mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 21:27:10 +00:00
fix: crypto errors and disable acme
This commit is contained in:
@@ -433,12 +433,9 @@ const cryptographyFactory = () => {
|
|||||||
getRandomValues: crypto.getRandomValues,
|
getRandomValues: crypto.getRandomValues,
|
||||||
randomUUID: crypto.randomUUID,
|
randomUUID: crypto.randomUUID,
|
||||||
subtle: {
|
subtle: {
|
||||||
// eslint-disable-next-line @typescript-eslint/unbound-method
|
generateKey: subtle.generateKey.bind(subtle),
|
||||||
generateKey: subtle.generateKey,
|
importKey: subtle.importKey.bind(subtle),
|
||||||
// eslint-disable-next-line @typescript-eslint/unbound-method
|
exportKey: subtle.exportKey.bind(subtle)
|
||||||
importKey: subtle.importKey,
|
|
||||||
// eslint-disable-next-line @typescript-eslint/unbound-method
|
|
||||||
exportKey: subtle.exportKey
|
|
||||||
},
|
},
|
||||||
constants: crypto.constants,
|
constants: crypto.constants,
|
||||||
X509Certificate: crypto.X509Certificate,
|
X509Certificate: crypto.X509Certificate,
|
||||||
|
|||||||
@@ -18,6 +18,7 @@ import {
|
|||||||
} from "@app/ee/services/secret-scanning-v2/secret-scanning-v2-types";
|
} from "@app/ee/services/secret-scanning-v2/secret-scanning-v2-types";
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import { buildRedisFromConfig, TRedisConfigKeys } from "@app/lib/config/redis";
|
import { buildRedisFromConfig, TRedisConfigKeys } from "@app/lib/config/redis";
|
||||||
|
import { crypto } from "@app/lib/crypto";
|
||||||
import { logger } from "@app/lib/logger";
|
import { logger } from "@app/lib/logger";
|
||||||
import { QueueWorkerProfile } from "@app/lib/types";
|
import { QueueWorkerProfile } from "@app/lib/types";
|
||||||
import { CaType } from "@app/services/certificate-authority/certificate-authority-enums";
|
import { CaType } from "@app/services/certificate-authority/certificate-authority-enums";
|
||||||
@@ -438,9 +439,14 @@ export const queueServiceFactory = (
|
|||||||
|
|
||||||
queueContainer[name] = new Queue(name as string, {
|
queueContainer[name] = new Queue(name as string, {
|
||||||
...queueSettings,
|
...queueSettings,
|
||||||
settings: {
|
...(crypto.isFipsModeEnabled()
|
||||||
repeatKeyHashAlgorithm: "sha256"
|
? {
|
||||||
},
|
settings: {
|
||||||
|
...queueSettings?.settings,
|
||||||
|
repeatKeyHashAlgorithm: "sha256"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
: {}),
|
||||||
connection
|
connection
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -448,9 +454,14 @@ export const queueServiceFactory = (
|
|||||||
if (appCfg.QUEUE_WORKERS_ENABLED && isQueueEnabled(name)) {
|
if (appCfg.QUEUE_WORKERS_ENABLED && isQueueEnabled(name)) {
|
||||||
workerContainer[name] = new Worker(name, jobFn, {
|
workerContainer[name] = new Worker(name, jobFn, {
|
||||||
...queueSettings,
|
...queueSettings,
|
||||||
settings: {
|
...(crypto.isFipsModeEnabled()
|
||||||
repeatKeyHashAlgorithm: "sha256"
|
? {
|
||||||
},
|
settings: {
|
||||||
|
...queueSettings?.settings,
|
||||||
|
repeatKeyHashAlgorithm: "sha256"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
: {}),
|
||||||
connection
|
connection
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ import acme from "acme-client";
|
|||||||
import { TableName } from "@app/db/schemas";
|
import { TableName } from "@app/db/schemas";
|
||||||
import { CustomAWSHasher } from "@app/lib/aws/hashing";
|
import { CustomAWSHasher } from "@app/lib/aws/hashing";
|
||||||
import { crypto } from "@app/lib/crypto/cryptography";
|
import { crypto } from "@app/lib/crypto/cryptography";
|
||||||
import { BadRequestError, NotFoundError } from "@app/lib/errors";
|
import { BadRequestError, CryptographyError, NotFoundError } from "@app/lib/errors";
|
||||||
import { OrgServiceActor } from "@app/lib/types";
|
import { OrgServiceActor } from "@app/lib/types";
|
||||||
import { blockLocalAndPrivateIpAddresses } from "@app/lib/validator";
|
import { blockLocalAndPrivateIpAddresses } from "@app/lib/validator";
|
||||||
import { TAppConnectionDALFactory } from "@app/services/app-connection/app-connection-dal";
|
import { TAppConnectionDALFactory } from "@app/services/app-connection/app-connection-dal";
|
||||||
@@ -190,6 +190,12 @@ export const AcmeCertificateAuthorityFns = ({
|
|||||||
enableDirectIssuance: boolean;
|
enableDirectIssuance: boolean;
|
||||||
actor: OrgServiceActor;
|
actor: OrgServiceActor;
|
||||||
}) => {
|
}) => {
|
||||||
|
if (crypto.isFipsModeEnabled()) {
|
||||||
|
throw new CryptographyError({
|
||||||
|
message: "ACME is currently not supported in FIPS mode of operation."
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
const { dnsAppConnectionId, directoryUrl, accountEmail, dnsProviderConfig } = configuration;
|
const { dnsAppConnectionId, directoryUrl, accountEmail, dnsProviderConfig } = configuration;
|
||||||
const appConnection = await appConnectionDAL.findById(dnsAppConnectionId);
|
const appConnection = await appConnectionDAL.findById(dnsAppConnectionId);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user