mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 19:28:51 +00:00
feat: added reading SANs from CSR
This commit is contained in:
@@ -149,9 +149,7 @@ export const registerCertificateEstRouter = async (server: FastifyZodProvider) =
|
|||||||
const { rawCertificate } = await server.services.certificateAuthority.signCertFromCa({
|
const { rawCertificate } = await server.services.certificateAuthority.signCertFromCa({
|
||||||
isInternal: true,
|
isInternal: true,
|
||||||
certificateTemplateId: req.params.certificateTemplateId,
|
certificateTemplateId: req.params.certificateTemplateId,
|
||||||
csr: req.body,
|
csr: req.body
|
||||||
altNames: "",
|
|
||||||
ttl: "1h"
|
|
||||||
});
|
});
|
||||||
|
|
||||||
void res.header("Content-Type", "application/pkcs7-mime; smime-type=certs-only");
|
void res.header("Content-Type", "application/pkcs7-mime; smime-type=certs-only");
|
||||||
|
|||||||
@@ -1366,6 +1366,8 @@ export const certificateAuthorityServiceFactory = ({
|
|||||||
notAfterDate = new Date(notAfter);
|
notAfterDate = new Date(notAfter);
|
||||||
} else if (ttl) {
|
} else if (ttl) {
|
||||||
notAfterDate = new Date(new Date().getTime() + ms(ttl));
|
notAfterDate = new Date(new Date().getTime() + ms(ttl));
|
||||||
|
} else if (certificateTemplate?.ttl) {
|
||||||
|
notAfterDate = new Date(new Date().getTime() + ms(certificateTemplate.ttl));
|
||||||
}
|
}
|
||||||
|
|
||||||
const caCertNotBeforeDate = new Date(caCertObj.notBefore);
|
const caCertNotBeforeDate = new Date(caCertObj.notBefore);
|
||||||
@@ -1410,6 +1412,7 @@ export const certificateAuthorityServiceFactory = ({
|
|||||||
await x509.SubjectKeyIdentifierExtension.create(csrObj.publicKey)
|
await x509.SubjectKeyIdentifierExtension.create(csrObj.publicKey)
|
||||||
];
|
];
|
||||||
|
|
||||||
|
let altNamesFromCsr: string = "";
|
||||||
let altNamesArray: {
|
let altNamesArray: {
|
||||||
type: "email" | "dns";
|
type: "email" | "dns";
|
||||||
value: string;
|
value: string;
|
||||||
@@ -1438,7 +1441,24 @@ export const certificateAuthorityServiceFactory = ({
|
|||||||
// If altName is neither a valid email nor a valid hostname, throw an error or handle it accordingly
|
// If altName is neither a valid email nor a valid hostname, throw an error or handle it accordingly
|
||||||
throw new Error(`Invalid altName: ${altName}`);
|
throw new Error(`Invalid altName: ${altName}`);
|
||||||
});
|
});
|
||||||
|
} else {
|
||||||
|
// attempt to read from CSR if altNames is not explicitly provided
|
||||||
|
const sanExtension = csrObj.extensions.find((ext) => ext.type === "2.5.29.17");
|
||||||
|
if (sanExtension) {
|
||||||
|
const sanNames = new x509.GeneralNames(sanExtension.value);
|
||||||
|
|
||||||
|
altNamesArray = sanNames.items
|
||||||
|
.filter((value) => value.type === "email" || value.type === "dns")
|
||||||
|
.map((name) => ({
|
||||||
|
type: name.type as "email" | "dns",
|
||||||
|
value: name.value
|
||||||
|
}));
|
||||||
|
|
||||||
|
altNamesFromCsr = sanNames.items.map((item) => item.value).join(",");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (altNamesArray.length) {
|
||||||
const altNamesExtension = new x509.SubjectAlternativeNameExtension(altNamesArray, false);
|
const altNamesExtension = new x509.SubjectAlternativeNameExtension(altNamesArray, false);
|
||||||
extensions.push(altNamesExtension);
|
extensions.push(altNamesExtension);
|
||||||
}
|
}
|
||||||
@@ -1484,7 +1504,7 @@ export const certificateAuthorityServiceFactory = ({
|
|||||||
status: CertStatus.ACTIVE,
|
status: CertStatus.ACTIVE,
|
||||||
friendlyName: friendlyName || csrObj.subject,
|
friendlyName: friendlyName || csrObj.subject,
|
||||||
commonName: cn,
|
commonName: cn,
|
||||||
altNames,
|
altNames: altNamesFromCsr || altNames,
|
||||||
serialNumber,
|
serialNumber,
|
||||||
notBefore: notBeforeDate,
|
notBefore: notBeforeDate,
|
||||||
notAfter: notAfterDate
|
notAfter: notAfterDate
|
||||||
|
|||||||
@@ -106,8 +106,8 @@ export type TSignCertFromCaDTO =
|
|||||||
pkiCollectionId?: string;
|
pkiCollectionId?: string;
|
||||||
friendlyName?: string;
|
friendlyName?: string;
|
||||||
commonName?: string;
|
commonName?: string;
|
||||||
altNames: string;
|
altNames?: string;
|
||||||
ttl: string;
|
ttl?: string;
|
||||||
notBefore?: string;
|
notBefore?: string;
|
||||||
notAfter?: string;
|
notAfter?: string;
|
||||||
}
|
}
|
||||||
|
|||||||
+1
-1
@@ -147,7 +147,7 @@ export const CertificateTemplateEnrollmentModal = ({ popUp, handlePopUpToggle }:
|
|||||||
/>
|
/>
|
||||||
{data && (
|
{data && (
|
||||||
<FormControl label="EST Label">
|
<FormControl label="EST Label">
|
||||||
<Input value={data.certificateTemplateId} disabled />
|
<Input value={data.certificateTemplateId} isDisabled className="bg-white/[0.07]" />
|
||||||
</FormControl>
|
</FormControl>
|
||||||
)}
|
)}
|
||||||
<Controller
|
<Controller
|
||||||
|
|||||||
Reference in New Issue
Block a user