No need for allowEmptyCommonName flag, just allow empty CN for all

This commit is contained in:
Fang-Pen Lin
2025-11-21 10:33:36 -08:00
parent 2b19425cc7
commit 810c06c6d7
4 changed files with 5 additions and 24 deletions
@@ -1577,8 +1577,7 @@ export const internalCertificateAuthorityServiceFactory = ({
keyUsages, keyUsages,
extendedKeyUsages, extendedKeyUsages,
signatureAlgorithm, signatureAlgorithm,
keyAlgorithm, keyAlgorithm
allowEmptyCommonName
} = dto; } = dto;
let collectionId = pkiCollectionId; let collectionId = pkiCollectionId;
@@ -1717,20 +1716,7 @@ export const internalCertificateAuthorityServiceFactory = ({
const csrObj = new x509.Pkcs10CertificateRequest(csr); const csrObj = new x509.Pkcs10CertificateRequest(csr);
const dn = parseDistinguishedName(csrObj.subject); const dn = parseDistinguishedName(csrObj.subject);
let cn = commonName || dn.commonName; const cn = (commonName || dn.commonName) ?? "";
if (!cn) {
if (allowEmptyCommonName ?? false) {
// Notice: for modern TLS certificates, the CN is deprecated, many ACME clients will generate CSRs with without a CN
// we allow empty CN here to support ACME clients mostly. Since it's unclear what's the side effect of
// allowing empty CN for legacy PKI code, let's only do it if a true allowEmptyCommonName value is provided.
cn = "";
} else {
throw new BadRequestError({
message: "A common name (CN) is required in the CSR or as a parameter to this endpoint"
});
}
}
const { caPrivateKey, caSecret } = await getCaCredentials({ const { caPrivateKey, caSecret } = await getCaCredentials({
caId: ca.id, caId: ca.id,
@@ -1948,7 +1934,7 @@ export const internalCertificateAuthorityServiceFactory = ({
certificateTemplateId: certificateTemplate?.id, certificateTemplateId: certificateTemplate?.id,
status: CertStatus.ACTIVE, status: CertStatus.ACTIVE,
friendlyName: friendlyName || csrObj.subject, friendlyName: friendlyName || csrObj.subject,
commonName: cn!, commonName: cn,
altNames: altNamesFromCsr || altNames, altNames: altNamesFromCsr || altNames,
serialNumber, serialNumber,
notBefore: notBeforeDate, notBefore: notBeforeDate,
@@ -164,7 +164,6 @@ export type TSignCertFromCaDTO =
keyAlgorithm?: string; keyAlgorithm?: string;
isFromProfile?: boolean; isFromProfile?: boolean;
profileId?: string; profileId?: string;
allowEmptyCommonName?: boolean;
} }
| ({ | ({
isInternal: false; isInternal: false;
@@ -184,7 +183,6 @@ export type TSignCertFromCaDTO =
keyAlgorithm?: string; keyAlgorithm?: string;
isFromProfile?: boolean; isFromProfile?: boolean;
profileId?: string; profileId?: string;
allowEmptyCommonName?: boolean;
} & Omit<TProjectPermission, "projectId">); } & Omit<TProjectPermission, "projectId">);
export type TGetCaCertificateTemplatesDTO = { export type TGetCaCertificateTemplatesDTO = {
@@ -511,8 +511,7 @@ export const certificateV3ServiceFactory = ({
actorAuthMethod, actorAuthMethod,
actorOrgId, actorOrgId,
enrollmentType, enrollmentType,
removeRootsFromChain, removeRootsFromChain
allowEmptyCommonName
}: TSignCertificateFromProfileDTO): Promise<Omit<TCertificateFromProfileResponse, "privateKey">> => { }: TSignCertificateFromProfileDTO): Promise<Omit<TCertificateFromProfileResponse, "privateKey">> => {
const profile = await validateProfileAndPermissions( const profile = await validateProfileAndPermissions(
profileId, profileId,
@@ -583,8 +582,7 @@ export const certificateV3ServiceFactory = ({
notAfter: normalizeDateForApi(notAfter), notAfter: normalizeDateForApi(notAfter),
signatureAlgorithm: effectiveSignatureAlgorithm, signatureAlgorithm: effectiveSignatureAlgorithm,
keyAlgorithm: effectiveKeyAlgorithm, keyAlgorithm: effectiveKeyAlgorithm,
isFromProfile: true, isFromProfile: true
allowEmptyCommonName
}); });
const cert = await certificateDAL.findOne({ serialNumber, caId: ca.id }); const cert = await certificateDAL.findOne({ serialNumber, caId: ca.id });
@@ -39,7 +39,6 @@ export type TSignCertificateFromProfileDTO = {
notAfter?: Date; notAfter?: Date;
enrollmentType: EnrollmentType; enrollmentType: EnrollmentType;
removeRootsFromChain?: boolean; removeRootsFromChain?: boolean;
allowEmptyCommonName?: boolean;
} & Omit<TProjectPermission, "projectId">; } & Omit<TProjectPermission, "projectId">;
export type TOrderCertificateFromProfileDTO = { export type TOrderCertificateFromProfileDTO = {