cert chain tweaks

This commit is contained in:
x
2025-04-30 16:26:31 -04:00
parent 7f836ed9bc
commit 6a973be6f3
3 changed files with 27 additions and 24 deletions
@@ -484,13 +484,13 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
response: {
200: z.object({
certificate: z.string().trim().describe(CERTIFICATES.GET_CERT.certificate),
certificateChain: z.string().trim().describe(CERTIFICATES.GET_CERT.certificateChain),
certificateChain: z.string().trim().nullable().describe(CERTIFICATES.GET_CERT.certificateChain),
serialNumber: z.string().trim().describe(CERTIFICATES.GET_CERT.serialNumberRes)
})
}
},
handler: async (req) => {
const { certificate, certificateChain, serialNumber, cert, ca } = await server.services.certificate.getCertBody({
const { certificate, certificateChain, serialNumber, cert } = await server.services.certificate.getCertBody({
serialNumber: req.params.serialNumber,
actor: req.permission.type,
actorId: req.permission.id,
@@ -500,7 +500,7 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
await server.services.auditLog.createAuditLog({
...req.auditLogInfo,
projectId: ca.projectId,
projectId: cert.projectId,
event: {
type: EventType.DELETE_CERT,
metadata: {
@@ -1388,7 +1388,8 @@ export const certificateAuthorityServiceFactory = ({
notBefore: notBeforeDate,
notAfter: notAfterDate,
keyUsages: selectedKeyUsages,
extendedKeyUsages: selectedExtendedKeyUsages
extendedKeyUsages: selectedExtendedKeyUsages,
projectId: ca.projectId
},
tx
);
@@ -1422,6 +1423,7 @@ export const certificateAuthorityServiceFactory = ({
kmsService
});
// TODO(andrey): Might need tweaks after other PR merge
return {
certificate: leafCert.toString("pem"),
certificateChain: `${issuingCaCertificate}\n${caCertChain}`.trim(),
@@ -1779,7 +1781,8 @@ export const certificateAuthorityServiceFactory = ({
notBefore: notBeforeDate,
notAfter: notAfterDate,
keyUsages: selectedKeyUsages,
extendedKeyUsages: selectedExtendedKeyUsages
extendedKeyUsages: selectedExtendedKeyUsages,
projectId: ca.projectId
},
tx
);
@@ -1813,6 +1816,7 @@ export const certificateAuthorityServiceFactory = ({
kmsService
});
// TODO(andrey): Might need tweaks after other PR merge
return {
certificate: leafCert,
certificateChain: `${issuingCaCertificate}\n${caCertChain}`.trim(),
@@ -174,17 +174,10 @@ export const certificateServiceFactory = ({
const getCertBody = async ({ serialNumber, actorId, actorAuthMethod, actor, actorOrgId }: TGetCertBodyDTO) => {
const cert = await certificateDAL.findOne({ serialNumber });
// TODO(andrey): Remove this later.
if (!cert.caId || !cert.caCertId) {
throw new Error("ERROR");
}
const ca = await certificateAuthorityDAL.findById(cert.caId);
const { permission } = await permissionService.getProjectPermission({
actor,
actorId,
projectId: ca.projectId,
projectId: cert.projectId,
actorAuthMethod,
actorOrgId,
actionProjectType: ActionProjectType.CertificateManager
@@ -195,7 +188,7 @@ export const certificateServiceFactory = ({
const certBody = await certificateBodyDAL.findOne({ certId: cert.id });
const certificateManagerKeyId = await getProjectKmsCertificateKeyId({
projectId: ca.projectId,
projectId: cert.projectId,
projectDAL,
kmsService
});
@@ -209,6 +202,10 @@ export const certificateServiceFactory = ({
const certObj = new x509.X509Certificate(decryptedCert);
let certificateChain = null;
// TODO(andrey): Update this after the "store cert chain on cert body" PR gets merged
if (cert.caCertId) {
const { caCert, caCertChain } = await getCaCertChain({
caCertId: cert.caCertId,
certificateAuthorityDAL,
@@ -217,12 +214,14 @@ export const certificateServiceFactory = ({
kmsService
});
certificateChain = `${caCert}\n${caCertChain}`.trim();
}
return {
certificate: certObj.toString("pem"),
certificateChain: `${caCert}\n${caCertChain}`.trim(),
certificateChain,
serialNumber: certObj.serialNumber,
cert,
ca
cert
};
};