feat: added reading SANs from CSR

This commit is contained in:
Sheen Capadngan
2024-08-20 01:39:40 +08:00
parent bb27d38a12
commit 16519f9486
4 changed files with 25 additions and 7 deletions
@@ -149,9 +149,7 @@ export const registerCertificateEstRouter = async (server: FastifyZodProvider) =
const { rawCertificate } = await server.services.certificateAuthority.signCertFromCa({ const { rawCertificate } = await server.services.certificateAuthority.signCertFromCa({
isInternal: true, isInternal: true,
certificateTemplateId: req.params.certificateTemplateId, certificateTemplateId: req.params.certificateTemplateId,
csr: req.body, csr: req.body
altNames: "",
ttl: "1h"
}); });
void res.header("Content-Type", "application/pkcs7-mime; smime-type=certs-only"); void res.header("Content-Type", "application/pkcs7-mime; smime-type=certs-only");
@@ -1366,6 +1366,8 @@ export const certificateAuthorityServiceFactory = ({
notAfterDate = new Date(notAfter); notAfterDate = new Date(notAfter);
} else if (ttl) { } else if (ttl) {
notAfterDate = new Date(new Date().getTime() + ms(ttl)); notAfterDate = new Date(new Date().getTime() + ms(ttl));
} else if (certificateTemplate?.ttl) {
notAfterDate = new Date(new Date().getTime() + ms(certificateTemplate.ttl));
} }
const caCertNotBeforeDate = new Date(caCertObj.notBefore); const caCertNotBeforeDate = new Date(caCertObj.notBefore);
@@ -1410,6 +1412,7 @@ export const certificateAuthorityServiceFactory = ({
await x509.SubjectKeyIdentifierExtension.create(csrObj.publicKey) await x509.SubjectKeyIdentifierExtension.create(csrObj.publicKey)
]; ];
let altNamesFromCsr: string = "";
let altNamesArray: { let altNamesArray: {
type: "email" | "dns"; type: "email" | "dns";
value: string; value: string;
@@ -1438,7 +1441,24 @@ export const certificateAuthorityServiceFactory = ({
// If altName is neither a valid email nor a valid hostname, throw an error or handle it accordingly // If altName is neither a valid email nor a valid hostname, throw an error or handle it accordingly
throw new Error(`Invalid altName: ${altName}`); throw new Error(`Invalid altName: ${altName}`);
}); });
} else {
// attempt to read from CSR if altNames is not explicitly provided
const sanExtension = csrObj.extensions.find((ext) => ext.type === "2.5.29.17");
if (sanExtension) {
const sanNames = new x509.GeneralNames(sanExtension.value);
altNamesArray = sanNames.items
.filter((value) => value.type === "email" || value.type === "dns")
.map((name) => ({
type: name.type as "email" | "dns",
value: name.value
}));
altNamesFromCsr = sanNames.items.map((item) => item.value).join(",");
}
}
if (altNamesArray.length) {
const altNamesExtension = new x509.SubjectAlternativeNameExtension(altNamesArray, false); const altNamesExtension = new x509.SubjectAlternativeNameExtension(altNamesArray, false);
extensions.push(altNamesExtension); extensions.push(altNamesExtension);
} }
@@ -1484,7 +1504,7 @@ export const certificateAuthorityServiceFactory = ({
status: CertStatus.ACTIVE, status: CertStatus.ACTIVE,
friendlyName: friendlyName || csrObj.subject, friendlyName: friendlyName || csrObj.subject,
commonName: cn, commonName: cn,
altNames, altNames: altNamesFromCsr || altNames,
serialNumber, serialNumber,
notBefore: notBeforeDate, notBefore: notBeforeDate,
notAfter: notAfterDate notAfter: notAfterDate
@@ -106,8 +106,8 @@ export type TSignCertFromCaDTO =
pkiCollectionId?: string; pkiCollectionId?: string;
friendlyName?: string; friendlyName?: string;
commonName?: string; commonName?: string;
altNames: string; altNames?: string;
ttl: string; ttl?: string;
notBefore?: string; notBefore?: string;
notAfter?: string; notAfter?: string;
} }
@@ -147,7 +147,7 @@ export const CertificateTemplateEnrollmentModal = ({ popUp, handlePopUpToggle }:
/> />
{data && ( {data && (
<FormControl label="EST Label"> <FormControl label="EST Label">
<Input value={data.certificateTemplateId} disabled /> <Input value={data.certificateTemplateId} isDisabled className="bg-white/[0.07]" />
</FormControl> </FormControl>
)} )}
<Controller <Controller