mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 11:29:21 +00:00
cert chain tweaks
This commit is contained in:
@@ -484,13 +484,13 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
|
|||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
certificate: z.string().trim().describe(CERTIFICATES.GET_CERT.certificate),
|
certificate: z.string().trim().describe(CERTIFICATES.GET_CERT.certificate),
|
||||||
certificateChain: z.string().trim().describe(CERTIFICATES.GET_CERT.certificateChain),
|
certificateChain: z.string().trim().nullable().describe(CERTIFICATES.GET_CERT.certificateChain),
|
||||||
serialNumber: z.string().trim().describe(CERTIFICATES.GET_CERT.serialNumberRes)
|
serialNumber: z.string().trim().describe(CERTIFICATES.GET_CERT.serialNumberRes)
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const { certificate, certificateChain, serialNumber, cert, ca } = await server.services.certificate.getCertBody({
|
const { certificate, certificateChain, serialNumber, cert } = await server.services.certificate.getCertBody({
|
||||||
serialNumber: req.params.serialNumber,
|
serialNumber: req.params.serialNumber,
|
||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
@@ -500,7 +500,7 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
|
|||||||
|
|
||||||
await server.services.auditLog.createAuditLog({
|
await server.services.auditLog.createAuditLog({
|
||||||
...req.auditLogInfo,
|
...req.auditLogInfo,
|
||||||
projectId: ca.projectId,
|
projectId: cert.projectId,
|
||||||
event: {
|
event: {
|
||||||
type: EventType.DELETE_CERT,
|
type: EventType.DELETE_CERT,
|
||||||
metadata: {
|
metadata: {
|
||||||
|
|||||||
@@ -1388,7 +1388,8 @@ export const certificateAuthorityServiceFactory = ({
|
|||||||
notBefore: notBeforeDate,
|
notBefore: notBeforeDate,
|
||||||
notAfter: notAfterDate,
|
notAfter: notAfterDate,
|
||||||
keyUsages: selectedKeyUsages,
|
keyUsages: selectedKeyUsages,
|
||||||
extendedKeyUsages: selectedExtendedKeyUsages
|
extendedKeyUsages: selectedExtendedKeyUsages,
|
||||||
|
projectId: ca.projectId
|
||||||
},
|
},
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
@@ -1422,6 +1423,7 @@ export const certificateAuthorityServiceFactory = ({
|
|||||||
kmsService
|
kmsService
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// TODO(andrey): Might need tweaks after other PR merge
|
||||||
return {
|
return {
|
||||||
certificate: leafCert.toString("pem"),
|
certificate: leafCert.toString("pem"),
|
||||||
certificateChain: `${issuingCaCertificate}\n${caCertChain}`.trim(),
|
certificateChain: `${issuingCaCertificate}\n${caCertChain}`.trim(),
|
||||||
@@ -1779,7 +1781,8 @@ export const certificateAuthorityServiceFactory = ({
|
|||||||
notBefore: notBeforeDate,
|
notBefore: notBeforeDate,
|
||||||
notAfter: notAfterDate,
|
notAfter: notAfterDate,
|
||||||
keyUsages: selectedKeyUsages,
|
keyUsages: selectedKeyUsages,
|
||||||
extendedKeyUsages: selectedExtendedKeyUsages
|
extendedKeyUsages: selectedExtendedKeyUsages,
|
||||||
|
projectId: ca.projectId
|
||||||
},
|
},
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
@@ -1813,6 +1816,7 @@ export const certificateAuthorityServiceFactory = ({
|
|||||||
kmsService
|
kmsService
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// TODO(andrey): Might need tweaks after other PR merge
|
||||||
return {
|
return {
|
||||||
certificate: leafCert,
|
certificate: leafCert,
|
||||||
certificateChain: `${issuingCaCertificate}\n${caCertChain}`.trim(),
|
certificateChain: `${issuingCaCertificate}\n${caCertChain}`.trim(),
|
||||||
|
|||||||
@@ -174,17 +174,10 @@ export const certificateServiceFactory = ({
|
|||||||
const getCertBody = async ({ serialNumber, actorId, actorAuthMethod, actor, actorOrgId }: TGetCertBodyDTO) => {
|
const getCertBody = async ({ serialNumber, actorId, actorAuthMethod, actor, actorOrgId }: TGetCertBodyDTO) => {
|
||||||
const cert = await certificateDAL.findOne({ serialNumber });
|
const cert = await certificateDAL.findOne({ serialNumber });
|
||||||
|
|
||||||
// TODO(andrey): Remove this later.
|
|
||||||
if (!cert.caId || !cert.caCertId) {
|
|
||||||
throw new Error("ERROR");
|
|
||||||
}
|
|
||||||
|
|
||||||
const ca = await certificateAuthorityDAL.findById(cert.caId);
|
|
||||||
|
|
||||||
const { permission } = await permissionService.getProjectPermission({
|
const { permission } = await permissionService.getProjectPermission({
|
||||||
actor,
|
actor,
|
||||||
actorId,
|
actorId,
|
||||||
projectId: ca.projectId,
|
projectId: cert.projectId,
|
||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
actorOrgId,
|
actorOrgId,
|
||||||
actionProjectType: ActionProjectType.CertificateManager
|
actionProjectType: ActionProjectType.CertificateManager
|
||||||
@@ -195,7 +188,7 @@ export const certificateServiceFactory = ({
|
|||||||
const certBody = await certificateBodyDAL.findOne({ certId: cert.id });
|
const certBody = await certificateBodyDAL.findOne({ certId: cert.id });
|
||||||
|
|
||||||
const certificateManagerKeyId = await getProjectKmsCertificateKeyId({
|
const certificateManagerKeyId = await getProjectKmsCertificateKeyId({
|
||||||
projectId: ca.projectId,
|
projectId: cert.projectId,
|
||||||
projectDAL,
|
projectDAL,
|
||||||
kmsService
|
kmsService
|
||||||
});
|
});
|
||||||
@@ -209,6 +202,10 @@ export const certificateServiceFactory = ({
|
|||||||
|
|
||||||
const certObj = new x509.X509Certificate(decryptedCert);
|
const certObj = new x509.X509Certificate(decryptedCert);
|
||||||
|
|
||||||
|
let certificateChain = null;
|
||||||
|
|
||||||
|
// TODO(andrey): Update this after the "store cert chain on cert body" PR gets merged
|
||||||
|
if (cert.caCertId) {
|
||||||
const { caCert, caCertChain } = await getCaCertChain({
|
const { caCert, caCertChain } = await getCaCertChain({
|
||||||
caCertId: cert.caCertId,
|
caCertId: cert.caCertId,
|
||||||
certificateAuthorityDAL,
|
certificateAuthorityDAL,
|
||||||
@@ -217,12 +214,14 @@ export const certificateServiceFactory = ({
|
|||||||
kmsService
|
kmsService
|
||||||
});
|
});
|
||||||
|
|
||||||
|
certificateChain = `${caCert}\n${caCertChain}`.trim();
|
||||||
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
certificate: certObj.toString("pem"),
|
certificate: certObj.toString("pem"),
|
||||||
certificateChain: `${caCert}\n${caCertChain}`.trim(),
|
certificateChain,
|
||||||
serialNumber: certObj.serialNumber,
|
serialNumber: certObj.serialNumber,
|
||||||
cert,
|
cert
|
||||||
ca
|
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user