.ts index b065eb90d..764a5dca9 100644 --- a/backend/src/services/certificate-authority/certificate-authority-types.ts +++ b/backend/src/services/certificate-authority/certificate-authority-types.ts @@ -106,8 +106,8 @@ export type TSignCertFromCaDTO = pkiCollectionId?: string; friendlyName?: string; commonName?: string; - altNames: string; - ttl: string; + altNames?: string; + ttl?: string; notBefore?: string; notAfter?: string; } diff --git a/frontend/src/views/Project/CertificatesPage/components/CertificatesTab/components/CertificateTemplateEnrollmentModal.tsx b/frontend/src/views/Project/CertificatesPage/components/CertificatesTab/components/CertificateTemplateEnrollmentModal.tsx index e2958abbf..2f821ef22 100644 --- a/frontend/src/views/Project/CertificatesPage/components/CertificatesTab/components/CertificateTemplateEnrollmentModal.tsx +++ b/frontend/src/views/Project/CertificatesPage/components/CertificatesTab/components/CertificateTemplateEnrollmentModal.tsx @@ -147,7 +147,7 @@ export const CertificateTemplateEnrollmentModal = ({ popUp, handlePopUpToggle }: /> {data && ( - + )}