mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 19:28:09 +00:00
Update/remove comments
This commit is contained in:
@@ -389,8 +389,6 @@ export const certificateAuthorityServiceFactory = ({
|
|||||||
/**
|
/**
|
||||||
* Renew certificate for CA with id [caId]
|
* Renew certificate for CA with id [caId]
|
||||||
* Note: Currently implements CA renewal with same key-pair only
|
* Note: Currently implements CA renewal with same key-pair only
|
||||||
*
|
|
||||||
* TODO: check rebuilt chain?
|
|
||||||
*/
|
*/
|
||||||
const renewCaCert = async ({ caId, notAfter, actorId, actorAuthMethod, actor, actorOrgId }: TRenewCaCertDTO) => {
|
const renewCaCert = async ({ caId, notAfter, actorId, actorAuthMethod, actor, actorOrgId }: TRenewCaCertDTO) => {
|
||||||
const ca = await certificateAuthorityDAL.findById(caId);
|
const ca = await certificateAuthorityDAL.findById(caId);
|
||||||
@@ -950,7 +948,8 @@ export const certificateAuthorityServiceFactory = ({
|
|||||||
plainText: Buffer.from(certificateChain)
|
plainText: Buffer.from(certificateChain)
|
||||||
});
|
});
|
||||||
|
|
||||||
// TODO: validate that >latest< public-private key of CA is used to sign the certificate
|
// TODO: validate that latest key-pair of CA is used to sign the certificate
|
||||||
|
// once renewal with new key pair is supported
|
||||||
const { caSecret, caPublicKey } = await getCaCredentials({
|
const { caSecret, caPublicKey } = await getCaCredentials({
|
||||||
caId: ca.id,
|
caId: ca.id,
|
||||||
certificateAuthorityDAL,
|
certificateAuthorityDAL,
|
||||||
|
|||||||
Reference in New Issue
Block a user