diff --git a/backend/src/ee/routes/v1/ssh-host-router.ts b/backend/src/ee/routes/v1/ssh-host-router.ts index 63756a652..3ad5acfb6 100644 --- a/backend/src/ee/routes/v1/ssh-host-router.ts +++ b/backend/src/ee/routes/v1/ssh-host-router.ts @@ -460,4 +460,25 @@ export const registerSshHostRouter = async (server: FastifyZodProvider) => { return publicKey; } }); + + server.route({ + method: "GET", + url: "/:sshHostId/host-ca-public-key", + config: { + rateLimit: publicSshCaLimit + }, + schema: { + description: "Get public key of the host SSH CA linked to the host", + params: z.object({ + sshHostId: z.string().trim().describe(SSH_HOSTS.GET_USER_CA_PUBLIC_KEY.sshHostId) + }), + response: { + 200: z.string() + } + }, + handler: async (req) => { + const publicKey = await server.services.sshHost.getSshHostHostCaPk(req.params.sshHostId); + return publicKey; + } + }); }; diff --git a/backend/src/ee/services/ssh-host/ssh-host-service.ts b/backend/src/ee/services/ssh-host/ssh-host-service.ts index fb8d73da4..dd3e64b29 100644 --- a/backend/src/ee/services/ssh-host/ssh-host-service.ts +++ b/backend/src/ee/services/ssh-host/ssh-host-service.ts @@ -590,6 +590,30 @@ export const sshHostServiceFactory = ({ return publicKey; }; + const getSshHostHostCaPk = async (sshHostId: string) => { + const host = await sshHostDAL.findById(sshHostId); + if (!host) { + throw new NotFoundError({ + message: `SSH host with ID ${sshHostId} not found` + }); + } + + const sshCaSecret = await sshCertificateAuthoritySecretDAL.findOne({ sshCaId: host.hostSshCaId }); + + const { decryptor: secretManagerDecryptor } = await kmsService.createCipherPairWithDataKey({ + type: KmsDataKey.SecretManager, + projectId: host.projectId + }); + + const decryptedCaPrivateKey = secretManagerDecryptor({ + cipherTextBlob: sshCaSecret.encryptedPrivateKey + }); + + const publicKey = await getSshPublicKey(decryptedCaPrivateKey.toString("utf-8")); + + return publicKey; + }; + return { listSshHosts, createSshHost, @@ -598,6 +622,7 @@ export const sshHostServiceFactory = ({ getSshHost, issueSshHostUserCert, issueSshHostHostCert, - getSshHostUserCaPk + getSshHostUserCaPk, + getSshHostHostCaPk }; }; diff --git a/backend/src/lib/api-docs/constants.ts b/backend/src/lib/api-docs/constants.ts index 33b797d64..1746e58e0 100644 --- a/backend/src/lib/api-docs/constants.ts +++ b/backend/src/lib/api-docs/constants.ts @@ -1363,6 +1363,9 @@ export const SSH_HOSTS = { }, GET_USER_CA_PUBLIC_KEY: { sshHostId: "The ID of the SSH host to get the user SSH CA public key for." + }, + GET_HOST_CA_PUBLIC_KEY: { + sshHostId: "The ID of the SSH host to get the host SSH CA public key for." } };