mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 23:27:14 +00:00
No need for allowEmptyCommonName flag, just allow empty CN for all
This commit is contained in:
+3
-17
@@ -1577,8 +1577,7 @@ export const internalCertificateAuthorityServiceFactory = ({
|
|||||||
keyUsages,
|
keyUsages,
|
||||||
extendedKeyUsages,
|
extendedKeyUsages,
|
||||||
signatureAlgorithm,
|
signatureAlgorithm,
|
||||||
keyAlgorithm,
|
keyAlgorithm
|
||||||
allowEmptyCommonName
|
|
||||||
} = dto;
|
} = dto;
|
||||||
|
|
||||||
let collectionId = pkiCollectionId;
|
let collectionId = pkiCollectionId;
|
||||||
@@ -1717,20 +1716,7 @@ export const internalCertificateAuthorityServiceFactory = ({
|
|||||||
const csrObj = new x509.Pkcs10CertificateRequest(csr);
|
const csrObj = new x509.Pkcs10CertificateRequest(csr);
|
||||||
|
|
||||||
const dn = parseDistinguishedName(csrObj.subject);
|
const dn = parseDistinguishedName(csrObj.subject);
|
||||||
let cn = commonName || dn.commonName;
|
const cn = (commonName || dn.commonName) ?? "";
|
||||||
|
|
||||||
if (!cn) {
|
|
||||||
if (allowEmptyCommonName ?? false) {
|
|
||||||
// Notice: for modern TLS certificates, the CN is deprecated, many ACME clients will generate CSRs with without a CN
|
|
||||||
// we allow empty CN here to support ACME clients mostly. Since it's unclear what's the side effect of
|
|
||||||
// allowing empty CN for legacy PKI code, let's only do it if a true allowEmptyCommonName value is provided.
|
|
||||||
cn = "";
|
|
||||||
} else {
|
|
||||||
throw new BadRequestError({
|
|
||||||
message: "A common name (CN) is required in the CSR or as a parameter to this endpoint"
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
const { caPrivateKey, caSecret } = await getCaCredentials({
|
const { caPrivateKey, caSecret } = await getCaCredentials({
|
||||||
caId: ca.id,
|
caId: ca.id,
|
||||||
@@ -1948,7 +1934,7 @@ export const internalCertificateAuthorityServiceFactory = ({
|
|||||||
certificateTemplateId: certificateTemplate?.id,
|
certificateTemplateId: certificateTemplate?.id,
|
||||||
status: CertStatus.ACTIVE,
|
status: CertStatus.ACTIVE,
|
||||||
friendlyName: friendlyName || csrObj.subject,
|
friendlyName: friendlyName || csrObj.subject,
|
||||||
commonName: cn!,
|
commonName: cn,
|
||||||
altNames: altNamesFromCsr || altNames,
|
altNames: altNamesFromCsr || altNames,
|
||||||
serialNumber,
|
serialNumber,
|
||||||
notBefore: notBeforeDate,
|
notBefore: notBeforeDate,
|
||||||
|
|||||||
-2
@@ -164,7 +164,6 @@ export type TSignCertFromCaDTO =
|
|||||||
keyAlgorithm?: string;
|
keyAlgorithm?: string;
|
||||||
isFromProfile?: boolean;
|
isFromProfile?: boolean;
|
||||||
profileId?: string;
|
profileId?: string;
|
||||||
allowEmptyCommonName?: boolean;
|
|
||||||
}
|
}
|
||||||
| ({
|
| ({
|
||||||
isInternal: false;
|
isInternal: false;
|
||||||
@@ -184,7 +183,6 @@ export type TSignCertFromCaDTO =
|
|||||||
keyAlgorithm?: string;
|
keyAlgorithm?: string;
|
||||||
isFromProfile?: boolean;
|
isFromProfile?: boolean;
|
||||||
profileId?: string;
|
profileId?: string;
|
||||||
allowEmptyCommonName?: boolean;
|
|
||||||
} & Omit<TProjectPermission, "projectId">);
|
} & Omit<TProjectPermission, "projectId">);
|
||||||
|
|
||||||
export type TGetCaCertificateTemplatesDTO = {
|
export type TGetCaCertificateTemplatesDTO = {
|
||||||
|
|||||||
@@ -511,8 +511,7 @@ export const certificateV3ServiceFactory = ({
|
|||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
actorOrgId,
|
actorOrgId,
|
||||||
enrollmentType,
|
enrollmentType,
|
||||||
removeRootsFromChain,
|
removeRootsFromChain
|
||||||
allowEmptyCommonName
|
|
||||||
}: TSignCertificateFromProfileDTO): Promise<Omit<TCertificateFromProfileResponse, "privateKey">> => {
|
}: TSignCertificateFromProfileDTO): Promise<Omit<TCertificateFromProfileResponse, "privateKey">> => {
|
||||||
const profile = await validateProfileAndPermissions(
|
const profile = await validateProfileAndPermissions(
|
||||||
profileId,
|
profileId,
|
||||||
@@ -583,8 +582,7 @@ export const certificateV3ServiceFactory = ({
|
|||||||
notAfter: normalizeDateForApi(notAfter),
|
notAfter: normalizeDateForApi(notAfter),
|
||||||
signatureAlgorithm: effectiveSignatureAlgorithm,
|
signatureAlgorithm: effectiveSignatureAlgorithm,
|
||||||
keyAlgorithm: effectiveKeyAlgorithm,
|
keyAlgorithm: effectiveKeyAlgorithm,
|
||||||
isFromProfile: true,
|
isFromProfile: true
|
||||||
allowEmptyCommonName
|
|
||||||
});
|
});
|
||||||
|
|
||||||
const cert = await certificateDAL.findOne({ serialNumber, caId: ca.id });
|
const cert = await certificateDAL.findOne({ serialNumber, caId: ca.id });
|
||||||
|
|||||||
@@ -39,7 +39,6 @@ export type TSignCertificateFromProfileDTO = {
|
|||||||
notAfter?: Date;
|
notAfter?: Date;
|
||||||
enrollmentType: EnrollmentType;
|
enrollmentType: EnrollmentType;
|
||||||
removeRootsFromChain?: boolean;
|
removeRootsFromChain?: boolean;
|
||||||
allowEmptyCommonName?: boolean;
|
|
||||||
} & Omit<TProjectPermission, "projectId">;
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
export type TOrderCertificateFromProfileDTO = {
|
export type TOrderCertificateFromProfileDTO = {
|
||||||
|
|||||||
Reference in New Issue
Block a user