Add ssh host host ca public key endpoint

This commit is contained in:
Tuan Dang
2025-04-08 18:54:08 -07:00
parent 20ebfcefaa
commit 5a114586dc
3 changed files with 50 additions and 1 deletions

View File

@@ -460,4 +460,25 @@ export const registerSshHostRouter = async (server: FastifyZodProvider) => {
return publicKey;
}
});
server.route({
method: "GET",
url: "/:sshHostId/host-ca-public-key",
config: {
rateLimit: publicSshCaLimit
},
schema: {
description: "Get public key of the host SSH CA linked to the host",
params: z.object({
sshHostId: z.string().trim().describe(SSH_HOSTS.GET_USER_CA_PUBLIC_KEY.sshHostId)
}),
response: {
200: z.string()
}
},
handler: async (req) => {
const publicKey = await server.services.sshHost.getSshHostHostCaPk(req.params.sshHostId);
return publicKey;
}
});
};

View File

@@ -590,6 +590,30 @@ export const sshHostServiceFactory = ({
return publicKey;
};
const getSshHostHostCaPk = async (sshHostId: string) => {
const host = await sshHostDAL.findById(sshHostId);
if (!host) {
throw new NotFoundError({
message: `SSH host with ID ${sshHostId} not found`
});
}
const sshCaSecret = await sshCertificateAuthoritySecretDAL.findOne({ sshCaId: host.hostSshCaId });
const { decryptor: secretManagerDecryptor } = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.SecretManager,
projectId: host.projectId
});
const decryptedCaPrivateKey = secretManagerDecryptor({
cipherTextBlob: sshCaSecret.encryptedPrivateKey
});
const publicKey = await getSshPublicKey(decryptedCaPrivateKey.toString("utf-8"));
return publicKey;
};
return {
listSshHosts,
createSshHost,
@@ -598,6 +622,7 @@ export const sshHostServiceFactory = ({
getSshHost,
issueSshHostUserCert,
issueSshHostHostCert,
getSshHostUserCaPk
getSshHostUserCaPk,
getSshHostHostCaPk
};
};

View File

@@ -1363,6 +1363,9 @@ export const SSH_HOSTS = {
},
GET_USER_CA_PUBLIC_KEY: {
sshHostId: "The ID of the SSH host to get the user SSH CA public key for."
},
GET_HOST_CA_PUBLIC_KEY: {
sshHostId: "The ID of the SSH host to get the host SSH CA public key for."
}
};