diff --git a/backend/src/services/certificate/certificate-fns.ts b/backend/src/services/certificate/certificate-fns.ts index 5cd4929bb..961fb27ff 100644 --- a/backend/src/services/certificate/certificate-fns.ts +++ b/backend/src/services/certificate/certificate-fns.ts @@ -105,9 +105,12 @@ export const buildCertificateChain = async ({ kmsService, kmsId }: TBuildCertificateChainDTO) => { + if (!encryptedCertificateChain && (!caCert || !caCertChain)) { + return null; + } + let certificateChain = `${caCert}\n${caCertChain}`.trim(); - // If the certificate was generated after ~05/01/25 it will have a encryptedCertificateChain attached to it's body if (encryptedCertificateChain) { const kmsDecryptor = await kmsService.decryptWithKmsKey({ kmsId }); const decryptedCertChain = await kmsDecryptor({ diff --git a/backend/src/services/certificate/certificate-types.ts b/backend/src/services/certificate/certificate-types.ts index 373fa028c..ae04eae6b 100644 --- a/backend/src/services/certificate/certificate-types.ts +++ b/backend/src/services/certificate/certificate-types.ts @@ -95,8 +95,8 @@ export type TGetCertificateCredentialsDTO = { }; export type TBuildCertificateChainDTO = { - caCert: string; - caCertChain: string; + caCert?: string; + caCertChain?: string; encryptedCertificateChain?: Buffer; kmsService: Pick; kmsId: string;