This commit is contained in:
Fang-Pen Lin
2025-11-13 09:22:13 -08:00
parent 3a3a6f3152
commit 58963b8185
3 changed files with 31 additions and 36 deletions
@@ -687,7 +687,7 @@ export const pkiAcmeServiceFactory = ({
const csrIdentifierValues = new Set( const csrIdentifierValues = new Set(
(certificateRequest.subjectAlternativeNames ?? []) (certificateRequest.subjectAlternativeNames ?? [])
.map((san) => san.value.toLowerCase()) .map((san) => san.value.toLowerCase())
.concat([certificateRequest.commonName!.toLowerCase()]) .concat([certificateRequest.commonName.toLowerCase()])
); );
if ( if (
csrIdentifierValues.size !== orderWithAuthorizations.authorizations.length || csrIdentifierValues.size !== orderWithAuthorizations.authorizations.length ||
@@ -727,7 +727,7 @@ export const pkiAcmeServiceFactory = ({
enrollmentType: EnrollmentType.ACME enrollmentType: EnrollmentType.ACME
}); });
return { certificateId: result.certificateId }; return { certificateId: result.certificateId };
} else { }
const { certificateAuthority } = (await certificateProfileDAL.findByIdWithConfigs(profileId, tx))!; const { certificateAuthority } = (await certificateProfileDAL.findByIdWithConfigs(profileId, tx))!;
// TODO: for internal CA, we rely on the internal certificate authority service to check CSR against the template // TODO: for internal CA, we rely on the internal certificate authority service to check CSR against the template
// we should check the CSR against the template here // we should check the CSR against the template here
@@ -739,11 +739,7 @@ export const pkiAcmeServiceFactory = ({
commonName: certificateRequest.commonName!, commonName: certificateRequest.commonName!,
altNames: certificateRequest.subjectAlternativeNames?.map((san) => san.value), altNames: certificateRequest.subjectAlternativeNames?.map((san) => san.value),
// TODO: not 100% sure what are these columns for, but let's put the values for common website SSL certs for now // TODO: not 100% sure what are these columns for, but let's put the values for common website SSL certs for now
keyUsages: [ keyUsages: [CertKeyUsage.DIGITAL_SIGNATURE, CertKeyUsage.KEY_ENCIPHERMENT, CertKeyUsage.KEY_AGREEMENT],
CertKeyUsage.DIGITAL_SIGNATURE,
CertKeyUsage.KEY_ENCIPHERMENT,
CertKeyUsage.KEY_AGREEMENT
],
extendedKeyUsages: [CertExtendedKeyUsage.SERVER_AUTH] extendedKeyUsages: [CertExtendedKeyUsage.SERVER_AUTH]
}, },
{ {
@@ -758,7 +754,6 @@ export const pkiAcmeServiceFactory = ({
} }
); );
return { certificateId: cert.id }; return { certificateId: cert.id };
}
})(); })();
await acmeOrderDAL.updateById( await acmeOrderDAL.updateById(
orderId, orderId,
@@ -61,7 +61,7 @@ export const registerBddNockRouter = async (server: FastifyZodProvider) => {
} }
}, },
onRequest: verifyAuth([AuthMode.JWT]), onRequest: verifyAuth([AuthMode.JWT]),
handler: async (req) => { handler: async () => {
checkIfBddNockApiEnabled(); checkIfBddNockApiEnabled();
logger.info("Cleaning all nocks"); logger.info("Cleaning all nocks");
nock.cleanAll(); nock.cleanAll();
@@ -78,7 +78,7 @@ export const registerBddNockRouter = async (server: FastifyZodProvider) => {
} }
}, },
onRequest: verifyAuth([AuthMode.JWT]), onRequest: verifyAuth([AuthMode.JWT]),
handler: async (req) => { handler: async () => {
checkIfBddNockApiEnabled(); checkIfBddNockApiEnabled();
logger.info("Restore network requests from nock"); logger.info("Restore network requests from nock");
nock.restore(); nock.restore();
@@ -337,8 +337,8 @@ export const orderCertificate = async (
serialNumber: certObj.serialNumber, serialNumber: certObj.serialNumber,
notBefore: certObj.notBefore, notBefore: certObj.notBefore,
notAfter: certObj.notAfter, notAfter: certObj.notAfter,
keyUsages: keyUsages, keyUsages,
extendedKeyUsages: extendedKeyUsages, extendedKeyUsages,
projectId: ca.projectId projectId: ca.projectId
}, },
innerTx innerTx