Merge pull request #3187 from akhilmhdh/feat/connector

feat: added ca to cli
This commit is contained in:
Maidul Islam
2025-03-05 10:13:27 -05:00
committed by GitHub
2 changed files with 21 additions and 9 deletions
+5
View File
@@ -1,3 +1,8 @@
public_ip: 127.0.0.1 public_ip: 127.0.0.1
auth_secret: changeThisOnProduction auth_secret: changeThisOnProduction
realm: infisical.org realm: infisical.org
# set port 5349 for tls
# port: 5349
# tls_private_key_path: /full-path
# tls_ca_path: /full-path
# tls_cert_path: /full-path
+15 -8
View File
@@ -3,6 +3,7 @@ package gateway
import ( import (
"context" "context"
"crypto/tls" "crypto/tls"
"crypto/x509"
"errors" "errors"
"fmt" "fmt"
"net" "net"
@@ -37,8 +38,10 @@ type GatewayRelayConfig struct {
RelayMaxPort uint16 `yaml:"relay_max_port"` RelayMaxPort uint16 `yaml:"relay_max_port"`
TlsCertPath string `yaml:"tls_cert_path"` TlsCertPath string `yaml:"tls_cert_path"`
TlsPrivateKeyPath string `yaml:"tls_private_key_path"` TlsPrivateKeyPath string `yaml:"tls_private_key_path"`
TlsCaPath string `yaml:"tls_ca_path"`
tls tls.Certificate tls tls.Certificate
tlsCa string
isTlsEnabled bool isTlsEnabled bool
} }
@@ -79,19 +82,19 @@ func NewGatewayRelay(configFilePath string) (*GatewayRelay, error) {
return nil, errMissingTlsCert return nil, errMissingTlsCert
} }
tlsCertFile, err := os.ReadFile(cfg.TlsCertPath) cert, err := tls.LoadX509KeyPair(cfg.TlsCertPath, cfg.TlsPrivateKeyPath)
if err != nil { if err != nil {
return nil, err return nil, fmt.Errorf("Failed to read load server tls key pair: %w", err)
}
tlsPrivateKeyFile, err := os.ReadFile(cfg.TlsPrivateKeyPath)
if err != nil {
return nil, err
} }
cert, err := tls.LoadX509KeyPair(string(tlsCertFile), string(tlsPrivateKeyFile)) if cfg.TlsCaPath != "" {
ca, err := os.ReadFile(cfg.TlsCaPath)
if err != nil { if err != nil {
return nil, err return nil, fmt.Errorf("Failed to read tls ca: %w", err)
} }
cfg.tlsCa = string(ca)
}
cfg.tls = cert cfg.tls = cert
cfg.isTlsEnabled = true cfg.isTlsEnabled = true
} }
@@ -140,8 +143,12 @@ func (g *GatewayRelay) Run() error {
} }
if g.Config.isTlsEnabled { if g.Config.isTlsEnabled {
caCertPool := x509.NewCertPool()
caCertPool.AppendCertsFromPEM([]byte(g.Config.tlsCa))
listenerConfigs[i].Listener = tls.NewListener(conn, &tls.Config{ listenerConfigs[i].Listener = tls.NewListener(conn, &tls.Config{
Certificates: []tls.Certificate{g.Config.tls}, Certificates: []tls.Certificate{g.Config.tls},
ClientCAs: caCertPool,
}) })
} else { } else {
listenerConfigs[i].Listener = conn listenerConfigs[i].Listener = conn