feat(smtp-service): Custom CA Certs

This commit is contained in:
x032205
2025-05-23 03:19:45 -04:00
parent 424e4670e5
commit 65bc522ae9
2 changed files with 34 additions and 9 deletions
+15 -3
View File
@@ -69,6 +69,9 @@ const envSchema = z
SMTP_PASSWORD: zpStr(z.string().optional()), SMTP_PASSWORD: zpStr(z.string().optional()),
SMTP_FROM_ADDRESS: zpStr(z.string().optional()), SMTP_FROM_ADDRESS: zpStr(z.string().optional()),
SMTP_FROM_NAME: zpStr(z.string().optional().default("Infisical")), SMTP_FROM_NAME: zpStr(z.string().optional().default("Infisical")),
SMTP_CUSTOM_CA_CERT: zpStr(
z.string().optional().describe("PEM-encoded custom CA certificate(s) for the SMTP server")
),
COOKIE_SECRET_SIGN_KEY: z COOKIE_SECRET_SIGN_KEY: z
.string() .string()
.min(32) .min(32)
@@ -298,6 +301,17 @@ export const initEnvConfig = (logger?: CustomLogger) => {
}; };
export const formatSmtpConfig = () => { export const formatSmtpConfig = () => {
const tlsOptions: {
rejectUnauthorized: boolean;
ca?: string | string[];
} = {
rejectUnauthorized: envCfg.SMTP_TLS_REJECT_UNAUTHORIZED
};
if (envCfg.SMTP_CUSTOM_CA_CERT) {
tlsOptions.ca = envCfg.SMTP_CUSTOM_CA_CERT;
}
return { return {
host: envCfg.SMTP_HOST, host: envCfg.SMTP_HOST,
port: envCfg.SMTP_PORT, port: envCfg.SMTP_PORT,
@@ -309,8 +323,6 @@ export const formatSmtpConfig = () => {
from: `"${envCfg.SMTP_FROM_NAME}" <${envCfg.SMTP_FROM_ADDRESS}>`, from: `"${envCfg.SMTP_FROM_NAME}" <${envCfg.SMTP_FROM_ADDRESS}>`,
ignoreTLS: envCfg.SMTP_IGNORE_TLS, ignoreTLS: envCfg.SMTP_IGNORE_TLS,
requireTLS: envCfg.SMTP_REQUIRE_TLS, requireTLS: envCfg.SMTP_REQUIRE_TLS,
tls: { tls: tlsOptions
rejectUnauthorized: envCfg.SMTP_TLS_REJECT_UNAUTHORIZED
}
}; };
}; };
@@ -410,6 +410,19 @@ SSL: Available on ports 465, 8465, and 443
</Note> </Note>
</Accordion> </Accordion>
### Custom CA Certificate for Email Service TLS
If your SMTP server uses a certificate signed by a custom Certificate Authority, you need to tell Infisical to trust this custom CA. To do this, set the following environment variables:
```
SMTP_PORT=465 # Or your SMTPS/STARTTLS port
SMTP_CUSTOM_CA_CERT='[CERTIFICATE PEM]'
# Always keep these as true for custom CA
SMTP_REQUIRE_TLS=true
SMTP_TLS_REJECT_UNAUTHORIZED=true
```
## Authentication ## Authentication
By default, users can only login via email/password based login method. By default, users can only login via email/password based login method.