mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 06:28:11 +00:00
Merge pull request #3187 from akhilmhdh/feat/connector
feat: added ca to cli
This commit is contained in:
@@ -1,3 +1,8 @@
|
|||||||
public_ip: 127.0.0.1
|
public_ip: 127.0.0.1
|
||||||
auth_secret: changeThisOnProduction
|
auth_secret: changeThisOnProduction
|
||||||
realm: infisical.org
|
realm: infisical.org
|
||||||
|
# set port 5349 for tls
|
||||||
|
# port: 5349
|
||||||
|
# tls_private_key_path: /full-path
|
||||||
|
# tls_ca_path: /full-path
|
||||||
|
# tls_cert_path: /full-path
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ package gateway
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"crypto/tls"
|
"crypto/tls"
|
||||||
|
"crypto/x509"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
"net"
|
"net"
|
||||||
@@ -37,8 +38,10 @@ type GatewayRelayConfig struct {
|
|||||||
RelayMaxPort uint16 `yaml:"relay_max_port"`
|
RelayMaxPort uint16 `yaml:"relay_max_port"`
|
||||||
TlsCertPath string `yaml:"tls_cert_path"`
|
TlsCertPath string `yaml:"tls_cert_path"`
|
||||||
TlsPrivateKeyPath string `yaml:"tls_private_key_path"`
|
TlsPrivateKeyPath string `yaml:"tls_private_key_path"`
|
||||||
|
TlsCaPath string `yaml:"tls_ca_path"`
|
||||||
|
|
||||||
tls tls.Certificate
|
tls tls.Certificate
|
||||||
|
tlsCa string
|
||||||
isTlsEnabled bool
|
isTlsEnabled bool
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -79,19 +82,19 @@ func NewGatewayRelay(configFilePath string) (*GatewayRelay, error) {
|
|||||||
return nil, errMissingTlsCert
|
return nil, errMissingTlsCert
|
||||||
}
|
}
|
||||||
|
|
||||||
tlsCertFile, err := os.ReadFile(cfg.TlsCertPath)
|
cert, err := tls.LoadX509KeyPair(cfg.TlsCertPath, cfg.TlsPrivateKeyPath)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, fmt.Errorf("Failed to read load server tls key pair: %w", err)
|
||||||
}
|
|
||||||
tlsPrivateKeyFile, err := os.ReadFile(cfg.TlsPrivateKeyPath)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
}
|
||||||
|
|
||||||
cert, err := tls.LoadX509KeyPair(string(tlsCertFile), string(tlsPrivateKeyFile))
|
if cfg.TlsCaPath != "" {
|
||||||
if err != nil {
|
ca, err := os.ReadFile(cfg.TlsCaPath)
|
||||||
return nil, err
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("Failed to read tls ca: %w", err)
|
||||||
|
}
|
||||||
|
cfg.tlsCa = string(ca)
|
||||||
}
|
}
|
||||||
|
|
||||||
cfg.tls = cert
|
cfg.tls = cert
|
||||||
cfg.isTlsEnabled = true
|
cfg.isTlsEnabled = true
|
||||||
}
|
}
|
||||||
@@ -140,8 +143,12 @@ func (g *GatewayRelay) Run() error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if g.Config.isTlsEnabled {
|
if g.Config.isTlsEnabled {
|
||||||
|
caCertPool := x509.NewCertPool()
|
||||||
|
caCertPool.AppendCertsFromPEM([]byte(g.Config.tlsCa))
|
||||||
|
|
||||||
listenerConfigs[i].Listener = tls.NewListener(conn, &tls.Config{
|
listenerConfigs[i].Listener = tls.NewListener(conn, &tls.Config{
|
||||||
Certificates: []tls.Certificate{g.Config.tls},
|
Certificates: []tls.Certificate{g.Config.tls},
|
||||||
|
ClientCAs: caCertPool,
|
||||||
})
|
})
|
||||||
} else {
|
} else {
|
||||||
listenerConfigs[i].Listener = conn
|
listenerConfigs[i].Listener = conn
|
||||||
|
|||||||
Reference in New Issue
Block a user